Skip to main content
Legal

Data Processing Agreement

DRAFT — pending operator legal review. This text has not been approved by the site operator and may change before publication.

The binding Data Processing Agreement has not been published. A signed DPA must be in place before production personal data is processed. This page shows the structure of the agreement; every clause marked [[ to be supplied: … ]] is being drafted and reviewed by counsel. For the current early-access document, contact hello@itsmx.eu.

1. Parties

Processor:

[[ to be supplied: legal entity name ]]
[[ to be supplied: postal address ]]
Commercial register: [[ to be supplied: commercial register entry, or confirmation that none applies ]]
VAT ID: [[ to be supplied: VAT ID, or confirmation that none applies ]]
E-mail: hello@itsmx.eu

Controller: the customer. [[ to be supplied: how the controller is identified in the contract ]]

2. Subject matter and duration

[[ to be supplied: counsel-reviewed clause — subject matter; duration tied to the service agreement ]]

3. Nature and purpose of processing

[[ to be supplied: counsel-reviewed clause — nature and purpose of processing in TENSOR ]]

4. Types of personal data and categories of data subjects

[[ to be supplied: counsel-reviewed clause — data types and data subject categories ]]

5. Obligations and rights of the controller

[[ to be supplied: counsel-reviewed clause — controller obligations and rights ]]

6. Processing only on documented instructions (Art. 28(3)(a) GDPR)

[[ to be supplied: counsel-reviewed clause — processing only on documented instructions ]]

7. Confidentiality of authorised personnel (Art. 28(3)(b) GDPR)

[[ to be supplied: counsel-reviewed clause — confidentiality of authorised personnel ]]

8. Security of processing (Art. 32) — technical and organisational measures (Art. 28(3)(c) GDPR)

[[ to be supplied: counsel-reviewed clause — security of processing (art. 32) — technical and organisational measures ]]

9. Engaging sub-processors (Art. 28(3)(d) GDPR)

The current list of sub-processors is published on the sub-processor page.

[[ to be supplied: counsel-reviewed clause — engaging sub-processors ]]

10. Assistance with data subject requests (Art. 28(3)(e) GDPR)

[[ to be supplied: counsel-reviewed clause — assistance with data subject requests ]]

11. Assistance with Arts. 32–36 (security, breach notification, DPIA) (Art. 28(3)(f) GDPR)

[[ to be supplied: counsel-reviewed clause — assistance with arts. 32–36 (security, breach notification, dpia) ]]

12. Deletion or return of data at the end of the service (Art. 28(3)(g) GDPR)

[[ to be supplied: counsel-reviewed clause — deletion or return of data at the end of the service ]]

13. Information and audits (Art. 28(3)(h) GDPR)

[[ to be supplied: counsel-reviewed clause — information and audits ]]