Data Processing Agreement (AVV, Art. 28 GDPR)
This is a convenience translation. Only the German version is legally binding.
Agreement on the processing of personal data on behalf of the controller pursuant to Art. 28 DSGVO/GDPR for the “EUTHENIA” platform. Version: October 2026 (version 2026-10.1). It is accepted upon registration; the version and the time of acceptance are recorded.
between the Customer (the company that has registered with EUTHENIA; hereinafter “Controller”) and EPATRONIC Systems GmbH, Altrottstr. 31, 69190 Walldorf, represented by its Managing Director (Geschäftsführer) Damian Hillebrand (hereinafter “Processor”).
§ 1 Subject matter and duration
(1) The Processor provides the Controller with the “EUTHENIA” platform as software-as-a-service (contract of use under the General Terms and Conditions (AGB), hereinafter “Main Contract”) and, in doing so, processes personal data on behalf of and on the instructions of the Controller.
(2) This agreement applies for the term of the Main Contract, including the free trial period.
§ 2 Nature, purpose, data and data subjects
The nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
§ 3 Instructions
(1) The Processor processes data only on documented instructions from the Controller, including with regard to transfers to a third country, unless it is required to do so by Union or Member State law; in such a case, it informs the Controller in advance, insofar as legally permissible.
(2) Instructions are given through the use of the functions and settings of the platform and in text form (Textform) to the contact persons named in Annex 4.
(3) If the Processor considers an instruction to infringe data protection law, it informs the Controller without undue delay and may suspend its execution until it is confirmed.
§ 4 Obligations of the Processor
- Confidentiality: It only uses persons who have committed themselves to confidentiality.
- Security: It takes the measures set out in Annex 2 (Art. 32 GDPR) and develops them further; a material reduction is not permitted.
- Logging: The platform logs logins and important changes (time, user, action, object concerned).
- Assistance: It assists the Controller with requests from data subjects (Art. 15–22 GDPR), the data protection impact assessment and consultations with the supervisory authority (Art. 32–36 GDPR). Any resulting effort is governed by the Main Contract.
- Breaches: It notifies personal data breaches without undue delay, at the latest within 48 hours of becoming aware of them, with the available information on their nature, scope, consequences and measures taken (Art. 33, 34 GDPR).
- Records: It maintains a record of processing activities pursuant to Art. 30(2) GDPR.
- No automated decisions: Evaluations, calculations and planning suggestions of the platform do not make decisions producing legal effects (Art. 22 GDPR); the Controller reviews and adopts results itself.
§ 5 Sub-processors
(1) The Controller grants general authorisation for the use of the sub-processors listed in Annex 3.
(2) The Processor gives notice in text form at least 30 days before engaging or replacing a sub-processor. The Controller may object within 14 days for good cause under data protection law; if no agreement is reached, both parties have a special right of termination with effect from the end of the billing period.
(3) The Processor contractually binds sub-processors to the same data protection obligations and is liable for them pursuant to Art. 28(4) GDPR.
§ 6 Transfers to third countries
Data is only transferred to third countries if the requirements of Art. 44 et seqq. GDPR are met (adequacy decision, in particular the EU-US Data Privacy Framework, or standard contractual clauses). Annex 3 states the location and legal basis.
§ 7 Audit rights and evidence
(1) On request, the Processor provides the information necessary to demonstrate compliance (in particular a description of the measures, reports on backup and recovery, and third-party audit reports once available).
(2) The Controller may carry out audits itself or through an auditor bound to confidentiality. Audits must be announced 14 days in advance and carried out during normal business hours without disrupting operations; evidence under paragraph 1 takes precedence.
§ 8 Return and deletion
(1) After the end of the processing, the Processor deletes or returns all personal data, at the Controller’s choice, unless there is a statutory obligation to retain it.
(2) The Controller may export its data itself before the end of the contract (data export in system administration); the Processor provides documents and the complete data set on request within 10 working days.
(3) Deletion takes place within 30 days of the end of the contract; backups are overwritten in the regular rotation (after 6 months at the latest). Log entries contain no content (only time, user, action, object identifier).
§ 9 Liability and final provisions
(1) Art. 82 GDPR applies; as between the parties, the liability provisions of the Main Contract apply.
(2) Amendments require text form (Textform). In the event of conflicts, this agreement takes precedence over the Main Contract insofar as data protection is concerned. If a provision is invalid, the remainder of the agreement remains valid. German law applies; the place of jurisdiction, where permissible, is Mannheim.
(3) If the content of the agreement is amended, the Processor communicates the new version in text form; earlier acceptances remain stored as evidence.
Annex 1 – Description of the processing
- Subject matter/purpose: Provision of the platform: business software (ERP) with customer, supplier and item management, quotations, orders, invoices and e-invoices, point of sale (till), customer service, sales and marketing (CRM), projects, human resources management, production, logistics, document storage and evaluations.
- Nature: Storage, organisation, retrieval, use, transmission within the scope of the functions (e.g. sending documents by email at the user’s instigation), erasure.
- Types of data: Master and contact data, contract, document and payment data (e.g. bank details), communication and appointment data, documents, personnel data (e.g. master data, working hours, absences, salary data), usage and log data (email, IP address, time, action).
- Data subjects: Employees of the Controller, customers, prospective customers, suppliers and their contact persons, job applicants.
- Special categories (Art. 9 GDPR): not intended; they can only be contained in personnel data recorded by the Controller or in stored documents. The Controller ensures the legal basis.
Annex 2 – Technical and organisational measures
The measures are described under Security & data protection and form part of this agreement in their respective current version.
Annex 3 – Sub-processors
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (Germany): hosting of the platform, database and document storage in the Nuremberg data centre; data processing agreement pursuant to Art. 28 GDPR.
- STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin (Germany): sending of the platform’s emails and storage target (HiDrive) for off-site backups that are already encrypted before transfer; the key is not held by the provider; data processing agreement pursuant to Art. 28 GDPR (version 3.6, concluded on 12.05.2026); data processing in the EU.
- Optional, only if connected by the user: Microsoft Ireland Operations Ltd. (Microsoft Teams in the call centre) for the respective connected account.
Annex 4 – Contact persons
Processor: Damian Hillebrand, Managing Director (Geschäftsführer), [email protected]. Controller: the person stated upon registration (the company’s administrator).