Agreement for order processing for SaaS services (DPA)
Preamble
The customer has commissioned branchly GmbH, Am Kartoffelgarten 14, 81671 Munich ("branchly") with the SaaS operation of an AI content navigation system. In the performance of the contract, branchly receives access to personal data of the customer. Art. 28 of the General Data Protection Regulation (GDPR) sets specific requirements for such a data processing agreement. To comply with these requirements, the parties conclude this Agreement.
1. Subject Matter of the Agreement, Scope of the Order
1.1 branchly provides the SaaS services based on the customer's commissioning in accordance with branchly's offer and the Terms and Conditions for SaaS Services ("Main Contract").
1.2 To specify the rights and obligations under data protection law, the parties enter into this Data Processing Agreement. The subject matter and duration of the service provision by branchly are governed by the Main Contract. In case of doubt, the provisions of this Agreement take precedence over the provisions of the Main Contract.
2. Scope, Purpose, and Execution of Data Processing; Types of Data and Categories of Data Subjects; Bound by Instructions
2.1 The scope and purpose of the data processing by branchly arise from the Main Contract and the associated service description.
2.2 In the context of service provision, branchly potentially has access to data stored on the SaaS platform. This includes the following types of data:
– "Search queries of the customer; in rare cases, these may also contain personal information (e.g. email address, phone number of the customer)".
– IP addresses of end users (used only temporarily and for technical reasons to provide the service)
– Browser language and device type.
2.3 branchly may process personal data of the customer exclusively for the purposes of fulfilling the Main Contract on behalf of the customer or based on individual instructions from the customer. If branchly processes data due to a legal obligation within the meaning of Art. 28 (3) (a) GDPR, branchly will inform the customer prior to processing, unless this is legally prohibited.
2.4 branchly must observe and implement individual instructions from the customer regarding the collection, processing, or use of data. The customer is entitled to issue corresponding instructions at any time. This also includes instructions regarding the rectification, deletion, and blocking/restriction of data. If branchly is of the opinion that an instruction of the customer violates data protection provisions, it will notify the customer. The reasonable costs of executing instructions that go beyond the contractual services of the Main Contract will be reimbursed by the customer in accordance with branchly's applicable hourly rates.
3. Subcontracting Relationships
3.1 branchly is entitled to engage further processors ("subprocessors"). Currently, branchly engages the following subprocessors .
Contractual agreements with subprocessors are structured by branchly to ensure they comply with the provisions of the GDPR.
3.2. branchly informs the customer of any intended changes regarding the addition or replacement of other subprocessors, thereby giving the customer the opportunity to object to such changes. If the customer has justified objections to the use of such a new subprocessor on the grounds that the use does not comply with the requirements of the GDPR, the customer is entitled to object to the use of the subprocessor to branchly within 14 days of receiving the notification of change. If branchly subsequently declares to the customer, despite a justified objection, that it will not refrain from using the subprocessor, the customer is entitled to terminate the Main Contract in writing with four weeks' notice.
3.3 Subcontracting relationships within the meaning of this provision are understood as services that relate directly to the provision of the principal service. In particular, this does not include ancillary services that branchly uses, e.g. as telecommunications services, postal/transport services, maintenance and user service, or the disposal of data media. However, to ensure data protection and data security, branchly is obliged to enter into appropriate and legally compliant contractual agreements and implement control measures even for outsourced ancillary services.
4. Data Secrecy and Confidentiality
branchly ensures that employees engaged in processing personal data are bound to confidentiality or are subject to an appropriate statutory duty of confidentiality. These obligations must be framed in such a way that they remain in effect even after termination of the employment relationship between the employee and branchly.
5. Protective Measures and Audits
5.1 branchly implements the technical and organizational measures (TOMs) required pursuant to Art. 32 GDPR. branchly may modify and adapt the technical and organizational measures, in particular to reflect advances in the state of the art, provided that the initial security level is not diminished.
5.2 Upon request, branchly makes all necessary information available to the customer to demonstrate compliance with the obligations pursuant to Art. 28 GDPR, e.g. by presenting appropriate documentation. In addition, branchly facilitates audits by the customer or another auditor commissioned by the customer. For this purpose, branchly permits the auditor, after prior notification for audit purposes, to verify compliance with the obligations relevant to data processing on branchly's business premises during standard business hours without significantly disrupting business operations. The reasonable costs of branchly's cooperation in such an audit will be reimbursed by the customer in accordance with branchly's hourly rates. 5.3 The customer undertakes to treat all information, documents, data, and findings disclosed or made known by branchly in the context of the aforementioned audits and information requests strictly confidentially, to use them exclusively for data protection control, and not to use them otherwise. Employees or external third parties engaged by the customer must, unless bound to professional secrecy by law, be subjected to a duty of confidentiality equivalent to the one defined herein.
6. Duty to Inform and Support
6.1 If branchly becomes aware of a personal data breach affecting the customer's data, it will notify the customer without undue delay. In agreement with the customer, branchly will take appropriate measures to secure the data and mitigate potential adverse effects on data subjects. branchly assists the customer in fulfilling the reporting and notification obligations under Art. 33 and 34 GDPR.
6.2 Taking into account the nature of the processing and the information available to it, branchly supports the customer in conducting data protection impact assessments pursuant to Art. 35, 36 GDPR.
6.3 Should the data held by branchly be endangered by attachment or seizure, by insolvency or composition proceedings, or by other events or measures by third parties, branchly must inform the customer without undue delay. branchly will promptly inform all parties responsible in this context that sovereignty and ownership of the data lie exclusively with the customer as the "controller" within the meaning of the GDPR.
7. Deletion of Data
7.1 The deletion of data collected, processed, and used in the context of the contractual relationship takes place upon termination of the Main Contract, provided that no statutory retention periods preclude this.
7.2 If data media have been provided by the customer in the course of data processing, branchly will return them at the latest upon termination of the Main Contract.
8. Rights of Data Subjects
8.1 If a data subject directly contacts branchly to exercise data subject rights (e.g. regarding rectification, blocking or restriction of processing, or deletion of data), branchly will promptly forward this request to the customer.
8.2 Upon request, branchly supports the customer in safeguarding these rights, e.g. with regard to information obligations (notification, provision of information), rectification, blocking or restriction of processing, and deletion of personal data. The reasonable costs of support by branchly will be reimbursed by the customer in accordance with branchly's hourly rates.
9. Term and Final Provisions
9.1 This Agreement terminates upon termination of the Main Contract. It remains in force beyond the termination of the Main Contract for as long as branchly possesses personal data of the customer.
9.2 The liability provisions agreed upon between the parties in the Main Contract also apply to liability between the parties in connection with this Data Processing Agreement.
9.3 Amendments and additions to this Agreement must be in writing. This also applies to any waiver of this written form requirement.
9.4 German law shall apply exclusively, to the exclusion of conflict of law rules that refer to other legal systems. The UN Convention on Contracts for the International Sale of Goods (UNCITRAL) does not apply.