Data processing agreement (Art. 28 GDPR)

Auftragsverarbeitungsvertrag (AVV). Part of the terms of service. Customers accept it when they register; a countersigned copy is available on request from [email protected].

1. Parties and subject matter

Controller: the Customer. Processor: Zack Data+AI solutions, Am See 21, 88356 Ostrach. The processor processes personal data on behalf of the controller to provide the Service "ReplyPronto" for the duration of the main contract.

2. Nature, purpose and data

3. Instructions

The processor processes data only on documented instructions of the controller, which are given by these terms and the controller's settings in the Service. The processor informs the controller if it believes an instruction infringes data protection law.

4. Confidentiality

Persons authorised to process the data are committed to confidentiality.

5. Technical and organisational measures (Art. 32 GDPR)

6. Subprocessors

The controller gives general authorisation to use the subprocessors listed on the subprocessor page. The processor informs the controller of intended changes by email or on that page at least 14 days in advance; the controller may object for important data protection reasons and, if no solution is found, cancel the contract. The processor imposes equivalent data protection obligations on subprocessors.

7. Support for the controller

The processor supports the controller, as far as reasonable, in responding to data subject requests (the Service offers viewing, export and deletion functions), in security, breach notification and data protection impact assessments. The processor notifies the controller without undue delay, where possible within 48 hours, after becoming aware of a personal data breach.

8. Deletion and return

After the end of the contract or when the controller deletes its account, the processor deletes all personal data processed on behalf of the controller, unless law requires storage. The controller can export leads beforehand.

9. Audits

The processor provides the controller with information necessary to demonstrate compliance, primarily through this agreement, the documentation of technical and organisational measures and certificates of its providers. On-site audits require at least 30 days' notice, take place during business hours, must not disrupt operations and are at the controller's expense.

10. Liability

Liability is governed by Art. 82 GDPR and, in the relationship between the parties, by the liability provisions of the terms of service.