Data Processing Agreement (DPA)
Version 1.0 — As of: March 12, 2026 | Deutsche Version
between the Customer of the VIAVENDO.AI Cloud platform (hereinafter “Controller”) and VIAVENDO.AI (hereinafter “Processor”)
— jointly “Parties” —
(1) This Data Processing Agreement (hereinafter “DPA”) specifies the data protection rights and obligations of the Parties in connection with the processing of personal data on behalf of the Controller by the Processor pursuant to Art. 28 of Regulation (EU) 2016/679 (GDPR).
(2) The subject matter of the data processing is the provision of the VIAVENDO.AI Cloud platform as Software-as-a-Service (SaaS), as defined in the Terms of Service and the service description.
(3) The duration of the processing corresponds to the term of the main contract (SaaS contract). This DPA terminates automatically upon termination of the main contract, without prejudice to any retention obligations.
(1) The Processor processes personal data on behalf of the Controller exclusively for the purpose of providing and operating the VIAVENDO.AI Cloud platform. This includes in particular:
(1) Types of personal data: The types of data processed depend on the Controller’s use of the Platform. Typically, these include:
(2) Categories of data subjects:
(3) The Controller is responsible for ensuring that no special categories of personal data within the meaning of Art. 9 GDPR are entered into the Platform, unless the Controller has a separate legal basis for doing so and has informed the Processor in advance.
(1) The Processor shall process personal data only on documented instructions from the Controller — including with regard to transfers of personal data to a third country or an international organization — unless required to do so by Union or Member State law to which the Processor is subject (Art. 28(3)(a) GDPR).
(2) The Controller’s instructions are documented in this DPA, the Terms of Service, and the service description. Instructions beyond these require text form (email is sufficient).
(3) The Processor shall inform the Controller without undue delay if it is of the opinion that an instruction violates data protection law. The Processor is entitled to suspend the execution of the relevant instruction until confirmation or modification by the Controller.
(1) The Processor ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR).
(2) The Processor shall take all technical and organizational measures required pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk. The current measures are documented in Annex 1 (Technical and Organizational Measures).
(3) The Processor shall assist the Controller, taking into account the nature of the processing, by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller’s obligations to respond to requests for exercising data subject rights (Art. 15–22 GDPR).
(4) The Processor shall assist the Controller, taking into account the nature of the processing and the information available to the Processor, in ensuring compliance with the obligations pursuant to Art. 32–36 GDPR (security of processing, notification of personal data breaches, data protection impact assessments, prior consultation).
(5) The Processor shall, at the choice of the Controller, delete or return all personal data after the end of the provision of processing services, and delete existing copies unless Union or Member State law requires storage of the personal data. The period for data deletion after contract termination is 30 days (cf. §19(5) Terms of Service).
(1) The Controller is solely responsible for the lawfulness of data processing and for safeguarding the rights of data subjects (“Controller” within the meaning of the GDPR).
(2) The Controller issues all instructions for data processing and shall ensure their lawfulness.
(3) The Controller shall inform the Processor without undue delay if it discovers errors or irregularities in the processing of its data.
(4) The Controller shall designate a contact person for data protection matters.
(1) If a data subject contacts the Processor directly with requests pursuant to Art. 15–22 GDPR, the Processor shall forward this request to the Controller without undue delay.
(2) The Processor shall support the Controller within its capabilities in responding to and fulfilling data subject rights. The costs thereof shall be borne by the Controller to the extent the effort exceeds regular service provision.
(1) The Processor shall inform the Controller without undue delay after becoming aware of a personal data breach (Art. 33(2) GDPR).
(2) The notification shall contain at least the following information:
(3) The obligation to notify the supervisory authority (Art. 33 GDPR) and to inform the data subjects (Art. 34 GDPR) rests with the Controller.
(1) The Controller hereby grants the Processor general written authorization to engage further processors (sub-processors) (Art. 28(2) GDPR).
(2) The sub-processors currently engaged are listed in Annex 2 (List of Sub-processors).
(3) The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors. The Controller has the opportunity to object to the change within 14 days of receipt of the notification.
(4) If the Controller raises a substantiated objection, the Processor shall not engage the sub-processor in question. If no mutually agreeable solution can be found, both Parties have a special right of termination.
(5) The Processor shall ensure that each sub-processor is subject to the same data protection obligations as those set out in this DPA, in particular by concluding a data processing agreement pursuant to Art. 28 GDPR.
(6) If a sub-processor fails to fulfill its data protection obligations, the Processor shall be liable to the Controller for ensuring compliance with the sub-processor’s obligations.
(1) The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and shall allow for and contribute to audits — including inspections — conducted by the Controller or an auditor mandated by the Controller.
(2) The following serve as standard documentation:
(3) On-site inspections are possible with timely advance notice (at least 14 days) during normal business hours. The Controller shall ensure that the inspection is conducted proportionately and does not disproportionately disrupt the Processor’s business operations.
(4) The costs of an on-site inspection shall be borne by the Controller, unless the inspection reveals a breach of duty by the Processor.
(1) The liability provisions of the main contract (§18 Terms of Service) apply supplementarily.
(2) Liability towards data subjects is governed by Art. 82 GDPR.
(1) In the event of conflicts between this DPA and the Terms of Service or other agreements between the Parties, the provisions of this DPA shall prevail with respect to the protection of personal data.
(2) Amendments and supplements to this DPA must be in text form. The Processor is entitled to unilaterally amend this DPA with a notice period of at least 30 days, provided this is required due to changes in legislation, case law, or regulatory requirements. In such case, the Controller has a right to object. In the event of a substantiated objection, both Parties have a special right of termination.
(3) The law of the Federal Republic of Germany applies. The place of jurisdiction is, to the extent permitted by law, the registered office of the Processor.
(4) Should individual provisions of this DPA be or become invalid, the validity of the remaining provisions shall not be affected. In place of the invalid provision, the effective provision that most closely approximates its economic purpose shall be deemed agreed (severability clause).