Cookie settings

Here you decide which technologies we may use. You can change or withdraw your choice at any time.

Necessary

Stores only your own choice (consent status). This function is required for operation and is always active.

Always on

Analytics (Google Analytics)

Helps us understand which content is used. Sets identifiers (cookies) and sends usage data to Google. Loaded only after you consent.

Not active at the moment: analytics has not been set up on this website yet. No analytics data is collected.

Your choice is stored locally in your browser (key “evb_consent”). Privacy policy

Skip to content

Legal

Data Processing Agreement (DPA / AVV)

Draft data processing agreement under Art. 28 GDPR for business customers of the multi-tenant EVBINOS products.

Last updated:

1. Parties

Controller (customer)
REQUIRES CONFIGURATION / REVIEW: name, address and representative of the customer — completed per customer
Processor
Evangelos Binos
Hintergasse 23
65239 Hochheim am Main
Germany
EVBINOS
Main contract
REQUIRES CONFIGURATION / REVIEW: designation of the underlying contract or order

2. Subject matter and duration

The subject matter is the processing of personal data on behalf of the customer when using the EVBINOS products. The duration corresponds to the term of the main contract. REQUIRES CONFIGURATION / REVIEW: name the specific products and services.

3. Nature and purpose of the processing

The processing comprises storing, managing and transmitting data that the customer enters into the respective product, solely for the purpose of the contractually agreed service.

4. Data categories and data subjects

Data subjects and types of data depend on the product used. REQUIRES CONFIGURATION / REVIEW: confirm and complete per product.

Data subjectsData categories
Contacts / end customers of the customerREQUIRES CONFIGURATION / REVIEW: e.g. name, telephone number, email address, date of birth, message history — confirm
Customer’s staff (users)REQUIRES CONFIGURATION / REVIEW: e.g. account data, access credentials, usage / log data — confirm

5. Instructions

The processor processes personal data only on documented instructions from the customer, including with regard to transfers to third countries, unless required to do so by Union or Member State law (Art. 28(3)(a) GDPR). If it considers an instruction unlawful, it informs the customer without delay.

6. Confidentiality

Persons authorised to process the data are bound to confidentiality or are under a statutory obligation of confidentiality (Art. 28(3)(b) GDPR).

7. Technical and organisational measures

The processor implements appropriate technical and organisational measures under Art. 32 GDPR. They are documented in Annex II and continuously adapted to the state of the art (Art. 28(3)(c) GDPR).

8. Subprocessors

The customer grants a REQUIRES CONFIGURATION / REVIEW: general / specific — to be decided authorisation to engage subprocessors. The current list is published under Subprocessors. The customer is informed of intended changes and may object within a reasonable period. Subprocessors are contractually bound to at least equivalent data protection (Art. 28(2) and (4) GDPR). REQUIRES CONFIGURATION / REVIEW: define notice period and procedure.

9. Assistance to the customer

The processor assists the customer by appropriate measures in responding to data-subject requests (Chapter III GDPR) and with the obligations under Art. 32 to 36 GDPR (Art. 28(3)(e) and (f) GDPR).

10. Notification of personal data breaches

The processor notifies the customer of a personal data breach without undue delay. REQUIRES CONFIGURATION / REVIEW: define the notification deadline and content of the notification.

11. Return and deletion

After the services end, the processor, at the customer’s choice, deletes or returns all personal data unless storage is required by law (Art. 28(3)(g) GDPR). REQUIRES CONFIGURATION / REVIEW: define export format and deletion periods including backups.

12. Evidence and audits

The processor makes available to the customer the information necessary to demonstrate compliance and allows for audits, including inspections (Art. 28(3)(h) GDPR). REQUIRES CONFIGURATION / REVIEW: define procedure, notice period and cost allocation.

13. Third-country transfers

Processing outside the EU/EEA takes place only under the conditions of Art. 44 et seq. GDPR. REQUIRES CONFIGURATION / REVIEW: name locations and transfer mechanisms, if any.

14. Liability

Liability is governed by Art. 82 GDPR and the main contract. REQUIRES CONFIGURATION / REVIEW: legal review of the liability provision.

15. Final provisions

In the event of conflict, this DPA takes precedence over the main contract with regard to data protection. German law applies. REQUIRES CONFIGURATION / REVIEW: define place of jurisdiction, written/text form and signature.

Annexes

  • Annex I — Details of the processing (sections 3 and 4). REQUIRES CONFIGURATION / REVIEW: complete per customer.
  • Annex II — Technical and organisational measures (TOMs). REQUIRES CONFIGURATION / REVIEW: transfer from the internal TOM document and review.
  • Annex III — Subprocessors: list of subprocessors