§ 1 Subject Matter and Duration of Processing
(1) This Data Processing Agreement (hereinafter the "DPA") specifies the data protection obligations of the parties arising from the agreement concluded between them for the use of EA-PowerTools as Software-as-a-Service (hereinafter the "Main Agreement"). It applies to all activities in which the Processor or sub-processors engaged by the Processor process personal data of the Controller.
(2) The subject matter of the processing is the provision and operation of the software, including the storage of data entered by the Controller (hosting).
(3) The duration of the processing corresponds to the term of the Main Agreement. The provisions on deletion and return of data under § 7 continue to apply beyond the end of the agreement.
(4) In all other respects, the definitions in Art. 4 GDPR apply.
§ 2 Nature, Purpose and Scope of Processing
(1) The nature and purpose of the processing arise from the Main Agreement: provision of cloud-based software applications for calculation and design tasks in the field of electrical energy supply, including storage, management and backup of customer data.
(2) The categories of personal data processed and of data subjects are described in Annex 1 to this DPA.
(3) Processing takes place exclusively in Member States of the European Union or in contracting states of the Agreement on the European Economic Area (EEA). A transfer to a third country requires the prior consent of the Controller and is only permitted if the requirements of Art. 44 et seq. GDPR are met. To the extent that access from a third country cannot be fully excluded with respect to the cloud provider used, the Processor shall ensure appropriate safeguards within the meaning of Art. 44 et seq. GDPR (in particular EU Standard Contractual Clauses or a certification under the EU-U.S. Data Privacy Framework).
§ 3 Controller's Right to Issue Instructions
(1) The Processor processes personal data exclusively on documented instructions from the Controller, unless the Processor is required to process by Union or Member State law; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
(2) The Main Agreement as well as the Controller's use of the software (including configurations, inputs and deletions made by the Controller) constitute instructions. Supplementary instructions must be in text form.
(3) The Processor shall inform the Controller without undue delay if the Processor is of the opinion that an instruction infringes the GDPR or other data protection provisions. The Processor is entitled to suspend the execution of the instruction concerned until it is confirmed or amended.
§ 4 Obligations of the Processor
(1) The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
(2) The Processor takes all technical and organisational measures (hereinafter "TOMs") required pursuant to Art. 32 GDPR. The TOMs implemented at the time of conclusion of the agreement are described in Annex 2. The Processor may adapt the TOMs to technical and organisational developments, provided that the agreed level of protection is not reduced.
(3) The Processor shall assist the Controller by appropriate technical and organisational measures in fulfilling the Controller's obligation to respond to requests from data subjects (Art. 12 to 23 GDPR). Requests from data subjects addressed directly to the Processor shall be forwarded by the Processor to the Controller without undue delay.
(4) Taking into account the nature of the processing and the information available to the Processor, the Processor shall assist the Controller in ensuring compliance with the obligations set out in Art. 32 to 36 GDPR (security of processing, notification of personal data breaches, data protection impact assessment, prior consultation).
(5) The Processor shall notify the Controller of personal data breaches affecting the Controller without undue delay after becoming aware of them. The notification shall, where possible, include the information pursuant to Art. 33(3) GDPR.
(6) Where legally required, the Processor shall appoint a data protection officer and communicate that officer's contact details to the Controller. The contact for data protection matters is: info@ea-powertools.com.
(7) The Processor maintains a record of processing activities pursuant to Art. 30(2) GDPR.
§ 5 Sub-processing
(1) The Controller grants the Processor a general authorisation to engage sub-processors. The sub-processors used at the time of conclusion of the agreement are listed in Annex 3 and approved by the Controller.
(2) The Processor shall inform the Controller in text form at least four weeks before the intended engagement or replacement of a sub-processor. The Controller may object to the change within two weeks of receipt of the information on important data protection grounds. If no objection is raised, the change shall be deemed approved. In the event of a justified objection, the Processor is entitled to terminate the Main Agreement and this DPA extraordinarily with reasonable notice if performance without the proposed sub-processor is not reasonably possible for the Processor.
(3) The Processor shall impose on each sub-processor, by way of a contract, the same data protection obligations as set out in this DPA. Where a sub-processor fails to fulfil its data protection obligations, the Processor shall remain liable to the Controller for the performance of the sub-processor's obligations.
(4) Ancillary services of third parties without a direct connection to the processing of the Controller's data (e.g. telecommunications services, postal and transport services, cleaning and maintenance services) do not constitute sub-processing relationships.
§ 6 Evidence and Audit Rights
(1) The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR.
(2) Evidence may in particular be provided by current attestations, certifications (e.g. ISO/IEC 27001) or suitable self-declarations. Certifications and audit reports of the sub-processors used (in particular of the data centre operator) may also be used as evidence.
(3) The Controller is entitled, after prior notice with reasonable lead time and during regular business hours, to carry out audits — including inspections — or to have them carried out by an auditor bound to confidentiality who is not a competitor of the Processor. For audits that go beyond the provision of existing evidence under paragraph 2, the Processor may charge a reasonable fee for the effort involved, unless the audit is prompted by concrete indications of data protection infringements.
§ 7 Deletion and Return of Data
(1) Copies or duplicates of the data shall not be created without the Controller's knowledge. This does not apply to backup copies to the extent they are required to ensure proper data processing, or to data that are required in view of statutory retention obligations.
(2) After termination of the Main Agreement, the Controller has the opportunity to retrieve its data within 30 days via the export functions provided (cf. § 9(6) of the Terms and Conditions). After expiry of this period, the Processor shall delete all personal data of the Controller in a data-protection-compliant manner, unless statutory retention obligations prevent this. Deletion from backup copies shall take place in accordance with the regular backup cycle, but no later than a further 14 days thereafter.
(3) Upon request, the Processor shall confirm the deletion to the Controller in text form.
§ 8 Liability and Final Provisions
(1) The liability of the parties is governed by the provisions of the Main Agreement (in particular § 14 of the Terms and Conditions) as well as Art. 82 GDPR.
(2) In the event of conflicts between this DPA and the Main Agreement, the provisions of this DPA shall prevail with respect to data protection matters.
(3) The law of the Federal Republic of Germany shall apply. The place of jurisdiction is Dresden if the Controller is a merchant, a legal entity under public law or a special fund under public law.
(4) Should individual provisions of this DPA be or become invalid, the validity of the remaining provisions shall remain unaffected.
Annex 1 — Subject Matter of Processing
Categories of data subjects:
- a) Employees, contact persons and other users of the Controller (user accounts);
- b) where applicable, employees and contact persons of customers, clients or business partners of the Controller, to the extent that their data are contained in project data.
Categories of personal data:
- a) Master data of user accounts (name, business email address, company affiliation, role/permissions);
- b) Usage and log data (login times, IP addresses, activity logs);
- c) Content data, to the extent that the Controller introduces personal data into project data (e.g. names of contact persons in project descriptions or reports).
Special categories of personal data (Art. 9 GDPR): The processing of special categories of personal data is not the subject of the Main Agreement and must be refrained from by the Controller.
Annex 2 — Technical and Organisational Measures (TOMs)
1. Confidentiality (Art. 32(1)(b) GDPR)
- a) Physical access control: The software is operated in certified data centres of the cloud provider named in Annex 3 (including physical access control systems, video surveillance, security personnel in accordance with the certifications of the data centre operator, e.g. ISO/IEC 27001).
- b) System access control: Authentication with username and password, password policies, storage of passwords exclusively as cryptographic hashes, option for two-factor authentication, automatic session locks, role-based administration with logging.
- c) Data access control: Role and permission concept based on the need-to-know principle, separate permissions for development, operations and support, logging of administrative access.
- d) Separation control: Logical tenant separation of customer data, separation of production, test and development environments.
- e) Pseudonymisation and encryption: Transport encryption of all connections (TLS), encryption of stored data (encryption at rest) at the cloud infrastructure level.
2. Integrity (Art. 32(1)(b) GDPR)
- a) Transmission control: Encrypted data transmission, no disclosure to third parties outside the approved sub-processors, logging of data exports.
- b) Input control: Logging of the creation, modification and deletion of user accounts and material data operations.
3. Availability and Resilience (Art. 32(1)(b) and (c) GDPR)
- a) Daily data backups with a retention period of at least 14 days, geo-redundant storage within the EU region.
- b) Multi-tier infrastructure redundancy, uninterruptible power supply and fire protection in accordance with the standards of the data centre operator.
- c) Protective measures against malware and attacks (firewalls, network segmentation, basic DDoS protection of the cloud provider), timely deployment of security-relevant updates.
- d) Emergency concept with defined recovery procedures; regular tests of the restorability of backups.
4. Procedures for Regular Testing, Assessment and Evaluation (Art. 32(1)(d) GDPR)
- a) Regular review of the effectiveness of the TOMs and adaptation to the state of the art.
- b) Privacy-friendly default settings in development (Privacy by Design and by Default, Art. 25 GDPR).
- c) Commitment of all employees to confidentiality and regular awareness training on data protection and information security.
- d) Job control: Careful selection of sub-processors, conclusion of contracts pursuant to Art. 28(4) GDPR, regular review of certifications.
Annex 3 — Approved Sub-processors
The sub-processors used at the time of conclusion of the agreement and approved by the Controller are set out in the current list at www.ea-powertools.com/subprozessoren. For each sub-processor, the list contains: name or company, address, the service performed, the place of processing and — where applicable — the safeguards for third-country access pursuant to Art. 44 et seq. GDPR.
In particular, a cloud infrastructure provider is used for hosting, storage and data backup; processing takes place exclusively in data centres within the European Union (cf. § 2(3) of this DPA). Changes to the list are made in accordance with the procedure set out in § 5 of this DPA (information at least four weeks in advance, Controller's right to object).