1
Daten
2
Verifikation
3
Signieren

Data Collection

Please enter your customer details to generate the agreement.

E-Mail-Code eingeben

Wir haben einen 6-stelligen Verifizierungscode an Ihre E-Mail-Adresse gesendet.

Vertrag prüfen & signieren

Ihre Kundendaten wurden per 2FA verifiziert. Bitte bestätigen Sie den Vertrag.

Preview DPA_EVONIUS.PDF

Data Processing Agreement (DPA)

pursuant to Art. 28 GDPR


between

[Company Name]
[Company Address]

represented by [Representative]
Customer No.: [Customer ID]

- Controller -

and

Evonius, Owner Thomas Hörner
Dr.-Ernst-Derra-Str. 4, 94036 Passau
E-Mail: policies@evonius.net
- Processor -


1. Subject Matter and Duration of the Order

The Processor provides cloud and hosting infrastructure services for the Controller.

Category Description
Data SubjectsCustomers, Employees, Users of the Controller
Data TypesContact data, Master data, Log files, IP addresses
Processing ScopeStorage, Hosting, Backup, Database Administration

The duration of this Agreement corresponds to the duration of the main service agreement.

2. Scope and Responsibility

The Controller is responsible for compliance with statutory data protection provisions.

3. Obligations of the Processor

  • Processing exclusively on documented instructions from the Controller.
  • Confidentiality commitment of all authorized personnel.
  • Implementation of required Technical and Organizational Measures.
  • Assistance with data subject rights and notifications.

4. Technical and Organizational Measures (TOMs)

The Processor guarantees state-of-the-art security measures.

Measure Category Implemented Specification
Physical Access ControlProtection against unauthorized physical access to data processing facilities (server rooms, biometrics, logging).
System Access ControlPrevention of unauthorized system use (strong passwords, 2FA, IP whitelisting).
Data Access ControlRole-based access management, encryption of data at rest (AES-256).
Disclosure ControlEncryption of data transmission via TLS 1.3/HTTPS, VPN tunnels.
Input ControlDetailed audit logging of all system and data modifications.
Job ControlCareful selection and contractual binding of all service providers pursuant to Art. 28 GDPR.

5. Subcontractors

The Controller approves the engagement of the following subcontractors:

Company Location Service Provided
Hetzner Online GmbHGunzenhausen, GermanyHosting & Data Center Infrastructure
netcup GmbHKarlsruhe, GermanyHosting & Data Center Infrastructure

6. Data Subject Rights

The Processor supports the Controller in fulfilling data subject requests.

7. Audits and Inspections

The Controller has the right to inspect compliance with TOMs.

8. Termination and Deletion

Upon contract termination, data will be completely deleted in accordance with data protection rules.

9. Liability

Liability is governed by Art. 82 GDPR and statutory provisions.

10. Final Provisions

Amendments to this agreement must be made in writing.