Data Processing Agreement
pursuant to Art. 28 GDPR
§ 1 Parties
This Data Processing Agreement ("DPA") is entered into between:
Controller (Client):
, , Email:
Processor:
Y. Baris Ozgun, Krefelder Str. 4, 10555 Berlin, Deutschland, Email: contact@thebozgun.com
This DPA forms part of the main contract and takes precedence over it with respect to data protection matters. Subject matter: .
§ 2 Duration
This DPA takes effect on the date of last signature and ends upon termination of the main contract. Obligations that by nature survive termination (confidentiality, deletion) remain in force.
§ 3 Nature, Scope and Purpose of Processing
The Processor processes personal data solely for the purpose of providing the agreed services ( ). Processing activities include: collection, storage, transmission, processing and deletion. Processing for any other purpose is prohibited.
§ 4 Categories of Data and Data Subjects
Data categories:
Data subjects:
Special categories under Art. 9 GDPR are not processed unless separately agreed in writing.
§ 5 Controller's Right to Issue Instructions
The Processor processes personal data solely on documented instructions from the Controller. Instructions shall be given in writing; verbal instructions must be confirmed in writing without undue delay.
If the Processor considers an instruction to be in breach of data protection law, it shall immediately inform the Controller and may suspend execution pending clarification.
§ 6 Obligations of the Processor
Confidentiality (Art. 28(3)(b), Art. 29 GDPR): All persons authorised to process personal data are bound by confidentiality obligations and trained in applicable data protection requirements.
Security (Art. 32 GDPR): The Processor implements all technical and organisational measures required by Art. 32 GDPR, as detailed in Annex 1.
The Processor assists the Controller in complying with obligations under Art. 32–36 GDPR.
§ 7 Sub-processors
Sub-processors may only be engaged with the Controller's prior written approval. Approved sub-processors are listed in Annex 2. Intended changes are communicated at least 14 days in advance; the Controller may object, triggering a right of extraordinary termination for both parties.
Sub-processors are bound by the same data protection obligations as the Processor (Art. 28(4) GDPR).
§ 8 Assistance with Data Subject Rights
The Processor assists the Controller in fulfilling data subject requests under Art. 15–22 GDPR. Requests addressed to the Processor are forwarded to the Controller without undue delay.
§ 9 Notification of Personal Data Breaches
Personal data breaches are reported to the Controller immediately, and in any event within 24 hours of becoming aware, including the nature of the breach, affected categories, likely consequences, and measures taken.
§ 10 Deletion and Return of Data
Upon completion of services or on the Controller's instruction, all personal data is deleted or returned and existing copies deleted, unless retention is required by law. Deletion is confirmed in writing.
§ 11 Audit and Inspection Rights
The Processor makes all necessary information available to demonstrate compliance and permits audits (including on-site inspections) by the Controller or its appointed auditor (14 days notice, once per year, costs borne by the Controller).
§ 12 Liability
Each party is liable for data protection breaches within its own scope of responsibility under Art. 82 GDPR. The Processor's total aggregate liability per incident is capped at . This cap does not apply in cases of wilful misconduct, gross negligence, or injury to life, body or health.
§ 13 Final Provisions
Written form: Amendments require written form. No oral collateral agreements exist.
Governing law: Law of the Federal Republic of Germany.
Jurisdiction: Exclusive place of jurisdiction: Berlin.
Severability: Invalid provisions are replaced by valid ones closest to their economic purpose.
Signatures
Place, Date
,
Controller – Signature
Name / Position
Place, Date
,
Processor – Signature
Name / Position
Y. Baris Ozgun
Annex 1 – Technical and Organisational Measures (Art. 32 GDPR)
| Control area | Description |
|---|---|
| Physical access control | Remote work from home office, lockable workspace, no own server rooms; physical infrastructure exclusively with providers listed in Annex 2. |
| System access control | Password manager, strong individual passwords, two-factor authentication on all accounts, fully encrypted hard drive. |
| Data access control | Role-based access rights on a least-privilege basis, separate credentials per client and per environment. |
| Transmission control | TLS encryption for all transmissions, SSH access exclusively via key, no transmission over unencrypted channels. |
| Input control | Version control with Git, traceable commit history, logging of changes to production systems. |
| Order control | Processing exclusively on documented instructions from the controller, orders in written form. |
| Availability control | Regular automated backups, recovery tests, redundant infrastructure of the hosting providers used. |
| Separation control | Separate environments and databases per client and per project (Development, Staging, Production). |
| Encryption | TLS 1.2 or higher in transport, encryption of data at rest, encrypted backups. |
Annex 2 – List of Approved Sub-processors
| Provider | Purpose / Service | Country |
|---|---|---|
| to be determined on a project basis | ||
| to be determined on a project basis | ||
| to be determined on a project basis | ||
Changes are communicated at least 14 days before taking effect.