Last updated Sept 1, 2026

Data processing agreement

between the Provider
— hereinafter referred to as the “Controller” —

and

sqanit GmbH, Balanstraße 71a, 81541 Munich, Germany
— hereinafter referred to as the “Processor” —

The Controller and Processor are collectively referred to as the “Parties”.

1. General
1.1

This agreement contains a written order from the Controller to the Processor within the meaning of Article 28 of Regulation (EU) 2016/679, the European General Data Protection Regulation (“GDPR”).

1.2

Where the Federal Data Protection Act (“BDSG”) is mentioned in this agreement, these references refer exclusively to the version of the BDSG applicable from 25 May 2018.

2. Definitions
2.1

“Personal Data” means any information relating to an identified or identifiable natural person. An identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as:

  • A name
  • An identification number
  • Location data
  • An online identifier
  • One or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
2.2

“Processing” or “processing” means any operation or set of operations performed on Personal Data or sets of Personal Data, whether or not by automated means, such as:

  • Collection
  • Recording
  • Organisation
  • Structuring
  • Storage
  • Adaptation or alteration
  • Retrieval
  • Consultation
  • Use
  • Disclosure by transmission
  • Dissemination or otherwise making available
  • Alignment or combination
  • Restriction
  • Deletion
  • Destruction
3. Subject and Term of the Agreement
3.1

The subject, type and purpose of the processing of Personal Data by the Processor on behalf of the Controller are set out in the agreement between the Controller and the Processor in accordance with the Processor’s Terms of Use (“ToU Agreement”).

3.2

The following types of Personal Data are subject to this agreement:

  • Contact details, such as names, email addresses, postal addresses, telephone numbers, login data, profession and job title
  • Location data and technical data relating to devices that can be assigned to a natural person
  • Inquiries and data relating to the processing of orders in connection with devices, in particular communication data
  • Information concerning malfunctions and their rectification, repairs and spare-parts requirements, which may also include photos, videos and other files
3.3

The processing concerns the following categories of data subjects:

  • Employees of the Controller
  • Contractual partners of the Controller, in particular users
3.4

This agreement does not apply to activities in which the Processor independently processes the Provider’s Personal Data.

This applies to the processing of contact data belonging to the Controller’s contact persons who are responsible for implementing the contract in accordance with the ToU Agreement.

The Controller is responsible for the processing within the meaning of Article 4(7) GDPR.

The assessment of whether the processing of Personal Data under the ToU Agreement and this agreement complies with the GDPR and, where applicable, other applicable data protection laws, is at the Controller’s sole discretion.

The Controller shall inform the Processor without delay if the Controller identifies any errors or irregularities in the processing.

3.5

The term of this agreement shall correspond to the term of the ToU Agreement.

4. General Duties of the Processor
4.1

The Processor shall process the Controller’s Personal Data exclusively in accordance with the ToU Agreement and any further documented instructions issued by the Controller under this agreement, unless the Processor is required to process the Personal Data under the laws of the European Union or the Federal Republic of Germany.

The Processor shall inform the Controller of such legal requirements before carrying out the processing, unless the law prohibits such information on important grounds of public interest.

4.2

The Processor confirms that it has appointed a data protection officer pursuant to Section 37 of the GDPR.

The Processor shall provide the Controller with the data protection officer’s contact information upon request.

4.3

The Controller is responsible for fulfilling the Controller’s obligations to respond to requests from data subjects exercising their rights under Articles 12 to 23 GDPR.

The Processor shall inform the Controller without delay if data subjects assert such rights against the Processor.

Furthermore, taking into account the nature of the processing, the Processor shall assist the Controller through appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller’s obligations.

4.4

In the event of a Personal Data breach, including a breach of this agreement or any additional instructions issued by the Controller under this agreement, the Processor shall inform the Controller without delay.

The Processor acknowledges that Articles 33 and 34 GDPR may impose notification and information obligations in the event of a Personal Data breach.

The Processor shall assist the Controller in fulfilling these obligations.

4.5

If the Controller is required under Article 35 GDPR to carry out a data protection impact assessment, the Processor shall assist the Controller with this assessment, depending on the type of processing and the information available.

The Processor shall also assist the Controller, where applicable, in consultation with the supervisory authority pursuant to Article 36 GDPR.

5. Instructions
5.1

The Processor shall process the Controller’s Personal Data only on documented instructions.

Instructions shall be issued in text form.

Oral instructions are permitted as an exception in urgent situations but must be confirmed by the Controller in text form without delay.

If an instruction requires the Processor to perform services that are not included in the ToU Agreement, the Controller shall pay the Processor remuneration to be determined by the Processor in accordance with Section 316 of the German Civil Code (“Bürgerliches Gesetzbuch”).

5.2

The Processor shall inform the Controller without delay if it believes that an instruction constitutes a breach of applicable data protection laws or this agreement.

The Processor is permitted to suspend execution of the relevant instruction until the Controller confirms or modifies it.

6. Technical and Organisational Measures

The Processor shall take all measures required under Article 32 GDPR.

7. Monitoring Rights of the Controller

The Controller reserves the right to monitor compliance with:

  • Statutory data protection provisions
  • The contractual agreements concluded between the Parties
  • Any additional instructions issued by the Controller to the Processor

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR.

The Processor shall also allow for and contribute to audits, including inspections, conducted by the Controller or another auditor appointed by the Controller.

The implementation of technical and organisational measures may be verified through:

  • Approved codes of conduct pursuant to Article 40 GDPR
  • A certificate issued under an approved certification procedure pursuant to Article 42 GDPR
8. Additional Processors and Subcontractors

If the processing of the Controller’s Personal Data involves other processors, referred to as “Subcontractors”, the following provisions shall apply.

The involvement of Subcontractors is generally permitted.

The Processor shall inform the Controller in advance of each Subcontractor it intends to involve and shall give the Controller the opportunity to object.

At the time this agreement is concluded, the Processor shall use the following Subcontractor:

Hetzner Online GmbH

Managing Directors:

  • Martin Hetzner
  • Stephan Konvickova
  • Günther Müller

Street / P.O. Box:

Industriestr. 25

Postcode and Location:

91710 Gunzenhausen, Germany

Hetzner Online GmbH is the data centre and infrastructure provider for sqanit’s private cloud system and provides all related services.

A data processing agreement is in place with Hetzner Online GmbH.

The Processor shall define its contractual arrangements with each Subcontractor in such a way that they comply with the data protection provisions applicable between the Controller and the Processor.

In the event of subcontracting, the Controller shall be granted control and inspection rights in relation to the Subcontractor in accordance with this agreement.

This includes the Controller’s right, upon written request, to obtain information from the Subcontractor about the essential content of the contract and the implementation of data protection obligations within the subcontracting relationship.

Where necessary, this may include inspecting relevant contract documents.

For clarification, the Parties agree that Article 32(4) GDPR also applies to Subcontractors.

Subcontracting relationships within the meaning of this provision do not include services obtained by the Processor from third parties as ancillary services supporting the fulfilment of the order.

These services include, for example:

  • Telecommunications services
  • Cleaning services

However, to ensure the privacy and security of the Controller’s Personal Data, the Processor shall enter into appropriate contractual arrangements with such service providers to safeguard Personal Data in accordance with applicable law.

This also applies to ancillary services.

9. Deletion of Data

After completion of the contractually agreed services, or at an earlier time upon the Controller’s request, and no later than upon termination of the ToU Agreement, the Processor shall delete the Controller’s Personal Data.

This obligation does not apply where the laws of the European Union or the Federal Republic of Germany require or permit further storage of the Personal Data.

10. Obligations to Maintain Confidentiality

The Processor warrants and guarantees that all individuals employed by the Processor who process the Personal Data, including individuals employed by Subcontractors, have committed themselves to confidentiality or are subject to an appropriate statutory professional obligation of confidentiality.

11. Remuneration and Liability
11.1

The Processor’s remuneration is specified in the ToU Agreement.

11.2

The Processor shall be liable to the Controller in accordance with the provisions of Clause 10 of the ToU Agreement.

Explore our collection of 200+ Premium Webflow Templates

Need to customize this template? Hire our Webflow team!