Pursuant to Art. 28 GDPR.
This Data Processing Agreement ("DPA") supplements the Terms & Conditions between the customer ("Controller") and Nowaity UG (haftungsbeschränkt), Feldmochinger Strasse 26, 80992 Munich, Germany ("Processor"), and governs the Processor's processing of personal data on the Controller's behalf in connection with the KONFORMA Service, as required by Art. 28 GDPR.
This DPA applies for as long as the Processor processes personal data on behalf of the Controller under the main agreement, and terminates automatically when that agreement ends and all personal data has been deleted or returned in accordance with Section 8.
The Processor processes personal data to provide the KONFORMA Service: account and organization management, storage and processing of product/release/SBOM data the Controller uploads, vulnerability monitoring and alerting, generation of compliance documents, and related hosting, backup and support activities.
Data subjects: the Controller's employees, contractors and end users who hold accounts in the Service; individuals named as contacts, security contacts or signatories in product and organization records; individuals mentioned in vulnerability reports or incident records submitted by the Controller.
Categories of data: contact data (name, email, role), authentication data, organization and billing metadata, and any personal data the Controller chooses to include in product data, SBOM records, incident records or free-text fields. The Processor does not intentionally process special categories of data under Art. 9 GDPR and asks the Controller not to submit such data through the Service.
The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do otherwise by EU or member state law. This DPA together with the main agreement constitutes the Controller's initial instruction; further instructions may be given in writing (including by email) and must be reasonable and technically feasible.
The Processor ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and are informed about the applicable data protection requirements before processing personal data.
The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption of data in transit, access controls, and reliance on sub-processors that provide comparable safeguards. A summary of the measures is available on request at contact@usekonforma.com.
The Controller authorizes the Processor to engage the following sub-processors, each of which is bound by a data processing agreement providing an equivalent level of protection:
The Processor will inform the Controller of any intended addition or replacement of sub-processors, giving the Controller the opportunity to object on reasonable data-protection grounds within 14 days.
Where a sub-processor is located outside the EEA, the Processor ensures an adequate level of protection, in particular through the EU Standard Contractual Clauses.
Taking into account the nature of the processing, the Processor assists the Controller, insofar as reasonably possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR, and in complying with the Controller's obligations under Art. 32–36 GDPR (security, breach notification, data protection impact assessments), in particular by notifying the Controller without undue delay after becoming aware of a personal data breach concerning Controller data.
Upon termination of the Service, the Processor makes Controller data available for export for 30 days and thereafter deletes it, unless EU or member state law requires continued storage, in line with the retention periods described in the Privacy Policy.
The Processor provides the Controller with the information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to reasonable notice and confidentiality.
Liability between the parties under this DPA follows the liability provisions of the main agreement (see Terms & Conditions, Section 9), except where the GDPR mandates otherwise. This DPA is governed by the law applicable to the main agreement.
Operator note: this is a template. Complete the sub-processor list and TOM summary, and have it reviewed by qualified legal counsel before relying on it. Not legal advice. The German version prevails. Last updated: [month/year].