Data Processing Agreement

Pursuant to Art. 28 GDPR.

Draft template: not legal advice. This is a standard Art. 28 GDPR data processing agreement template drafted for KONFORMA. It has not been reviewed by a lawyer. Have it checked by qualified counsel before relying on it, and before offering it to customers who require a signed DPA (e.g. enterprise customers, public-sector customers). Contact contact@usekonforma.com to arrange a countersigned copy.

1. Parties and subject matter

This Data Processing Agreement ("DPA") supplements the Terms & Conditions between the customer ("Controller") and Nowaity UG (haftungsbeschränkt), Feldmochinger Strasse 26, 80992 Munich, Germany ("Processor"), and governs the Processor's processing of personal data on the Controller's behalf in connection with the KONFORMA Service, as required by Art. 28 GDPR.

2. Duration

This DPA applies for as long as the Processor processes personal data on behalf of the Controller under the main agreement, and terminates automatically when that agreement ends and all personal data has been deleted or returned in accordance with Section 8.

3. Nature and purpose of processing

The Processor processes personal data to provide the KONFORMA Service: account and organization management, storage and processing of product/release/SBOM data the Controller uploads, vulnerability monitoring and alerting, generation of compliance documents, and related hosting, backup and support activities.

4. Categories of data subjects and personal data

Data subjects: the Controller's employees, contractors and end users who hold accounts in the Service; individuals named as contacts, security contacts or signatories in product and organization records; individuals mentioned in vulnerability reports or incident records submitted by the Controller.

Categories of data: contact data (name, email, role), authentication data, organization and billing metadata, and any personal data the Controller chooses to include in product data, SBOM records, incident records or free-text fields. The Processor does not intentionally process special categories of data under Art. 9 GDPR and asks the Controller not to submit such data through the Service.

5. Controller's instructions

The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do otherwise by EU or member state law. This DPA together with the main agreement constitutes the Controller's initial instruction; further instructions may be given in writing (including by email) and must be reasonable and technically feasible.

6. Confidentiality and personnel

The Processor ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and are informed about the applicable data protection requirements before processing personal data.

7. Technical and organizational measures

The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption of data in transit, access controls, and reliance on sub-processors that provide comparable safeguards. A summary of the measures is available on request at contact@usekonforma.com.

8. Sub-processors

The Controller authorizes the Processor to engage the following sub-processors, each of which is bound by a data processing agreement providing an equivalent level of protection:

The Processor will inform the Controller of any intended addition or replacement of sub-processors, giving the Controller the opportunity to object on reasonable data-protection grounds within 14 days.

9. International transfers

Where a sub-processor is located outside the EEA, the Processor ensures an adequate level of protection, in particular through the EU Standard Contractual Clauses.

10. Assistance to the Controller

Taking into account the nature of the processing, the Processor assists the Controller, insofar as reasonably possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR, and in complying with the Controller's obligations under Art. 32–36 GDPR (security, breach notification, data protection impact assessments), in particular by notifying the Controller without undue delay after becoming aware of a personal data breach concerning Controller data.

11. Deletion and return of data

Upon termination of the Service, the Processor makes Controller data available for export for 30 days and thereafter deletes it, unless EU or member state law requires continued storage, in line with the retention periods described in the Privacy Policy.

12. Audits

The Processor provides the Controller with the information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to reasonable notice and confidentiality.

13. Liability and governing law

Liability between the parties under this DPA follows the liability provisions of the main agreement (see Terms & Conditions, Section 9), except where the GDPR mandates otherwise. This DPA is governed by the law applicable to the main agreement.

Operator note: this is a template. Complete the sub-processor list and TOM summary, and have it reviewed by qualified legal counsel before relying on it. Not legal advice. The German version prevails. Last updated: [month/year].