Pursuant to Article 28 of the General Data Protection Regulation (GDPR)
This Data Processing Agreement ("DPA") is an addendum to the Terms and Conditions and Hosting Agreement between AGXL Limited / GoMaKe UG ("Data Processor" or "Provider") and the Customer ("Data Controller").
1.1. The Data Processor provides hosting services to the Data Controller. In providing these services, the Data Processor may process personal data on behalf of the Data Controller.
1.2. The duration of this DPA corresponds to the duration of the main Hosting Agreement. It terminates automatically upon the permanent deletion of the Data Controller's hosting account and associated data.
2.1. The processing involves storing, transmitting, and organizing data solely for the purpose of providing web hosting, database hosting, and email infrastructure as explicitly requested by the Data Controller.
2.2. The Data Processor does not access, read, evaluate, or utilize the personal data hosted on the customer's server for its own purposes.
3.1. The categories of personal data and data subjects are determined by the Data Controller, as the Data Processor provides generic infrastructure. This typically includes customer data, employee data, communication data, and website user data (e.g., IP addresses) collected by the Data Controller's web applications.
4.1. The Data Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Art. 32 GDPR.
4.2. These measures include, but are not limited to: access control (physical and digital), encrypted transmission (SSL/TLS), network isolation, and DDoS protection.
5.1. Due to the "Local Geo Webhosting" model, the Data Processor utilizes external data center operators and network providers worldwide as sub-processors to physically host the server infrastructure.
5.2. The Data Controller hereby grants general authorization for the engagement of these sub-processors. The Data Processor ensures that sub-processors are bound by data protection obligations compatible with this DPA and the GDPR.
5.3. Right to Object: The Data Processor shall inform the Data Controller of any intended changes concerning the addition or replacement of sub-processors. The Data Controller has the right to object to such changes within 14 days of notification on legitimate data protection grounds. If an objection cannot be resolved, the Data Controller may terminate the affected hosting service.
6.1. The Data Processor will process personal data only on documented instructions from the Data Controller, including with regard to transfers of personal data to a third country.
6.2. The Data Processor will assist the Data Controller, insofar as this is possible, in fulfilling its obligation to respond to requests for exercising the data subject's rights (Art. 12-23 GDPR).
6.3. The Data Processor shall notify the Data Controller without undue delay after becoming aware of a personal data breach affecting the Data Controller's hosting environment.
6.4. Confidentiality: The Data Processor ensures that all persons authorized to process the personal data (e.g., employees, support staff) have committed themselves to strict confidentiality or are under an appropriate statutory obligation of confidentiality.
6.5. DPIA Assistance: The Data Processor shall assist the Data Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR (Security of processing, Data Protection Impact Assessments, and Prior Consultation), taking into account the nature of processing and the information available to the Data Processor.
7.1. Upon termination of the provision of data processing services, the Data Processor shall delete all personal data hosted on the relevant infrastructure, unless Union or Member State law requires storage of the personal data.
8.1. The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR.
8.2. The Data Controller has the right to conduct audits. To protect the security of our global infrastructure, the Data Controller agrees that audit requests will primarily be satisfied by the Data Processor providing recent, independent third-party security certifications (e.g., ISO 27001, SOC 2) from our underlying data center partners. On-site audits must be announced 30 days in advance and are conducted entirely at the Data Controller's expense.
9.1. Due to the "Local Geo Webhosting" feature, the physical location of data processing depends on the server location chosen by the Data Controller.
9.2. If the Data Controller selects a server location outside the European Economic Area (EEA) or in a country without an adequacy decision by the EU Commission, the transfer and processing are governed by the EU Standard Contractual Clauses (SCCs), which are hereby incorporated by reference, to guarantee a GDPR-compliant level of data protection.