Data Processing Agreement

Data Processing Agreement

in accordance with Art. 28 General Data Protection Regulation (GDPR)

Status: April 2026

This data processing agreement (DPA) is part of the usage contract between the customer (controller/data controller) and EUCERTA AG (processor/data processor). It is automatically accepted upon conclusion of the usage contract for app.eucerta.eu / cockpit.eucerta.eu. A separate signature is not required according to Art. 28 Para. 9 DSGVO.

Preamble

This data processing agreement (hereinafter "DPA") specifies the data protection obligations of the contracting parties in accordance with Art. 28 GDPR. It applies to all activities where EUCERTA AG processes personal data of the client as a data processor in the context of using the platforms app.eucerta.eu and cockpit.eucerta.eu.

EUCERTA AG processes personal data exclusively according to the client's instructions and in accordance with the DSGVO as well as the Swiss Data Protection Act (nDSG).

§ 1 – Contracting Parties

Client (Controller within the meaning of Art. 4 No. 7 GDPR):

The company or the natural or legal person who has concluded the usage contract with EUCERTA AG (hereinafter "Client" or "Customer").

Contractor (Processor within the meaning of Art. 4 No. 8 GDPR):

EUCERTA AG, registered in the Swiss Commercial Register

Email:support@eucerta.eu| Web:www.eucerta.eu

(hereinafter "EUCERTA" or "Contractor")

§ 2 – Subject Matter and Duration of Processing

(1) The subject matter of the data processing is the provision and operation of the SaaS platforms app.eucerta.eu (management system for ISO certification processes) and cockpit.eucerta.eu (administration portal) for the client.

(2) This DPA applies for the entire duration of the usage contract. It ends automatically upon termination of the usage contract, subject to the regulations on data storage and deletion in § 8 of this DPA.

§ 3 – Type and Purpose of Processing

EUCERTA processes the following categories of personal data within the scope of the commissioned service provision:

Data category

Processing purpose

Storage location

Account data (name, email, company name, address)

Access to the platform, communication, contract processing

app.eucerta.eu (Server EU)

Audit data (uploaded documents, form responses, evidence)

Implementation of ISO certification process

app.eucerta.eu (Server EU)

Certificate data (number, scope, date)

Exhibition and management of certificates

cockpit.eucerta.eu (Server EU)

Usage data (IP address, login data, activity log)

IT security, platform operations, troubleshooting

Server log files (automatically deleted after 30 days)

AI-processed content (via Anthropic Claude API)

AI-supported document creation, audit support

Anthropic API – max. 7 days, no training with customer data

Affected persons: Employees, managing directors and other representatives of the client who use the system or whose data is processed as part of the certification process.

§ 4 – Obligations of the Contractor (EUCERTA)

4.1 Obligation to follow instructions

(3) EUCERTA processes personal data of the client exclusively on the basis of documented instructions from the client as well as in accordance with the requirements of this DPA.

(4) Instructions may be given in writing (including email). Verbal instructions must be confirmed in writing immediately.

(5) If EUCERTA is of the opinion that an instruction violates applicable data protection law, EUCERTA will immediately inform the client and suspend the execution of the instruction until a legally compliant clarification is achieved.

4.2 Confidentiality

(6) EUCERTA ensures that all persons who have access to the client's personal data are committed to confidentiality or are subject to a statutory duty of confidentiality.

(7) EUCERTA processes the data exclusively for the commissioned purposes. Use for its own purposes or for third parties is excluded.

4.3 Technical and organizational measures (Art. 32 GDPR)

(8) EUCERTA implements appropriate technical and organizational measures (TOM) to ensure a level of protection commensurate with the risk. These include in particular:

• Encryption of data transmission (TLS/SSL) and storage of sensitive data

• Access and authorization management (Least Privilege Principle)

• Regular security updates and vulnerability analyses

• Backup systems and disaster recovery procedures

• Physical security measures at the server location (data center in the EU)

(9) The current TOM can be requested by the client at any time via email tosupport@eucerta.eurequested.

§ 5 – Notification obligations for data protection breaches (Art. 33 and 34 GDPR)

This section explicitly fulfills the requirements according to Art. 33 DSGVO (notification to supervisory authority) and Art. 34 DSGVO (notification of affected persons).

(10) EUCERTA will inform the client immediately and completely – at the latest within 24 hours of becoming aware – of any personal data breach that could lead to a violation of the rights and freedoms of natural persons.

(11) The notification to the client is sent by email to the address stored in the user account as well as additionally to the contact person specified in the usage contract. The notification contains at least the following information:

• Description of the type of violation (categories and approximate number of affected persons and data records)

• Name and contact details of the responsible contact person at EUCERTA

• Probable consequences of the violation

• Measures taken or proposed for remediation and mitigation

(12) EUCERTA documents all data protection breaches internally in accordance with Art. 33 para. 5 DSGVO and provides the client with access to this documentation upon request.

(13) The obligation to report the breach to the competent data protection supervisory authority (pursuant to Art. 33 para. 1 DSGVO) and the notification of affected persons (pursuant to Art. 34 DSGVO) lies with the client as the controller. EUCERTA supports the client in this to the best of its ability.

(14) EUCERTA also reports such incidents where a data protection breach is initially only suspected and the suspicion is later not confirmed, if there were sufficient indications of an incident at the time of reporting.

§ 6 – Support Obligation of the Contractor (Art. 28 Para. 3 lit. e GDPR)

This section explicitly fulfills the requirement of the obligation to assist in accordance with Art. 28 para. 3 lit. e DSGVO.

(15) EUCERTA supports the client in accordance with Art. 28 Para. 3 lit. e DSGVO in fulfilling the following data protection obligations through appropriate technical and organizational measures:

• Responding to data subject requests (information, rectification, erasure, restriction, data portability according to Art. 15–22 GDPR)

• Compliance with security obligations according to Art. 32 GDPR

• Notification of personal data protection breaches according to Art. 33, 34 DSGVO (see § 5 of this AVV)

• Conducting data protection impact assessments in accordance with Art. 35 GDPR

• Prior consultation with the supervisory authority in accordance with Art. 36 GDPR

(16) If EUCERTA receives a request from a data subject that relates to the client's data, EUCERTA forwards this immediately to the client. EUCERTA does not respond to requests from data subjects in its own name, but only upon instruction from the client.

(17) For the support according to this § 6, EUCERTA provides the following functions via the platform functions of app.eucerta.eu and cockpit.eucerta.eu, which the client can use independently:

• Data export: complete export of all personal data as CSV/JSON (file format according to § 9 of this DPA)

• Data self-deletion: independent deletion of individual data records in the system

• User inquiries: direct contact viasupport@eucerta.eufor complex data subject requests

§ 7 – Right of inspection of the client (Art. 28 para. 3 lit. h DSGVO)

This section expressly fulfills the right of control pursuant to Art. 28 Para. 3 lit. h DSGVO.

(18) The client has the right to monitor EUCERTA's compliance with the provisions of this DPA as well as applicable data protection regulations at any time to the necessary extent.

(19) The right of inspection can be exercised as follows:

• Written inquiries (via email to support@eucerta.eu): EUCERTA responds to inquiries regarding data processing, TOM and security measures within 10 working days.

• Provision of evidence: EUCERTA provides relevant certifications, test reports and certificates upon request (e.g. according to ISO 27001 or comparable evidence).

• On-site inspection: The client may conduct an on-site audit at EUCERTA's business premises during regular business hours after prior notification with a notice period of at least 15 working days. Inspections must be limited to the minimum necessary extent.

• Authorized Third Party: The client may commission a qualified third party (e.g. external data protection auditor) to conduct the control, provided that this party is bound to confidentiality.

(20) EUCERTA is obligated to provide the client with all information required for the control and to make the corresponding evidence available.

(21) EUCERTA immediately informs the client if a supervisory authority conducts control measures at EUCERTA, insofar as these relate to the processing of the client's data.

(22) The costs for on-site inspections according to para. 2 (third bullet point) shall be borne by the client, insofar as the effort exceeds what is required under the contractually owed documentation and provision of information.

§ 8 – Data Deletion and Return Upon Contract Termination

(23) Upon termination of the usage contract, all personal data of the client stored on app.eucerta.eu and cockpit.eucerta.eu will be deleted or returned upon request of the client.

(24) The following deadlines apply:

Data category

Deletion period

Notice

User accounts, contact data

30 days after contract termination

On request also immediately; retrieval possible via data export

Audit Documents, Form Responses

30 days after contract termination

Previous export as PDF/CSV recommended

Certificate data (reference)

30 days after contract termination

Certificate PDF remains with the customer; deletion of platform reference

Server log files

30 days (automatic)

Independent of contract termination

Invoices, payment receipts

NO deletion by EUCERTA

Legal retention obligation 10 years (§ 257 HGB, § 147 AO); data at Digistore24

Claude API (AI Processing)

Max. 7 days (automatic)

Processing by Anthropic API – no use for AI training

(25) At the client's request, EUCERTA makes all data available for download in a common, machine-readable format prior to deletion (see § 9 of this DPA).

(26) Upon completion of deletion, EUCERTA shall provide the client with written proof of deletion upon request.

(27) Documentation that serves as proof of proper data processing will be retained beyond the end of the contract insofar as this is legally required.

§ 9 – Data Export by the Client (Right to Data Portability)

(28) The client can independently export their personal data as well as all data created during use from app.eucerta.eu and cockpit.eucerta.eu at any time. The following export formats are available:

Data type

I need the German text to translate. You've only provided the word "Format" which appears to be either a heading or you're asking about the format. Could you please provide the German text you'd like me to translate?

Description

Certificates

PDF

Official Certificate with QR Code for Verification

Audit Documentation & QM Manual

PDF

Complete documentation of the management system

Form responses & raw data

CSV

All entered data in tabular form (machine-readable)

Complete data export (DSGVO Art. 20)

ZIP (PDF + CSV + JSON)

All personal data and documents as a complete package

(29) The export can be accessed by the client themselves through the "My Account" / "Settings" area in app.eucerta.eu and cockpit.eucerta.eu – without requiring consultation with EUCERTA.

§ 10 – Use of Subcontractors (Sub-Processors)

(30) EUCERTA uses the following subcontractors to provide the commissioned services, to whom personal data of the client may be transmitted:

Subcontractor

Purpose

Location / Data Protection Level

Anthropic PBC (Claude API)

AI Support for Document Creation and Audits

USA – commercial API conditions; no training with customer data; max. 7 days storage

Hosting Provider (EU Data Center)

Server infrastructure for app.eucerta.eu and cockpit.eucerta.eu

EU – GDPR compliant, server location Germany/Switzerland

Digistore24 GmbH

Payment processing (no access to audit/certificate data)

Germany – GDPR-compliant; own privacy policy

(31) EUCERTA concludes separate data processing agreements with all subcontractors to whom personal data is transmitted, ensuring a data protection level equivalent to this DPA.

(32) In the event of significant changes regarding the use of subcontractors, EUCERTA will inform the client in a timely manner. The client may object to a planned change if there are factual reasons.

§ 11 – Obligations of the Client

(33) The client is responsible for the lawfulness of the processing of personal data within the meaning of the DSGVO.

(34) The client ensures that they have a valid legal basis for processing personal data before it is entered into the platform.

(35) The client informs EUCERTA immediately about errors or irregularities in the processing of personal data that become known to them.

(36) The obligation to report to the supervisory authority resulting from Art. 33 Para. 1 DSGVO lies with the client.

§ 12 – Liability and Final Provisions

(37) The liability provisions between the parties are governed by Art. 82 GDPR as well as the liability agreements made in the usage contract.

(38) This DPA is subject to the law of the Federal Republic of Germany, supplemented by the relevant provisions of the Swiss Data Protection Act (nDSG).

(39) Amendments to this DPA require text form. EUCERTA will announce amendments with at least 30 days' advance notice. The client has the right to terminate the usage contract extraordinarily in case of material amendments.

(40) Should individual provisions of this DPA be or become invalid, the validity of the remaining provisions shall remain unaffected.

(41) This DPA is valid in electronic form in accordance with Art. 28 Para. 9 GDPR and is accepted by both parties upon conclusion of the usage contract for app.eucerta.eu or cockpit.eucerta.eu. A signature in paper form is not required.

Accepted through contract conclusion:

Client (Controller)

The company / the person according to the usage agreement

Accepted: through contract conclusion (online, according to GTC)

Contractor (Data Processor)

EUCERTA AG, Zurich, Switzerland

Represented by: Christian Paredes, Managing Director

This AVV is available at eucerta.eu/avv. Status: April 2026.