Data Processing Agreement (DPA)
This is a translation for convenience. The German version is the legally binding text. View the German version.
| Contractor | NK IT Service – Nikolaj Kinas, Rauentaler Str. 22/1, 76437 Rastatt, Germany – sole trader |
| support@nk-it.de | |
| Scope of activity | Web hosting, web development, IT maintenance, remote support, monitoring, licence management, IT services |
| Client | As set out in the underlying main contract or in the client portal |
| Contract version | 4.0 |
| Valid from | Date of digital confirmation in the NK IT client portal |
Section 1 – Subject matter, definitions and order of precedence
1.1 The Contractor processes personal data exclusively on behalf of and on documented instructions from the Client in accordance with Article 28 GDPR, to the extent that this is necessary for the services owed under the contract.
1.2 For the purposes of this agreement, the Client is the controller (Article 4(7) GDPR) and the Contractor is the processor (Article 4(8) GDPR).
1.3 This DPA forms part of the respective main contract. In the event of conflicts, the provisions of this DPA take precedence in matters of data protection law. Liability limitations and service levels of the main contract apply in addition, unless mandatory data protection law provides otherwise.
1.4 Where the Contractor processes data in fulfilment of its own legal obligations – for example for invoicing, contract management, evidence of the conclusion of the contract, tax obligations or the pursuit of legal claims – it acts as a controller in its own right in that respect. Such processing on its own behalf is not covered by this DPA.
1.5 Annexes 1 to 5 form an integral part of this agreement. Updates may be communicated in text form, provided that the level of protection is not materially reduced.
Section 2 – Nature, purpose and duration of the processing
2.1 The subject matter of this agreement is the processing of personal data in connection with the following commissioned IT services: web hosting and server operation, web development and website creation, IT maintenance and technical support, remote support, monitoring and alerting, licence management and security software, general IT services.
2.2 The processing serves exclusively to perform the main contract and to keep IT operations secure. No processing takes place for marketing, profiling or other extraneous purposes of the Contractor.
2.3 The duration of the processing corresponds to the term of the main contract plus the retention and deletion periods set out in Section 12.
Section 3 – Categories of personal data and of data subjects
3.1 The categories of data processed and the data subjects concerned are listed in detail in Annex 2.
3.2 Special categories of data under Article 9 GDPR as well as criminal-offence data and data covered by professional secrecy are not part of the standard service. The Client is obliged to inform the Contractor of such data before the service begins.
3.3 Wherever possible, anonymised or pseudonymised data is to be used in test and development environments.
Section 4 – Obligations and area of responsibility of the Client
4.1 The Client remains solely responsible for the lawfulness of the processing, the choice of legal bases, compliance with information obligations and the data protection compliant use of the commissioned services.
4.2 The Client names the contacts authorised to issue instructions and keeps these details up to date. It informs the Contractor without undue delay of security incidents or compromised access credentials.
4.3 The Client may not issue instructions that infringe applicable law or endanger the security of the systems. In the case of manifestly unlawful instructions, the Contractor may refuse to carry them out.
4.4 Where the Client specifies particular cloud or software services, it is also responsible for whether these are permissible under data protection law.
4.5 The Client is obliged to back up data adequately before changes or migrations that carry a risk, unless a backup is expressly part of the agreed scope of services.
Section 5 – General obligations of the Contractor
5.1 Bound by instructions: The Contractor processes personal data exclusively on documented instructions from the Client. This agreement, the main contract, service descriptions, support tickets, e-mails and approvals in the client portal count as documented instructions.
5.2 Confidentiality: The Contractor ensures that all persons involved in the processing are bound to confidentiality. Access is granted on a need-to-know basis.
5.3 No use for own purposes: The Contractor is expressly prohibited from using the entrusted data for its own purposes – in particular advertising, profiling or disclosure to unapproved third parties.
5.4 Immediate measures: The Contractor is entitled to take the immediate measures required to maintain security, even without prior instruction. The Client is informed without undue delay.
5.5 Support services: As part of standard operations, the Contractor supports the Client with data subject rights (Articles 15–22 GDPR), notification obligations and data protection impact assessments. Extensive additional services are provided against separate remuneration.
Section 6 – Technical and organisational measures (TOMs)
6.1 The Contractor takes appropriate technical and organisational measures in accordance with Article 32 GDPR. The measures applicable at the time the contract is concluded are described in Annex 3.
6.2 Where the Client manages its own systems, devices or accounts, it remains responsible for their secure basic configuration.
Section 7 – Sub-processors
7.1 The Client grants general authorisation for the use of the sub-processors listed in Annex 4. The Contractor ensures that agreements are in place with them which meet the requirements of this DPA.
7.2 Changes are communicated in text form at least 14 calendar days before they take effect. An objection is possible within 14 days, stating a specific data protection reason.
7.3 For transfers to third countries (including US-based services), the Contractor relies on the current Standard Contractual Clauses (SCC) and/or the EU-US Data Privacy Framework.
Section 8 – Instructions, contacts and change management
8.1 Instructions must be issued in text form (e-mail, client portal, ticket system). Verbal instructions must be confirmed in writing without undue delay.
8.2 Standardised operating processes, security updates, monitoring and backup routines are deemed to be instructions documented in advance by the Client.
8.3 Instructions that result in additional work or additional services are remunerated separately.
Section 9 – Support with data subject rights and compliance
9.1 Requests from data subjects that reach the Contractor and concern the area of responsibility of the Client are forwarded without undue delay. A direct response is only given on express instruction.
9.2 The Contractor supports the Client within the scope of Article 28(3)(e)–(h) GDPR (data subject rights under Articles 15–22, data protection impact assessment, consultation of the supervisory authority) insofar as its systems are affected.
9.3 Support services are provided during regular business hours. Extensive additional services are remunerated separately.
Section 10 – Notification of personal data breaches
10.1 On becoming aware of a personal data breach, the Contractor reports it to the Client without undue delay, at the latest within 24 hours of its internal initial assessment. Incomplete information may be supplied later.
10.2 As far as available, the report contains: the nature of the incident, the systems/services affected, the categories of data affected, the assessed impact and the measures taken.
10.3 The Contractor is entitled to take the immediate measures required for containment, even without a prior individual instruction.
10.4 Assessing the obligation to notify the supervisory authorities (72-hour deadline, Article 33 GDPR) and the data subjects (Article 34 GDPR) remains the responsibility of the Client as controller.
Section 11 – Inspection rights, evidence and audits
11.1 Evidence is provided primarily by means of suitable documents: this DPA, descriptions of the technical and organisational measures, self-disclosure or certification records (preferred method, free of charge).
11.2 On-site inspections are permitted where documents are not sufficient or where there is a specific indication of serious breaches. They must be announced at least 20 working days in advance and take place during regular business hours.
11.3 The costs of an on-site audit are borne by the Client. In the absence of a specific reason, on-site audits are limited to once a year.
11.4 Penetration tests or active technical interventions require separate written consent.
Section 12 – Deletion, return and retention after the end of the contract
12.1 After the main contract ends, the processed data is returned or deleted at the choice of the Client. This choice must be communicated in text form within 30 days of the end of the contract.
12.2 Data is returned in a common, technically available format. The effort required for special exports is remunerated separately.
12.3 Retention period: data subject to retention obligations under commercial and tax law is kept for 8 years (§ 147 AO, § 257 HGB). It is then securely and irreversibly deleted.
12.4 Backup copies may remain in place until the rotation cycles expire in the normal course, provided they are not used productively.
12.5 Confirmation of deletion is issued in text form on request.
Section 13 – Confidentiality, personnel and remote access
13.1 All persons deployed are granted access only within the scope of their tasks, are bound to confidentiality and are made aware of data protection requirements.
13.2 Remote access and administrative access are permitted to the extent necessary to provide the services. The Client acknowledges that modern IT services cannot be provided without such access.
13.3 Provided the level of security set out in Annex 3 is maintained, the services may also be delivered while working from home or working remotely.
Section 14 – Specially protected data and high-risk processing
14.1 If the Client processes data that is subject to professional secrecy obligations or to special statutory protection rules (e.g. health data, data held by lawyers), it must disclose this in text form before the service begins.
14.2 For environments with a particularly high need for protection, the Contractor may require additional protective measures or separate project annexes.
14.3 If the Contractor only becomes aware during the provision of the services that data with a special need for protection is being processed, it may provisionally suspend the service until the matter is clarified.
Section 15 – Liability, indemnification and the relationship between the parties
15.1 The mandatory liability provisions of the GDPR (Article 82) remain unaffected. In all other respects, the main contract applies in addition.
15.2 The Client shall indemnify the Contractor on first demand against claims by third parties which are based on unlawful instructions, missing legal bases, unlawful data content or security deficiencies within the area of responsibility of the Client.
15.3 The Contractor is not liable for disruptions caused by systems managed by the Client, unsecured access credentials, third-party providers specified by the Client or external outages (force majeure).
15.4 No guarantee is given that supervisory authorities will accept any particular data protection arrangements.
Section 16 – Final provisions
16.1 Amendments must be made in text form. The Contractor may adapt this DPA in the event of material legal or technical changes; the Client is informed at least 30 days before the changes take effect.
16.2 The law of the Federal Republic of Germany applies. The place of jurisdiction is – to the extent legally permissible – the registered office of the Contractor.
16.3 Severability clause: Invalid provisions do not affect the validity of the remaining provisions.
16.4 This DPA may be concluded digitally. Timestamp, user ID and IP address are deemed suitable evidence that the contract has been concluded.
Annex 1 – Details of the commissioned processing activities
| Service module | Processing operations | Examples of data |
|---|---|---|
| Web hosting / server operation | Storing, backing up, logging, administering | Operating and usage data, contact enquiries, logs |
| Web development | Collecting, testing, migrating, versioning | CMS content, form data, user accounts |
| IT support / maintenance | Reading out, changing, documenting, restoring | User and contact data, tickets, system configurations |
| Remote support | Accessing, viewing, editing, logging | All data technically accessible in the systems concerned |
| Monitoring | Collecting, logging, analysing, alerting | IP addresses, host names, event logs |
| Backup / restore | Copying, archiving, restoring, deleting | Backup images of the production data |
| Security software / licences | Installing, configuring, updating, logging | Device, user, licence and security event data |
Annex 2 – Categories of personal data and of data subjects
| Data category | Examples | Data subjects |
|---|---|---|
| Contact data | Name, company, address, e-mail, telephone | Employees, customers, contacts |
| Contract & billing data | Customer numbers, invoice data, IBAN, contract data | Clients, contractual partners |
| Access & authorisation data | User names, password hashes, MFA details, SSH keys | Employees, administrators, users |
| Usage & communication data | Email content, tickets, support docs, forms | Employees, customers, end users |
| Content data in client environments | Website content, database records, CMS and shop data | End customers, users, members |
| Log & telemetry data | IP addresses, timestamps, browser data, log files | Users, visitors, administrators |
| Device & inventory data | Inventory, serial and licence numbers, configuration details | Employees, administrators |
Not covered are special categories of data under Article 9 GDPR and data protected by professional secrecy, unless expressly agreed in advance.
Annex 3 – Technical and organisational measures (TOMs)
| No. | Area | Measures |
|---|---|---|
| 1 | Organisation & governance | Documented responsibilities, need-to-know principle, all personnel bound to confidentiality and data protection |
| 2 | Physical access control | Access to offices and local systems only for authorised persons; for external data centres the measures of the data centre operator apply |
| 3 | System access control | Personalised accounts, strong passwords (at least 12 characters), two-factor authentication (2FA) for all admin systems |
| 4 | Data access control | Role-based assignment of rights, restriction to the systems required, regular review |
| 5 | Transmission control | Data transfers via TLS/HTTPS (at least 1.2), VPN, SSH; remote support via secured tools |
| 6 | Storage control | Backup storage encrypted wherever possible; passwords stored as hashes, not in plain text |
| 7 | Input control | Logging of security-relevant events; logs deleted or rotated according to set periods |
| 8 | Separation of client data | Logical separation of client data through separate accounts, directories and databases |
| 9 | Availability | Regular backups, 24/7 monitoring via Pulseway, patch management, GDATA/Bitdefender endpoint protection, firewalls |
| 10 | Recoverability | Restore procedures for commissioned backup and system services, documented emergency processes |
| 11 | Protection against malware | Current security updates, GDATA CyberDefense and/or Bitdefender, automatic definition updates |
| 12 | Working from home / mobile working | Secured devices, encrypted communication, screen lock, restrictive local copies of data |
| 13 | Deletion | Deletion according to process, deadline or client instruction; storage media securely erased or physically destroyed |
| 14 | Review | Regular review of the protective measures, assessment of new risks, adaptation to the state of the art |
Annex 4 – Sub-processors
| Provider | Service | Location | Third-country transfer |
|---|---|---|---|
| HostEurope GmbH | Web hosting, server infrastructure | DE / EU | No third-country transfer |
| Hetzner Online GmbH | Servers, cloud, storage | DE / EU | No third-country transfer |
| IONOS SE | Hosting, domains, cloud | DE / EU | No third-country transfer |
| Microsoft Ireland / Corp. | Microsoft 365, Azure, Exchange | EU / int. | SCC + Data Privacy Framework |
| Google Ireland / LLC | Workspace, cloud, security tools | EU / int. | SCC + Data Privacy Framework |
| Amazon Web Services EMEA | Cloud, compute, storage, backup | EU / int. | SCC + Data Privacy Framework |
| G DATA CyberDefense AG | Endpoint protection, licences | DE / EU | No third-country transfer |
| Bitdefender SRL | Endpoint protection, EDR/XDR | EU (RO) | Telemetry where applicable, SCC |
| Pulseway (MMSOFT Design) | Monitoring, RMM, automation | EU / int. | SCC / DPF where applicable |
| TeamViewer Germany GmbH | Remote support, remote access | DE / EU | Depending on routing, SCC |
| Meta / WhatsApp Business | Communication (where commissioned) | EU / int. | Third-country transfer possible, SCC |
Annex 5 – Contacts, instruction channels and standard processes
| Topic | Provision |
|---|---|
| Persons authorised to issue instructions (Client) | As per main contract / client portal |
| Point of receipt (Contractor) | NK IT Service – Nikolaj Kinas | support@nk-it.de | portal/ticket system |
| Standard instruction channels | Email, client portal, ticket system; verbal instructions to be confirmed in writing without undue delay |
| Security and incident reports | Primarily via the known support contacts; in urgent cases additionally by telephone |
| Audit and information requests | In text form, stating purpose and scope; remote evidence takes precedence |
| Data subject requests | Forwarded to the Client; no direct response without instruction |
| Return / export after the end of the contract | Request in text form within 30 days of the end of the contract |
| Data breach notification | Initial report to the Client within 24 h; the Client notifies the supervisory authority (72-hour deadline, Article 33 GDPR) |
