Data Processing Agreement (DPA)
Pursuant to Art. 28 of Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR)
This is a non-binding English translation provided for convenience. In case of any discrepancy or ambiguity, the German original version is legally binding.
§ 1 Subject Matter and Duration of the Data Processing
(1) The subject matter of this agreement is the processing of personal data by the Processor on behalf of the Controller in connection with the use of the CERTavia services.
(2) The data processing begins with the first use of CERTavia services and ends upon termination of the contractual relationship. The provisions on deletion following the end of the contract remain unaffected (§ 9).
§ 2 Nature and Purpose of the Processing, Type of Personal Data, Categories of Data Subjects
| Processing context | Type of data | Data subjects | Purpose |
|---|---|---|---|
| Infrastructure scan (certavia.org/scan) | Domain name (may be personal data for natural persons), technical scan results | Employees or owners of the company entering their domain name | Technical review of the public infrastructure to produce the infrastructure evidence document |
| Scan report by email (optional) | Email address, domain name, CES score, cluster ratings, timestamp | Employees or owners who provide their email address | One-time delivery of the scan result upon request |
| Purchase of an infrastructure evidence document | Email address (from Stripe), domain name, time of purchase | Employees or owners who make the purchase | Contract performance: creation and delivery of the ordered evidence document |
| Newsletter sign-up | Email address, newsletter type, timestamp of sign-up and confirmation, IP address at DOI confirmation | Employees or owners who subscribe to the newsletter | Delivery of the subscribed newsletter; proof of consent |
| Contact form | Name, email address, message content, and if applicable phone number and company | Employees or owners who use the contact form | Processing and responding to the inquiry |
| Customer portal — team invitations (Annual/Enterprise) | Email address of the invited person, no further data | Colleagues invited by account holders who have not themselves consented | Granting portal access to team members; deletion upon decline or at the latest 30 days after invitation without acceptance |
The CERTavia scanner processes exclusively publicly accessible technical infrastructure parameters (DNS records, HTTP headers, SSL configuration, public web content). Page content, internal system data, and personal user data of the scanned domain are not collected.
§ 3 Controller's Right to Issue Instructions
(1) The Processor shall process personal data exclusively on documented instructions from the Controller, unless required to do so by Union or Member State law.
(2) Instructions may be given in writing (by email to [email protected]). Verbal instructions must be confirmed in writing without delay.
(3) If the Processor is of the opinion that an instruction infringes applicable data protection law, it shall inform the Controller thereof without delay. The Processor is entitled to suspend the execution of the instruction until the matter is clarified.
§ 4 Obligations of the Processor
The Processor undertakes in particular to:
- Process personal data exclusively on the instructions of the Controller (§ 3);
- Ensure that all persons authorized to process the data are bound by confidentiality (Art. 28(3)(b) GDPR);
- Take all technical and organizational measures required under Art. 32 GDPR (§ 6);
- Comply with the conditions for engaging further processors set out in § 7;
- Taking into account the nature of the processing, assist the Controller in complying with data subject rights (Art. 12–22 GDPR);
- Assist the Controller in complying with the obligations set out in Art. 32–36 GDPR;
- At the Controller's choice, delete or return all personal data upon termination of the processing (§ 9);
- Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR.
§ 5 Notification Obligations
(1) The Processor shall assist the Controller in complying with the obligations under Art. 32–36 GDPR (security of processing, notification of personal data breaches, data protection impact assessment, prior consultation).
(2) The Processor shall notify the Controller of personal data breaches without undue delay, and in any event within 72 hours of becoming aware of them. Notification shall be sent by email to the Controller's most recently known email address.
§ 6 Technical and Organizational Measures (TOMs)
The Processor implements appropriate technical and organizational measures pursuant to Art. 32 GDPR to protect the personal data processed. The measures currently implemented include:
Confidentiality
- Transport encryption: TLS 1.2 / 1.3 for all data transfers
- Encryption of data at rest in the Hetzner database (AES-256)
- Access control: role-based access management, MFA for administrative access
- Pseudonymization of scan logs through IP truncation (last octet removed)
Integrity
- Cryptographic signature of all audit records (Ed25519)
- DNS anchoring of vault records for tamper resistance
- Audit logs for administrative database access
Availability and Resilience
- Hosting infrastructure in certified data centers (Hetzner, ISO 27001)
- Cloudflare CDN with DDoS protection for the web presence
- Regular data backups (daily backups, 7-day retention)
Procedures for Regular Review
- Semi-annual review and update of security measures
- Automatic deletion routines for expired data records (scan leads after 30 days, vault records after 90 days on the Basic tier)
§ 7 Use of Sub-Processors
(1) The Processor is entitled to engage further processors (sub-processors). Sub-processor relationships shall be disclosed to the Controller. Publication at certavia.org/datenschutz constitutes the Controller's general authorization unless the Controller objects within 14 days of disclosure.
(2) Sub-processors currently engaged:
| Sub-processor | Location | Processing purpose | Third-country safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Gunzenhausen, Germany | Hosting of the scan API and database (scan_leads, newsletter_leads) | EU processing (no third country) |
| Cloudflare, Inc. | San Francisco, USA | Hosting of certavia.org (Cloudflare Pages), CDN, DDoS protection, Turnstile CAPTCHA | EU-US Data Privacy Framework |
| Stripe, Inc. / Stripe Payments Europe, Ltd. | San Francisco, USA / Dublin, Ireland | Payment processing | EU-US Data Privacy Framework, SCCs |
| Resend, Inc. | San Francisco, USA | Transactional emails, newsletter delivery, double opt-in confirmations | SCCs pursuant to Art. 46 GDPR |
| Calendly LLC | Atlanta, USA | Booking of initial calls (Enterprise inquiries) | SCCs pursuant to Art. 46 GDPR |
(3) The Processor imposes data protection obligations on its sub-processors that are equivalent to those agreed in this contract.
§ 8 Controller's Audit Rights
(1) The Controller has the right to verify the Processor's compliance with data protection provisions and with the agreements in this contract.
(2) Reviews are generally conducted by requesting documentation, certificates, or audit reports. On-site inspections are possible upon prior notice (at least 14 days) and at the Controller's expense.
(3) Requests for evidence and documentation should be directed to: [email protected]
§ 9 Deletion and Return After Termination
(1) Upon termination of the contractual relationship, the Processor shall, at the Controller's choice, delete or return all personal data processed in connection with the engagement, unless a statutory obligation requires further retention.
(2) Upon request, the Processor shall confirm complete deletion in writing.
(3) Statutory retention obligations (in particular accounting records, 10 years) remain unaffected.
§ 10 Liability
Liability between the Controller and Processor is governed by Art. 82 GDPR and the general liability provisions of the CERTavia Terms and Conditions.
§ 11 Governing Law and Jurisdiction
This contract is governed by the law of the Federal Republic of Germany. The provisions of the CERTavia Terms and Conditions apply to disputes.
§ 12 Formation of Contract
This DPA becomes effective upon acceptance of the CERTavia Terms and Conditions when purchasing a product or signing up for a newsletter. A countersigned copy can be issued upon request.
Processor
Litzki Systems LLC
7901 4th St N, #32272
St. Petersburg, FL 33702, USA
Represented by: Thorsten Litzki
[email protected]
Controller (Client)
The company using CERTavia services.
Company name and details per proof of purchase or registration data.