Data Processing Addendum
Data processing agreement pursuant to Article 28 GDPR
1. Subject Matter, Scope, and Legal Foundations
Subject Matter of the Agreement
This Data Processing Addendum (DPA) governs the processing of personal data pursuant to Article 28 of the General Data Protection Regulation (GDPR) between the controller (customer) and the processor Workbase Platforms Sp. z o.o. (Leadbase). This Agreement forms an integral part of the main agreement and specifies the data protection obligations of both parties.
Scope
This Agreement applies to all processing activities involving personal data that Leadbase performs for the controller as part of providing the agreed services. This includes in particular:
- Lead data enrichment and validation
- CRM integration and data transfer
- API-based data processing
- Webhook processing and real-time updates
- Data export and reporting services
- Backup and archiving of customer data
Legal Foundations
This Agreement is based on the following legal foundations:
- EU General Data Protection Regulation (GDPR): Articles 28, 32, 33, 44-49
- Federal Data Protection Act (BDSG) in its current version
- Polish data protection law (Ustawa o ochronie danych osobowych)
- EU Standard Contractual Clauses for international data transfers
Definitions
The definitions in the GDPR apply to this Agreement. In addition, the following terms are defined as follows:
- Leadbase Services: All services provided through the platform
- Customer Data: All personal data provided by the controller
- Enriched Data: Information supplemented through Leadbase Services
- Third-Party Data Sources: External data providers and public sources
2. Nature, Purpose, and Duration of Data Processing
Detailed Processing Purposes
Personal data is processed exclusively for the following clearly defined purposes:
Primary Processing Purposes
- Lead Enrichment: Supplementing incomplete contact data with missing information
- Data Validation: Reviewing and correcting existing records
- CRM Synchronization: Bidirectional data transfer with customer systems
- Duplicate Detection: Identifying and cleaning up duplicate records
- Data Quality Review: Automated quality assessment and improvement
Secondary Processing Purposes
- System Monitoring: Monitoring the quality of data processing
- Performance Analytics: Aggregated analyses for service optimization
- Compliance Reporting: Documentation for audit and compliance purposes
- Technical Support: Troubleshooting and customer support
Types and Methods of Processing
- Automated Processing: API-based data queries and transfers
- Algorithm-Based Processing: Machine learning for data matching
- Manual Processing: Only for customer support and problem resolution
- Batch Processing: Scheduled bulk processing of records
- Real-Time Processing: Immediate data processing through webhooks
Processing Duration
Processing takes place for the duration of the contractual relationship plus statutory retention periods. Specific deletion periods:
- Active Processing: During the term of the contract
- Backup Storage: 90 days after the end of the contract
- Log Data: 12 months for security and compliance purposes
- Compliance Documentation: 10 years as required by law
3. Comprehensive Categories of Personal Data and Data Subjects
Persons
Categories of Data Subjects
Primary Target Groups
- Managing Directors and C-Level Executives: CEOs, CTOs, CFOs, CMOs
- Managers: Department heads, team leaders, regional directors
- Sales Employees: Account managers, sales representatives, business development
- Marketing Professionals: Marketing managers, digital marketing specialists
- IT Decision-Makers: IT managers, system administrators, software architects
- Procurement and Purchasing Professionals:{" "} Procurement managers, buyers
Extended Target Groups
- HR Professionals: HR managers, recruiters, talent acquisition
- Finance Professionals: Controllers, accountants, finance directors
- Operations Managers: Operations managers, logistics managers, production managers
- Compliance Officers: Legal departments, data protection officers
Categories of Personal Data
Identification Data
- Master Data: First and last name, title, gender
- Contact Data: Email addresses (business/private), telephone numbers (landline/mobile)
- Address Data: Business and private address, postal code, city, country
- Online Identities: Social media profiles, LinkedIn, XING, website URLs
Professional Information
- Position and Hierarchy: Job title, department, reporting line, seniority
- Areas of Responsibility: Professional areas, budget responsibility, team size
- Professional Experience: Career history, previous positions, industry experience
- Qualifications: Education, certifications, specializations
Company-Related Data
- Company Information: Company name, legal form, registration number
- Corporate Structure: Parent company, subsidiaries, locations
- Business Data: Industry, revenue, number of employees, founding year
- Technology Stack: Software used, CRM systems, IT infrastructure
Behavioral Data and Preferences
- Communication Preferences: Preferred channels, times, languages
- Interest Profiles: Professional topics, product interests, event participation
- Engagement Data: Email open rates, website visits, content interactions
Special Categories and Exclusions
Leadbase generally processes NO special categories of personal data under Article 9 GDPR (racial/ethnic origin, political opinions, religious beliefs, trade union membership, health data, sex life). If such data is processed accidentally, it will be deleted immediately and the controller will be notified.
4. Detailed Technical and Organizational Measures (TOMs)
Leadbase has implemented comprehensive technical and organizational measures that meet the requirements of Article 32 GDPR and reflect the state of the art:
Technical Security Measures
Encryption and Cryptography
- Data Transmission: TLS 1.3 with Perfect Forward Secrecy for all API communications
- Data Storage: AES-256 encryption for data at rest (Data at Rest)
- Database Encryption: Transparent Data Encryption (TDE) at database level
- Backup Encryption: End-to-end encrypted backups with separate keys
- Key Management: Hardware Security Modules (HSM) for key management
Access Control and Authentication
- Multi-Factor Authentication: Mandatory for all admin access
- Role-Based Authorization:{" "} Least-privilege principle with granular permissions
- Session Management: Automatic session timeouts and concurrent session control
- API Security: OAuth 2.0 with JWT tokens and rate limiting
- Privileged Access Management: Just-in-time access for administrative activities
Network and Infrastructure Security
- Firewall Systems: Next-generation firewalls with deep packet inspection
- Intrusion Detection/Prevention: Real-time monitoring and automatic defense
- VPN Access: Encrypted VPN connections for remote access
- Network Segmentation: Isolated network zones according to security levels
- DDoS Protection: Cloudflare Enterprise with anti-DDoS functionality
Monitoring and Logging
- SIEM System: Security Information and Event Management with real-time alerting
- Audit Logging: Complete logging of all data access
- Log Integrity: Cryptographic signing of log files
- Anomaly Detection: Machine-learning-based detection of abnormal activity
- 24/7 SOC: Security Operations Center with continuous monitoring
Organizational Security Measures
Personnel and Training
- Background Checks: Comprehensive screening of all employees before hiring
- Confidentiality Obligations: Legally binding NDAs for all employees
- Security Awareness Training: Regular training on data protection and IT security
- Phishing Simulations: Monthly tests of employee awareness
- Incident Response Training: Regular exercises for emergency situations
Processes and Policies
- Information Security Policy: Comprehensive security policies
- Data Classification: Classification of all data according to protection requirements
- Change Management: Controlled change processes for all systems
- Vendor Management: Security assessment of all suppliers
- Business Continuity: Emergency and recovery plans
Physical Security
- Data Center Security: Tier III/IV data centers with biometric controls
- Office Security: Access control, clean desk policy, visitor management
- Hardware Security: Secure destruction of data media
- Environmental Controls: Climate monitoring, fire protection, UPS systems
Data Protection by Design (Privacy by Design)
- Data Minimization: Processing only the required data fields
- Pseudonymization: Use of hash values wherever possible
- Anonymization: Statistical analyses without personal references
- Purpose Limitation: Strict purpose limitation in the system architecture
- Data Protection Impact Assessment: Regular data protection impact assessments
5. Comprehensive Management of Sub-Processors
Principles of Sub-Processing
Sub-processors are engaged exclusively under the provisions of Article 28 GDPR and only with the controller's prior written authorization or within the scope of a general written authorization.
Current Sub-Processors
Leadbase works with the following carefully selected sub-processors:
Cloud Infrastructure and Hosting
- Amazon Web Services (AWS): EU regions (Frankfurt, Ireland): server hosting, database
- Google Cloud Platform: EU regions: backup services and analytics
- Cloudflare Inc.: EU locations: CDN, DDoS protection, edge computing
Communications and Support
- Email Delivery: Transactional emails
- Intercom: Customer support chat and ticketing system
- Slack Technologies: Internal communication (only in support cases)
Analytics and Monitoring
- Google Analytics 4: Website analytics (IP anonymization enabled)
- Sentry.io: Error tracking and performance monitoring
- New Relic: Application performance monitoring
Payment Processing
- Autumn: Subscription billing and revenue management
- Stripe Inc.: Payment processing (through Autumn)
Selection Criteria for Sub-Processors
- GDPR Compliance: Demonstrated compliance with GDPR requirements
- Certifications: ISO 27001, SOC 2 Type II, or comparable standards
- Data Protection Certifications: Privacy Shield successor framework or EU adequacy decision
- Technical Security: State-of-the-art security measures
- Financial Stability: Sufficient creditworthiness and insurance coverage
- Transparency: Willingness to undergo audits and provide compliance evidence
Contracts with Sub-Processors
- GDPR-Compliant DPA: Data processing agreements under Article 28 GDPR
- Instruction Binding: Obligation to process only according to documented instructions
- Confidentiality: Comprehensive confidentiality obligations
- Security Measures: Minimum requirements for technical and organizational measures
- Audit Rights: Right to review compliance with the agreements
- Liability: Clear liability provisions and proof of insurance
- Deletion: Obligation to securely delete data after the end of the contract
Adding New Sub-Processors
When adding new sub-processors, Leadbase informs the controller in writing at least 30 days in advance about planned changes. The controller has the right to object in writing within 14 days. In the event of a justified objection, Leadbase will seek alternative solutions or grant the controller an extraordinary right of termination.
Monitoring and Compliance Oversight
- Regular Audits: Annual review of all sub-processors
- Compliance Monitoring: Continuous monitoring of contractual compliance
- Incident Reporting: Immediate notification of security incidents
- Performance Reviews: Regular assessment of service quality
6. International Data Transfers and Safeguards
Principles for International Data Transfers
Leadbase transfers personal data only to third countries for which an adequate level of data protection has been established or for which appropriate safeguards exist under Articles 44-49 GDPR.
Transfers to Countries with an Adequacy Decision
- United Kingdom: EU Commission adequacy decision of June 28, 2021
- Switzerland: EU Commission adequacy decision
- Other EU Adequacy Countries: According to the current status of the EU Commission
Transfers to the USA
The following safeguards apply to transfers of data to the USA:
- EU-US Data Privacy Framework: For DPF-certified companies
- EU Standard Contractual Clauses (SCC): As the primary legal basis
- Additional Safeguards: Encryption, pseudonymization, data minimization
- Transfer Impact Assessment (TIA): Regular assessment of the level of protection
EU Standard Contractual Clauses (SCC)
For transfers to third countries without an adequacy decision, Leadbase uses the current EU Standard Contractual Clauses of the EU Commission dated June 4, 2021:
- Module 2: Controller to Processor
- Module 3: Processor to Processor
- Additional Safeguards: Technical and organizational safeguards
- Exit Clauses: Suspension in the event of insufficient protection
Additional Technical Safeguards
- End-to-End Encryption: Protection against unauthorized access by authorities
- Pseudonymization: Replacement of direct identifiers with pseudonyms
- Data Minimization: Transfer of only the absolutely necessary data
- Segregation: Physical and logical separation of EU and third-country data
- Key Management: EU-based key management under EU control
Monitoring and Compliance
- Transfer Logs: Complete logging of all third-country transfers
- Regular Reviews: Semiannual review of transfer mechanisms
- Legal Updates: Immediate adjustment when the legal situation changes
- Incident Response: Contingency plans in the event transfer mechanisms are suspended
Transparency Toward Controllers
Leadbase proactively informs controllers about:
- All planned third-country transfers and their legal basis
- Changes to sub-processors in third countries
- Government access or corresponding requests
- Changes in the legal or factual circumstances
7. Data Subject Rights and Assistance Obligations
General Duty to Assist
Leadbase supports the controller with suitable technical and organizational measures in fulfilling its obligations to respond to requests from data subjects exercising their rights under Chapter III GDPR.
Specific Assistance with Data Subject Rights
Right of Access (Article 15 GDPR)
- Data Provision: Export of all data stored about a person within 5 business days
- Structured Preparation: Machine-readable formats (JSON, CSV, XML)
- Processing Evidence: Documentation of all processing activities
- Source Information: Information about the origin of enriched data
- Recipient Lists: List of all data recipients
Right to Rectification (Article 16 GDPR)
- Immediate Correction: Prompt correction of inaccurate data
- Synchronization: Forwarding corrections to all data recipients
- Completion: Supplementing incomplete data upon request
- Documentation: Evidence of corrections performed
Right to Erasure (Article 17 GDPR)
- Complete Deletion: Removal from all systems and backups
- Technical Implementation: Cryptographic erasure through destruction of keys
- Cascade Deletion: Automatic deletion in connected systems
- Deletion Confirmation: Evidence of complete data removal
- Recipient Information: Notification of all data recipients
Right to Restriction of Processing (Article 18 GDPR)
- Technical Blocking: Marking and isolating the affected data
- Access Control: Restriction of processing authorization
- Notification System: Warning before any processing of blocked data
- Tamper-Proof Documentation: Evidence of the restriction measures
Right to Data Portability (Article 20 GDPR)
- Structured Export Formats: JSON, CSV, XML according to industry standards
- API-Based Transfer: Direct transfer to other controllers
- Automated Portability: Self-service portal for data export
- Data Validation: Checking export integrity before transfer
Right to Object (Article 21 GDPR)
- Immediate Cessation of Processing: Within 24 hours after an objection
- Balancing of Interests: Review of overriding legitimate interests
- Documented Reasoning: Written explanation of the decision
- Cessation of Profiling: Discontinuation of automated profiling
Procedure and Service Level Agreements
- Acknowledgment of Receipt: Within 24 hours after the request
- Identity Verification: Secure verification of the requesting person
- Processing Time: Maximum 5 business days for complete implementation
- No Charge: No processing fees for justified requests
- Transparent Communication: Regular updates on processing status
Technical Implementation
- Automated Workflows: Systems for efficient request processing
- Data Discovery: Automatic identification of all relevant records
- Audit Trail: Complete logging of all measures
- Quality Assurance: Multiple validation before implementation
8. Personal Data Breaches and Incident Response
Definition and Categorization of Personal Data Breaches
A personal data breach is a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data transmitted, stored, or otherwise processed.
Severity Categorization
- Category 1: Critical: High likelihood of significant risks (notification within 2 hours)
- Category 2: High: Possible risks to rights and freedoms (notification within 12 hours)
- Category 3: Medium: Limited impact (notification within 24 hours)
- Category 4: Low: Minimal or no impact (notification within 72 hours)
Incident Response Process
Immediate Measures (0-1 Hour)
- Incident Detection: Automated detection through SIEM systems
- Initial Assessment: Rapid assessment of severity
- Containment: Immediate containment to limit damage
- Team Alerting: Notification of the incident response team
- Communication Channel: Establishment of dedicated communication channels
Medium-Term Measures (1-24 Hours)
- Detailed Analysis: Comprehensive forensic investigation
- Damage Assessment: Assessment of the impact on data subjects
- Root Cause Analysis: Identification of causes and vulnerabilities
- Customer Notification: Informing the controller within the agreed deadlines
- Documentation: Complete logging of all measures
Long-Term Measures (24-72 Hours)
- Remediation: Complete resolution of security vulnerabilities
- System Hardening: Strengthening of security measures
- Lessons Learned: Analysis and integration of improvements
- Compliance Reporting: Complete documentation for supervisory authorities
- Communications Management: Coordinated internal and external communication
Notification Obligations and Procedures
Notification of the Controller
- Immediate Reporting: Within the agreed deadlines according to severity
- Structured Information: Standardized incident report with all relevant details
- Continuous Updates: Regular status reports until complete remediation
- Final Documentation: Comprehensive final report with all findings
Report Contents
- Nature of the Breach: Detailed description of the incident
- Categories of Affected Data: Specification of the compromised data
- Number of Affected Persons: Estimated or known number
- Likely Consequences: Assessment of risks to data subjects
- Measures Taken: Immediate measures and planned remediation
- Contact Information: Contact person for further information
Assistance with Notifications to Authorities
Leadbase supports the controller in fulfilling its notification obligation to the competent supervisory authority under Article 33 GDPR by providing:
- Complete Documentation: Provision of all relevant information
- Technical Expertise: Professional support in root cause analysis
- Compliance Advice: Advice on legal notification obligations
- Direct Cooperation: Cooperation with supervisory authorities on instruction
Preventive Measures and Continuous Improvement
- Vulnerability Management: Regular vulnerability scans and remediation
- Penetration Testing: Annual external security tests
- Incident Response Drills: Regular exercises and emergency simulations
- Security Awareness: Continuous employee training
- Technology Updates: Regular updates and patches for all systems
9. Comprehensive Audit Rights and Compliance Evidence
General Audit Rights of the Controller
The controller has the right to review Leadbase's compliance with the provisions of this Agreement and data protection requirements. This includes both its own reviews and the engagement of external auditors.
Types of Audits and Reviews
Document-Based Audits
- Compliance Documentation: Evidence of compliance with all agreed measures
- Certificates and Attestations: ISO 27001, SOC 2 Type II, GDPR compliance
- Policy Reviews: Review of all security and data protection policies
- Incident Reports: Complete documentation of all security incidents
- Training Evidence: Proof of employee training and certifications
Remote Audits
- Virtual System Reviews: Remote access to audit-relevant systems
- Online Interviews: Discussions with key personnel by video conference
- Digital Evidence Collection: Electronic provision of evidence
- Real-Time Monitoring: Live insight into monitoring systems and dashboards
On-Site Audits
- Physical Inspection: Review of office and data center security
- Employee Interviews: In-person discussions with security and data protection personnel
- Technical Reviews: Inspection of IT infrastructure and security systems
- Process Observation: Monitoring of critical business processes
Available Compliance Evidence
International Certifications
- ISO 27001:2013: Information Security Management System
- SOC 2 Type II: Service Organization Control for Security, Availability, Confidentiality
- ISO 27017: Cloud Security Controls
- ISO 27018: Privacy in Public Cloud Computing
- ISO 22301: Business Continuity Management
Data Protection-Specific Evidence
- GDPR Compliance Certificate: External audit of GDPR compliance
- Privacy Impact Assessments:{" "} Data protection impact assessments for all services
- Data Protection Officer Certification:{" "} Qualifications of the DPO
- Privacy by Design Assessment: Assessment of privacy-friendly system design
Technical Security Evidence
- Penetration Test Reports: Annual external security tests
- Vulnerability Assessment: Regular vulnerability analyses
- Encryption Standards Compliance: Evidence of encryption standards
- Business Continuity Testing: Reports on emergency and recovery tests
Audit Procedures and Planning
Audit Notice and Planning
- Lead Time: At least 30 days' advance notice for on-site audits
- Scope Definition: Clear delimitation of the areas to be reviewed
- Auditor Qualifications: Evidence of the auditors' professional suitability
- Confidentiality Agreements: NDA signature by all auditors
- Scheduling Coordination: Coordination with all relevant stakeholders
Conducting the Audit
- Dedicated Support: Provision of an audit coordinator
- Document Access: Full access to all relevant documents
- System Demonstrations: Demonstration of critical security systems
- Interview Sessions: Discussions with key personnel
- Evidence Collection: Collection and provision of evidence
Audit Follow-Up
- Draft Report Review: Opportunity to comment before finalization
- Finding Response: Timely response to identified vulnerabilities
- Remediation Plan: Detailed plan to remedy deficiencies
- Follow-Up Audits: Review of implementation of improvement measures
- Continuous Improvement: Integration of findings into ongoing processes
Costs and Frequency
- Regular Audits: One document-based audit per year free of charge
- Additional Audits: Free of charge in the event of justified suspicion or incidents
- On-Site Audits: Travel and accommodation costs borne by the controller
- External Auditors: Fees for external auditors borne by the controller
- Compliance Reports: Standard compliance reports provided free of charge
Restrictions and Safeguards
- Trade Secrets: Protection of Leadbase's confidential business information
- Other Customers: No jeopardizing the security of other customers' data
- Operational Disruptions: Minimization of interruptions to ongoing operations
- Time Limitation: Reasonable duration of audit activities
10. Liability, Insurance, and Damages
Principles of Allocation of Liability
Liability between the controller and Leadbase is governed by the provisions of the GDPR, in particular Article 82, and the provisions of the main agreement. Both parties are liable for damage they cause by violating their data protection obligations.
Liability of Leadbase
Fault-Based Liability
- Intent and Gross Negligence: Unlimited liability for all damage
- Breach of Cardinal Obligations: Liability up to the amount of the foreseeable, typical damage
- Simple Negligence: Liability only in the event of breach of material contractual obligations
- Vicarious Agents: Liability for the fault of employees and sub-processors
Specific Data Protection Liability
- Data Protection Breaches: Liability for damage caused by inadequate technical safeguards
- Unlawful Processing: Liability for processing without instructions or beyond instructions
- Sub-Processors: Full liability for data protection breaches by subcontractors
- International Transfers: Liability for damage caused by unauthorized third-country transfers
Exclusions and Limitations of Liability
- Force Majeure: No liability for unforeseeable, unavoidable events
- Controller's Fault: No liability for damage caused by incorrect instructions
- Contributory Causation: Reduced liability where the controller contributed to the damage
- Limitation Period: Claims for damages become time-barred 3 years after knowledge
Liability of the Controller
- Unlawful Processing: Liability for unlawful processing instructions
- Incorrect Legal Bases: Liability where the legal basis is missing or incorrect
- Inaccurate Information: Liability for damage caused by incorrect data information
- Missing Data Subject Rights: Liability for inadequate information of data subjects
Types and Scope of Damage
Material Damage
- Direct Damage: Direct costs of data protection breaches
- Recovery Costs: Costs of data recovery and system repair
- Compliance Costs: Costs of notifications to supervisory authorities and data subjects
- Legal Costs: Reasonable attorneys' fees and court costs
Non-Material Damage
- Violations of Personality Rights: Compensation for non-material damage from violation of personality rights
- Reputational Damage: Loss of business opportunities through loss of trust
- Opportunity Costs: Lost profits due to business interruption
Regulatory Sanctions
- GDPR Fines: Official sanctions under Article 83 GDPR
- Orders of Supervisory Authorities: Costs of implementing official requirements
- International Sanctions: Fines and penalties in other jurisdictions
Insurance Coverage
Leadbase Cyber Insurance
- Coverage Limit: At least EUR 10 million for cyber risks
- Scope of Coverage: Data protection breaches, cyber attacks, business interruption
- Geographic Coverage: Worldwide, including the USA and Canada
- Regulatory Defense: Coverage for defense against regulatory proceedings
- Crisis Management: PR support and crisis management
General Liability Insurance
- Coverage Limit: At least EUR 5 million for general liability
- Professional Liability: Specific coverage for IT services
- Financial Losses: Coverage for pure financial losses
- Proof Obligation: Annual submission of current insurance certificates
Damage Handling and Mitigation
- Immediate Measures: Immediate damage limitation and prevention
- Cooperation: Close cooperation in settling damage claims
- Documentation: Complete documentation of all damage and measures
- External Expertise: Involvement of lawyers and experts
- Preventive Measures: Implementation of measures to prevent damage
11. Term, Termination, and Data Return
Term and Renewal
This Data Processing Agreement enters into force upon conclusion of the main agreement and applies for the entire term of the contractual relationship. If the main agreement is renewed, this Agreement is automatically extended for the corresponding term.
Ordinary Termination
- Termination with Main Agreement: This Agreement ends automatically with the main agreement
- Separate Termination: Termination of this Agreement alone is possible while the main agreement continues
- Notice Period: 3 months to the end of a calendar quarter
- Written Form: Termination must be in writing (email is sufficient)
Extraordinary Termination
Termination Right of the Controller
- Serious Data Protection Breach: In the event of material violations of data protection obligations
- Official Order: If processing is prohibited by supervisory authorities
- Sub-Processors: If Leadbase refuses to replace impermissible sub-processors
- Audit Refusal: If cooperation in justified audits is refused
- Insolvency: If insolvency proceedings are opened over Leadbase's assets
Termination Right of Leadbase
- Unlawful Instructions: In the event of persistent unlawful processing instructions
- Payment Default: In the event of payment arrears exceeding 2 monthly installments
- Refusal to Cooperate: In the event of insufficient cooperation by the controller
- Legal Impossibility: If a change in the legal situation makes processing impossible
Comprehensive Data Return and Deletion Process
Data Return Options
- Complete Export: Export of all personal data in structured formats
- Selective Export: Export of specific data categories at the controller's request
- System-to-System Transfer: Direct transfer to new processors
- API-Based Transfer: Continuous data transfer through standardized interfaces
Export Formats and Standards
- Structured Formats: JSON, XML, CSV according to industry standards
- Database Dumps: Native database exports where technically compatible
- API-Compliant Formats: REST/GraphQL-compatible data structures
- Human-Readable Reports: PDF reports for compliance purposes
Data Integrity and Validation
- Checksums: Cryptographic checksums for all exported data
- Completeness Check: Verification of export completeness
- Data Quality Check: Validation of data integrity before export
- Documentation: Detailed documentation of all exported data fields
Secure Data Deletion
Scope of Deletion
- Complete Deletion: Removal of all personal data from all systems
- Backup Deletion: Secure deletion from all backup and archiving systems
- Log Cleanup: Anonymization or deletion of log entries containing personal references
- Cache Clearing: Deletion from all temporary storage and cache systems
Deletion Methods
- Cryptographic Erasure: Destruction of encryption keys
- Secure Deletion: Multiple overwriting according to NIST standards
- Physical Destruction: Physical destruction of storage media when hardware is replaced
- Database Shredding: Complete removal at database level
Deletion Confirmation
- Deletion Certificate: Written confirmation of complete data deletion
- Audit Trail: Documentation of all deletion activities
- Technical Verification: Technical proof of successful deletion
- Compliance Statement: Confirmation of compliance with all regulatory requirements
Exceptions to the Deletion Obligation
- Statutory Retention Obligations: Tax and commercial-law archiving obligations (max. 10 years)
- Legal Proceedings: Retention for ongoing or threatened court proceedings
- Compliance Documentation: Anonymized retention for audit and compliance purposes
- Security Analyses: Anonymized security logs for incident response (max. 2 years)
Schedule and Service Level Agreements
- Data Export: Provision within 30 days after the end of the contract
- Transition Period: 90 days to ensure data migration
- Deletion: Complete deletion within 120 days after the end of the contract
- Support: Technical support throughout the entire transition phase
Costs of Data Return
- Standard Export: Provision in standard formats free of charge
- Custom Exports: Reasonable cost contribution for special export requirements
- Express Services: Surcharge for accelerated data return (< 14 days)
- Technical Support: Basic support free of charge, special services subject to a fee
12. Final Provisions and Legal Framework
Relationship to the Main Agreement
This Data Processing Agreement is an integral part of the main agreement concluded between the parties. In the event of conflicts between the provisions, the provisions of this DPA take precedence insofar as they concern data protection aspects.
Amendments and Additions
- Written Form Requirement: Amendments must be in writing (email is sufficient)
- Legal Updates: Automatic adjustment in the event of changes to the GDPR or relevant laws
- Technical Updates: Adjustment of technical measures in line with the state of the art
- Notification Obligation: Information about material changes 30 days in advance
- Right to Object: Right to terminate in the event of unreasonable changes
Applicable Law and Jurisdiction
- German Law: Application of German law excluding the UN Convention on Contracts for the International Sale of Goods
- GDPR Priority: Direct application of the EU General Data Protection Regulation
- Jurisdiction: Munich for all disputes arising from this Agreement
- International Jurisdiction: German courts for all data protection proceedings
Dispute Resolution and Mediation
- Out-of-Court Dispute Resolution: Obligation to conduct mediation before filing a lawsuit
- Mediation Body: Recognized mediation institution in Munich
- Expedited Procedures: Accelerated procedures in urgent data protection cases
- Expert Determination: Expert proceedings for technical points of dispute
Multilingualism and Interpretation
- German Version: The German version is authoritative for matters of interpretation
- Translations: English translations are available but are not legally binding
- Technical Terms: GDPR terminology according to German case law
Severability
If individual provisions of this Agreement are or become invalid or unenforceable, this does not affect the validity of the remaining provisions. The parties undertake to replace invalid provisions with valid provisions that come closest to the economic purpose of the invalid provision.
Transfer and Assignment
- Consent Requirement: Transfer of rights and obligations only with consent
- Intra-Group Transfer: Free transfer within the group of companies
- Asset Deal: Automatic transfer upon sale of the business
- Notification Obligation: Information about all transfers
Contact and Communication
For data protection inquiries: Email: privacy@leadbase.io Post: Data Protection Officer, Franz-Joseph-Str. 11, 80801 Munich, Germany For contractual matters: Email: legal@leadbase.io Post: Legal Department, Franz-Joseph-Str. 11, 80801 Munich, Germany For technical questions: Email: support@leadbase.io
Effective Date and Validity
This Data Processing Agreement enters into force upon signing of the main agreement and replaces all previous agreements concerning the same subject matter. The Agreement remains fully effective even if individual provisions are partially invalid.