Data Processing Agreement (DPA)
Parties
This Data Processing Agreement ("DPA") is entered into between:
Data Controller ("Controller"):
The Customer as identified in the TSI Solution GmbH account registration or signed Order Form.
Data Processor ("Processor"):
TSI Solution GmbH, Pfalzgasse 7/1/61, 1220 Wien, Austria
UID: ATU82721002 · FN: 666498 w
Email: privacy (at) tel-tsi.eu
Together referred to as the "Parties". This DPA forms part of the Terms of Service between the Parties.
1. Definitions
Terms used but not defined here have the meanings given in the GDPR (EU) 2016/679 and the Terms of Service.
- "GDPR" - Regulation (EU) 2016/679 of the European Parliament and of the Council.
- "Personal Data" - any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller.
- "Processing" - any operation performed on Personal Data, as defined in Art. 4(2) GDPR.
- "Sub-processor" - any third party engaged by the Processor to carry out Processing on behalf of the Controller.
- "Data Subject" - the natural person to whom the Personal Data relates (e.g. employees or authorised users of the Controller).
2. Subject Matter and Duration
The Processor shall process Personal Data on behalf of the Controller for the purpose of providing the TEL TSI Compliance Companion SaaS service ("Service") as described in the Terms of Service. Processing shall continue for the duration of the subscription term and shall cease upon termination of the Terms of Service, subject to Clause 9 (Return and Deletion).
3. Nature, Purpose, and Scope of Processing
3.1 Processing Activities
| Activity | Personal Data Involved | Purpose |
|---|---|---|
| Account management | Email address, organisation name, user role | Authentication, access control, account administration |
| Assessment storage | Assessment answers and progress (state_json), assessment name, timestamps | Saving and restoring self-assessment progress; generating compliance reports |
| Team management | Email addresses of invited team members | Multi-user organisation workspace management |
| Billing administration | Subscription status, plan, payment-processor customer ID | Subscription enforcement and billing management |
| Technical operations | IP addresses in server logs (retained max 30 days) | Security monitoring, abuse prevention, debugging |
3.2 Categories of Data Subjects
Authorised Users of the Controller who use the Service (typically employees, contractors, or compliance officers of the Controller's organisation).
3.3 Special Categories
The Service is not designed to process special categories of personal data as defined in Art. 9 GDPR (e.g. health data, biometric data). The Controller must not submit such data to the Service.
4. Controller's Obligations
The Controller represents and warrants that:
- it has a valid legal basis under the GDPR for directing the Processor to process Personal Data;
- it has provided all required notices to and obtained all required consents from Data Subjects;
- its instructions to the Processor comply with applicable data protection law;
- it will not instruct the Processor to process Personal Data in a manner that would cause the Processor to violate the GDPR or other applicable law.
5. Processor's Obligations
5.1 Instructions
The Processor shall process Personal Data only on documented instructions from the Controller. The Terms of Service and this DPA constitute the Controller's documented instructions. The Processor shall inform the Controller without undue delay if, in its opinion, an instruction violates the GDPR or other applicable data protection law.
5.2 Confidentiality
The Processor shall ensure that persons authorised to process Personal Data are bound by an appropriate duty of confidentiality and receive adequate data protection training.
5.3 Security
The Processor shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, at minimum:
- Encryption of all Personal Data in transit (TLS 1.2+) and at rest (AES-256);
- Row-Level Security (RLS) in the database ensuring each organisation can only access its own data;
- Short-lived JWT authentication tokens (1-hour expiry) and refresh token rotation;
- Access to production systems restricted to authorised personnel;
- Vulnerability disclosure channel at security (at) tel-tsi.eu.
5.4 Data Subject Rights
The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures to fulfil its obligations to respond to Data Subject requests under Chapter III of the GDPR (rights of access, rectification, erasure, restriction, portability, and objection). The Processor shall forward any Data Subject request it receives directly to the Controller within 5 business days.
5.5 Data Protection Impact Assessments
The Processor shall provide reasonable assistance to the Controller in carrying out data protection impact assessments (DPIAs) and, where required, prior consultations with supervisory authorities, to the extent that such assessments or consultations relate to the Processing activities described in this DPA.
5.6 Notification of Personal Data Breaches
The Processor shall notify the Controller without undue delay - and in any case within 48 hours - after becoming aware of a Personal Data Breach affecting Controller's Personal Data. Notification shall include, to the extent available: a description of the nature of the breach; the categories and approximate number of Data Subjects affected; the categories and approximate volume of records affected; the likely consequences; and the measures taken or proposed to address the breach.
6. Sub-processors
6.1 Authorised Sub-processors
The Controller provides general authorisation for the Processor to engage Sub-processors in the following categories. The current list of specific Sub-processors, including their corporate identity and location, is maintained by the Processor and made available to the Controller on request to privacy (at) tel-tsi.eu:
| Category | Service | Location | Transfer Mechanism |
|---|---|---|---|
| Cloud database & authentication hosting | Database hosting, authentication (email/password and third-party single sign-on), Edge Functions | EU (Frankfurt, Germany) | Sub-processor DPA; data stays in EEA |
| Product analytics | Aggregate, cookieless usage measurement (page views and feature usage); in-memory storage only, no cookies, no session recording | EU | Sub-processor DPA; data stays in EEA |
| Web analytics | Aggregate, cookieless page-view measurement (page URL, referring page, browser, device type, approximate location to city level); no cookies, no local storage, no session recording. The visitor identifier is derived from the request by the provider and discarded after 24 hours. Provided by the application and API hosting sub-processor listed below, and it inherits that location. | EU edge / US | Sub-processor DPA; EU SCCs for US transfers |
| Application & API hosting | Front-end and serverless API hosting | EU edge / US | Sub-processor DPA; EU SCCs for US transfers |
| Payment processing | Payment processing (billing data only) | US / EU | Sub-processor DPA; EU SCCs; independent controller for payment card data |
| Email delivery | Transactional and notification email delivery (recipient email address and message content only) | US | Sub-processor DPA; EU SCCs for US transfers |
6.2 Changes to Sub-processors
The Processor shall give the Controller at least 14 days' prior written notice (by email to the account owner) of any intended addition or replacement of Sub-processors. The Controller may object to such changes on reasonable data-protection grounds within 14 days. If the Controller objects and the Processor is unable to resolve the objection, either party may terminate the Agreement with 30 days' notice without liability for the termination itself.
6.3 Processor Obligations for Sub-processors
The Processor shall impose on each Sub-processor data protection obligations equivalent to those in this DPA by way of a written contract. The Processor remains fully liable to the Controller for the performance of Sub-processors' obligations.
7. International Data Transfers
Processing of Personal Data under this DPA takes place primarily within the EEA (EU Frankfurt region). Where any transfer to a third country outside the EEA is required (e.g. via application hosting or payment processing), it shall be made:
- pursuant to Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914), incorporated herein by reference; or
- on the basis of another transfer mechanism approved under Art. 46 GDPR.
Copies of applicable SCCs are available from privacy (at) tel-tsi.eu on request.
8. Audits and Compliance
The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with Art. 28 GDPR. Upon at least 30 days' prior written notice, the Processor shall allow for and contribute to audits conducted by the Controller or a mutually agreed third-party auditor, provided that:
- audits are conducted during normal business hours and do not unreasonably disrupt operations;
- the Controller bears all costs of such audits unless a material breach by the Processor is identified;
- the auditor executes a non-disclosure agreement acceptable to the Processor.
The Processor may satisfy audit requests by providing up-to-date third-party security certifications or audit reports (e.g. SOC 2 Type II reports from its Sub-processors) in lieu of on-site audits.
9. Return and Deletion of Personal Data
Upon expiry or termination of the Terms of Service, the Processor shall:
- make all Customer Personal Data available for download in JSON format for a period of 30 days from the termination date;
- delete all copies of Customer Personal Data from its systems and those of its Sub-processors (to the extent permitted by Sub-processor agreements) within 60 days of the termination date, unless retention is required by applicable law (e.g. Austrian tax law retention of billing records for 7 years);
- provide written confirmation of deletion to the Controller upon request.
10. Liability
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Where both Parties are liable in respect of the same damage suffered by a Data Subject, Art. 82(5) GDPR apportions liability between them according to their respective degrees of responsibility for the damage.
11. Governing Law
This DPA is governed by the laws of Austria. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Wien (Vienna), Austria, subject to any mandatory consumer-protection jurisdiction rights.
12. Order of Precedence
In case of conflict between this DPA and the Terms of Service, this DPA shall prevail to the extent the conflict concerns the processing of Personal Data. In all other matters, the Terms of Service shall prevail.
Signatures
This DPA is effective upon acceptance of the Terms of Service. Enterprise Customers requiring a countersigned copy should contact privacy (at) tel-tsi.eu.
TSI Solution GmbH
Pfalzgasse 7/1/61, 1220 Wien, Austria
Annex A - Technical and Organisational Measures (TOMs)
The following measures are implemented by TSI Solution GmbH as of the version date of this DPA:
| Category | Measure |
|---|---|
| Pseudonymisation & Encryption | All Personal Data encrypted in transit (TLS 1.2+) and at rest (AES-256, managed by our EU database provider). Authentication tokens are short-lived JWTs. |
| Confidentiality | Database Row-Level Security (RLS) ensures each organisation accesses only its own data. Production access limited to authorised personnel under NDA. |
| Integrity & Availability | Our infrastructure providers offer automated daily backups with point-in-time recovery and a high-availability edge network. Target uptime: 99% monthly. |
| Access Controls | Role-based access (admin / contributor / viewer) enforced at application level and via database Row-Level Security (RLS). |
| Incident Management | Breach notification to Controller within 48 hours. Security incidents tracked to resolution. Vulnerability disclosure at security (at) tel-tsi.eu. |
| Supplier Management | All Sub-processors bound by Data Processing Agreements. Sub-processor list maintained and notified to Controller as per Clause 6. |
| Physical Security | All infrastructure is cloud-hosted. Physical security of data centres is the responsibility of our infrastructure sub-processors under their respective certifications. |