Data Processing Agreement (DPA)

Version 1.2 Template date: 7 July 2026 GDPR Art. 28 compliant
How to use this template. This DPA is entered into by TSI Solution GmbH (as Processor) and the Customer (as Controller) when the Customer's use of the TEL TSI Compliance Companion involves processing personal data of EU/EEA data subjects on the Customer's behalf. By accepting the Terms of Service, Customers who are data controllers are deemed to have accepted this DPA. Enterprise Customers may request a countersigned copy by emailing privacy (at) tel-tsi.eu.

Parties

This Data Processing Agreement ("DPA") is entered into between:

Data Controller ("Controller"):
The Customer as identified in the TSI Solution GmbH account registration or signed Order Form.

Data Processor ("Processor"):
TSI Solution GmbH, Pfalzgasse 7/1/61, 1220 Wien, Austria
UID: ATU82721002  ·  FN: 666498 w
Email: privacy (at) tel-tsi.eu

Together referred to as the "Parties". This DPA forms part of the Terms of Service between the Parties.

1. Definitions

Terms used but not defined here have the meanings given in the GDPR (EU) 2016/679 and the Terms of Service.

2. Subject Matter and Duration

The Processor shall process Personal Data on behalf of the Controller for the purpose of providing the TEL TSI Compliance Companion SaaS service ("Service") as described in the Terms of Service. Processing shall continue for the duration of the subscription term and shall cease upon termination of the Terms of Service, subject to Clause 9 (Return and Deletion).

3. Nature, Purpose, and Scope of Processing

3.1 Processing Activities

Activity Personal Data Involved Purpose
Account management Email address, organisation name, user role Authentication, access control, account administration
Assessment storage Assessment answers and progress (state_json), assessment name, timestamps Saving and restoring self-assessment progress; generating compliance reports
Team management Email addresses of invited team members Multi-user organisation workspace management
Billing administration Subscription status, plan, payment-processor customer ID Subscription enforcement and billing management
Technical operations IP addresses in server logs (retained max 30 days) Security monitoring, abuse prevention, debugging

3.2 Categories of Data Subjects

Authorised Users of the Controller who use the Service (typically employees, contractors, or compliance officers of the Controller's organisation).

3.3 Special Categories

The Service is not designed to process special categories of personal data as defined in Art. 9 GDPR (e.g. health data, biometric data). The Controller must not submit such data to the Service.

4. Controller's Obligations

The Controller represents and warrants that:

5. Processor's Obligations

5.1 Instructions

The Processor shall process Personal Data only on documented instructions from the Controller. The Terms of Service and this DPA constitute the Controller's documented instructions. The Processor shall inform the Controller without undue delay if, in its opinion, an instruction violates the GDPR or other applicable data protection law.

5.2 Confidentiality

The Processor shall ensure that persons authorised to process Personal Data are bound by an appropriate duty of confidentiality and receive adequate data protection training.

5.3 Security

The Processor shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, at minimum:

5.4 Data Subject Rights

The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures to fulfil its obligations to respond to Data Subject requests under Chapter III of the GDPR (rights of access, rectification, erasure, restriction, portability, and objection). The Processor shall forward any Data Subject request it receives directly to the Controller within 5 business days.

5.5 Data Protection Impact Assessments

The Processor shall provide reasonable assistance to the Controller in carrying out data protection impact assessments (DPIAs) and, where required, prior consultations with supervisory authorities, to the extent that such assessments or consultations relate to the Processing activities described in this DPA.

5.6 Notification of Personal Data Breaches

The Processor shall notify the Controller without undue delay - and in any case within 48 hours - after becoming aware of a Personal Data Breach affecting Controller's Personal Data. Notification shall include, to the extent available: a description of the nature of the breach; the categories and approximate number of Data Subjects affected; the categories and approximate volume of records affected; the likely consequences; and the measures taken or proposed to address the breach.

6. Sub-processors

6.1 Authorised Sub-processors

The Controller provides general authorisation for the Processor to engage Sub-processors in the following categories. The current list of specific Sub-processors, including their corporate identity and location, is maintained by the Processor and made available to the Controller on request to privacy (at) tel-tsi.eu:

Category Service Location Transfer Mechanism
Cloud database & authentication hosting Database hosting, authentication (email/password and third-party single sign-on), Edge Functions EU (Frankfurt, Germany) Sub-processor DPA; data stays in EEA
Product analytics Aggregate, cookieless usage measurement (page views and feature usage); in-memory storage only, no cookies, no session recording EU Sub-processor DPA; data stays in EEA
Web analytics Aggregate, cookieless page-view measurement (page URL, referring page, browser, device type, approximate location to city level); no cookies, no local storage, no session recording. The visitor identifier is derived from the request by the provider and discarded after 24 hours. Provided by the application and API hosting sub-processor listed below, and it inherits that location. EU edge / US Sub-processor DPA; EU SCCs for US transfers
Application & API hosting Front-end and serverless API hosting EU edge / US Sub-processor DPA; EU SCCs for US transfers
Payment processing Payment processing (billing data only) US / EU Sub-processor DPA; EU SCCs; independent controller for payment card data
Email delivery Transactional and notification email delivery (recipient email address and message content only) US Sub-processor DPA; EU SCCs for US transfers

6.2 Changes to Sub-processors

The Processor shall give the Controller at least 14 days' prior written notice (by email to the account owner) of any intended addition or replacement of Sub-processors. The Controller may object to such changes on reasonable data-protection grounds within 14 days. If the Controller objects and the Processor is unable to resolve the objection, either party may terminate the Agreement with 30 days' notice without liability for the termination itself.

6.3 Processor Obligations for Sub-processors

The Processor shall impose on each Sub-processor data protection obligations equivalent to those in this DPA by way of a written contract. The Processor remains fully liable to the Controller for the performance of Sub-processors' obligations.

7. International Data Transfers

Processing of Personal Data under this DPA takes place primarily within the EEA (EU Frankfurt region). Where any transfer to a third country outside the EEA is required (e.g. via application hosting or payment processing), it shall be made:

Copies of applicable SCCs are available from privacy (at) tel-tsi.eu on request.

8. Audits and Compliance

The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with Art. 28 GDPR. Upon at least 30 days' prior written notice, the Processor shall allow for and contribute to audits conducted by the Controller or a mutually agreed third-party auditor, provided that:

The Processor may satisfy audit requests by providing up-to-date third-party security certifications or audit reports (e.g. SOC 2 Type II reports from its Sub-processors) in lieu of on-site audits.

9. Return and Deletion of Personal Data

Upon expiry or termination of the Terms of Service, the Processor shall:

10. Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Where both Parties are liable in respect of the same damage suffered by a Data Subject, Art. 82(5) GDPR apportions liability between them according to their respective degrees of responsibility for the damage.

11. Governing Law

This DPA is governed by the laws of Austria. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Wien (Vienna), Austria, subject to any mandatory consumer-protection jurisdiction rights.

12. Order of Precedence

In case of conflict between this DPA and the Terms of Service, this DPA shall prevail to the extent the conflict concerns the processing of Personal Data. In all other matters, the Terms of Service shall prevail.

Signatures

This DPA is effective upon acceptance of the Terms of Service. Enterprise Customers requiring a countersigned copy should contact privacy (at) tel-tsi.eu.

Data Processor
 
Signature
 
Name & title
 
Date

TSI Solution GmbH
Pfalzgasse 7/1/61, 1220 Wien, Austria

Data Controller (Customer)
 
Signature
 
Name & title
 
Date
 
Company name & registered address

Annex A - Technical and Organisational Measures (TOMs)

The following measures are implemented by TSI Solution GmbH as of the version date of this DPA:

Category Measure
Pseudonymisation & Encryption All Personal Data encrypted in transit (TLS 1.2+) and at rest (AES-256, managed by our EU database provider). Authentication tokens are short-lived JWTs.
Confidentiality Database Row-Level Security (RLS) ensures each organisation accesses only its own data. Production access limited to authorised personnel under NDA.
Integrity & Availability Our infrastructure providers offer automated daily backups with point-in-time recovery and a high-availability edge network. Target uptime: 99% monthly.
Access Controls Role-based access (admin / contributor / viewer) enforced at application level and via database Row-Level Security (RLS).
Incident Management Breach notification to Controller within 48 hours. Security incidents tracked to resolution. Vulnerability disclosure at security (at) tel-tsi.eu.
Supplier Management All Sub-processors bound by Data Processing Agreements. Sub-processor list maintained and notified to Controller as per Clause 6.
Physical Security All infrastructure is cloud-hosted. Physical security of data centres is the responsibility of our infrastructure sub-processors under their respective certifications.