Home · Legal Notices · DPA
Data Processing Agreement (DPA)
Data processing agreement for the use of the beUnity Platform · Version 1.5 · dated 18 July 2025
Note: This English translation is provided for convenience only. The legally binding version is the German original.
Preamble
This agreement specifies the data protection obligations of the contracting parties arising from the contract concluded between the parties (General Terms and Conditions of the Contractor). It applies to all activities connected with the contract in which employees of the Contractor, or persons commissioned by the Contractor, process personal data (hereinafter "data") of the Client on the Client's instructions.
Version: 1.5, dated: 18 July 2025
Parties
Agreement between the customers of beUnity AG (hereinafter referred to as the "Client") and beUnity AG, Gattikonerstrasse 123, 8136 Gattikon (hereinafter referred to as the "Contractor") on commissioned data processing pursuant to Art. 28 GDPR.
Subject matter, duration and specification of the commissioned processing
- Details of the Contractor's services are set out in the respective contract between the Contractor and the Client (hereinafter "Contract").
- The subject matter and duration of the engagement as well as the nature and purpose of the processing result from the Contract, unless otherwise specified in Annex A.
- The term of this DPA follows the term of the Contract, unless obligations extending beyond it arise from the provisions of this DPA.
Scope of application and responsibility
- The Contractor processes the data specified in Annex A on behalf of the Client for the purpose and to the extent stated therein.
- The instructions are initially defined by the Contract and may thereafter be amended, supplemented or replaced by the Client through individual instructions in writing or in an electronic format (text form) addressed to the office designated by the Contractor (individual instruction). Instructions not provided for in the Contract are treated as a request for a change of services. Instructions of a specifying or clarifying nature do not constitute changes of services. The same applies to instructions intended to ensure compliance with applicable data protection requirements. Oral instructions must be confirmed by the Client in writing or in text form without delay.
Obligations of the Contractor
- The Contractor may process data of data subjects only within the scope of the engagement and the Client's instructions, unless a mandatory statutory exception applies. The Contractor informs the Client without delay if it considers an instruction to be unlawful. The Contractor may suspend the implementation of the instruction until it has been confirmed or amended by the Client.
- Within its area of responsibility, the Contractor structures its internal organisation in such a way that it meets the specific requirements of data protection. It will take technical and organisational measures to adequately protect the Client's data that satisfy the applicable legal requirements. The Contractor must take technical and organisational measures that ensure the confidentiality, integrity, availability and resilience of the systems and services in connection with the processing on a lasting basis. The Client is aware of these technical and organisational measures.
- The measures taken by the Contractor are described in more detail in Annex B. The technical and organisational measures are subject to technical progress and further development. In this respect, the Contractor is permitted to implement alternative adequate measures. In doing so, the security level of the defined measures must not be undercut. Significant changes must be documented and notified to the Client in good time in advance.
- To the extent agreed, the Contractor supports the Client, within the scope of its capabilities, in fulfilling the requests and claims of data subjects and in complying with data protection obligations.
- The Contractor warrants that the persons authorised to process the data have been obliged to process data only in accordance with the instructions. Furthermore, the Contractor warrants that the persons authorised to process the personal data have committed themselves to confidentiality or are subject to an appropriate statutory duty of secrecy. The duty of confidentiality/secrecy continues to apply after the end of the engagement.
- The Contractor informs the Client without delay if it becomes aware of breaches of the protection of the Client's personal data or has concrete suspicion of such a breach. The Contractor takes the necessary measures to secure the data and to mitigate possible adverse consequences for the data subjects, and consults with the Client on this without delay.
- The Contractor names the following contact for data protection questions arising under the Contract: The data protection officer of beUnity AG, datenschutz@beunity.io.
- The Contractor warrants that it complies with its respective data protection obligations and employs a procedure for the regular review of the effectiveness of the technical and organisational measures for ensuring the security of the processing. The Contractor rectifies or erases the contractual data if the Client so instructs. If erasure in compliance with data protection law or a corresponding restriction of data processing is not possible, the Contractor undertakes the destruction of data carriers and other materials in compliance with data protection law on the basis of an individual engagement by the Client, or returns these data carriers to the Client, unless already agreed in the Contract. In special cases to be determined by the Client, the data is retained or handed over; remuneration and protective measures for this are to be agreed separately, unless already agreed in the Contract.
- Upon completion of the engagement, data, data carriers and all other materials must, at the Client's request, either be handed over or deleted. If additional costs arise due to differing specifications for the handover or deletion of the data, these are borne by the Client.
- In the event of a claim against the Client by a data subject in connection with the commissioned processing, the Contractor undertakes to support the Client in defending against the claim within the scope of its capabilities.
Obligations of the Client
- The Client must inform the Contractor without delay if it discovers errors or irregularities with regard to data protection provisions in the results of the engagement.
- The Client names to the Contractor the contact person for data protection questions arising under the Contract, insofar as this person differs from the contact persons already named by the Client.
Requests from data subjects
- If a data subject approaches the Contractor with requests for rectification, erasure or information, the Contractor will refer the data subject to the Client, provided that an assignment to the Client is possible based on the data subject's information. The Contractor forwards the data subject's request to the Client without delay. The Contractor supports the Client within the scope of its capabilities, upon instruction and to the extent agreed. The Contractor is not liable if the data subject's request is not answered by the Client, or is not answered correctly or in good time, provided the Contractor is not at fault in this respect.
Means of verification
- The Contractor demonstrates to the Client its compliance with the obligations set out in this DPA by appropriate means. This is done in particular through regular self-audits and/or certification (e.g. in accordance with ISO 27001).
- Should inspections by the Client or an auditor commissioned by the Client be necessary in individual cases, these will generally be carried out during normal business hours, without disrupting operations, following registration and taking into account an appropriate lead time. If the auditor commissioned by the Client is in a competitive relationship with the Contractor, the Contractor has a right of objection against that auditor.
- Should a data protection supervisory authority or another sovereign supervisory authority of the Client carry out an inspection, paragraph 2 applies accordingly in principle. Signing a confidentiality undertaking is not required if the supervisory authority is subject to professional or statutory confidentiality where a breach is punishable under the criminal code.
Subprocessors (further processors)
- The engagement of subprocessors by the Contractor is permissible provided that they, in turn, fulfil the requirements of this agreement to the extent of the subcontract.
- Before engaging or replacing subprocessors, the Contractor informs the Client. The information must be provided at least two months in advance in each case. The Client may object to the change vis-à-vis the Contractor for good cause within these two months. If no objection is raised within the period, consent to the change is deemed given. This does not apply if there is a legitimate objection under data protection law. If there is an important data protection reason and an amicable solution between the parties is not possible, the Contractor is granted a special right of termination if the Contractor would otherwise objectively no longer be able to fulfil its service obligations under the Contract.
- A subcontracting relationship requiring consent exists where the Contractor engages further contractors to perform all or part of the services agreed in this DPA. The Contractor will conclude agreements with these third parties to the extent necessary to ensure appropriate data protection and information security measures. Subprocessors who have no access to customer data or do not process customer data are exempt from this section and will accordingly not appear in the list referred to.
- The Contractor ensures that an agreement in accordance with Art. 28 para. 4 GDPR or the corresponding requirements of the revFADP is concluded with every subprocessor that processes personal data on its behalf, containing the same data protection obligations as this contract.
- See Annex C to the DPA "Approved subprocessors"
Duties to inform
- Should the Client's data held by the Contractor be jeopardised by seizure or confiscation, by insolvency or composition proceedings, or by other events or measures of third parties, the Contractor must inform the Client without delay. The Contractor will inform all parties responsible in this context without delay that responsibility for and control over the data under data protection law remain with the Client as controller.
Liability
- The parties are liable to each other in accordance with Art. 82 GDPR. The Contractor is fully responsible for the subprocessors it engages.
Miscellaneous
- In all other respects, the provisions of the Contract apply. In the event of any contradictions between provisions of this DPA and the provisions of the Contract, this DPA prevails. Should individual parts of this DPA be invalid, this does not affect the validity of the Contract and the remainder of the DPA.
- Annexes A and B form an integral part of this DPA.
- All legal notices, annexes, references and documents (e.g. imprint, privacy, GTC, terms of use, data processing agreement, TOM) of beUnity AG are available in a clear overview on the Legal Notices page.
Annex A: Description of the personal data / data categories and description of the categories of data subjects
Subject matter of the engagement
Processing of the Client's personal data in the context of its use of the Contractor's services as a SaaS (Software as a Service) provider of the community platform beunity.app.
Nature and purpose of the intended processing of data
The personal data processed by the Client is transferred to the Contractor within the scope of the Software as a Service offering. The Contractor processes this data exclusively in accordance with the agreement reached (operation of the beUnity community platform).
Nature of the personal data
The data types depend on the data transmitted by the Client. They are (depending on the engagement):
- Personal master data (address, name) including contact details (e.g. telephone, e-mail)
- Contract data, including billing and payment data
- History of the contract data
Categories of data subjects
The categories of data subjects depend on the data transmitted by the Client. They are (depending on the engagement):
- Member data of the community members
- Employees (including applicants and former employees) of the Client
- Customers of the Client
- Prospects of the Client
- Service providers of the Client
- Contact details of contact persons
Erasure, blocking and rectification of data
Requests for erasure, blocking and rectification must be addressed to the Client; in all other respects, the provisions of the Contract apply.
Annex B: Technical and organisational measures (TOM)
For security reasons, this annex is not publicly accessible and is made available upon legitimate request by existing or prospective customers.
Annex C: Approved subprocessors and processors
The list of our subprocessors (including name, location and purpose) is publicly available under Approved subprocessors and processors. We provide further technical details or contractual documents upon legitimate request.