* This English version of the Data Processing Agreement is an automatically generated translation of the original German document. It is provided solely for convenience. In the event of any discrepancies or inconsistencies, the German version shall prevail and is legally binding.
Preamble
The client ("Controller") wishes to engage the contractor ("Processor") to provide the services specified in § 2. The performance of the contract involves the processing of personal data. Article 28 of the GDPR, in particular, sets out specific requirements for such data processing. To ensure compliance with these requirements, the parties enter into the following agreement.
§ 1 Definitions
For terms used in this agreement that are defined in Articles 4, 9, and 10 of the GDPR, the statutory definitions in the version applicable at the time of the conclusion of the contract shall also apply to this agreement.
§ 2 Subject Matter of the Contract
2.1 The contractor provides software-as-a-service (SaaS) for the client based on the main contract. In doing so, the contractor and its employees or those commissioned by the contractor will have access to personal data and will process it exclusively on behalf of and in accordance with the instructions of the client. The scope and purpose of the data processing by the contractor are defined in the main contract (and, if applicable, in the associated service description) as well as in Annex 1 to this agreement. The client is responsible for assessing the legality of the data processing.
2.2 The parties enter into this agreement to specify their respective rights and obligations under data protection law. In the event of any conflict, the provisions of this agreement shall take precedence over the provisions of the main contract.
2.3 The term of this agreement is governed by the term of the main contract, unless the following provisions establish obligations that extend beyond the term of the main contract. Termination rights arising from this agreement remain unaffected by the foregoing provision.
2.4 This agreement shall remain in effect beyond the end of the main contract for as long as the contractor possesses personal data that was provided by the client or collected by the contractor on the client's behalf.
2.5 The contractually agreed data processing shall generally take place within a member state of the European Union or another contracting state to the Agreement on the European Economic Area. Any transfer to a third country shall only occur if the specific requirements of Articles 44 et seq. of the GDPR are met.
§ 3 Right to Issue Instructions
3.1 The contractor may only process data within the scope of the main contract and in accordance with the client's instructions. If the contractor is required by the law of the European Union or the member states to which it is subject to perform further processing, it shall inform the client of these legal requirements prior to processing, provided that it is legally permitted to do so.
3.2 The client's instructions are initially defined by this agreement and may subsequently be changed, supplemented, or replaced by the client through individual instructions provided in writing, in text form, or via the provided software (individual instruction). The client is entitled to issue such instructions at any time. This includes instructions regarding the rectification and erasure of data as well as the restriction of processing.
3.3 All instructions issued must be documented by both the client and the contractor. Instructions that go beyond the services agreed upon in the main contract will be treated as a request for a change in services. Provisions regarding the remuneration of any additional expenses incurred by the contractor due to supplementary instructions from the client remain unaffected.
3.4 If the contractor believes that an instruction from the client violates data protection regulations, it must notify the client immediately. The contractor is entitled to suspend the execution of the instruction in question until it is confirmed or modified by the client. The contractor may refuse to carry out an obviously unlawful instruction.
Section 4 Type of Data Processed, Categories of Data Subjects
In the course of performing the main contract, the contractor will have access to the personal data of the data subjects specified in Annex 1. This data may include special categories of personal data listed and marked as such in Annex 1, provided they are submitted by the client.
Section 5 Technical and Organizational Measures of the Contractor
5.1 The Contractor is obligated to comply with statutory data protection provisions and shall not disclose information obtained from the Client to third parties or expose it to unauthorized access without appropriate instructions. Paper documents and data must be secured against unauthorized access in accordance with the state of the art.
5.2 The Contractor shall organize its internal operations within its area of responsibility to meet the specific requirements of data protection. The Contractor guarantees that it has implemented all necessary technical and organizational measures for the appropriate protection of the Client's data in accordance with Art. 32 GDPR, specifically at least the measures listed in Annex 2. Upon request by the Client, the Contractor shall disclose the specific circumstances regarding the determination and implementation of these measures. The Contractor reserves the right to improve the security measures implemented, provided that it ensures the contractually agreed level of protection is not compromised and that the Client is informed immediately of any significant changes.
5.3 The contact person for data protection at the Contractor is:
Ariadne GmbH, Am Kraftversorgungsturm 5, 52070 Aachen, Germany, Attn: Data Protection Officer, datenschutz@ariadne.io
Any change in the person of the Data Protection Officer/contact person for data protection must be communicated to the Client immediately.
5.4 Persons employed by the Contractor for data processing are prohibited from processing personal data without authorization. The Contractor shall appropriately obligate all persons entrusted with the processing and fulfillment of this contract (hereinafter referred to as employees) (confidentiality obligation, Art. 28 (3) subpara. 1 sentence 2 lit. b GDPR), instruct them on the specific data protection obligations arising from this contract as well as the existing instructions and purpose limitations, and ensure compliance with the aforementioned obligations with due care. These obligations must be structured to remain in effect even after the termination of this contract or the employment relationship between the employee and the Contractor. Upon request, the Contractor shall provide the Client with proof of these employee obligations in an appropriate manner.
Section 6 Contractor's Information Obligations
6.1 In the event of disruptions to processing activities, suspected data breaches or violations of the Contractor's contractual obligations, or suspected other security-relevant incidents involving the Contractor, persons employed by the Contractor in the context of the order, or third parties, the Contractor shall inform the Client in text form immediately, but no later than 48 hours after becoming aware of the incident. The initial report may be preliminary; missing or new information shall be provided without undue delay. The same applies to audits of the Contractor by the data protection supervisory authority that concern processing or matters relevant to the Client. The report regarding a personal data breach shall, as far as possible, contain the following information:
6.2 The Contractor shall immediately take the necessary measures to secure the affected data and to mitigate possible adverse consequences for the data subject(s), inform the Client thereof, request further instructions, and provide the Client with further information at any time, provided the Client's data is affected by a breach under paragraph 1.
6.3 Should the Client's data at the Contractor be endangered by seizure or confiscation, insolvency or composition proceedings, or other events or measures by third parties, the Contractor shall inform the Client immediately, unless prohibited by court or official order. In this context, the Contractor shall immediately inform all competent authorities that the decision-making authority regarding the data lies exclusively with the Client.
6.4 The Contractor shall inform the Client immediately of any significant changes to the security measures under Section 5 (2).
6.5 The Contractor shall cooperate to a reasonable extent in the creation of the record of processing activities by the Client, as well as in the preparation of a data protection impact assessment pursuant to Art. 35 GDPR and, if applicable, in prior consultation with the data protection supervisory authorities pursuant to Art. 36 GDPR. The Contractor shall provide the Client with the necessary information in an appropriate manner.
Section 7 Client's Audit Rights
7.1 Before commencing data processing and thereafter on a regular basis, the Client shall satisfy itself of the Contractor's technical and organizational measures. For this purpose, the Client may, for example, obtain information from the Contractor, request existing expert reports, certifications, or internal audits, or, if possible and after timely coordination, personally inspect the Contractor's technical and organizational measures during normal business hours or have them inspected by a qualified third party, provided the latter is not in a competitive relationship with the Contractor. The Client shall conduct audits only to the extent necessary and shall not disproportionately disrupt the Contractor's business operations. On-site audits are secondary, i.e., they occur only if the previously provided information, reports, certifications, or questionnaires are insufficient for an appropriate assessment.
7.2 The Contractor undertakes to provide the Client, upon oral or written request and within a reasonable period, with all information and evidence necessary to conduct an audit of the Contractor's technical and organizational measures in accordance with Annex 2.
Support services that go beyond this shall be reimbursed by the Client. This does not apply to support services required due to an official order, a security incident at the Contractor, or a material breach of this agreement by the Contractor.
On-site audits must be announced in text form with at least 14 calendar days' notice and shall take place no more than once every twelve months. They are to be limited to one audit day between 9:00 a.m. and 6:00 p.m.; if this is demonstrably insufficient, the audit may be extended to immediately following working days by mutual agreement. If the Client conducts an audit beyond this without the Contractor having given cause for it, the Contractor is entitled to reimbursement of the reasonable costs incurred as a result.
Travel and accommodation expenses, as well as a reasonable daily rate for the contractor, shall be borne by the client.
7.3 The client shall document the results of the checks it performs and communicate them to the contractor. In the event of errors or irregularities, particularly those identified by the client during the review of service results, the client must inform the contractor without delay. If the inspection reveals facts that require changes to the mandated procedure to prevent future occurrences, the client shall notify the contractor of the necessary procedural changes without delay.
7.4 Upon request, the contractor shall provide the client with proof that its employees are bound by the obligations set forth in Section 5 (4).
Section 8 Use of Subcontractors
8.1 The client grants the contractor general authorization to engage further subcontractors within the meaning of Art. 28 GDPR to fulfill its contractually agreed services. The contractor shall list all existing subcontracts at the time of contract conclusion in Appendix 3 to this agreement. The client must be informed in advance of any intended addition or replacement of subcontractors.
8.2 The client may object to the engagement of additional subcontractors or the replacement of existing ones within a period of 2 (two) weeks after receiving notification of the change, either in writing or in text form. In the event of an objection, the contractor may, at its own discretion, either provide the service without the intended change or—if it is not possible for the contractor to provide the service without the intended change—terminate the services affected by the change for good cause.
8.3 The contractor is obligated to select subcontractors carefully based on their suitability and reliability. When engaging subcontractors, the contractor must impose the obligations set forth in this agreement upon them and ensure that the client can exercise its rights under this agreement (in particular its audit and inspection rights) directly against the subcontractors as well. If subcontractors are to be involved in a third country, the contractor must ensure that an adequate level of data protection is guaranteed by the respective subcontractor (e.g., by concluding an agreement based on the EU Standard Contractual Clauses). Upon request, the contractor shall provide the client with proof of the conclusion of the aforementioned agreements with its subcontractors.
Should the adequacy of the protection level under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) cease to apply, the contractor shall immediately ensure that the affected data transfers are continued on the basis of the EU Standard Contractual Clauses (SCC) and a supplementary Transfer Impact Assessment (TIA), and shall inform the client accordingly.
8.4 A subcontracting relationship within the meaning of these provisions does not exist if the contractor commissions third parties for services that are to be considered purely ancillary. These include, for example, postal, transport, and shipping services, cleaning services, telecommunications services without a specific connection to the services the contractor provides for the client, and security services. Maintenance and testing services constitute subcontracting relationships within the meaning of Paragraph 1 insofar as they are provided for IT systems that are also used in connection with the provision of services for the client.
Section 9 Inquiries and Rights of Data Subjects
9.1 The contractor shall support the client with appropriate technical and organizational measures in fulfilling the client's obligations under Art. 12–22 as well as 32 and 36 GDPR.
9.2 If a data subject asserts rights, such as the right to information, rectification, or erasure regarding their data, directly against the contractor, the contractor shall not respond independently but shall refer the data subject to the client without delay and await the client's instructions.
Section 10 Liability
10.1 The client and the contractor shall be liable to data subjects in accordance with the provisions set forth in Art. 82 GDPR. The contractor shall coordinate any fulfillment of liability claims with the client.
10.2 The contractor shall indemnify the client against all claims asserted by data subjects against the client due to a breach of an obligation imposed on the contractor by the GDPR, or due to the non-observance or violation of an obligation stipulated in this agreement or of an instruction issued separately by the client.
10.3 The parties shall each indemnify the other from liability if/to the extent that a party proves that it is in no way responsible for the circumstance that caused the damage to a data subject. Otherwise, Art. 82 (5) GDPR shall apply.
10.4 Unless otherwise stipulated above, liability under this agreement shall correspond to that of the main contract.
Section 11 Extraordinary Right of Termination
The client may terminate the main contract in whole or in part without notice if the contractor fails to comply with its obligations under this agreement, intentionally or through gross negligence violates provisions of the GDPR, or is unable or unwilling to carry out an instruction from the client. In the case of minor breaches—i.e., those that are neither intentional nor grossly negligent—the client shall grant the contractor a reasonable period of time within which the contractor may remedy the breach.
Section 12 Termination of the Main Contract
12.1 Upon termination of the main contract, or at any time upon request, the Processor shall return to the Controller all documents, data, and data carriers provided to them, or—at the Controller's request, provided there is no legal obligation under European Union or German law to store the personal data—delete them. This obligation to return or destroy data also applies to any data backups held by the Processor. The Processor must provide documented proof of proper deletion.
12.2 The Controller has the right to verify the complete and contractually compliant return or deletion of data by the Processor in an appropriate manner, or to have it audited by a qualified third party, provided that the third party is not a competitor of the Processor. Any costs incurred for the engagement and audit by a third party shall be borne by the Controller.
12.3 The Processor is obligated to maintain the confidentiality of information that becomes known to them in connection with the main contract, even after the main contract has ended.
Section 13 Church Data Protection
13.1 For a Controller subject to the Act on Church Data Protection (KDG), the parties expressly incorporate §§ 29 – 33 KDG and compliance with the provisions on data processing set forth therein.
13.2 For a Controller subject to the Church Act on Data Protection of the Evangelical Church in Germany (DSG-EKD), the parties expressly incorporate §§ 30 – 32 DSG-EKD and compliance with the provisions on data processing set forth therein.
Section 14 Final Provisions
14.1 The parties agree that the Processor has no right of retention regarding the data to be processed or the associated data carriers.
14.2 Amendments and supplements to this agreement, the declaration of termination, and any modification of this clause must be made in text form to be effective.
14.3 Should individual provisions of this agreement be or become legally invalid or unenforceable, in whole or in part, the validity of the remaining provisions shall not be affected.
14.4 This agreement is governed by German law. The exclusive place of jurisdiction is Aachen.
Section 15 Appendices
The following appendices are an integral part of this Data Processing Agreement:
Type(s) of personal data:
The types of personal data processed under this agreement include all data that the Controller voluntarily processes within the interactive management system software Q.wiki. This typically includes, in particular:
As a general rule, the processor does not collect or process any special categories of personal data within the meaning of Art. 9 (1) GDPR in the course of operating Q.wiki. Such data is only processed if the controller enters such information into the system voluntarily and on their own responsibility. In these cases, processing is carried out exclusively in accordance with the instructions of the controller and on the basis of this data processing agreement.
Categories of data subjects:
The group of persons affected by the data processing depends on the individuals to whom the controller grants access to the interactive management system software Q.wiki. This may include, in particular,
The processor implements the following technical and organizational measures for data security within the meaning of Art. 32 GDPR.
Certification: The processor operates an information security management system (ISMS) and is certified according to ISO/IEC 27001. A current certificate can be provided upon request.
Provider standards: Physical security and data center operations are carried out according to recognized standards of the cloud/data center provider (e.g., ISO/IEC 27001).
Access control (physical access)
Access control (logical system access)
Access control (permissions and data access)
Mobile working
Pseudonymization and encryption
Separation control (principle of separation)
Input control
Transfer control
Availability and resilience
Data protection and information security management
Handling of security incidents
Endpoint security (employees)
The processor engages third parties to process data on behalf of the controller ("sub-processors"). These include the following companies:


