between
the customer
– hereinafter referred to as the Client or Controller –
and
Converia GmbH
Kaufstr. 2–4
99423 Weimar
Germany
– hereinafter referred to as the processor –
1. Subject matter and duration of the data processing
The subject matter and duration of the data processing are governed by the provisions of the respective underlying order. If there are multiple orders between the controller and the processor, this agreement shall apply to all such orders for the duration of each respective order.
2. Scope, nature, and purpose of the data processing, type of personal data, and categories of data subjects
The scope, nature, and purpose of the data processing, the type of personal data, and the categories of data subjects are described in Annex 1.
The data processing systems used for the operation of the Converia conference management system are located in a data center in Germany. The processor is entitled to relocate data processing for individual components that do not involve the direct receipt of event information to other countries. This applies in particular to the ordering of products where the use of subcontractors based abroad is indicated. Data processing abroad is therefore permissible if commissioned accordingly by the controller. Relocating data processing to countries outside the European Union or the European Economic Area is only permitted if the requirements set out in Art. 44 et seq. GDPR are met.
3. Technical and organizational measures
The processor shall implement the technical and organizational measures required under Art. 32 GDPR to ensure compliance with data protection regulations during this data processing. Regarding the technical and organizational measures established as binding within the framework of this contractual relationship, reference is made to Annex 2.
Technical and organizational measures are subject to technical progress and further development. The processor may therefore deviate from the measures agreed upon with the controller and replace them with alternative, adequate measures, provided that the level of protection of the originally agreed measures is not reduced.
4. Controller's obligations toward data subjects
The controller is solely responsible for fulfilling legal obligations toward data subjects, i.e., the obligation to implement legally mandated information and notification duties, as well as the obligation to respond to and implement requests from data subjects to exercise their rights (hereinafter collectively: "obligations toward data subjects"), including the assessment of legality in this context. In addition to the information and notification duties to be fulfilled by the controller, the controller is specifically responsible for responding to and implementing the data subjects' rights to access, rectification, erasure, restriction of processing, data portability, and objection, as well as responding to and implementing rights related to automated individual decision-making, including profiling.
The processor shall, where possible and taking into account the nature of the processing, assist the controller with appropriate technical and organizational measures to fulfill its obligations toward data subjects. The processor's obligation to assist the controller exists only to the extent that the controller is unable to fulfill its obligations toward data subjects itself due to the specific design of the data processing, or does not have the necessary information available. This means, in particular, that the controller must primarily use the information or tools provided by the processor, specifically within the Converia conference management software, to fulfill its obligations toward data subjects.
The processor shall also, where possible, assist the controller with appropriate technical and organizational measures to fulfill its aforementioned obligations toward data subjects within the one-month period from receipt of the data subject's request, unless there are grounds for extending this period under applicable law.
If, in the context of a data subject's request, it is necessary to verify the identity of the data subject, potentially by requesting additional information, the controller is responsible for this.
Should a data subject contact the processor directly with a request regarding the controller's obligations toward data subjects, the processor shall forward this request to the controller, who will then decide on the further course of action. Should it be necessary in an individual case for the processor to fulfill the obligations toward data subjects directly, the processor is only obligated to act in this regard if it has received documented instructions from the controller as defined in Section 9 of this agreement.
The processor shall only respond to requests for information from third parties (e.g., police, public prosecutor's office, courts, supervisory authorities, or other authorities) relating to personal data for which the controller is the controller within the meaning of the GDPR if it has received documented instructions from the controller to do so, or if it is legally obligated to provide such information (e.g., in the case of a duty to testify and the absence of a right to refuse to testify).
The processor shall inform the controller immediately of the content and scope of any information request so that the controller can fulfill its information obligations toward the data subjects.
Expenses incurred in assisting the controller shall be reimbursed in accordance with Section 12 of this agreement.
5. Obligations of the processor
The processor shall assist the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to the processor.
In accordance with the aforementioned provisions, the processor has, in particular, appointed a data protection officer (Art. 37-39 GDPR).
Contact details of the data protection officer
We have appointed a data protection officer.
Attorney at Law
Stephan Hansen-Oest
Im Tal 10a
24939 Flensburg
Email: kanzlei@hansen-oest.com
Furthermore, the processor exclusively employs persons for data processing who have been committed to data secrecy in writing or who are subject to an appropriate statutory duty of confidentiality under the GDPR. Regarding the controller's obligation to conduct any necessary data protection impact assessment and the associated potential obligation to consult the supervisory authority (Art. 35, 36 GDPR), the processor will support the controller to the necessary extent in compiling the required information, provided and to the extent that the relevant information is not already available to the controller, e.g., due to their access to the Converia conference management software. The processor's obligation to support the controller in the aforementioned sense applies no earlier than three months before the GDPR comes into effect on May 25, 2018, i.e., no earlier than February 25, 2018.
Expenses incurred in supporting the controller will be reimbursed in accordance with Section 12 of this agreement.
6. Sub-processing (other processors)
"Other processors" within the meaning of the GDPR are referred to below as "sub-processors."
6.1 The controller hereby grants the processor a general authorization to engage sub-processors (unless it has already granted prior separate written approval, e.g., when ordering a product where the use of a sub-processor was explicitly mentioned), provided that
- the processor informs the controller of the intended use of the sub-processor in advance in writing, in an electronic format, or in text form, and
- the processor imposes data protection obligations on the sub-processor via a written or electronic contractual agreement that correspond to the data protection obligations of this agreement.
The obligation to inform the controller also applies to any intended change regarding the addition or replacement of sub-processors.
The controller has the right to object to the engagement of or intended changes regarding the addition or replacement of sub-processors in justified cases, provided there is reasonable cause to believe that the new sub-processor cannot ensure the protection of the controller's personal data. The controller's objection to the use of a sub-processor must be made within one month, starting from the end of the month in which the information was received by the processor. After this period, the right to object is forfeited.
If the controller objects to the use of a sub-processor, the processor is entitled to terminate the affected part of the service. This right of extraordinary termination must be exercised with one month's notice, starting from the end of the month in which the objection was received. Upon exercise of this right, the contractual relationship regarding the affected part of the service will end within three months, starting from the end of the month in which the right of extraordinary termination was exercised. The processor is not liable for any costs, expenses, or damages resulting from such termination (in particular, not for migration costs), unless there is a justified case within the meaning of this Section 6.1.
6.2 The controller has the right to request an up-to-date list of the sub-processors currently in use upon conclusion of the contract and during audits conducted under Section 7 of this agreement. A current list of sub-processors is provided in Appendix 1.
6.3 For the purposes of this specific data processing agreement, sub-processors are defined only as third parties who provide all or part of the contractually agreed main service or contribute to its fulfillment. Third parties engaged by the processor as ancillary services to support the execution of the order, who provide services permitted by law, or who provide services directly to the controller and thus have a direct contractual relationship with the controller (e.g., banks including acquirers, i.e., the organizer's banks that process customer credit card payments, credit agencies, telecommunications providers, postal service providers, transport service providers, cleaning staff, or data carrier disposal companies) are not considered sub-processors. However, the processor will also enter into appropriate contractual agreements with these third parties to ensure data protection and data security and will implement control measures if required by law (especially if the corresponding ancillary services constitute data processing in the relationship between the processor and the third party).
6.4 The processor will monitor any sub-processors it engages in accordance with the provisions of the applicable law. The controller does not have a direct right of audit regarding any sub-processors engaged by the processor.
7. Controller's Right to Audit
The controller is entitled to verify the processor's compliance with the agreed technical and organizational measures and legal obligations related to data processing before processing begins and periodically thereafter. The controller is also entitled to have these audits carried out by third parties.
The Processor is obligated to tolerate and cooperate with inspections. A date for conducting the inspections must be coordinated between the Controller and the Processor in good time in advance.
Expenses incurred in supporting the Controller will be remunerated in accordance with Section 12 of this Agreement.
8. Processor's Duty to Report Breaches
The Processor must inform the Controller immediately if it becomes aware of data breaches in the context of the order processing that could trigger reporting obligations to the supervisory authority or a duty to notify the data subjects. This applies regardless of whether the respective data breach is based on a violation of data protection regulations or the stipulations made in the Order by the Processor or its employees, or on circumstances independent of this (such as attacks by third parties or force majeure). Articles 33 and 34 of the GDPR apply.
The Controller is responsible for fulfilling any reporting and information obligations in the aforementioned sense. The Processor shall support the Controller, taking into account the nature of the processing and the information available to it, to the extent necessary in fulfilling these obligations. The Processor's support service in these cases is limited to providing the information that the Controller absolutely requires to fulfill its obligations but which the Controller is not aware of itself or to which it has no access (e.g., through access to the Converia conference management software).
9. Scope of the Controller's Authority to Issue Instructions
The Controller is responsible for ensuring that the order processing is carried out lawfully in accordance with applicable law and that the rights of the data subjects are protected. Accordingly, it is responsible for defining the framework conditions for this to the Processor. The framework conditions are specified in detail in this Agreement and the underlying Orders. The Processor and the persons under its authority may only process the Controller's personal data within this framework and, beyond that, only on the documented instruction of the Controller. Processing outside of a documented instruction is only permitted if the Processor is required to do so by Union or Member State law to which it is subject.
Instructions must be issued in writing or by email, preferably via the Processor's support portal at https://support.converia.de.
The Controller's authority to issue instructions is limited to the fulfillment of data protection obligations established by the applicable data protection law as specified in the provisions of this Agreement, and exists only within the scope of the services offered by the Processor and the variants or modalities offered within that framework. The Processor is not obligated to fulfill instructions that go beyond this. This also applies if an instruction relates to the implementation of specific technical and organizational measures. Such adjustments generally require a mutual agreement between the Controller and the Processor by way of an extension of the Order and the arrangement of corresponding remuneration.
Otherwise, the Controller always retains the option to instruct the Processor to discontinue a specific service within a period that is reasonable under the circumstances of the individual case. The term of the Order and the Controller's obligation to pay remuneration remain unaffected by this. The Order remains in effect regarding the affected service until it is terminated due to the expiration of time, ordinary termination, or any existing extraordinary or special right of termination.
The Processor shall inform the Controller immediately if it believes that an instruction violates applicable data protection law.
10. Termination of Order Processing
At the request of the Controller, but no later than upon termination of the processing of the order, i.e., after completion of the processing service, the Processor shall, at the documented instruction of the Controller, either delete all personal data or return it to the Controller, unless there is an obligation under Union law or the law of the Member States for the Processor to store the personal data (statutory retention obligations applicable to the Processor).
Unless otherwise stipulated in the underlying Order and unless the Controller provides the Processor with a separate documented instruction to the contrary, the following applies: Event data for individual events will be deactivated three months after the event and deleted from the Converia database 12 months after the event. In the case of an ongoing Order (e.g., Converia Framework Agreement), the user has the option to deactivate or delete the data from the Converia database themselves after an event. Therefore, the duty to delete the data lies with the Controller. Before deletion, the data is available to the Controller for viewing, analysis, and secure download. Since the Controller's access to the Converia software is deactivated upon termination of the contract, it is the Controller's responsibility to independently download any data they still require in good time beforehand.
11. Liability
The Processor's liability to the Controller for claims for damages resulting from a breach of data protection obligations is governed by the following provisions. A breach of data protection obligations by the Processor occurs if it violates legal obligations applicable to it under data protection regulations, as specified in the provisions of this Agreement and in documented instructions from the Controller that are compliant with data protection law and permitted under this Agreement.
If the Controller and the Processor are liable for damages to a data subject or any other person due to joint and several liability under the provisions of the GDPR or any other data protection regulation applicable to the Processor, the following shall apply to the internal settlement between the Controller and the Processor: In principle, the Processor is only liable for a breach of data protection obligations as defined in this Agreement. Furthermore, it is only liable for intentional or grossly negligent breaches of duty, unless the claims for damages arise from injury to life, body, or health, or from a breach of data protection obligations that is in direct connection with the fulfillment of essential contractual obligations (cardinal duties). Essential contractual obligations are those whose fulfillment is mandatory for achieving the purpose of the contract. Liability for breaches of data protection obligations in connection with cardinal duties is limited to compensation for foreseeable and typical damages. In particular, there is no obligation to compensate for wasted expenditure or lost profits of data subjects or other persons. Likewise, there is no obligation to compensate for consequential damages of data subjects or other persons, except in cases of intentional or grossly negligent breaches of duty. No further liability of the Processor exists. The provisions of the Product Liability Act remain unaffected, insofar as it applies in an individual case. The burden of proof for the existence of the requirements of this paragraph, in particular for the existence of a breach of data protection obligations by the Processor as defined above and the Processor's culpability as defined above, lies with the Controller.
Liability for damages incurred by the Controller itself due to a breach of data protection obligations by the Processor, which are not related to damages suffered by data subjects or other persons, shall only exist in principle if there is a breach of data protection obligations as defined in this Agreement and if such breach is in direct connection with the fulfillment of essential contractual obligations (cardinal duties). Essential contractual obligations are those whose fulfillment is mandatory for achieving the purpose of the contract. Regarding the scope and amount, the Processor's liability in these cases shall be governed by the provisions of the Order. Similarly, the Processor's liability for damages resulting from other breaches of duty shall also be governed by the provisions of the Order.
12. Remuneration
Should the Processor incur expenses in fulfilling obligations under this Agreement that exceed the contractually agreed primary services and regular day-to-day business, particularly in the context of Sections 4, 5, 7, 8, and 9 of this Agreement, the Controller and the Processor shall agree on reasonable additional remuneration based on the actual expenses incurred. In such cases, the Processor shall carry out a documented instruction from the Controller once it has received confirmation from the Controller regarding remuneration for the specific individual case. If significant additional effort arises from the exercise of a right of inspection as defined in Section 7, the Processor’s cooperation shall only occur after the Controller has confirmed remuneration.
13. Final Provisions
Should individual provisions of this agreement be incomplete, invalid, or unenforceable, the validity of the remaining provisions shall not be affected. In such a case, the incomplete, invalid, or unenforceable provision shall be replaced by a provision that reflects what the parties would have intended had they been aware of the incompleteness, invalidity, or unenforceability.
This agreement fully replaces any prior agreements between the parties regarding data processing or order processing. Data protection provisions in other parts of the contract (e.g., General Terms and Conditions) shall only take precedence over this agreement if they further elaborate on the provisions herein. If they alter the core content of this agreement or fall short of the level of data protection agreed upon here, they shall be superseded by this agreement.
This agreement is governed by German law. The place of jurisdiction is Weimar.
Any amendments to this agreement must be made in writing.