Data Processing Agreement
Agreement on the Processing of Personal Data on Behalf of a Controller pursuant to Art. 28 GDPR
between Detesia GmbH, Bahnhofstrasse 88, 66386 St. Ingbert, Germany
– as the Controller – hereinafter referred to as the "Client" –
and the respective Customer
– as the Processor – hereinafter referred to as the "Contractor" –
– Client and Contractor hereinafter each also referred to as a "Party" and collectively as the "Parties" –
Preamble
The Contractor provides services to the Client in the context of the browser-based provision of deepfake detection software, which is made available to the Client as a web-based application accessible via an internet browser through the Contractor's website, on the basis of the concluded main agreement (hereinafter: the "Main Agreement"). Part of the performance of the Main Agreement involves the processing of personal data within the meaning of the General Data Protection Regulation ("GDPR"). To fulfil the requirements of the GDPR for such constellations, the Parties enter into the following agreement, the performance of which shall not be separately remunerated unless expressly agreed otherwise.
This is a convenience translation of the German original. In case of any discrepancies, the German version shall prevail.
Section 1 – Subject Matter/Scope of the Commission
(1) The cooperation of the Parties pursuant to the Main Agreement entails that the Contractor receives access to personal data of the Client (hereinafter "Client Data") and processes such data exclusively on behalf of and in accordance with the instructions of the Client within the meaning of Art. 4 No. 8 and Art. 28 GDPR.
(2) The processing of Client Data by the Contractor shall be carried out exclusively in the manner, scope, and for the purpose specified in Annex 1. The categories of data subjects affected by the data processing are set out in Annex 2 to this Agreement. The duration of the processing corresponds to the term of the Main Agreement.
(3) The Contractor is prohibited from processing Client Data in a manner that deviates from or goes beyond the specifications in Annexes 1 and 2. This also applies to the use of anonymised data.
(4) The processing of Client Data shall take place exclusively within the territory of the Federal Republic of Germany, in a Member State of the European Union, or in another Contracting State of the Agreement on the European Economic Area. Any transfer to a third country requires the prior written consent of the Client and may only take place if the specific requirements of Art. 44 to 49 GDPR are met.
(5) The provisions of this Agreement apply to all activities related to the Main Agreement in which the Contractor and its employees or persons commissioned by the Contractor come into contact with personal data originating from or collected for the Client.
Section 2 – Instruction Authority of the Client
(1) The Contractor shall process Client Data only within the scope of the commission and exclusively on behalf of and in accordance with the instructions of the Client pursuant to Art. 28 GDPR (commissioned processing); this applies in particular to the transfer of personal data to a third country or to an international organisation. The Client has the sole right to issue instructions regarding the type, scope, and method of processing activities (hereinafter also "right of instruction"). If the Contractor is obliged to carry out further processing by the law of the European Union or the Member States to which it is subject, it shall inform the Client of these legal requirements prior to processing.
(2) Instructions shall generally be issued by the Client in writing; orally issued instructions shall be confirmed in writing by the Contractor. The persons authorised to issue and receive instructions are set out in Annex 3. In the event of a change or prolonged unavailability of the persons named in Annex 3, the successor or substitute shall be notified to the other Party without delay in text form. The Contractor shall notify the Client of a change in the person authorised to issue instructions in good time. Until receipt of such notification by the Client, the named persons shall continue to be deemed authorised to receive instructions.
(3) If the Contractor is of the opinion that an instruction from the Client violates data protection provisions, it shall immediately notify the Client. The Contractor shall be entitled to suspend the execution of the relevant instruction until it is confirmed or amended by the Client.
Section 3 – Protective Measures of the Contractor
(1) The Contractor is obligated to comply with the statutory provisions on data protection and not to disclose information obtained from the Client's domain to third parties or expose it to their access. Documents and data shall be secured against access by unauthorised persons, taking into account the state of the art.
(2) Furthermore, the Contractor shall commit all persons entrusted by it with the processing and performance of this Agreement (hereinafter referred to as "Employees") in writing to confidentiality (commitment to confidentiality, Art. 28(3)(b) GDPR) and shall ensure compliance with this commitment with due diligence. At the Client's request, the Contractor shall provide written or electronic proof of the Employees' commitment.
(3) The Contractor shall organise its internal operations to meet the specific requirements of data protection. It undertakes to take all appropriate technical and organisational measures for the adequate protection of Client Data pursuant to Art. 32 GDPR, in particular the measures set out in Annex 4 to this Agreement, and to maintain them for the duration of the processing of Client Data.
(4) The Contractor reserves the right to modify the technical and organisational measures taken, provided that it ensures that the contractually agreed level of protection is not compromised. The Contractor shall immediately inform the Client in writing if it has reason to believe that the measures pursuant to Annex 4 are no longer sufficient and shall coordinate with the Client regarding further technical and organisational measures.
(5) At the Client's request, the Contractor shall demonstrate compliance with the technical and organisational measures specified in Annex 4 through appropriate evidence.
Section 4 – Information and Support Obligations of the Contractor
(1) In the event of disruptions, suspected data protection breaches or breaches of contractual obligations by the Contractor, suspected security-relevant incidents, or other irregularities in the processing of Client Data by the Contractor, persons employed by the Contractor in the course of the commission, or by third parties, the Contractor shall inform the Client without delay, but no later than within 36 hours, in written or electronic form. The same applies to audits of the Contractor by the data protection supervisory authority. The notifications pursuant to Section 4(1) sentence 1 shall contain at least the information referred to in Art. 33(3) GDPR.
(2) In the case of Section 4(1), the Contractor shall support the Client in fulfilling its obligations regarding investigation, remediation, and information measures to the extent reasonable. In particular, the Contractor shall immediately take the necessary measures to secure the data and to mitigate possible adverse consequences for the data subjects, inform the Client thereof, and request further instructions.
(3) The Contractor undertakes to provide the Client, upon oral or written request, within a reasonable period, with all information and evidence necessary for the conduct of an audit pursuant to Section 7(1) of this Agreement. Furthermore, the Contractor shall provide the Client, upon request, with a comprehensive and up-to-date data protection and security concept for the commissioned processing as well as information on authorised persons with access rights.
Section 5 – Other Obligations of the Contractor
(1) The Contractor is obligated to maintain a record of all categories of processing activities carried out on behalf of the Client pursuant to Art. 30(2) GDPR. The record shall be made available to the Client upon request.
(2) The Contractor is obligated to support the Client in preparing a data protection impact assessment pursuant to Art. 35 GDPR and any prior consultation of the supervisory authority pursuant to Art. 36 GDPR.
(3) The Contractor confirms that it will appoint a data protection officer as soon as a legal obligation to do so exists. The contact details of the data protection officer shall be communicated to the Client without delay after appointment. A change in the person of the company data protection officer/data protection contact person shall be communicated to the Client in writing without delay.
(4) Should Client Data held by the Contractor be jeopardised by seizure or confiscation, insolvency or composition proceedings, or other events or measures of third parties, the Contractor shall inform the Client without delay, unless prohibited from doing so by court or administrative order. In this context, the Contractor shall immediately inform all relevant authorities that decision-making authority over the data lies exclusively with the Client as the "Controller" within the meaning of the GDPR.
Section 6 – Sub-Contractor Relationships
(1) The Contractor is not authorised to establish sub-processing relationships with sub-contractors ("sub-contractor relationship") within the scope of its contractual obligations. Exceptions are only permissible with the Client's prior express written consent in individual cases. In such cases, the Contractor shall ensure that the provisions agreed upon in this Agreement also apply to the sub-contractors it engages, and that the Client is granted all audit rights pursuant to Section 7 of this Agreement vis-a-vis the sub-contractor. Sub-contractor relationships with third parties outside the European Economic Area are not permitted.
(2) A sub-contractor relationship within the meaning of these provisions does not exist when the Contractor engages third parties for services that are to be regarded as purely ancillary services. These include, for example, postal, transport, and shipping services, cleaning services, security services, telecommunications services without specific relevance to services that the Contractor provides for the Client, and other measures to ensure the confidentiality, availability, integrity, and resilience of the hardware and software of data processing systems. The Contractor's obligation to ensure compliance with data protection and data security in these cases remains unaffected.
Section 7 – Audit Rights
(1) The Client is entitled to regularly verify compliance with the provisions of this Agreement, in particular the implementation and compliance with the technical and organisational measures pursuant to Section 3(3) of this Agreement. For this purpose, the Client may, for example, obtain information from the Contractor, have existing certificates from experts, certifications, or internal audits presented, or have the Contractor's technical and organisational measures personally inspected during regular business hours, or have them inspected by a qualified third party, provided that such third party is not in a competitive relationship with the Contractor.
(2) The Client shall conduct audits only to the extent necessary and shall take reasonable consideration of the Contractor's business operations. The Parties shall agree on the timing and manner of the audit in a timely fashion.
(3) The Client shall document the audit results and communicate them to the Contractor. In the event of errors or irregularities that the Client discovers, in particular during the review of processing results, the Client shall immediately inform the Contractor. If the audit reveals circumstances the future avoidance of which requires changes to the prescribed procedural workflow, the Client shall immediately communicate the necessary procedural changes to the Contractor.
Section 8 – Rights of Data Subjects
(1) The Contractor shall, to the extent possible, support the Client with appropriate technical and organisational measures in fulfilling its obligations under Art. 12 to 22 and Art. 32 to 36 GDPR. It shall provide the Client with the requested information about Client Data without delay, but no later than within 7 working days, insofar as the Client does not have access to the relevant information itself.
(2) If the data subject asserts their rights pursuant to Art. 16 to 18 GDPR, the Contractor is obligated to rectify, delete, or restrict Client Data upon the Client's instruction without delay, but no later than within a period of 7 working days. The Contractor shall provide the Client with written proof of the deletion, rectification, or restriction of data upon request.
(3) If a data subject asserts rights, such as the right to information, rectification, or deletion regarding their data, directly against the Contractor, the Contractor shall immediately forward this request to the Client and await its instructions. Without a corresponding individual instruction, the Contractor shall not contact the data subject.
Section 9 – Term and Termination
(1) The term of this Agreement corresponds to the term of the Main Agreement. If the Main Agreement is subject to ordinary termination, the provisions on ordinary termination shall apply accordingly. In case of doubt, termination of the Main Agreement shall also constitute termination of this Agreement and termination of this Agreement shall also constitute termination of the Main Agreement.
(2) The Client is entitled at any time to extraordinary termination of this Agreement for good cause. Good cause exists if the Contractor fails to fulfil its obligations under this Agreement, intentionally or with gross negligence violates provisions of the GDPR, or is unable or unwilling to carry out an instruction from the Client. In particular, good cause exists in the cases specified in Annex 5. In the event of simple – i.e. neither intentional nor grossly negligent – breaches, the Client shall first set the Contractor a reasonable deadline within which the Contractor may remedy the breach. After the fruitless expiry of this deadline, the Client shall then have the right to extraordinary termination.
Section 10 – Deletion and Return After Termination
(1) After termination of the Main Agreement or at any time upon the Client's request, the Contractor shall return to the Client all documents, data, and data carriers provided to it, or, at the Client's request, completely and irrevocably delete them, provided no statutory retention obligation exists. This also applies to copies of Client Data held by the Contractor, such as data backups, but not to documentation serving as proof of the proper and orderly processing of Client Data. Such documentation shall be retained by the Contractor for a period of 3 years and surrendered to the Client upon request.
(2) The Contractor shall confirm the deletion to the Client in writing. The Client has the right to verify the complete and contractually compliant return or deletion of data at the Contractor's premises in an appropriate manner; Section 7(2) of this Agreement shall apply accordingly.
(3) The Contractor is obligated to treat all data that became known to it in connection with the Main Agreement as confidential, even after termination of the Main Agreement.
Section 11 – Liability
(1) The liability of the Parties shall be governed by Art. 82 GDPR. Any liability of the Contractor towards the Client for breach of obligations under this Agreement or the Main Agreement shall remain unaffected.
(2) The Parties shall mutually indemnify each other from liability if a Party demonstrates that it is in no way responsible for the circumstance that caused the damage to a data subject. Section 11(2) sentence 1 shall apply accordingly in the case of a fine imposed on a Party, whereby the indemnification shall be to the extent that the other Party bears responsibility for the violation sanctioned by the fine.
Section 12 – Final Provisions
(1) The Parties agree that the Contractor's right of retention pursuant to Section 273 of the German Civil Code (BGB) with respect to the data to be processed and the associated data carriers is excluded.
(2) Amendments and supplements to this Agreement shall be made in writing. This also applies to the waiver of this written form requirement.
(3) In case of doubt, the provisions of this Agreement shall take precedence over the provisions of the Main Agreement. Should individual provisions of this Agreement prove to be wholly or partially invalid or unenforceable, or become invalid or unenforceable as a result of changes in legislation after the conclusion of the Agreement, the validity of the remaining provisions shall not be affected. The invalid or unenforceable provision shall be replaced by a valid and enforceable provision that most closely reflects the purpose and intent of the invalid provision.
(4) This Agreement is governed by German law. The exclusive place of jurisdiction is Saarbruecken.
Annexes
Annex 1 – Specification of the Type, Scope, and Purpose of Data Processing
1. Subject Matter of Processing
The subject matter of processing is the use of a browser-based deepfake detection software within the framework of a Software-as-a-Service (SaaS) model. The software enables the customer to upload media files (e.g. images, audio, and video files) which are automatically analysed for deepfake characteristics. The processing encompasses uploading, storing, analysing, and providing analysis results to the customer. Further processing for other purposes is excluded.
2. Types of Data Processed
All media files provided by the customer that may contain personal data are processed, in particular images, voices, names, metadata, and other identification features. Additionally, technical usage data (e.g. IP addresses, access times, browser information) are processed insofar as this is necessary for the provision and security of the service.
3. Categories of Data Subjects
The natural persons depicted, named, or otherwise identifiable in the media files are affected, as well as the users/customers who use the software.
4. Purpose of Processing
Processing takes place exclusively for the purpose of analysing and detecting deepfakes in the files provided by the customer. The results are made available to the customer. Processing for other purposes, in particular for advertising purposes or profiling, does not take place.
5. Scope of Processing
Processing is limited to uploading, storing, analysing, and transmitting results within the SaaS solution. Disclosure to third parties or use for the Processor's own purposes is excluded, unless this is necessary for contract performance or due to legal obligations. Data is only processed for the duration of the contractual relationship and, upon its termination, is deleted or returned in accordance with the Controller's instructions, unless statutory retention obligations apply.
6. Technical and Organisational Measures
The Processor undertakes to take all technical and organisational measures required under Art. 32 GDPR to ensure a level of protection appropriate to the risk. These include, in particular, encryption, access restrictions, pseudonymisation, and ensuring the confidentiality and integrity of systems and services.
7. Binding Instructions and Rights of the Controller
The Processor processes personal data exclusively on the basis of documented instructions from the Controller. The Controller retains decision-making authority over the type, scope, and purpose of processing and may issue instructions at any time.
8. Duration of Processing
Processing takes place for the duration of the SaaS contractual relationship. Upon its termination, personal data shall be deleted or returned at the Controller's discretion, unless statutory retention obligations apply.
9. Support and Accountability Obligations
The Processor supports the Controller in fulfilling its obligations regarding data subject rights, transparency, and demonstrating compliance with data protection requirements, and provides the information necessary for this purpose.
10. Sub-Processing
The engagement of sub-processors is only permissible with the prior consent of the Controller. The Controller shall be informed of planned changes; the Controller has the right to object.
Annex 2 – Description of Data Types and Categories of Data Subjects
1. Data Types
a) Image Files
- Uploaded or transmitted digital image files (e.g. JPEG, PNG, BMP, TIFF) that may contain depictions of natural persons.
- Regularly contain personal data within the meaning of Section 46 No. 1 BDSG, as individual persons are identifiable by their appearance, clothing, or other characteristics.
- May contain biometric data, in particular facial images, that enable or confirm unique identification (Section 46 No. 12, 14c BDSG).
- Metadata of image files (e.g. timestamps, geolocation, device information) that may allow inferences about the data subject.
b) Video Files
- Uploaded or transmitted digital video files (e.g. MP4, AVI, MOV, WMV) that may contain image and audio recordings of natural persons.
- Contain personal data, as persons are identifiable by image, voice, behaviour, movement patterns, or other characteristics.
- May contain biometric data (facial images, voice profiles) for unique identification (Section 46 No. 12, 14c BDSG).
- Metadata of video files (e.g. timestamps, geolocation, device information).
c) Accompanying Usage Data
- IP addresses, upload times, user identifiers, browser and device information, insofar as necessary for the provision of the service.
- This data is personal data when it can be attributed to a natural person.
d) Special Categories of Personal Data
- Image and video files may contain special categories of personal data within the meaning of Section 46 No. 14 BDSG, e.g. information on ethnic origin, religious beliefs, health data (visible disabilities, medical devices), biometric data (face, voice).
2. Categories of Data Subjects
a) Depicted or Recorded Persons
- Natural persons who are recognisable or identifiable in the uploaded images or videos (e.g. by face, voice, clothing, behaviour, tattoos, other characteristic features).
b) Users/Customers
- Natural persons who use the deepfake detection software, in particular in the context of personal registration, authentication, or logging of usage activities (e.g. IP address, user identifier).
c) Third Parties Named in Metadata or Accompanying Information
- Persons whose personal data is contained in metadata, file names, or accompanying texts (e.g. name in file name, geolocation, time information).
Annex 3 – Persons Authorised to Issue and Receive Instructions
Within the framework of the Data Processing Agreement pursuant to Art. 28 GDPR, the following persons at the provider (GmbH) are authorised to issue and receive instructions:
1. Management of Detesia GmbH
- Philipp Dewald, Managing Director, philipp@detesia.com, +49 162 62 76130
- Peter Stolz, Managing Director, peter@detesia.com, +49 152 23 363793
- Tim Walita, Managing Director, tim@detesia.com, +49 151 58377686
The managing directors are authorised as legal representatives of the GmbH pursuant to Section 164(1) BGB to receive and issue instructions within the framework of the Data Processing Agreement.
2. Changes
Changes to the persons authorised to issue and receive instructions shall be communicated to the contractual partner without delay in text form.
Annex 4 – Technical and Organisational Measures of the Contractor (Art. 32 GDPR)
The following technical and organisational measures serve to protect the personal data processed by the Contractor within the scope of the commissioned processing. They have been taken in consideration of the state of the art, the costs of implementation, the nature, scope, circumstances, and purposes of processing, as well as the likelihood and severity of risks associated with the processing, to ensure a level of protection appropriate to the risk pursuant to Art. 32 GDPR.
1. Access Control
The Contractor ensures that only authorised persons gain access to systems, applications, and data that contain or process personal data. This includes in particular:
- Personalised authentication for all administrative and productive access points as well as appropriate password and session protection mechanisms.
- Use of two-factor authentication for particularly sensitive access points.
- Logging of access attempts and regular review of authorisations.
These measures ensure that unauthorised persons can neither use systems nor access personal data.
2. Data Transfer and Disclosure
The Contractor takes appropriate measures to protect personal data during transmission and storage. In particular, data transfer between the Client and the software is exclusively encrypted (e.g. via TLS/HTTPS), and stored data is encrypted where possible. Procedures for controlling data movements and preventing unauthorised disclosure are implemented.
3. Integrity and Auditability
Procedures are employed to track whether and by whom personal data has been entered, modified, or deleted. These include logged change and access entries as well as regular reviews of these logs.
4. Availability and Contingency Measures
The Contractor operates technical measures to ensure the availability and resilience of processing systems. These include:
- Ensuring redundant systems and services in the hosting environment.
- Regular backups and recovery processes for incident response.
- Monitoring of system availability.
These measures serve to quickly restore access to personal data in the event of technical disruptions.
5. Separation and Tenant Isolation
Personal data of different clients or purposes are logically and systematically processed separately. Mixing of different data sets is prevented, in particular through multi-tenant system architecture and data access roles.
6. Pseudonymisation and Data Minimisation
Where appropriate and technically feasible, personal data is pseudonymised or processed only to the extent necessary for the purpose of the commission. The retention period for personal content is limited to the processing-necessary minimum and is documented.
7. Damage Prevention and Security Awareness
The Contractor undertakes to implement appropriate organisational measures to address data protection and information security risks. These include:
- Awareness-raising and training of persons who handle personal data.
- Commitment of all persons entrusted with processing to confidentiality.
- Documentation and regular review of existing security measures.
These measures promote awareness and reduce the risk of human error.
8. Review and Adaptation
The Contractor regularly reviews the effectiveness of technical and organisational measures and adapts them to new risks, technologies, or legal requirements, while maintaining the contractually agreed level of protection.
Annex 5 – Specification of Good Cause
Good cause for extraordinary termination of this Data Processing Agreement exists in particular when the terminating Party, taking into account all circumstances of the individual case and weighing the mutual interests, cannot reasonably be expected to continue the contractual relationship until the agreed termination or until the expiry of a notice period (Section 314(1) BGB).
Such good cause exists in particular when:
- one of the Parties seriously or repeatedly violates essential contractual or legal obligations, in particular data protection requirements of the GDPR or this Agreement, and the other Party cannot reasonably be expected to adhere to the Agreement,
- the Customer uses the deepfake detection software for unlawful purposes or enables third parties to use it for such purposes,
- a Party, despite written warning, continues to or seriously violates its obligations under this Agreement,
- the Processor is no longer able to provide the contractually owed services in compliance with the statutory data protection requirements,
- a supervisory authority prohibits further processing of personal data within the framework of this Agreement,
- insolvency proceedings are opened against the assets of a Party or the opening is rejected for lack of assets.
Prior to pronouncing extraordinary termination, a written warning and setting of a deadline for remediation is generally required, unless special circumstances justify immediate termination (Section 314(2) BGB).
