HomeAboutPricingBlog
LoginTry for free→

Data Processing Agreement

Between the Customer as Controller and GraphApi.io GmbH as Processor

1. Subject of the Assignment

  1. The Controller commissions the Processor to process personal data based on the contract to which this processing agreement is annexed (the "Main Agreement"). This data processing Agreement shall take precedence over the Main Agreement in the event of any contradictions.
  2. The purpose of the processing of personal data by the Processor is to provide the services stipulated in the Main Agreement. The categories of data subjects and personal data affected by the processing shall be specified by the Controller in the settings of the client dashboard under "Processing of personal data". If no indication is made, the customers and employees of the Controller (current, potential, and former in each case), as well as data of all kinds, shall be affected by the processing.

2. Place of Processing

The commissioned processing shall occur exclusively in a member state of the European Union or another contracting state of the Agreement on the European Economic Area unless otherwise agreed with the Controller.

3. Responsibility and Right of Instruction of the Controller

  1. The Controller is the responsible party within the meaning of Art. 4 No. 7 DSGVO. He is responsible for compliance with legal data protection provisions.
  2. The Controller may issue instructions regarding the processing of personal data at any time.
  3. The Processor shall immediately notify the Controller in text form if instructions violate statutory regulations.
  4. If the Processor cannot follow an instruction for technical reasons, it must inform the Controller and coordinate further actions.

4. Duties of the Processor

  1. The Processor processes data exclusively per the Main Agreement and instructions from the Controller.
  2. The Processor confirms it is not legally required to appoint a data protection officer but will name a data protection contact.
  3. Confidentiality obligations will be imposed on all authorized data processors.
  4. The Processor supports the Controller in complying with Articles 32–36 GDPR.
  5. Assistance with data protection impact assessments (Art. 35 GDPR) and prior consultations (Art. 36 GDPR) will be provided.
  6. At the Controller’s request, the Processor provides proof of compliance with Art. 28 GDPR.
  7. The Processor will notify the Controller in case of third-party access attempts (e.g., insolvency proceedings).

5. Notification Obligation of the Controller

The Controller shall notify the Processor without undue delay if it detects errors or irregularities in processing or GDPR compliance.

6. Safety of the Processing

  1. The Processor shall take appropriate technical and organizational measures per Art. 32 DSGVO. Details are in Annex 1.
  2. The Processor may adjust security measures to technical or legal changes and must notify the Controller of critical changes.

7. Data Subject Rights

  1. The Processor shall assist the Controller in responding to data subject rights under Chapter 3 of the GDPR.
  2. If contacted by a data subject, the Processor will refer them to the Controller unless it is directly responsible under the GDPR.
  3. The Processor may charge a reasonable fee for these support services based on time spent.

8. Control Rights of the Controller

  1. The Controller has inspection rights to ensure GDPR compliance.
  2. Inspections may be delegated to third parties unless they are competitors of the Processor.
  3. The Processor shall cooperate with inspections and may require a confidentiality agreement.
  4. The Processor may charge a reasonable fee for inspection support.

9. Measures by Supervisory Authorities

  1. The Processor shall notify the Controller of any actions by authorities related to this Agreement.
  2. If the Controller is under investigation, the Processor shall assist, subject to reimbursement unless responsible.

10. Subprocessors

  1. The Processor uses subprocessors listed in Annex 2.
  2. Any changes to subprocessors must be communicated to the Controller and include:
    • Description of change
    • Name and address
    • Services and data involved
    • Relevant agreements and GDPR compliance evidence
    • Same info for further subprocessors if applicable
  3. The Controller may object within two weeks. If the objection is unreasonable, the Processor may terminate this Agreement with one month’s notice.
  4. The Processor must ensure subprocessor compliance with Art. 28 GDPR and the Controller’s instructions.

11. Violations of Data Protection Regulations

  1. The Processor must notify the Controller of any data breaches within 24 hours with details on:
    • Nature and scope of the breach
    • Contact details
    • Potential consequences
    • Measures taken
  2. Notifications to authorities or affected individuals remain the Controller’s responsibility.
  3. The Processor must clarify the incident and document measures taken.

12. Remuneration

The Processor shall not receive separate remuneration unless otherwise agreed.

13. Liability

Liability is governed by the Main Agreement. Data subjects’ direct statutory claims remain unaffected.

14. Term and Termination

The term aligns with the Main Agreement. Separate termination is only allowed for good cause unless otherwise stipulated.

15. Termination Consequences

  1. Upon contract end, the Processor must delete or return all personal data as instructed by the Controller.
  2. The Controller has the right to verify complete deletion or return.
  3. No right of retention applies to the Processor.

Annex 1 – Technical and Organizational Measures

Confidentiality (Art. 32(1)(b) GDPR)

Access Control

  • User login credentials
  • Access permissions process
  • User limits
  • Password protection and documentation
  • Access logging
  • Secondary application logins
  • Screen lock on inactivity

Access Control (Physical/Logical)

  • Authorization documentation
  • Data processing contracts for external maintenance
  • Logging of operations
  • Permissions and approvals process
  • Encryption of laptops, drives
  • Four-eyes principle
  • Separation of duties

Segregation Control

  • Separate databases and systems
  • Functional-based permissions
  • Multi-client systems
  • Development/production separation

Integrity (Art. 32(1)(b) GDPR)

Transfer Control

  • Encrypted emails, storage, file transfers
  • SSL/TLS protocols
  • USB/disk encryption
  • Secure shipping and transport logging
  • DLP system

Input Control

  • Access rights and logs
  • DMS with change history
  • Security software
  • Role-based responsibilities

Availability & Resilience

  • Security concepts and backups
  • Virus protection and updates
  • Offsite storage

Regular Assessment & Evaluation (Art. 32(1)(d) / Art. 25(1) GDPR)

  • Internal privacy policies
  • Training and secrecy obligations
  • Data protection officer (if appointed)
  • Processing records (Art. 30 GDPR)
  • DPIA and incident management procedures

Processing Only per Instruction

  • Contractual processing agreements
  • Instruction processes and accountability
  • Staff training
  • Sanctions for violations
  • Documented service provider selection

Annex 2 – Subprocessor

  • Amazon Web Services EMEA Sàrl
    38 Avenue John F. Kennedy, L-1855 Luxembourg (Lëtzebuerg)
    Operation data centers

Bring your ideas to life. Faster.

Product

  • Home
  • Pricing
  • Blog

Company

  • About
  • Contact

Resources

  • Docs
  • FAQ

© 2026 GraphApi.io GmbH · Turbofy® · All rights reserved

TermsPrivacyImprintDPAGDPR compliant