Skip to content

Data Processing Agreement (DPA)

Last updated: 26 July 2026

This is a translation. In case of ambiguity or conflict, the German version prevails.

Parties

This data processing agreement under Art. 28 GDPR is concluded between the customer (the “controller”) and

Timon Filipovic, trading as “Percelia
In der Breite 54, 79224 Umkirch, Germany
(the “processor” or “Percelia”).

The DPA forms part of the terms and conditions. In data protection matters the DPA prevails in case of conflict.

§ 1 Subject matter, duration, nature and purpose

  • Subject matter: processing of personal data that becomes accessible to Percelia when auditing the websites and web applications named by the controller.
  • Duration: for the term of the main contract (terms and conditions).
  • Nature and purpose: loading the audited pages in the processor's browser, capturing screenshots and markup excerpts, automated and AI-assisted evaluation, human review of uncertain findings, production of the report and conformance statement, optionally recurring monitoring.

§ 2 Data categories and data subjects

  • Data categories: content visible on, or contained in the markup of, the audited pages (typically test data), credentials of the test accounts provided by the controller, contact and account data of the dashboard users named by the controller.
  • Data subjects: employees and contact persons of the controller, and persons whose data is displayed on the audited pages.
  • Special categories under Art. 9 GDPR are not part of the engagement. The controller ensures that audited areas hold test data and that no accounts of real users are made accessible.

§ 3 Instructions

Percelia processes personal data solely on documented instructions from the controller, unless required otherwise by law. Placing the order, defining the audit scope and the configuration in the dashboard constitute the standing instruction. Percelia informs the controller without undue delay if, in its opinion, an instruction infringes data protection law.

§ 4 Confidentiality

Percelia commits the persons involved in the processing to confidentiality under Art. 28(3)(b), Art. 29 and Art. 32(4) GDPR. This also covers external reviewers involved in the human review step.

§ 5 Technical and organisational measures (Art. 32 GDPR)

  • Confidentiality: role-based access rights, multi-factor authentication for administrative accounts, separation of customer data at database level through row-level security, screenshot storage that is not publicly readable, retrievable only through time-limited authenticated links.
  • Integrity: encryption in transit (TLS 1.2+) and at rest, encrypted storage of test credentials with no way to read them back through an interface, version control and code reviews.
  • No effect on the controller's systems: the check that triggers forms blocks the submission and aborts writing requests; suggested fixes are verified against a copy of the page inside the processor's environment only.
  • Availability: operation and backups in EU regions, monitoring, defined incident response process.
  • Review: regular review of the measures and reassessment on material changes to the processing.

§ 6 Subprocessors

The controller grants general authorisation for the subprocessors listed in the privacy policy. Percelia announces intended changes at least 30 days in advance. The controller may object on legitimate data protection grounds; if the service cannot then be provided, both parties have a right of extraordinary termination. Percelia concludes an agreement with each subprocessor imposing materially comparable obligations.

§ 7 Assistance and personal data breaches

Percelia assists the controller in fulfilling data subject rights (Art. 12 to 22 GDPR) and the obligations under Art. 32 to 36 GDPR through appropriate technical and organisational measures. Percelia informs the controller without undue delay, at the latest within 48 hours of becoming aware, of a personal data breach (Art. 33 GDPR) and provides the information required for notification.

§ 8 Deletion and return

After the processing activity ends, Percelia returns or deletes all personal data at the controller's choice. An export of reports and finding data is available for 30 days. Data subject to a statutory retention obligation is excluded. Deletion is confirmed in text form on request.

§ 9 Audit rights

On request Percelia provides the controller with the information necessary to demonstrate compliance with Art. 28 GDPR. The controller may carry out checks once a year or for cause, as a rule on the basis of written information and the evidence provided by the subprocessors. On-site inspections are possible with at least 30 days' notice; the controller bears the cost.

§ 10 Third-country transfers

Where Percelia transfers personal data to third countries, this is based on an adequacy decision (EU-US Data Privacy Framework, Implementing Decision (EU) 2023/1795) or on the Standard Contractual Clauses under Implementing Decision (EU) 2021/914 with the necessary additional measures. The material transfer concerns the AI analysis in the USA; the transmitted content is not used to train models.

§ 11 Liability and final provisions

Art. 82 GDPR applies externally towards data subjects; internally the liability provisions of the terms and conditions apply. German law applies, the place of jurisdiction is Freiburg im Breisgau, Germany. Amendments require text form.

Note

This DPA is provided for acceptance when an order is placed and is available as a signed document on request. Enquiries to hello@percelia.eu.