Data Processing Agreement (DPA)

Last updated: 16 September 2026

between

eviral GmbH, Rheinpromenade 10, 40789 Monheim am Rhein

represented by its Managing Director Ömer Özcan

Düsseldorf Local Court, HRB 114450

Email: info@eviral.de

hereinafter "Processor"

and

the Customer (entrepreneur within the meaning of Section 14 BGB)

hereinafter "Controller"

1. Subject Matter of the Agreement

This agreement governs the processing of personal data by the Processor on behalf of the Controller pursuant to Article 28 GDPR. The subject matter is the provision of eviral's cloud-based reputation management platform, including AI-based analysis functions, review management, communication functions, and automation workflows, as well as the creation and publication of posts for the Controller's social media accounts.

2. Nature and Purpose of Processing

The processing serves the use of all functions of the platform, in particular:

  • aggregation and display of reviews
  • sending review requests via email, SMS, or WhatsApp
  • AI-based response suggestions
  • evaluation of reputation and performance
  • management of end-customer data
  • use of landing pages, widgets, and QR codes
  • creation, editing, and publication of posts for the Controller's social media accounts
  • processing of the image and video material provided by the Controller

3. Types of Data

The following personal data may be processed:

  • names, email addresses, telephone numbers
  • reviews, replies, feedback
  • technical data (IP address, browser information, timestamps)
  • communication content in connection with review requests
  • image and video recordings from the Controller's business, including persons, vehicles, and licence plates shown in them
  • metadata and logs

4. Categories of Data Subjects

  • end customers of the Controller
  • employees of the Controller
  • users of the platform
  • persons depicted in the image and video material provided

5. Duties of the Processor

The Processor undertakes to:

  • process data only within the framework of this agreement
  • not disclose data to third parties except where required for the performance of the service
  • bind all persons to confidentiality
  • implement appropriate technical and organizational measures
  • support the Controller in fulfilling data subject rights
  • report personal data breaches without undue delay
  • delete or hand over data after the end of the contract

6. Technical and Organizational Measures (TOMs)

The Processor guarantees measures such as:

  • TLS encryption
  • access restrictions and role models
  • secure EU server locations
  • regular backups
  • security logging
  • system monitoring

7. Sub-processors

The Controller grants its general written authorisation for the use of sub-processors in the following categories:

  • provider of the review and reputation platform (technical provision)
  • hosting and infrastructure providers with servers located in the EU
  • payment service providers
  • providers for telephony and for sending email, SMS, and messenger messages
  • providers for AI-supported text and speech processing

The Processor shall provide the Controller, upon request and in text form, with an up-to-date list of the sub-processors engaged, including name, address, and service provided.

The Processor shall inform the Controller in text form in good time before an additional sub-processor is engaged or an existing one is replaced. The Controller may object within four weeks of receipt of the notification for good cause.

8. Place of Processing

Processing takes place within the EU.

For services involving third-country transfers (Meta, Stripe, AI providers), standard contractual clauses pursuant to Article 46 GDPR are used.

Where posts are published on social media platforms, this is done on the instruction of the Controller. From the moment of publication, the platform operators process the content under their own responsibility and partly outside the EU. The Controller ensures that the persons depicted have consented to publication.

9. Rights and Obligations of the Controller

The Controller remains the owner of the data and is responsible for its lawfulness.

It must ensure that all stored end-customer data has been collected in compliance with the law.

10. Assistance with Data Subject Rights

The Processor supports with:

  • access requests
  • rectification
  • deletion
  • restriction and data portability

The Processor shall also support the Controller with a data protection impact assessment and with prior consultation of the supervisory authority, insofar as this is necessary and the required information is available to the Processor.

Upon request, the Processor shall make available to the Controller all information necessary to demonstrate compliance with this agreement and shall allow for reviews, including inspections. Reviews shall take place after reasonable prior notice, during usual business hours, and without unreasonable disruption of operations. Evidence may also be provided by means of current certificates, attestations, or reports from independent bodies.

11. Deletion of Data

After the end of the contract, data shall be deleted unless statutory retention obligations exist.

Export is the responsibility of the Controller.

12. Instructions Binding the Processor

The Processor may process personal data only in accordance with documented instructions of the Controller.

In the event of unclear instructions, clarification shall be sought.

If the Processor is of the opinion that an instruction infringes data protection law, it shall inform the Controller without undue delay and may suspend execution until confirmation is given.

13. Liability

Each party is liable within the framework of the statutory provisions.

The Processor is not liable for errors resulting from incorrect or unlawful instructions of the Controller.

14. Contract Term

This agreement applies for the duration of the use of the eviral platform and ends automatically with the main contract.

15. Final Provisions

German law applies.

The place of jurisdiction is Monheim am Rhein.

Amendments require text form.