Data Processing Agreement (DPA)
Last updated: 16 September 2026
between
eviral GmbH, Rheinpromenade 10, 40789 Monheim am Rhein
represented by its Managing Director Ömer Özcan
Düsseldorf Local Court, HRB 114450
Email: info@eviral.de
hereinafter "Processor"
and
the Customer (entrepreneur within the meaning of Section 14 BGB)
hereinafter "Controller"
1. Subject Matter of the Agreement
This agreement governs the processing of personal data by the Processor on behalf of the Controller pursuant to Article 28 GDPR. The subject matter is the provision of eviral's cloud-based reputation management platform, including AI-based analysis functions, review management, communication functions, and automation workflows, as well as the creation and publication of posts for the Controller's social media accounts.
2. Nature and Purpose of Processing
The processing serves the use of all functions of the platform, in particular:
- aggregation and display of reviews
- sending review requests via email, SMS, or WhatsApp
- AI-based response suggestions
- evaluation of reputation and performance
- management of end-customer data
- use of landing pages, widgets, and QR codes
- creation, editing, and publication of posts for the Controller's social media accounts
- processing of the image and video material provided by the Controller
3. Types of Data
The following personal data may be processed:
- names, email addresses, telephone numbers
- reviews, replies, feedback
- technical data (IP address, browser information, timestamps)
- communication content in connection with review requests
- image and video recordings from the Controller's business, including persons, vehicles, and licence plates shown in them
- metadata and logs
4. Categories of Data Subjects
- end customers of the Controller
- employees of the Controller
- users of the platform
- persons depicted in the image and video material provided
5. Duties of the Processor
The Processor undertakes to:
- process data only within the framework of this agreement
- not disclose data to third parties except where required for the performance of the service
- bind all persons to confidentiality
- implement appropriate technical and organizational measures
- support the Controller in fulfilling data subject rights
- report personal data breaches without undue delay
- delete or hand over data after the end of the contract
6. Technical and Organizational Measures (TOMs)
The Processor guarantees measures such as:
- TLS encryption
- access restrictions and role models
- secure EU server locations
- regular backups
- security logging
- system monitoring
7. Sub-processors
The Controller grants its general written authorisation for the use of sub-processors in the following categories:
- provider of the review and reputation platform (technical provision)
- hosting and infrastructure providers with servers located in the EU
- payment service providers
- providers for telephony and for sending email, SMS, and messenger messages
- providers for AI-supported text and speech processing
The Processor shall provide the Controller, upon request and in text form, with an up-to-date list of the sub-processors engaged, including name, address, and service provided.
The Processor shall inform the Controller in text form in good time before an additional sub-processor is engaged or an existing one is replaced. The Controller may object within four weeks of receipt of the notification for good cause.
8. Place of Processing
Processing takes place within the EU.
For services involving third-country transfers (Meta, Stripe, AI providers), standard contractual clauses pursuant to Article 46 GDPR are used.
Where posts are published on social media platforms, this is done on the instruction of the Controller. From the moment of publication, the platform operators process the content under their own responsibility and partly outside the EU. The Controller ensures that the persons depicted have consented to publication.
9. Rights and Obligations of the Controller
The Controller remains the owner of the data and is responsible for its lawfulness.
It must ensure that all stored end-customer data has been collected in compliance with the law.
10. Assistance with Data Subject Rights
The Processor supports with:
- access requests
- rectification
- deletion
- restriction and data portability
The Processor shall also support the Controller with a data protection impact assessment and with prior consultation of the supervisory authority, insofar as this is necessary and the required information is available to the Processor.
Upon request, the Processor shall make available to the Controller all information necessary to demonstrate compliance with this agreement and shall allow for reviews, including inspections. Reviews shall take place after reasonable prior notice, during usual business hours, and without unreasonable disruption of operations. Evidence may also be provided by means of current certificates, attestations, or reports from independent bodies.
11. Deletion of Data
After the end of the contract, data shall be deleted unless statutory retention obligations exist.
Export is the responsibility of the Controller.
12. Instructions Binding the Processor
The Processor may process personal data only in accordance with documented instructions of the Controller.
In the event of unclear instructions, clarification shall be sought.
If the Processor is of the opinion that an instruction infringes data protection law, it shall inform the Controller without undue delay and may suspend execution until confirmation is given.
13. Liability
Each party is liable within the framework of the statutory provisions.
The Processor is not liable for errors resulting from incorrect or unlawful instructions of the Controller.
14. Contract Term
This agreement applies for the duration of the use of the eviral platform and ends automatically with the main contract.
15. Final Provisions
German law applies.
The place of jurisdiction is Monheim am Rhein.
Amendments require text form.