Data Processing Agreement
v2.0.0As of: May 26, 2026
Data Processing Agreement (DPA)
under Art. 28 GDPR · Annex 1 to the Usage Agreement
Version 1.1.0 · effective 2026-05-19
§ 1 Subject Matter and Duration
(1) This agreement governs the processing of personal data by P&P Unternehmensgruppe Marco Pavlov Pereira (the "Processor") on behalf of the relevant Buyer organisation (the "Controller") in the use of the supplier portal.
(2) The agreement applies for the term of the main contract (Usage Agreement) and ends automatically with its termination.
§ 2 Nature and Purpose of Processing
(1) The Processor processes the data only for these purposes:
- onboarding and master-data maintenance of suppliers,
- handling of RFQs, offers, purchase orders,
- document management (mill certificates, declarations of conformity, EMPB),
- audit logging of security-critical changes (e.g. IBAN changes),
- providing the platform infrastructure.
(2) Processing for the Processor's own purposes, in particular for AI training, is excluded.
§ 3 Categories of Data and Data Subjects
(1) Data categories: master data (company name, address, VAT ID, HRB, GLN, DUNS); employee contacts (name, role, email, phone, mobile); bank details (IBAN, BIC, holder); contract data (orders, offers, prices); certificates (ISO 9001, IATF, EMPB); audit-log data (timestamps, user IDs, changed fields).
(2) Data subjects: employees and authorised representatives of suppliers and of the Controller.
§ 4 Processor Obligations
The Processor will:
(1) Process personal data only on documented instructions of the Controller (Art. 28(3)(a) GDPR). Use of platform functions per Controller configuration is deemed documented instruction.
(2) Ensure that authorised personnel have committed themselves to confidentiality (Art. 28(3)(b)).
(3) Implement the technical and organisational measures (TOMs) required by Art. 32. Current TOMs are attached as Annex 2.
(4) Assist the Controller in fulfilling data-subject rights (Art. 12-23) via technical functions for access, rectification, erasure, restriction and portability.
(5) Assist the Controller in compliance with Art. 32–36, in particular DPIA and prior consultation.
(6) On termination, at the Controller's choice, delete or return personal data and delete existing copies, unless mandatory retention obligations apply (Art. 28(3)(g)).
(7) Provide all information necessary to demonstrate compliance with Art. 28 and enable audits (Art. 28(3)(h)). Audits may be conducted by the Controller or an independent auditor with 30 days' notice, at most once per calendar year (more on cause).
(8) Notify the Controller of any personal-data breach without undue delay, no later than 24 hours after becoming aware (Art. 33). The notice contains the information per Art. 33(3), to the extent then available.
(9) Maintain a record of processing activities under Art. 30(2) and disclose it on request of the Controller or supervisory authority.
§ 5 Controller Obligations
(1) The Controller is solely responsible for the lawfulness of processing vis-à-vis data subjects (Art. 24).
(2) The Controller ensures a legal basis under Art. 6 for every processing transmitted to the Processor.
(3) The Controller informs data subjects per Art. 13/14.
§ 6 Subprocessors
(1) The Processor may engage further subprocessors only with the Controller's general authorisation (Art. 28(2)).
(2) The current list of subprocessors is attached as Annex 3 and deemed generally authorised.
(3) The Processor announces intended changes with at least 30 days' notice. The Controller may object on legitimate grounds within this period; in that case the Processor may terminate this agreement extraordinarily.
(4) The Processor imposes on each subprocessor obligations equivalent to those in this agreement (Art. 28(4)).
§ 7 International Transfers
(1) Processing takes place within the European Union (Frankfurt region; subprocessors per Annex 3).
(2) Should a transfer to a third country become necessary, it shall occur only on the basis of an Art. 46 GDPR safeguard (particularly SCCs 2021/914 and a Transfer Impact Assessment [TIA]).
(3) Transfers to authorities of a non-cooperative third country occur only where legally compelled; the Processor informs the Controller without undue delay where legally permitted.
§ 8 Annexes
- Annex 2: Technical and Organisational Measures (TOMs)
- Annex 3: List of Subprocessors
- Annex 4: Transfer Impact Assessment (TIA), available on request
§ 9 Relationship with Usage Agreement
In case of conflict, this DPA prevails over the Usage Agreement to the extent the conflict concerns processing of personal data.
§ 10 Final Provisions
(1) German law applies.
(2) The exclusive place of jurisdiction is the Processor's seat.
(3) The German version is binding in case of conflict.
SHA-256: 46165f332c010cba2eb35ebae3e52cfa85df21f46d67a6adb705abb18ad6e219