DATA PROCESSING ADDENDUM (DPA)

This Data Processing Addendum (“DPA”) forms an integral part of the Terms of Use (the “Agreement”) between the Enterprise (“Data Controller” or “Customer”) and SynoptiCons GmbH dba PAQR, domiciled in Klagenfurt am Wörthersee, Austria (“Data Processor” or “PAQR”, “we”, “us”, or “our”).

1. Definitions

Capitalized terms not defined in this DPA shall have the meaning set forth in the Agreement. The terms “Personal Data”, “Data Subject”, “Processing”, “Controller”, “Processor”, and “Supervisory Authority” shall have the meanings given to them in the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

2. Processing of Personal Data

2.1. Roles
The parties acknowledge that the Customer acts as the Data Controller and PAQR acts as the Data Processor of the Customer’s Personal Data.

2.2. Instructions
PAQR shall process Personal Data strictly in accordance with the Customer’s documented instructions, which are constituted by the Agreement, this DPA, and the Customer’s use of the Services.

2.3. Compliance
Both parties shall comply with all applicable Data Protection Laws. The Customer guarantees that it has a lawful basis for processing the Personal Data submitted to the Services.

3. Sub-Processors

3.1. General Authorization
The Customer provides general written authorization for PAQR to engage the sub-processors listed in the Appendix 1 of the PAQR Privacy Policy to process Personal Data.

3.2. Notification of Changes
PAQR shall notify the Customer of any intended additions or replacements of sub-processors at least fifteen (15) days before the new sub-processor processes any Personal Data.

3.3. Right to Object
The Customer may reasonably object to a new sub-processor within the 15-day notice period. If no objection is made, the new sub-processor is deemed accepted. PAQR will remain fully liable to the Customer for the performance of its sub-processors’ data protection obligations.

4. Security and Personal Data Breaches

4.1. Security Measures
PAQR shall implement and maintain appropriate technical and organizational measures to protect Personal Data, as detailed in Annex II.

4.2. Breach Notification
PAQR shall notify the Customer without undue delay, and no later than twelve (12) hours, after becoming aware of any confirmed unauthorized disclosure of or access to Customer Personal Data.

5. Data Deletion

Upon termination of the Agreement, PAQR will return or delete Personal Data in accordance with the timelines defined in the Terms of Use. Following the 30-day Retrieval Period, PAQR guarantees to permanently delete or irreversibly anonymize all Personal Data from active environments and backups within thirty (30) days.

6. International Data Transfers

For any transfers of Personal Data outside the European Economic Area (EEA) to a country not recognized by the European Commission as providing an adequate level of protection, the parties agree that the EU Standard Contractual Clauses (Module 2: Controller to Processor) are hereby incorporated by reference. For the purposes of the SCCs:

  • Clause 7 (Docking clause) shall apply.
  • Clause 9, Option 2 (General written authorization) applies, with a 15-day notice period.
  • Clause 17 (Governing Law) and Clause 18 (Choice of forum): The SCCs shall be governed by the laws of Austria, and disputes shall be resolved before the courts of Vienna, Austria.

7. Limitation of Liability

Any claims arising out of or related to this DPA, including any Personal Data Breaches, shall be subject strictly to the limitations and exclusions of liability (including the 12-month liability cap) set forth in the Terms of Use.

8. General Provisions

8.1. Amendments
PAQR reserves the right to modify or supplement this DPA, with notice to the Customer, if required to do so by a supervisory authority, to reflect changes in Data Protection Laws, or to align with updated Standard Contractual Clauses. Any such updates shall be governed by the modification procedures set forth in the Terms of Use.

8.2. Conflict of Documents (Order of Precedence)
In the event of any conflict or inconsistency among the following documents, the order of precedence shall be: (1) the Standard Contractual Clauses; (2) this DPA; and (3) the Terms of Use.

8.3. Severability
If any individual provisions of this DPA are determined to be invalid or unenforceable, the validity and enforceability of the other provisions of this DPA will not be affected.

ANNEX 1

Details of Processing

RefCategoryDetails
ACategories of Data SubjectsEnterprise Users, Workspace Users, End Users, and Business Partners.
BCategories of Personal DataAccount information (name, email, authentication data), professional information (job title, employer), technical device/usage data, and data entries/tasks inputted into the Services.
CSensitive Data TransferredThe uploading or processing of Sensitive Personal Data (including health data, biometrics, or racial/ethnic origins) is strictly prohibited by the Terms of Use.
DNature and Purpose of ProcessingStorage, computing, and processing to deliver the Services in accordance with the Terms of Use.

ANNEX 2

Technical and Organizational Measures (TOMs)

PAQR maintains the following minimum security standards, aligned with ISO/IEC 27001:2022 and SOC 2 frameworks:

Security MeasureDescription
Data Residency100% of customer production data is stored and processed exclusively within the EU (GCP Europe West, Belgium).
EncryptionData at rest is encrypted using AES-256. Data in transit is encrypted using TLS 1.3 (with TLS 1.2 minimum fallback).
Access ControlStrict Role-Based Access Control (RBAC) bounded by workspaces, with native Time-based One-Time Password (TOTP) Multi-Factor Authentication (MFA) available and enforceable globally for all enterprise accounts.
Vulnerability ManagementStrict SLAs requiring the remediation of critical vulnerabilities (CVSS ≥ 9.0) within 48 hours and high vulnerabilities (CVSS ≥ 7.0) within 14 business days.
Resiliency & Disaster RecoveryMulti-Availability Zone deployment with a Recovery Time Objective (RTO) of < 4 hours and a Recovery Point Objective (RPO) of < 1 hour, supported by immutable backups and continuous point-in-time recovery.