Data Processing Agreement (DPA)
Processing terms for customer data handled on behalf of MoveERP business customers.
Data Processing Agreement under Art. 28 GDPR
This DPA supplements the MoveERP main agreement where Walter Herbrandt / kölns-webdesign (the “processor”) processes personal data on behalf of the MoveERP business customer (the “controller”).
1. Subject and duration
The processing concerns technical provision and support of the booked MoveERP functions and generally lasts for the contract term plus any period needed for orderly return/deletion or legal obligations.
2. Nature and purpose
Depending on use, data may be collected, stored, structured, displayed, modified, calculated, converted into documents, emailed, exported and deleted to support enquiry, moving, calculation, quote, invoice and communication processes.
3. Data subjects
- Prospects and end customers of the controller
- Contacts at customers and business partners
- Employees and users of the controller
4. Data categories
In particular master/contact data, address and move data, quote/invoice data, inventory and service data, communication data and technical usage data.
5. Instructions
The processor processes personal data only on documented instructions from the controller unless required by law.
6. Confidentiality
Persons authorised to process the data are bound to confidentiality.
7. Security
Appropriate technical and organisational measures under Art. 32 GDPR are implemented, including access controls, permission concepts, encrypted transmission, backup/recovery measures and appropriate logging/update processes.
8. Sub-processors
Sub-processors may be used in compliance with Art. 28 GDPR. The current technical setup particularly includes ALL-INKL.COM for hosting/email and, where used for ordering, ablefy and technical service providers integrated by ablefy.
9. Assistance
The processor reasonably assists with data-subject rights, personal data breaches, DPIAs and supervisory-authority requests insofar as they relate to the processing.
10. Data breaches
Known personal-data breaches are reported to the controller without undue delay with the information then available.
11. Deletion and return
After the contract ends, personal data is deleted or returned according to the controller's choice where technically provided and unless statutory retention obligations apply.
12. Evidence and audits
The processor provides legally required information and permits proportionate audits by prior arrangement, provided operations are not disproportionately disrupted.
13. Controller responsibility
The controller remains responsible for the lawfulness of processing, legal bases, information duties to data subjects and the legality of its instructions.