MASProLegal

Art. 28 GDPR

Data processing agreement (DPA)

Last updated: 21 August 2026 · Part of the respective MASPro contract where MASPro processes personal data on behalf of a customer.

This English version is provided for convenience. In case of discrepancies, the German version prevails.

Parties: The processor is Ausbildungszentrum für Selbstverteidigung und Kampfkunst SportUnion (“MASPro”). The controller is the customer named in the MASPro contract. Individually signed agreements take precedence over this text.

1. Subject matter, duration and instructions

MASPro processes personal data solely to provide, maintain, secure and support the agreed platform functions, for the duration of the contract and in accordance with the controller’s documented instructions, unless Union or Member State law requires otherwise. An instruction that is evidently unlawful will be flagged and not carried out until the matter is clarified.

2. Nature, purpose, data and data subjects

3. MASPro’s obligations

MASPro places persons authorised to access data under a duty of confidentiality, provides reasonable assistance with data subject rights, data protection impact assessments and consultations with supervisory authorities, maintains a record of the relevant processing activities and makes the necessary compliance information available.

4. Security

Taking into account the state of the art, the costs, and the nature, scope and risks of processing, MASPro implements appropriate measures pursuant to Art. 32 GDPR. These include in particular encrypted transmission, role-based access, separate environments, secrets management, logging, backups, and update and incident processes. The measures may be developed further provided the level of protection is not materially reduced.

5. Sub-processors

The controller grants general authorisation for the categories and activated providers described under Security & providers. MASPro contractually obliges sub-processors to maintain an appropriate level of data protection and informs about material changes. The controller may object on reasoned data protection grounds; the parties will seek a reasonable solution, failing which the function concerned may be terminated.

6. Transfers to third countries

Transfers outside the EEA take place only on a permissible basis, in particular an adequacy decision or standard contractual clauses together with any additional measures required. Third-party connections activated by the controller itself also constitute a documented instruction to the extent they are necessary for the function.

7. Personal data breaches

Upon becoming aware of a breach affecting data processed on behalf of the controller, MASPro informs the controller without undue delay and makes available the information at its disposal so that the controller can assess its notification and communication obligations.

8. Data subject requests

If a request concerning data processed on behalf of a controller reaches MASPro directly, it is generally forwarded to the controller. MASPro responds only on the controller’s instruction or where mandatory law requires it, and provides the technical assistance available.

9. Return and deletion

After the end of the service, MASPro deletes or returns the data processed on behalf of the controller at the controller’s choice, unless a statutory obligation or a legitimate technical transition period prevents this. Data in backups is blocked and removed with the regular overwrite cycle.

10. Evidence and audits

MASPro makes appropriate information available as evidence. Audits are to be carried out with reasonable advance notice, during normal business hours, subject to confidentiality and without endangering other customers or systems. Existing audit reports and documentation may be used with priority; any necessary additional costs are generally borne by the controller, unless the audit reveals a material breach by MASPro.

11. Responsibility of the controller

The controller remains responsible for lawfulness, transparency, data minimisation, retention rules, user permissions, consents and its instructions. It configures optional integrations only where a sound legal basis exists and data subjects have been informed.