Art. 28 GDPR
Data processing agreement (DPA)
This English version is provided for convenience. In case of discrepancies, the German version prevails.
1. Subject matter, duration and instructions
MASPro processes personal data solely to provide, maintain, secure and support the agreed platform functions, for the duration of the contract and in accordance with the controller’s documented instructions, unless Union or Member State law requires otherwise. An instruction that is evidently unlawful will be flagged and not carried out until the matter is clarified.
2. Nature, purpose, data and data subjects
- Purposes: Club, member, lead, appointment, form, communication, automation, document, payment and administrative workflows in line with the configuration.
- Data: Core and contact data, contract/membership data, bookings, communication, documents, payment status, consents as well as usage and security data. Special categories may only be processed where a documented legal basis and a suitable configuration exist.
- Data subjects: Employees and users of the controller as well as its members, leads, booking contacts, legal guardians, suppliers and communication partners.
3. MASPro’s obligations
MASPro places persons authorised to access data under a duty of confidentiality, provides reasonable assistance with data subject rights, data protection impact assessments and consultations with supervisory authorities, maintains a record of the relevant processing activities and makes the necessary compliance information available.
4. Security
Taking into account the state of the art, the costs, and the nature, scope and risks of processing, MASPro implements appropriate measures pursuant to Art. 32 GDPR. These include in particular encrypted transmission, role-based access, separate environments, secrets management, logging, backups, and update and incident processes. The measures may be developed further provided the level of protection is not materially reduced.
5. Sub-processors
The controller grants general authorisation for the categories and activated providers described under Security & providers. MASPro contractually obliges sub-processors to maintain an appropriate level of data protection and informs about material changes. The controller may object on reasoned data protection grounds; the parties will seek a reasonable solution, failing which the function concerned may be terminated.
6. Transfers to third countries
Transfers outside the EEA take place only on a permissible basis, in particular an adequacy decision or standard contractual clauses together with any additional measures required. Third-party connections activated by the controller itself also constitute a documented instruction to the extent they are necessary for the function.
7. Personal data breaches
Upon becoming aware of a breach affecting data processed on behalf of the controller, MASPro informs the controller without undue delay and makes available the information at its disposal so that the controller can assess its notification and communication obligations.
8. Data subject requests
If a request concerning data processed on behalf of a controller reaches MASPro directly, it is generally forwarded to the controller. MASPro responds only on the controller’s instruction or where mandatory law requires it, and provides the technical assistance available.
9. Return and deletion
After the end of the service, MASPro deletes or returns the data processed on behalf of the controller at the controller’s choice, unless a statutory obligation or a legitimate technical transition period prevents this. Data in backups is blocked and removed with the regular overwrite cycle.
10. Evidence and audits
MASPro makes appropriate information available as evidence. Audits are to be carried out with reasonable advance notice, during normal business hours, subject to confidentiality and without endangering other customers or systems. Existing audit reports and documentation may be used with priority; any necessary additional costs are generally borne by the controller, unless the audit reveals a material breach by MASPro.
11. Responsibility of the controller
The controller remains responsible for lawfulness, transparency, data minimisation, retention rules, user permissions, consents and its instructions. It configures optional integrations only where a sound legal basis exists and data subjects have been informed.
MASPro