# Data Processing Agreement Document identifier: **EPV-AVV-2026-10-07-V0.3-IG** Language: English · Last updated: 7 October 2026 Incorporable framework version for the selected engagement. Clauses 1 to 12 and completed Annexes 1 to 3 form part of the agreement. Selecting one product does not authorise processing by other products. This version neither requires nor claims a positive external legal opinion. A document label does not replace an effective agreement between the parties, their actual roles or necessary safeguards. Historical versions remain unchanged. ## 1. Parties and main agreement Controller or Client: {{AUFTRAGGEBERBLOCK}}. Processor or Contractor: EPV Managing UG (haftungsbeschränkt) i.G., Rosental 5, 80331 Munich, Germany. Managing Director: Fernando Santoro.. Main agreement and version: {{HAUPTVERTRAG_REFERENZ}} · {{HAUPTVERTRAG_VERSION}}. Start: {{VERARBEITUNGSBEGINN}}. End or determining event: {{VERARBEITUNGSENDE_ODER_EREIGNIS}}. Organisations and mandates concerned: {{BETROFFENE_ORGANISATIONEN_MANDATE}}. EPV processes the personal data specified in Annex 1 on behalf of the Client. Where the Client is itself a processor, subcontracting requires the corresponding authorisation and a consistent chain of instructions. Processing undertaken by the parties for their own purposes is assessed separately. ## 2. Subject matter and permitted processing The subject matter, duration, nature and purpose of processing, data types and categories of data subjects are set out bindingly in Annex 1. Permitted activities may include receipt, storage, structuring, inspection, analysis, provision to authorised persons, export, rectification and deletion. Data must not be used for other mandates, advertising, general model training or personal-data-based product development without a separate lawful and documented basis. A mere reference value or hash does not establish anonymity. Special data under Articles 9 and 10 GDPR and unnecessary individual-level, guest or applicant data are not included in the baseline scope. ## 3. Instructions and Client obligations The Client determines the purposes and permitted content, ensures the required legal bases and information for data subjects and appoints persons authorised to issue instructions. It transfers only data necessary for the engagement and informs EPV of required rectifications, restrictions and deletions. EPV processes data only on documented instructions, including in relation to transfers to third countries, unless a legal obligation requires otherwise. In that case, EPV informs the Client of that obligation before processing, unless prohibited by law. If EPV considers an instruction to infringe data protection law, it informs the Client without delay. Pending clarification, only the affected processing is suspended, to the extent necessary. An outstanding general legal opinion does not constitute such a finding. Instructions, changes and clarifications are recorded traceably. ## 4. Confidentiality and access EPV uses only persons committed to confidentiality or subject to an appropriate statutory duty of confidentiality. Permissions are limited to the relevant task and organisation or mandate. Administrator and support access must be restricted and traceable. Persons who have left or are no longer authorised lose access without delay. Merely being employed by an affiliated company does not justify access. EPV provides appropriate instruction and enforces the agreed confidentiality obligations. ## 5. Technical and organisational measures EPV implements the technical and organisational measures required under Article 32 GDPR, taking into account the nature, scope, context, purposes and risks of processing. The measures agreed for the engagement are described in Annex 2. Their effectiveness is reviewed regularly. Technical developments must not reduce the level of protection below an equivalent standard. Material changes affecting the agreed protection are communicated to the Client. Source-code or test evidence is not equated with a complete current production acceptance. ## 6. Other processors The other processors fully identified in Annex 3 are authorised within the scope specified there. A general list of possible providers does not authorise every service offered by those providers. Proposed additions or replacements are notified at least 14 calendar days before use, identifying the provider, task, processing location and basis of protection. The Client may object on substantiated data protection grounds. The parties seek a suitable alternative. If no workable solution is available, only the affected processing is changed or terminated; data is not transferred to the new provider against a justified objection. EPV imposes at least the relevant data protection obligations of this agreement on other processors and remains responsible to the Client for their fulfilment. For short-notice changes within a provider chain, information and safeguards must still meet statutory requirements; an internal scheduling issue is not a substitute for permission. ## 7. Processing outside the EEA Locations, backups, replication and relevant support access are documented in Annex 3. Where Chapter V GDPR applies, a transfer takes place only with the necessary basis and appropriate safeguards. When Standard Contractual Clauses are used, the need for additional transfer assessment and supplementary measures is considered. A contracting entity established in the EU or an EU sending region does not constitute an assurance of an exclusively EU data path. Public-authority access requests and legal obstacles are communicated to the extent permitted by law. This agreement replaces neither Standard Contractual Clauses nor necessary actual safeguards. ## 8. Assistance with data subject rights EPV supports the Client through appropriate technical and organisational measures in relation to access, rectification, erasure, restriction, data portability and objection. Requests sent directly to EPV concerning the Client's data are forwarded without delay to the Client's designated contact; EPV responds substantively only to the extent agreed or legally required. Before providing information or data, identity, authority to represent another person and mandate or organisation assignment are appropriately verified. Other clients' data, trade secrets and third-party rights must not be disclosed without authorisation. ## 9. Security incidents EPV informs the Client without delay after becoming aware of a personal data breach affecting data processed on its behalf. Initial information may be provided before the investigation is complete; missing information is supplemented in stages. The information includes, where known, the nature of the incident, affected data and categories of persons, likely consequences, measures taken or proposed and a reachable contact. EPV preserves necessary evidence and assists with assessment, containment and remediation. The statutory decision on reporting and notification lies with the respective controller. The generally applicable 72-hour period for notification to a supervisory authority is not a waiting period for EPV to inform the Client. ## 10. Further assistance and controls Taking into account the nature of processing and information available, EPV supports the Client in complying with Articles 32 to 36 GDPR, including any necessary impact assessment and prior consultation. EPV makes available the information necessary to demonstrate compliance and permits appropriate audits, including inspections, by the Client or an auditor appointed by it. Confidentiality and other clients' rights are protected. Evidence reports may facilitate audits but do not remove statutory audit rights. Justified urgent audits must not be prevented by unreasonable advance-notice or fee rules. ## 11. Return and deletion After the agreed processing ends, EPV returns or deletes the data at the Client's choice and deletes existing copies, unless a legal obligation requires storage. Annex 1 specifies the return method, necessary transition period and subsequent deletion process. An effective earlier deletion instruction is taken into account separately. Legally required residual records are documented by data scope, legal basis and end date, access-restricted and separated from further operational use. A blanket reference to legal defence does not justify unlimited retention of all documents received for processing on the Client's behalf. Backup copies are subject to a documented, limited rotation cycle. They are not used for regular processing. Existing deletion and restriction instructions are reapplied after restoration. EPV confirms completion traceably and identifies remaining statutory or technical retention, including its end conditions. ## 12. Duration, precedence and confirmation This agreement applies for the duration of the agreed processing, including permitted residual retention. Within their scope, data protection provisions take precedence over conflicting general contractual terms. Mandatory rights and liability rules, particularly claims of data subjects, are not restricted. Confirmation in text form or by electronic contract acceptance: Client: {{AUFTRAGGEBER_ANNAHME_PERSON_ROLLE_DATUM_NACHWEIS}}. EPV: {{EPV_ANNAHME_PERSON_ROLLE_DATUM_NACHWEIS}}. Confirmations refer to this document identifier, including the completed annexes, and the immutable version stored with the acceptance evidence. An internal Owner adoption does not automatically record acceptance by the Client and is not a lawyer's attestation. ## Annex 1 – Binding scope of the individual engagement ### 1.1 Selection and boundaries Selected product module: **ABLE**. Permitted individual values are MANDAT, GENRAL or ABLE. Where multiple products are commissioned, a separate completed set of annexes is attached for each product. A MANDAT annex does not, in particular, permit transferring GEN│RAL or AB│LE data into EPV │ OS or Nexus. For {{BETROFFENE_ORGANISATIONEN_MANDATE}}, the parties agree the specific purpose **{{VERARBEITUNGSZWECK}}**, service scope **{{VERARBEITUNGSSCOPE}}** and processing activities described in the applicable module below. A service change expands the personal-data scope only after a corresponding documented agreement. Unnecessary data is not collected, transferred or further processed from documents supplied. ### 1.2 MANDAT module Where MANDAT is selected, EPV performs those parts of mandate management expressly subject to instructions. These include receiving necessary mandate documents, their structured mandate-specific storage, retrieval and inspection, handling tasks and status reports, preparing decision proposals for human review and providing approved documents to expressly authorised mandate contacts. Rectification, restriction, secure export, return and deletion form part of the engagement. Data subjects are the Client's professional contacts and mandate owners and the employees, independent contractors, customers, suppliers or business partners necessary within the specific data selection. Permitted data comprises necessary names, functions, business contact details, mandate-related communications, organisational, project, service and document information and the recorded processing and approval status. The specific selection and limitation are **{{BETROFFENENGRUPPEN_UND_DATENKATEGORIEN}}**. This processing module does not cover EPV's independent purposes in contract administration, its own legal obligations or its own professional or corporate-office decisions. The actual separate allocation of roles in mandate-specific Annex C applies to those purposes. No blanket processing-on-behalf arrangement is agreed for the entire Executive Mandate. ### 1.3 GEN│RAL module Where GENRAL is selected, EPV provides the commissioned management application for processing the hotel, organisational and management information selected by the Client. Permitted activities are receipt, structuring, calculation and presentation of agreed indicators, documentation of actions and assignment to authorised professional owners, and user-initiated export, rectification and deletion. Human decisions remain with the Client; this module does not establish automatic changes to employment, pricing or contractual relationships. Personal data is limited to necessary business user, role and action assignments and the content specifically identified under **{{BETROFFENENGRUPPEN_UND_DATENKATEGORIEN}}**. Aggregated hotel indicators are preferably provided without personal data. Individual guest profiles, guest identities, unnecessary individual employee performance data, payment instruments and applicant data are not covered. Personal identifiability is not excluded merely by omitting names or using an identifier. ### 1.4 AB│LE module Where ABLE is selected, EPV processes the agreed self-assessment answers, permitted assessment documents, findings, action assignments and assessment reports on the Client's behalf. Permitted activities are receipt, secure storage, technical file inspection, structuring and analysis for the agreed assessment purpose, provision to authorised persons and rectification, export, return and deletion. Data subjects are business contacts, assessment participants and expressly necessary action owners. Documents are limited to exclude unnecessary personal content before provision; necessary categories of persons and data types are identified under **{{BETROFFENENGRUPPEN_UND_DATENKATEGORIEN}}**. This module does not permit AI training, public release of confidential reports or automatic transfer into an Executive Mandate, Nexus or another client's data. Scope and the purchase/subscription model remain governed by the main agreement; this DPA adds no prices, terms or payment rules. ### 1.5 Common exclusions and recipients None of the baseline modules includes data under Articles 9 or 10 GDPR, data concerning minors, applicant or active-sourcing processing, personal-data use in Nexus or Intelligence, personal mandate content in Notion, general model training, solely automated decisions or live Stripe payments. Automatic intake of public website enquiries is also not part of this engagement. Other existing separate agreements are not thereby declared reviewed or invalid. A later extension requires an expressly amended processing description and the legal and protective bases actually required. Authorised receiving roles, organisations and specific interfaces: **{{BERECHTIGTE_ROLLEN_EMPFÄNGER_SCHNITTSTELLEN}}**. There is no authorisation for “all EPV companies” or unrestricted support access. Information, exports and transfers are limited to this assignment and the actual recipient's authority. ### 1.6 Instructions, contacts and duration Client persons or clearly assigned roles authorised to give instructions: **{{WEISUNGSBERECHTIGTE}}**. Instruction recipients and substitutes at EPV: **{{EPV_WEISUNGSEMPFÄNGER}}**. Traceable instruction channel and change register: **{{WEISUNGSKANAL_UND_REGISTER}}**. Oral emergency instructions are confirmed in that channel without delay. Privacy and incident contacts with a reachable substitute: **{{DATENSCHUTZ_UND_INCIDENT_KONTAKTE}}**. This identifies operational contacts and does not fabricate the appointment of a data protection officer. Processing starts on the stated contractual date and ends upon **{{VERARBEITUNGSENDE_ODER_EREIGNIS}}**. Expiring customer permissions are withdrawn in accordance with **{{ZUGRIFFSENDE_REGEL}}**; the end of access, end of the contract and final deletion are separate events. ### 1.7 Return and deletion arrangements The Client selects **{{RÜCKGABE_ODER_LÖSCHUNG}}**. Where data is returned, export takes place in **{{EXPORTFORMAT_UND_GESICHERTER_RÜCKGABEWEG}}** to a verified authorised recipient. The scope and integrity of transferred files and structured data are documented traceably. Any technically necessary transition period is exclusively **{{ÜBERGANGSZEITRAUM_UND_BEGRÜNDUNG}}**; it does not extend a deletion obligation that has already taken effect. Production working data, exports and copies no longer required are deleted according to the object-specific rule **{{LÖSCHREGELN_FRIST_AUSLÖSER_SYSTEM}}**. The parties distinguish working copies, their own records subject to statutory retention and purely technical logs. A medium such as “email” or “document” does not, by itself, establish a blanket statutory retention period. Actual backup rotation and forwarding of deletion instructions by system: **{{BACKUP_ROTATION_UND_LÖSCHWEITERGABE}}**. Backup copies that cannot be individually deleted remain in the restricted backup procedure only until their documented expiry; following restoration, deletion and restriction instructions are reapplied. A provider retention period is not inferred from an internal EPV working rule. Residual records with a specific statutory basis or another genuinely valid separate legal basis, their scope, access limitations and end condition: **{{RESTAUFBEWAHRUNG_UND_LEGAL_HOLD}}**. If no residual records are necessary, the entry expressly states “none”. Every deletion completion record documents the engagement, systems, data scope, date, result, exceptions, responsible person and evidence reference. ## Annex 2 – Agreed technical and organisational measures The following measures are contractual obligations for the selected processing scope. The corresponding specific system version, including deviations and evidence, forms part of the agreement as **{{TOM_ANLAGE_VERSION_NACHWEIS}}**. These clauses do not claim that every measure has already been technically implemented merely by publishing the text. 1. **Identity and authorisation.** Persons receive individual accounts and only task-based rights. Reading, modifying, approving, exporting and deleting are checked server-side against organisation, mandate and object. Administrative functions and sensitive exports receive additional protection appropriate to the risk. The authentication and session methods actually used are identified in the evidence; a one-time code is not represented as multifactor authentication without an additional factor. Revocations and role changes are implemented promptly and traceably. 2. **Tenant separation.** Customer data and document access are logically linked to the mandate or organisation. Hiding a button does not replace a server-side control. Negative access attempts, other parties' object identifiers and role changes are tested using synthetic data at appropriate intervals and following relevant changes. 3. **Confidential transmission and storage.** Processing uses appropriate transport and storage encryption for the actual data path. Keys and credentials are managed separately from source code, ordinary logs and contractual documents. Documents or secrets do not appear in ordinary operational logs. Limits of external email delivery and permitted message types are expressly identified in the provider record. 4. **Document intake.** Where files form part of the engagement, permitted formats and sizes are limited and files are processed under protection and in quarantine before release. The active inspection path, failure scenarios and release status are evidenced. Uninspected, malicious files or files with an unresolved status due to a technical error are not released to users. 5. **Traceability.** Processing, approvals, permission changes and security-relevant events are logged with data minimisation. Logs are access-restricted and protected against unnoticed alteration by appropriate measures. Retention periods follow Annex 1 and the actual provider terms. 6. **Availability and restoration.** Backup procedures, rotation, responsibilities and restoration are documented. Restoration tests check integrity and reapplication of deletion and restriction instructions. Unverified completeness or regions are not represented as guaranteed. 7. **Data subject rights and deletion.** Requests are assigned to the correct controller and data set. Identity is verified appropriately and only to the extent necessary. Exports are recipient-bound and protected. Deletion instructions cover affected copies, providers and justified exceptions; actual results are documented. 8. **Incidents and operations.** Detection, containment, initial information, updates and closure are governed by the existing incident procedure. Information to the Client without delay waits neither for complete forensic results nor for an external legal opinion. Patch, vulnerability and change management follow the documented risk. 9. **Personnel and support.** Authorised persons receive instruction and are committed to confidentiality. Support or other provider access is limited to specific purposes, permissions and the necessary duration. Offboarding and regular access reviews are documented. Material deviations from the agreed protection are not legitimised merely by an internal status change. EPV informs the Client and ensures a level of protection appropriate to the actual risk. Necessary measures concern the specifically affected activity, not other independent services as a whole. ## Annex 3 – Authorised other processors and data locations Binding selected register: **{{GENEHMIGTE_UNTERAUFTRAGSVERARBEITER}}**. Each record included in it identifies at least the precise contracting entity and product, associated account/contract reference without secrets, specific service, role and data scope, primary processing, backup and replication, support access, further subprocessor chain, applicable contract/DPA version and evidence of incorporation, return/deletion and the basis and, where necessary, assessment of third-country transfers. Unknown locations are expressly described as not guaranteed; they are not replaced by the provider's address. Merely stating “EU” without identifying the data categories and contractual basis is not a complete location description. The Client authorises the initial specifically selected records by accepting this completed annex. Subsequent additions and replacements follow clause 6. Unselected services are not authorised. Services used by EPV for its own purposes as a controller are identified separately and are not mistakenly listed as subprocessors for all customer data. Existing EPV documentation is assigned in this order: IONOS, Resend, where applicable the Azure file-inspection path actually used, other genuinely necessary services and, lastly, OpenAI/Sites including the relevant hosting and storage components. This working order is not an exception for a provider actually already involved. In this baseline scope, Notion receives no personal mandate content; Stripe payments and general AI services are not authorised by this annex. Selection follows the actual data flow: an IONOS domain contract does not evidence email or OS hosting; the Resend sending region Ireland does not evidence all storage and support locations; the Azure scanner region does not evidence upstream file storage. Public DPA texts do not replace evidence of incorporation that matches the EPV contracting party. Existing provider information must be recorded with its specific evidence type and date. ## Sources and version provenance – documentation, not an additional acceptance declaration This version consolidates [EPV DPA V0.1](https://app.notion.com/p/3d53c202c4d08189a83cc1c2d1b7dad7) and the [historical T-002 Annex C V0.1](https://app.notion.com/p/3c63c202c4d081b58866c05bbd01eca1); the clauses are based in particular on [Article 28 GDPR](https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:32016R0679). The former annex is not retrospectively changed or attributed another reviewer's conclusion. The dated version incorporated into the agreement must be archived; later changes to these sources do not automatically become part of the contract.