/
Data Processing Agreement (DPA) reev

Data Processing Agreement (DPA)

As of July 2026

Disclaimer: Translation of the original document in German. In the event of discrepancy, inconsistency or conflict with the German version (in particular due to translation delays), the German version shall prevail
This Data Processing Agreement (hereinafter the “DPA”) applies between reev GmbH, Sandstraße 3, 80335 München (hereinafter the “Processor”) and the respective customer that uses the Processor’s services and has concluded the main agreement underlying this DPA (hereinafter the “Controller”). The DPA is incorporated upon conclusion of the main agreement or acceptance of the General Terms and Conditions of the Processor and forms part of the contractual relationship between the parties.

1. General

1.1 The Processor processes personal data on behalf of the Controller within the meaning of Art. 4(8) and Art. 28 of Regulation (EU) 2016/679 – General Data Protection Regulation (GDPR). This Agreement governs the rights and obligations of the parties in connection with the processing of personal data.

1.2 Where this Agreement uses the term “Data processing” or “Processing” (of data), the definition of “processing” within the meaning of Art. 4(2) GDPR shall apply.

2. Subject Matter of the Order

The subject matter of the processing, the nature and purpose of the processing, the type of personal data and the categories of data subjects are set out in Annex 1 to this Agreement.

3. Rights and Obligations of the Controller

3.1 The Controller is the controller within the meaning of Art. 4(7) GDPR for the processing of data on behalf carried out by the Processor. Pursuant to Section 3(5), the Processor is entitled to inform the Controller if, in its opinion, processing of data that is legally inadmissible is the subject of the order and/or of an instruction.

3.2 The Controller, as the controller, is responsible for safeguarding data subject rights. The Processor shall inform the Controller without undue delay if data subjects assert their data subject rights in connection with this processing of data on behalf vis-à-vis the Processor.

3.3 The Controller shall be entitled at any time to issue supplementary instructions regarding the nature, scope and procedure of the data processing to the Processor. Instructions must be given in text form (e.g. e-mail).

3.4 Provisions concerning any remuneration of additional expenditure incurred by the Processor as a result of supplementary instructions of the Controller shall remain unaffected.

3.5 The Controller shall inform the Processor without undue delay if it discovers errors or irregularities in connection with the processing of personal data by the Processor.

3.6 In the event that an obligation to provide information to third parties exists under Art. 33, 34 GDPR or under any other statutory reporting obligation applicable to the Controller, the Controller shall be responsible for compliance therewith.

4. General Obligations of the Processor

4.1 The Processor processes personal data exclusively within the scope of the agreements made and/or in compliance with any supplementary instructions issued by the Controller. Excepted from this are statutory provisions that may oblige the Processor to process data otherwise. In such a case, the Processor shall notify the Controller of these legal requirements prior to the processing, unless the law in question prohibits such notification on grounds of an important public interest. The purpose, nature and scope of the data processing shall otherwise be governed exclusively by this Agreement and/or the instructions of the Controller. Any processing of data deviating therefrom is prohibited to the Processor, unless the Controller has consented thereto in writing.

4.2 The Processor shall, as a matter of principle, carry out the processing of data on behalf in Member States of the European Union (EU) or of the European Economic Area (EEA). Any transfer to a third country requires the prior consent of the Controller and may only take place if the special requirements of Art. 44-48 GDPR are met or an exception within the meaning of Art. 49 GDPR applies.

4.3 The Processor shall inform the Controller without undue delay if, in its opinion, an instruction issued by the Controller infringes statutory provisions. The Processor shall be entitled to suspend the implementation of the instruction in question until it is confirmed or amended by the Controller. Where the Processor can demonstrate that processing in accordance with the Controller’s instruction may lead to liability of the Processor under Art. 82 GDPR, the Processor shall be free to suspend further processing to that extent until the liability between the parties has been clarified.

5. Data Protection Officer of the Processor

5.1 The Processor confirms that it has appointed a data protection officer in accordance with Art. 37 GDPR. The Processor shall ensure that the data protection officer has the necessary qualifications and the necessary expertise.

5.2 The obligation to appoint a data protection officer under paragraph 1 may cease to apply at the discretion of the Controller if the Processor can demonstrate that it is not legally obliged to appoint a data protection officer and the Processor can demonstrate that internal arrangements exist which ensure that personal data are processed in compliance with the statutory provisions, the provisions of this Agreement and any further instructions of the Controller.

6. Reporting Obligations of the Processor

6.1 The Processor is obliged to notify the Controller without undue delay of any infringement of data protection provisions or of the contractual agreements made and/or the instructions issued by the Controller which has occurred in the course of the processing of data by it or by other persons engaged in the processing. The same applies to any personal data breach concerning data which the Processor processes on behalf of the Controller.

6.2 Furthermore, the Processor shall inform the Controller without undue delay if a supervisory authority takes action against the Processor under Art. 58 GDPR and this may also concern a review of the processing which the Processor performs on behalf of the Controller.

6.3 The Processor is aware that the Controller may be subject to a reporting obligation in the case of personal data breaches under Art. 33, 34 GDPR, which provides for notification to the supervisory authority within 72 hours of becoming aware. The Processor shall support the Controller in implementing the reporting obligations. In particular, the Processor shall notify the Controller of any unauthorised access to personal data processed on behalf of the Controller without undue delay, but at the latest within 72 hours of becoming aware of the access. The Processor’s notification to the Controller must in particular contain the following information:

  • a description of the nature of the personal data breach, where possible specifying the categories and the approximate number of data subjects concerned, the categories concerned and the approximate number of personal data records concerned;
  • a description of the measures taken or proposed by the Processor to remedy the personal data breach and, where appropriate, measures to mitigate its possible adverse effects.

7. Duties of Cooperation of the Processor

7.1 The Processor shall support the Controller in its obligation to respond to requests for the exercise of data subject rights under Art. 12-23 GDPR. The provisions of Section 12 of this Agreement shall apply.

7.2 The Processor shall assist in the preparation of the records of processing activities by the Controller. It shall provide the Controller with the information required in this respect in an appropriate manner.

7.3 The Processor shall assist the Controller, taking into account the nature of the processing and the information available to it, in complying with the obligations set out in Art. 32-36 GDPR.

7.4 For support services that are not included in the service description or are not attributable to misconduct of the Processor and that go beyond the statutory obligations of the Processor, the Processor may claim reasonable remuneration on the basis of a market-standard offer (cf. Section 14).

8. Provision on Mobile Workplaces

8.1 The Processor may permit its employees who are tasked with the processing of personal data for the Controller to process personal data at mobile workplaces outside the Processor’s business premises.

8.2 The Processor shall ensure that compliance with the contractually agreed technical and organisational measures is also guaranteed when its employees use mobile workplaces. Deviations from individual contractually agreed technical and organisational measures must be agreed in advance with the Controller and approved by it in text form.

8.3 In particular, the Processor shall ensure that, where personal data are processed at mobile workplaces, the storage locations are configured in such a way that local storage of data on IT systems is excluded. Should this not be possible, the Processor shall ensure that local storage takes place exclusively in encrypted form and that other persons present at the location of the respective mobile workplace do not obtain access to these data.

9. Audit Rights

9.1 The Controller shall be entitled, at any time and to the extent necessary, to monitor the Processor’s compliance with the statutory data protection provisions and/or compliance with the contractual arrangements made between the parties and/or compliance with the Controller’s instructions.

9.2 The Processor is obliged to provide information to the Controller insofar as this is necessary for carrying out the monitoring within the meaning of paragraph 1.

9.3 The Controller may, subject to prior notice given within a reasonable period, carry out the monitoring within the meaning of paragraph 1 at the Processor’s place of business during the usual business hours. In doing so, the Controller shall ensure that the monitoring measures are carried out only to the extent necessary, so as not to disrupt the Processor’s business operations disproportionately. The parties assume that monitoring is required at most once a year. Further audits must be justified by the Controller stating the occasion. In the case of on-site monitoring, the Controller shall reimburse the Processor, to a reasonable extent, for the expenses incurred, including the personnel costs for the support and accompaniment of the auditing personnel on site. The basis for the calculation of costs shall be communicated to the Controller by the Processor prior to carrying out the monitoring.

9.4 At the Processor’s option, evidence of compliance with the technical and organisational measures may, instead of an on-site inspection, also be furnished by submitting a suitable, current attestation, reports or excerpts of reports from independent bodies (e.g. auditors, internal audit, data protection officer, IT security department, data protection auditors or quality auditors) or a suitable certification, where the audit report enables the Controller to satisfy itself in an appropriate manner of compliance with the technical and organisational measures pursuant to Annex 3 to this Agreement. Should the Controller have justified doubts as to the suitability of the audit document within the meaning of sentence 1, an on-site inspection may be carried out by the Controller. The Controller is aware that an on-site inspection in data centres is not possible or only possible in justified exceptional cases. For support services that are not included in the service description or are not attributable to misconduct of the Processor and that go beyond the statutory obligations of the Processor, the Processor may claim reasonable remuneration on the basis of a market-standard offer (cf. Section 14).

9.5 The Processor is obliged, in the case of measures by the supervisory authority against the Controller within the meaning of Art. 58 GDPR, in particular with regard to obligations to provide information and to permit monitoring, to provide the Controller with the necessary information and to enable the respective competent supervisory authority to carry out an on-site inspection. The Processor shall inform the Controller of any such planned measures.

9.6 The parties agree that, in the case of processing of personal data at mobile workplaces, the monitoring measures shall, in order to safeguard the personality rights of further persons at these mobile workplaces, primarily take place by way of a review of the assurance of the measures to be taken by the Processor pursuant to Section 9(2) and (3). On a case-by-case basis, the Controller shall also be enabled to monitor the mobile workplace of the Processor’s employees.

10. Sub-processing

10.1 The Processor is entitled to use the sub-processors specified in Annex 2 to this Agreement for the processing of data on behalf. The replacement of sub-processors or the engagement of further sub-processors is permitted subject to the conditions set out in paragraph 2.

10.2 The Processor shall select the sub-processor carefully and, prior to engagement, verify that it is able to comply with the agreements made between the Controller and the Processor. In particular, the Processor shall verify, in advance and regularly during the term of the contract, that the sub-processor has taken the technical and organisational measures required under Art. 32 GDPR for the protection of personal data. In the case of a planned replacement of a sub-processor or a planned engagement of a new sub-processor, the Processor shall inform the Controller in good time, but at the latest 4 weeks prior to the replacement or the new engagement, in text form (“Information”). The Controller shall be entitled to object to the replacement or the new engagement of the sub-processor, stating the reasons in text form, within 2 weeks of receipt of the “Information”. The objection may be withdrawn by the Controller at any time in text form. In the event of an objection, the Processor may terminate the contractual relationship with the Controller subject to a notice period of at least 14 days to the end of a calendar month. In setting the notice period, the Processor shall give appropriate consideration to the interests of the Controller. If the Controller does not object within three weeks of receipt of the “Information”, this shall be deemed to constitute the Controller’s consent to the replacement or the new engagement of the sub-processor concerned.

10.3 The Processor is obliged to obtain confirmation from the sub-processor that it has appointed a data protection officer in accordance with Art. 37 GDPR, provided that the sub-processor is legally obliged to appoint a data protection officer.

10.4 The Processor shall ensure that the provisions agreed in this Agreement and any supplementary instructions of the Controller also apply vis-à-vis the sub-processor.

10.5 The Processor shall conclude a data processing agreement with the sub-processor which meets the requirements of Art. 28 GDPR. In addition, the Processor shall impose on the sub-processor the same obligations for the protection of personal data as are laid down between the Controller and the Processor. A copy of the data processing agreement shall be provided to the Controller on request.

10.6 The Processor is, in particular, obliged to ensure by means of contractual provisions that the audit rights (Section 9 of this Agreement) of the Controller and of supervisory authorities also apply vis-à-vis the sub-processor and that corresponding audit rights of the Controller and of supervisory authorities are agreed. It must also be contractually stipulated that the sub-processor must tolerate these monitoring measures and any on-site inspections.

10.7 Services which the Processor obtains from third parties as a mere ancillary service in order to carry out its business activity shall not be regarded as sub-processing within the meaning of paragraphs 1 to 6. These include, for example, cleaning services, mere telecommunications services without any specific connection to services which the Processor provides for the Controller, postal and courier services, transport services, security services. The Processor is nevertheless obliged, also in the case of ancillary services provided by third parties, to ensure that appropriate precautions and technical and organisational measures have been taken to guarantee the protection of personal data. The maintenance and servicing of IT systems or applications constitutes a sub-processing relationship requiring consent and processing on behalf within the meaning of Art. 28 GDPR where the maintenance and inspection concerns such IT systems as are also used in connection with the provision of services for the Controller and where personal data processed on behalf of the Controller can be accessed during the maintenance.

11. Confidentiality Obligation

11.1 When processing data for the Controller, the Processor is obliged to maintain confidentiality regarding data which it receives or of which it becomes aware in connection with the order.

11.2 The Processor has familiarised its employees with the data protection provisions relevant to them and has bound them to confidentiality.

11.3 The obligations of the employees under paragraph 2 shall be evidenced to the Controller on request.

12. Safeguarding of Data Subject Rights

12.1 The Controller is solely responsible for safeguarding data subject rights. The Processor is obliged to support the Controller in its obligation to process requests from data subjects under Art. 12-23 GDPR. In doing so, the Processor shall in particular ensure that the information required in this respect is provided to the Controller without undue delay, so that the Controller can in particular comply with its obligations under Art. 12(3) GDPR.

12.2 Insofar as cooperation by the Processor is necessary for the safeguarding of data subject rights – in particular as regards access, rectification, blocking or erasure – by the Controller, the Processor shall take the respective necessary measures in accordance with the Controller’s instructions. The Processor shall, where possible, support the Controller by means of appropriate technical and organisational measures in complying with its obligation to respond to requests for the exercise of data subject rights.

12.3 For support services that are not included in the service description or are not attributable to misconduct of the Processor and that go beyond the statutory obligations of the Processor, the Processor may claim reasonable remuneration on the basis of a market-standard offer (cf. Section 14).

13. Remuneration

Any claims for remuneration which the Processor may assert under the foregoing clauses must be reasonable. The billing of the expenditure incurred at the market-standard hourly rates charged by the Processor, on the basis of an offer agreed between the Controller and the Processor prior to the expenditure being incurred, shall be deemed reasonable.

14. Technical and Organisational Measures for Data Security

14.1 The Processor undertakes vis-à-vis the Controller to comply with the technical and organisational measures necessary to comply with the applicable data protection provisions. This includes, in particular, the requirements of Art. 32 GDPR.

14.2 The status of the technical and organisational measures existing at the time of conclusion of the contract is attached as Annex 3 to this Agreement. The parties agree that, in order to adapt to technical and legal circumstances, amendments to the technical and organisational measures may become necessary. The Processor shall agree material changes which may affect the integrity, confidentiality or availability of the personal data with the Controller in advance. Measures which entail only minor technical or organisational changes and which do not adversely affect the integrity, confidentiality and availability of the personal data may be implemented by the Processor without coordination with the Controller. The Controller may at any time request a current version of the technical and organisational measures taken by the Processor.

15. Term of the Order

15.1 This DPA shall take effect upon conclusion of the main agreement or upon the Controller’s acceptance of the Processor’s General Terms and Conditions in electronic form (Art. 28(9) GDPR) and shall run for the duration of the main agreement existing between the parties

15.2 The Controller may terminate the contract at any time without observing a notice period if there is a serious infringement by the Processor of the applicable data protection provisions or of obligations under this Agreement, if the Processor is unable or unwilling to carry out an instruction of the Controller, or if the Processor, in breach of contract, refuses access to the Controller or to the competent supervisory authority.

16. Termination

16.1 Upon termination of the contract, the Processor shall, at the Controller’s option, return to the Controller or erase all documents, data and processing or usage results created which have come into its possession and which are connected with the order relationship. The erasure shall be documented in an appropriate manner.

16.2 The Processor may store personal data processed in connection with the order beyond the termination of the contract if and insofar as the Processor is subject to a statutory retention obligation. In such cases, the data may be processed only for the purposes of fulfilling the respective statutory retention obligations. Upon expiry of the retention obligation, the data shall be erased without undue delay.

17. Final Provisions

17.1 Should the Controller’s property at the Processor be jeopardised by measures of third parties (such as by attachment or seizure), by insolvency proceedings or by other events, the Processor shall inform the Controller without undue delay. The Processor shall inform the creditors without undue delay of the fact that the data concerned are data processed on behalf.

17.2 Text form (§ 126b BGB) shall apply to ancillary agreements, amendments and supplements to this Agreement; this shall also apply to any amendment of this text form clause.

17.3 Should individual parts of this Agreement be invalid, this shall not affect the validity of the remaining provisions of the Agreement.

Annex 1 – Subject Matter of the Order 

The subject matter of the order results from the main agreement (offer together with the annex to the schedule of services and the Processor’s order confirmation).  

Duration: Term of the main agreement plus statutory retention periods.   

Type of Data 

Purpose of the Processing 

Categories of Data Subjects 

Name (First Name, Last Name) 

Email address 

Phone number (business) – optional 

Appendix: User Account and Identification When Sending Passwords 

Employees with access to the administration interface 

Email address, 

RFID tag number, recharge card number (if applicable) and card name 

Appendix: User Account and Identification When Sending Passwords 

  • Employees as Drivers of EVs (Electric Vehicles) 
  • Other individuals (guests, subcontractors) who are authorized to drive EVs and regularly use the charging infrastructure 

Last Name, First Name 

Address (Street, House Number, ZIP Code, City) 

Billing for Charging Sessions Completed 

  • Employees as EV Drivers 
  • Other individuals (guests, subcontractors) who are authorized to drive EVs and regularly use the charging infrastructure 

Scan of the vehicle registration certificate 

Account Information: 

  • Account Holder (Last Name, First Name) 
  • IBAN 

Settlement and Clearing of Greenhouse Gas Emission Allowance Trading 

Employees as EV Drivers 

Data on company vehicles: 

  • License plate number 
  • RFID Tag Number 
  • Optional: Manufacturer, Brand 

Authorizing and Assigning Charging Sessions 

Owners of the client’s company vehicles 

Scan of the vehicle registration certificate 

Administration of the Greenhouse Gas Emission Reduction Allowance Trading Program 

Owners of the client’s company vehicles 

Charging data: 

  • Charging Station and Connection 
  • RFID tag number of the driver or vehicle 
  • Start and End 
  • Amount of energy charged, charge status, and charging power every 5 minutes during the process 
  • Rate 

Authorizing, Assigning, and Billing Charging Sessions 

  • Employees as EV Drivers 
  • Other individuals (guests, subcontractors) who are authorized to drive EVs and regularly use the charging infrastructure 
  • Owners of the client’s company vehicles 

Statistical data on usage patterns (pseudonymized): 

  • Use of the Charging Infrastructure—Frequency, Energy Consumption, and Location per User 

Product Improvement 

  • Employees with access to the administration interface 
  • Employees as EV Drivers 
  • Other individuals (guests, subcontractors) who are authorized to drive EVs and regularly use the charging infrastructure 

 

Annex 2 – Sub-processors 

The Processor uses, for the processing of data on behalf of the Controller, services of third parties which process data on its behalf (“sub-processors”). 

These are the following undertaking(s): 

Sub-processor 

Subject of the  

engagement 

Place of Processing 

Data transfer to third countries (legal basis) 

Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L1855 Luxembourg  

Cloud Infrastructure and CDN 

Germany / EU 

/ 

Intercom R&D Unlimited Company
124 St Stephen’s Green
Dublin 2, D02 C628
Ireland 

Support and Live Chat 

Ireland / EU 

/ 

PostHog Inc., 2261 Market St., #4008, San Francisco, CA 94114, USA (servers in Frankfurt, Germany) 

Product and Usage Analysis for Product Improvement 

Germany / EU 

/ 

 

Annex 3 – Technical and Organisational Measures (TOMs)

1. Introduction 

In accordance with Art. 32 GDPR, reev GmbH (“reev”) implements appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. In doing so, reev takes into account the state of the art, the costs of implementation as well as the nature, scope, context and purposes of the processing, as well as the likelihood of occurrence and the severity of the risk to the rights and freedoms of natural persons.  

These measures serve to protect personal data against unauthorised or unlawful processing as well as against accidental loss, accidental destruction, alteration, disclosure or unauthorised access. The measures described below apply to the processing of personal data by reev in connection with reev’s products, services, internal processes and supporting cloud infrastructure, unless otherwise stipulated in a customer-specific agreement.  

reev maintains an information security management system (ISMS) certified to ISO/IEC 27001. The implementation, monitoring and demonstration of security controls may be supported by appropriate compliance tools, including Vanta.  

 

2. Technical Measures 

2.1 Confidentiality
Access Control

Access to information, systems, applications, infrastructure and personal data is restricted to authorised persons and is granted in accordance with business requirements and the principle of least privilege. reev applies a strict need-to-know principle.  

Access rights are provisioned, adjusted, reviewed and revoked in accordance with reev’s Access Control Policy and in line with defined joiner, mover and leaver processes. Access is revoked or adjusted when employees change their role or leave the company. Privileged access is restricted to authorised persons and is subject to additional controls.  

Authentication 

reev uses secure authentication mechanisms to prevent unauthorised access to information systems. Multi-factor authentication (MFA) is required for access to production environments and for further systems, insofar as this is required on a risk basis and according to criticality.  

As far as technically possible, centralised identity and access management, role-based access controls and secure password or authentication requirements are applied. 

Encryption of Data at Rest 

Confidential data at rest are protected by strong encryption mechanisms, including AES-256-bit encryption where applicable, in accordance with reev’s Cryptography Policy. Encryption keys and secrets are managed by means of controlled key management and secrets management mechanisms. Access to encryption keys and secrets is restricted to authorised systems and persons; keys are rotated in accordance with the internal security requirements.
 

Encryption in Transit 

Data transmitted over public networks are protected by means of Transport Layer Security (TLS) and strong cipher suites. Publicly accessible services are configured and regularly reviewed in such a way that secure TLS configurations are maintained. reev aims to ensure that public endpoints meet recognised industry standards for transport encryption.

Physical Security 

reev implements measures to prevent unauthorised physical access to information processing facilities. Physical access controls, security areas and entry controls are applied in accordance with reev’s Physical Security Policy. Insofar as infrastructure is hosted with third-party cloud service providers, physical security is covered by the respective provider’s certified data centre controls and contractual security commitments.  

Data Separation and Logical Segregation 

Where applicable, customer data are logically separated in order to prevent unauthorised access between customers, environments and systems. Production, development and test environments are separated from one another; production data are not used in non-production environments unless they are appropriately protected and the use is authorised.  

Pseudonymisation, Masking and Data Minimisation 

Where appropriate and technically possible, reev applies data minimisation, pseudonymisation, masking, aggregation or access restrictions in order to reduce the disclosure of personal data and to limit the processing to what is necessary for the respective purpose. 

2.2 Integrity 
Change Management 

Material changes to systems, networks, infrastructure and processing facilities are documented, reviewed, tested and approved prior to deployment in the production environment. Changes are tested in environments separate from production, for example in staging or development environments.  

Emergency changes are subject to appropriate review and documentation following their implementation. The change management procedures serve to reduce the risk of unauthorised, untested or unintended changes to production systems.  

Secure Development 

reev applies secure development principles and engineering standards to software development activities. Development, test, staging and production environments are separated from one another. Access to source code repositories and deployment pipelines is restricted to authorised persons.  

Security aspects are integrated into the development life cycle, including code reviews, testing, dependency management and secure configuration practices. 

Logging and Monitoring 

Production infrastructure and relevant applications are configured to generate logs for security-relevant events, including user authentication events, access to systems, administrative activities, relevant CRUD operations and changes to security settings, as far as technically possible. 

Logs are protected against unauthorised access, unauthorised alteration and unauthorised deletion. Logs are retained for a defined period determined by the criticality of the system, statutory requirements, contractual obligations and operational needs. Relevant production logs are stored for at least 30 days, unless a longer retention period applies.  

Protection of Integrity 

reev implements controls intended to protect systems and data against unauthorised alteration, including access restrictions, change management, logging, monitoring, backup procedures and secure deployment processes. 

2.3 Availability and Resilience 
Data Backup 

Backups of relevant systems and databases are carried out daily. Backups are stored separately from production data and protected against unauthorised access. Where applicable, reev uses Cross-Region Replication (CRR) in AWS to support redundancy, resilience and disaster recovery.  

Backup data are protected by appropriate technical and organisational measures, including access restrictions and encryption where applicable. 

Recovery Testing 

The recoverability of backups is tested at least annually in order to validate data integrity, recovery procedures and operational readiness. The results of recovery tests are documented and reviewed; identified issues are addressed by means of appropriate corrective measures.  

Redundancy and Resilience 

Information processing facilities are implemented with sufficient redundancy in order to meet availability and resilience requirements. reev employs appropriate infrastructure and cloud architecture controls in order to reduce the risk of service interruptions and data loss.  

Personal data processed in the reev platform are, by default, hosted in AWS data centres within the European Union, in particular in the eu-central-1 region, Frankfurt am Main. Insofar as Cross-Region Replication is used, this takes place within the European Union or the European Economic Area. Processing of personal data outside the EU/EEA takes place only in accordance with the provisions on international transfers described in Section 3.4.  

Business Continuity and Disaster Recovery 

reev maintains business continuity and disaster recovery measures for critical systems and processes. These measures are designed to support the continuous availability of services and the timely restoration of access to personal data in the event of a physical or technical incident in accordance with Art. 32 GDPR.  

Recovery procedures and responsibilities are defined and reviewed regularly. 

2.4 Vulnerability, Patch and Malware Management 
Technical Vulnerability Management 

reev obtains information on technical vulnerabilities through vulnerability scans, vendor advisories, dependency monitoring, security advisories and penetration tests. Vulnerabilities are assessed on the basis of severity, exploitability, exposure and potential impact.  

Critical vulnerabilities are remediated or mitigated without undue delay on a risk basis. High-risk vulnerabilities are remediated within defined internal time limits, as a rule within 30 days, insofar as this is technically and operationally possible, unless a documented risk-based exception applies.  

Patch Management 

Security updates are assessed and applied on the basis of risk, severity and system criticality. Patch management procedures are designed to reduce exposure to known vulnerabilities while at the same time maintaining system stability and availability.  

Penetration Tests and Security Assessments 

reev carries out penetration tests at least annually and conducts additional security assessments where appropriate, for example following material changes to systems or architecture. Findings are reviewed, prioritised and remediated on a risk basis.  

Malware Protection 

Anti-malware and endpoint protection measures are deployed on end devices provided by reev and on relevant e-mail systems. Protection mechanisms are, as far as technically possible, configured to update automatically.  

2.5 Regular Review, Assessment and Evaluation 

reev regularly tests, assesses and evaluates the effectiveness of the technical and organisational measures by means of internal reviews, vulnerability assessments, penetration tests, risk assessments, monitoring activities, audits and ISO/IEC 27001 control reviews. Identified weaknesses are tracked and addressed by means of appropriate corrective measures.  

3. Organisational Measures 

3.1 Governance and Risk Management
ISMS Framework

reev maintains an information security management system (ISMS) certified to ISO/IEC 27001. The ISMS defines governance structures, responsibilities, policies, controls, risk management procedures and continuous improvement processes for information security.

Risk Assessment

reev regularly carries out risk assessments in the area of information security in order to identify threats, vulnerabilities and risks to information assets and personal data. Risk treatment measures are defined, implemented, monitored and reviewed in accordance with the ISMS.  

Policy Management

Information security and data protection policies are reviewed at least annually or in the event of material changes. Policies are communicated to the relevant persons and made available via appropriate internal channels.  

Classification of Assets and Information

reev maintains processes for the identification and classification of information assets on the basis of their sensitivity, business importance and security requirements. Appropriate handling requirements are applied in accordance with the classification of the respective information or asset.  

3.2 Personnel Security 
Screening 

Insofar as legally permissible and proportionate to the respective role, reev carries out screening prior to the commencement of employment which corresponds to the responsibilities, access rights and risk profile of the position. 

Awareness and Training

All employees receive regular information security training, including training on data protection responsibilities, confidentiality, the secure handling of personal data, phishing awareness, the reporting of security incidents and relevant GDPR obligations. Training takes place at least annually and as part of onboarding.  

Confidentiality Obligations 

Employees, contractors and other persons with access to confidential information or personal data are obliged to enter into confidentiality obligations or non-disclosure agreements. These obligations continue to apply, insofar as legally enforceable, even after termination of the employment or contractual relationship.  

Acceptable Use and Endpoint Security

reev defines requirements for the acceptable use of corporate systems, devices and information assets. End devices provided by reev are subject to appropriate security controls, which may include device management, encryption, screen lock requirements, anti-malware protection and update management.  

3.3 Incident Management 
Incident Response Plan

reev maintains a formal incident response plan for the identification, reporting, assessment, escalation, containment, investigation and remediation of security incidents. Employees are obliged to report suspected or confirmed security incidents via defined reporting channels.  

Handling of Personal Data Breaches

Insofar as an incident concerns personal data, reev assesses whether the incident constitutes a personal data breach and examines reporting and notification obligations under Art. 33 and Art. 34 GDPR. Insofar as reev acts as a processor, reev notifies the respective controller within seventy-two (72) hours in accordance with Art. 33(2) GDPR and the applicable contractual obligations.  

Incidents and personal data breaches are documented, including the facts relating to the incident, the effects, the remedial measures taken and the decisions on reporting or notification. Findings from incidents are used to improve security controls and response procedures.  

3.4 Third-Party Provider and Supplier Management 
Supplier Security 

Information security and data protection requirements are established and agreed with suppliers on the basis of the nature of the services provided and the risk associated with the processing. Suppliers that process personal data on behalf of reev or of reev’s customers are subject to appropriate contractual obligations.  

Data Processing Agreements

reev does not transfer personal data to a processor or sub-processor unless appropriate contractual arrangements are in place, including a data processing agreement or equivalent data protection provisions, insofar as this is required under Art. 28 GDPR. 

Sub-processors

Sub-processors are engaged only in accordance with the applicable customer agreements and the requirements of Art. 28 GDPR. Where necessary, the obligations of sub-processors include appropriate data protection, confidentiality, security, support, audit, deletion or return, as well as onward transfer obligations.  

A current list of the sub-processors used by reev is maintained at reev.com/legal. reev informs customers at least 30 days in advance of intended changes to sub-processors that process personal data of the respective customer, unless a shorter period is required for security, availability or other urgent reasons. Customers may, on legitimate data protection grounds, object to the change within the notice period. In this case, the parties will cooperate in good faith in order to find an appropriate solution.  

International Transfers

Insofar as personal data are transferred to a country outside the European Economic Area or are accessed from there, reev implements appropriate transfer mechanisms and safeguards in accordance with Chapter V GDPR, for example adequacy decisions, standard contractual clauses and supplementary measures where necessary. 

3.5 Data Retention and Secure Deletion 

Personal data are retained only for as long as is necessary for the respective processing purpose or as is required under applicable law, contract or legitimate business needs. Retention and deletion procedures are implemented for relevant systems and data categories.  

Upon expiry of applicable retention periods or in the case of valid deletion requests, personal data are deleted, anonymised or otherwise handled in accordance with the applicable legal and contractual requirements, unless further retention is required or permitted by law. 

3.6 Data Subject Rights and Support of the Controller 

Insofar as reev acts as a processor, reev supports the controller, as far as possible and taking into account the nature of the processing, in fulfilling obligations in connection with data subject rights under Chapter III GDPR as well as with the security of processing under Art. 32 GDPR, in accordance with the applicable contractual obligations. 

3.7 Audit, Compliance, and Continuous Improvement 

reev monitors the effectiveness of its security controls by means of the ISMS, internal reviews, audits, risk assessments, technical assessments and corrective action processes. Security and compliance documentation is maintained in order to demonstrate the implementation of appropriate technical and organisational measures.  

The TOMs are reviewed regularly and updated as needed, particularly in light of changes in legal requirements, technology, the risk landscape, organizational structure, processing activities, or security practices. 

We are happy to support you!

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Requested hardware *