{"id":427919,"date":"2026-06-29T21:34:14","date_gmt":"2026-06-29T19:34:14","guid":{"rendered":"https:\/\/reev.com\/data-processing-agreement-dpa-reev\/"},"modified":"2026-07-22T11:24:23","modified_gmt":"2026-07-22T09:24:23","slug":"data-processing-agreement-dpa-reev","status":"publish","type":"page","link":"https:\/\/reev.com\/en\/data-processing-agreement-dpa-reev\/","title":{"rendered":"Data Processing Agreement (DPA) reev"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"427919\" class=\"elementor elementor-427919 elementor-424379\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-76d0be74 color-change e-flex e-con-boxed e-con e-parent\" data-id=\"76d0be74\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4dd4cd6d jet-breadcrumbs-align-left elementor-widget elementor-widget-jet-breadcrumbs\" data-id=\"4dd4cd6d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"jet-breadcrumbs.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-jet-breadcrumbs jet-blocks\">\n\t\t<div class=\"jet-breadcrumbs\">\n\t\t<div class=\"jet-breadcrumbs__content\">\n\t\t<div class=\"jet-breadcrumbs__wrap\"><div class=\"jet-breadcrumbs__item\"><a href=\"https:\/\/reev.com\/en\/\" class=\"jet-breadcrumbs__item-link is-home\" rel=\"home\" title=\"Home\">Home<\/a><\/div>\n\t\t<\/div>\n\t\t<\/div>\n\t\t<\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-01f25b9 color-change e-flex e-con-boxed e-con e-parent\" data-id=\"01f25b9\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-016607c e-con-full e-flex e-con e-child\" data-id=\"016607c\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d2266a5 elementor-widget__width-initial elementor-widget elementor-widget-heading\" data-id=\"d2266a5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Data Processing Agreement (DPA)<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ffb4e43 elementor-widget elementor-widget-text-editor\" data-id=\"ffb4e43\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"color: #000000;\">As of July 2026  <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d515fe0 e-flex e-con-boxed e-con e-parent\" data-id=\"d515fe0\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a844aac elementor-widget elementor-widget-text-editor\" data-id=\"a844aac\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<div id=\"message-list_1784646386.440649\" aria-setsize=\"-1\"><div aria-roledescription=\"Nachricht\"><span style=\"color: #000000;\"><strong>Disclaimer:<\/strong> Translation of the original document in German. In the event of discrepancy, inconsistency or conflict with the German version (in particular due to translation delays), the German version shall prevail<\/span><\/div><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ca381f6 elementor-widget elementor-widget-text-editor\" data-id=\"ca381f6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<div id=\"message-list_1784646386.440649\" aria-setsize=\"-1\"><div aria-roledescription=\"Nachricht\"><span class=\"TextRun Highlight SCXW75680320 BCX0\" lang=\"DE-DE\" style=\"color: #000000; font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, 'Helvetica Neue', Arial, 'Noto Sans', sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol', 'Noto Color Emoji';\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW75680320 BCX0\" data-ccp-parastyle=\"Paragraph\" data-ccp-parastyle-defn=\"{\">This Data Processing Agreement (hereinafter the \u201cDPA\u201d) applies between reev GmbH, Sandstra\u00dfe 3, 80335 M\u00fcnchen (hereinafter the \u201cProcessor\u201d) and the respective customer that uses the Processor&#8217;s services and has concluded the main agreement underlying this DPA (hereinafter the \u201cController\u201d). <\/span><\/span><span class=\"TextRun Highlight SCXW75680320 BCX0\" lang=\"DE-DE\" style=\"color: #000000; font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, 'Helvetica Neue', Arial, 'Noto Sans', sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol', 'Noto Color Emoji';\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW75680320 BCX0\" data-ccp-parastyle=\"Paragraph\"> The DPA is incorporated upon conclusion of the main agreement or acceptance of the General Terms and Conditions of the Processor and forms part of the contractual relationship between the parties.<\/span><\/span><\/div><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-54dc6a9c color-change e-flex e-con-boxed e-con e-parent\" data-id=\"54dc6a9c\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-0aab972 e-con-full e-flex e-con e-child\" data-id=\"0aab972\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e49607f elementor-widget elementor-widget-text-editor\" data-id=\"e49607f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h3><strong>1. <\/strong><b><span data-contrast=\"none\"><strong>General<\/strong> <\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>1.1<\/b> The Processor processes personal data on behalf of the Controller within the meaning of Art. 4(8) and Art. 28 of Regulation (EU) 2016\/679 \u2013 General Data Protection Regulation (GDPR). This Agreement governs the rights and obligations of the parties in connection with the processing of personal data. <\/span><\/p><p><span data-contrast=\"none\"><b>1.2<\/b> Where this Agreement uses the term \u201cData processing\u201d or \u201cProcessing\u201d (of data), the definition of \u201cprocessing\u201d within the meaning of Art. 4(2) GDPR shall apply.<\/span><\/p><h3><b><span data-contrast=\"none\">2. Subject Matter of the Order<\/span><\/b><\/h3><p>The subject matter of the processing, the nature and purpose of the processing, the type of personal data and the categories of data subjects are set out in Annex 1 to this Agreement.<\/p><h3><b><span data-contrast=\"none\">3. Rights and Obligations of the Controller<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>3.1 <\/b>The Controller is the controller within the meaning of Art. 4(7) GDPR for the processing of data on behalf carried out by the Processor. Pursuant to Section 3(5), the Processor is entitled to inform the Controller if, in its opinion, processing of data that is legally inadmissible is the subject of the order and\/or of an instruction. <\/span><\/p><p><span data-contrast=\"none\"><b>3.2<\/b> The Controller, as the controller, is responsible for safeguarding data subject rights. The Processor shall inform the Controller without undue delay if data subjects assert their data subject rights in connection with this processing of data on behalf vis-\u00e0-vis the Processor. <\/span><\/p><p><span data-contrast=\"none\"><b>3.3<\/b> The Controller shall be entitled at any time to issue supplementary instructions regarding the nature, scope and procedure of the data processing to the Processor. Instructions must be given in text form (e.g. e-mail). <\/span><\/p><p><span data-contrast=\"none\"><b>3.4<\/b> Provisions concerning any remuneration of additional expenditure incurred by the Processor as a result of supplementary instructions of the Controller shall remain unaffected.<\/span><\/p><p><span data-contrast=\"none\"><b>3.5<\/b> The Controller shall inform the Processor without undue delay if it discovers errors or irregularities in connection with the processing of personal data by the Processor.<\/span><\/p><p><span data-contrast=\"none\"><b>3.6<\/b> In the event that an obligation to provide information to third parties exists under Art. 33, 34 GDPR or under any other statutory reporting obligation applicable to the Controller, the Controller shall be responsible for compliance therewith.<\/span><\/p><h3><b><span data-contrast=\"none\">4. General Obligations of the Processor<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>4.1<\/b> The Processor processes personal data exclusively within the scope of the agreements made and\/or in compliance with any supplementary instructions issued by the Controller. Excepted from this are statutory provisions that may oblige the Processor to process data otherwise. In such a case, the Processor shall notify the Controller of these legal requirements prior to the processing, unless the law in question prohibits such notification on grounds of an important public interest. The purpose, nature and scope of the data processing shall otherwise be governed exclusively by this Agreement and\/or the instructions of the Controller. Any processing of data deviating therefrom is prohibited to the Processor, unless the Controller has consented thereto in writing. <\/span><\/p><p><span data-contrast=\"none\"><b>4.2<\/b> The Processor shall, as a matter of principle, carry out the processing of data on behalf in Member States of the European Union (EU) or of the European Economic Area (EEA). Any transfer to a third country requires the prior consent of the Controller and may only take place if the special requirements of Art. 44-48 GDPR are met or an exception within the meaning of Art. 49 GDPR applies. <\/span><\/p><p><span data-contrast=\"none\"><b>4.3<\/b> The Processor shall inform the Controller without undue delay if, in its opinion, an instruction issued by the Controller infringes statutory provisions. The Processor shall be entitled to suspend the implementation of the instruction in question until it is confirmed or amended by the Controller. Where the Processor can demonstrate that processing in accordance with the Controller&#8217;s instruction may lead to liability of the Processor under Art. 82 GDPR, the Processor shall be free to suspend further processing to that extent until the liability between the parties has been clarified. <\/span><\/p><h3><b><span data-contrast=\"none\">5. Data Protection Officer of the Processor<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>5.1<\/b> The Processor confirms that it has appointed a data protection officer in accordance with Art. 37 GDPR. The Processor shall ensure that the data protection officer has the necessary qualifications and the necessary expertise. <\/span><\/p><p><span data-contrast=\"none\"><b>5.2<\/b> The obligation to appoint a data protection officer under paragraph 1 may cease to apply at the discretion of the Controller if the Processor can demonstrate that it is not legally obliged to appoint a data protection officer and the Processor can demonstrate that internal arrangements exist which ensure that personal data are processed in compliance with the statutory provisions, the provisions of this Agreement and any further instructions of the Controller.<\/span><\/p><h3><b><span data-contrast=\"none\">6. Reporting Obligations of the Processor<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>6.1<\/b> The Processor is obliged to notify the Controller without undue delay of any infringement of data protection provisions or of the contractual agreements made and\/or the instructions issued by the Controller which has occurred in the course of the processing of data by it or by other persons engaged in the processing. The same applies to any personal data breach concerning data which the Processor processes on behalf of the Controller. <\/span><\/p><p><span data-contrast=\"none\"><b>6.2<\/b> Furthermore, the Processor shall inform the Controller without undue delay if a supervisory authority takes action against the Processor under Art. 58 GDPR and this may also concern a review of the processing which the Processor performs on behalf of the Controller.<\/span><\/p><p><span data-contrast=\"none\"><b>6.3<\/b> The Processor is aware that the Controller may be subject to a reporting obligation in the case of personal data breaches under Art. 33, 34 GDPR, which provides for notification to the supervisory authority within 72 hours of becoming aware. The Processor shall support the Controller in implementing the reporting obligations. In particular, the Processor shall notify the Controller of any unauthorised access to personal data processed on behalf of the Controller without undue delay, but at the latest within 72 hours of becoming aware of the access. The Processor&#8217;s notification to the Controller must in particular contain the following information: <\/span><\/p><ul><li><span data-contrast=\"none\">a description of the nature of the personal data breach, where possible specifying the categories and the approximate number of data subjects concerned, the categories concerned and the approximate number of personal data records concerned;<\/span><\/li><li><span data-contrast=\"none\">a description of the measures taken or proposed by the Processor to remedy the personal data breach and, where appropriate, measures to mitigate its possible adverse effects.<\/span><\/li><\/ul><h3><b><span data-contrast=\"none\">7. Duties of Cooperation of the Processor<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>7.1<\/b> The Processor shall support the Controller in its obligation to respond to requests for the exercise of data subject rights under Art. 12-23 GDPR. The provisions of Section 12 of this Agreement shall apply. <\/span><\/p><p><span data-contrast=\"none\"><b>7.2<\/b> The Processor shall assist in the preparation of the records of processing activities by the Controller. It shall provide the Controller with the information required in this respect in an appropriate manner. <\/span><\/p><p><span data-contrast=\"none\"><b>7.3<\/b> The Processor shall assist the Controller, taking into account the nature of the processing and the information available to it, in complying with the obligations set out in Art. 32-36 GDPR.<\/span><\/p><p><span data-contrast=\"none\"><b>7.4<\/b> For support services that are not included in the service description or are not attributable to misconduct of the Processor and that go beyond the statutory obligations of the Processor, the Processor may claim reasonable remuneration on the basis of a market-standard offer (cf. Section 14). <\/span><\/p><h3><b><span data-contrast=\"none\">8. Provision on Mobile Workplaces<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>8.1<\/b> The Processor may permit its employees who are tasked with the processing of personal data for the Controller to process personal data at mobile workplaces outside the Processor&#8217;s business premises.<\/span><\/p><p><span data-contrast=\"none\"><b>8.2<\/b> The Processor shall ensure that compliance with the contractually agreed technical and organisational measures is also guaranteed when its employees use mobile workplaces. Deviations from individual contractually agreed technical and organisational measures must be agreed in advance with the Controller and approved by it in text form. <\/span><\/p><p><span data-contrast=\"none\"><b>8.3<\/b> In particular, the Processor shall ensure that, where personal data are processed at mobile workplaces, the storage locations are configured in such a way that local storage of data on IT systems is excluded. Should this not be possible, the Processor shall ensure that local storage takes place exclusively in encrypted form and that other persons present at the location of the respective mobile workplace do not obtain access to these data. <\/span> <b> <\/b><\/p><h3><b><span data-contrast=\"none\">9. Audit Rights<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>9.1<\/b> The Controller shall be entitled, at any time and to the extent necessary, to monitor the Processor&#8217;s compliance with the statutory data protection provisions and\/or compliance with the contractual arrangements made between the parties and\/or compliance with the Controller&#8217;s instructions.<\/span><\/p><p><span data-contrast=\"none\"><b>9.2<\/b> The Processor is obliged to provide information to the Controller insofar as this is necessary for carrying out the monitoring within the meaning of paragraph 1.<\/span><\/p><p><span data-contrast=\"none\"><b>9.3<\/b> The Controller may, subject to prior notice given within a reasonable period, carry out the monitoring within the meaning of paragraph 1 at the Processor&#8217;s place of business during the usual business hours. In doing so, the Controller shall ensure that the monitoring measures are carried out only to the extent necessary, so as not to disrupt the Processor&#8217;s business operations disproportionately. The parties assume that monitoring is required at most once a year. Further audits must be justified by the Controller stating the occasion. In the case of on-site monitoring, the Controller shall reimburse the Processor, to a reasonable extent, for the expenses incurred, including the personnel costs for the support and accompaniment of the auditing personnel on site. The basis for the calculation of costs shall be communicated to the Controller by the Processor prior to carrying out the monitoring. <\/span><\/p><p><span data-contrast=\"none\"><b>9.4<\/b> At the Processor&#8217;s option, evidence of compliance with the technical and organisational measures may, instead of an on-site inspection, also be furnished by submitting a suitable, current attestation, reports or excerpts of reports from independent bodies (e.g. auditors, internal audit, data protection officer, IT security department, data protection auditors or quality auditors) or a suitable certification, where the audit report enables the Controller to satisfy itself in an appropriate manner of compliance with the technical and organisational measures pursuant to Annex\u202f3 to this Agreement. Should the Controller have justified doubts as to the suitability of the audit document within the meaning of sentence 1, an on-site inspection may be carried out by the Controller. The Controller is aware that an on-site inspection in data centres is not possible or only possible in justified exceptional cases. For support services that are not included in the service description or are not attributable to misconduct of the Processor and that go beyond the statutory obligations of the Processor, the Processor may claim reasonable remuneration on the basis of a market-standard offer (cf. Section 14). <\/span><\/p><p><span data-contrast=\"none\"><b>9.5<\/b> The Processor is obliged, in the case of measures by the supervisory authority against the Controller within the meaning of Art. 58 GDPR, in particular with regard to obligations to provide information and to permit monitoring, to provide the Controller with the necessary information and to enable the respective competent supervisory authority to carry out an on-site inspection. The Processor shall inform the Controller of any such planned measures. <\/span><\/p><p><span data-contrast=\"none\"><b>9.6<\/b> The parties agree that, in the case of processing of personal data at mobile workplaces, the monitoring measures shall, in order to safeguard the personality rights of further persons at these mobile workplaces, primarily take place by way of a review of the assurance of the measures to be taken by the Processor pursuant to Section 9(2) and (3). On a case-by-case basis, the Controller shall also be enabled to monitor the mobile workplace of the Processor&#8217;s employees. <\/span><\/p><h3><b><span data-contrast=\"none\">10. Sub-processing<\/span><\/b><\/h3><p><b>10.1<\/b> The Processor is entitled to use the sub-processors specified in <span data-contrast=\"none\"><span data-contrast=\"none\">Annex 2<\/span><\/span><span data-contrast=\"none\"> to this Agreement for the processing of data on behalf. The replacement of sub-processors or the engagement of further sub-processors is permitted subject to the conditions set out in paragraph 2. <\/span><\/p><p><span data-contrast=\"none\"><b>10.2<\/b> The Processor shall select the sub-processor carefully and, prior to engagement, verify that it is able to comply with the agreements made between the Controller and the Processor. In particular, the Processor shall verify, in advance and regularly during the term of the contract, that the sub-processor has taken the technical and organisational measures required under Art. 32 GDPR for the protection of personal data. In the case of a planned replacement of a sub-processor or a planned engagement of a new sub-processor, the Processor shall inform the Controller in good time, but at the latest 4 weeks prior to the replacement or the new engagement, in text form (\u201cInformation\u201d). The Controller shall be entitled to object to the replacement or the new engagement of the sub-processor, stating the reasons in text form, within 2 weeks of receipt of the \u201cInformation\u201d. The objection may be withdrawn by the Controller at any time in text form. In the event of an objection, the Processor may terminate the contractual relationship with the Controller subject to a notice period of at least 14 days to the end of a calendar month. In setting the notice period, the Processor shall give appropriate consideration to the interests of the Controller. If the Controller does not object within three weeks of receipt of the \u201cInformation\u201d, this shall be deemed to constitute the Controller&#8217;s consent to the replacement or the new engagement of the sub-processor concerned. <\/span><\/p><p><span data-contrast=\"none\"><b>10.3<\/b> The Processor is obliged to obtain confirmation from the sub-processor that it has appointed a data protection officer in accordance with Art. 37 GDPR, provided that the sub-processor is legally obliged to appoint a data protection officer. <\/span><\/p><p><span data-contrast=\"none\"><b>10.4<\/b> The Processor shall ensure that the provisions agreed in this Agreement and any supplementary instructions of the Controller also apply vis-\u00e0-vis the sub-processor.<\/span><\/p><p><span data-contrast=\"none\"><b>10.5<\/b> The Processor shall conclude a data processing agreement with the sub-processor which meets the requirements of Art. 28 GDPR. In addition, the Processor shall impose on the sub-processor the same obligations for the protection of personal data as are laid down between the Controller and the Processor. A copy of the data processing agreement shall be provided to the Controller on request. <\/span><\/p><p><span data-contrast=\"none\"><b>10.6<\/b> The Processor is, in particular, obliged to ensure by means of contractual provisions that the audit rights (Section 9 of this Agreement) of the Controller and of supervisory authorities also apply vis-\u00e0-vis the sub-processor and that corresponding audit rights of the Controller and of supervisory authorities are agreed. It must also be contractually stipulated that the sub-processor must tolerate these monitoring measures and any on-site inspections. <\/span><\/p><p><span data-contrast=\"none\"><b>10.7<\/b> Services which the Processor obtains from third parties as a mere ancillary service in order to carry out its business activity shall not be regarded as sub-processing within the meaning of paragraphs 1 to 6. These include, for example, cleaning services, mere telecommunications services without any specific connection to services which the Processor provides for the Controller, postal and courier services, transport services, security services. The Processor is nevertheless obliged, also in the case of ancillary services provided by third parties, to ensure that appropriate precautions and technical and organisational measures have been taken to guarantee the protection of personal data. The maintenance and servicing of IT systems or applications constitutes a sub-processing relationship requiring consent and processing on behalf within the meaning of Art. 28 GDPR where the maintenance and inspection concerns such IT systems as are also used in connection with the provision of services for the Controller and where personal data processed on behalf of the Controller can be accessed during the maintenance. <\/span><\/p><h3><b><span data-contrast=\"none\">11. Confidentiality Obligation<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>11.1<\/b> When processing data for the Controller, the Processor is obliged to maintain confidentiality regarding data which it receives or of which it becomes aware in connection with the order.<\/span><\/p><p><span data-contrast=\"none\"><b>11.2<\/b> The Processor has familiarised its employees with the data protection provisions relevant to them and has bound them to confidentiality. <\/span><\/p><p><span data-contrast=\"none\"><b>11.3<\/b> The obligations of the employees under paragraph 2 shall be evidenced to the Controller on request.<\/span><\/p><h3><b><span data-contrast=\"none\">12. Safeguarding of Data Subject Rights<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>12.1<\/b> The Controller is solely responsible for safeguarding data subject rights. The Processor is obliged to support the Controller in its obligation to process requests from data subjects under Art. 12-23 GDPR. In doing so, the Processor shall in particular ensure that the information required in this respect is provided to the Controller without undue delay, so that the Controller can in particular comply with its obligations under Art. 12(3) GDPR. <\/span><\/p><p><span data-contrast=\"none\"><b>12.2<\/b> Insofar as cooperation by the Processor is necessary for the safeguarding of data subject rights \u2013 in particular as regards access, rectification, blocking or erasure \u2013 by the Controller, the Processor shall take the respective necessary measures in accordance with the Controller&#8217;s instructions. The Processor shall, where possible, support the Controller by means of appropriate technical and organisational measures in complying with its obligation to respond to requests for the exercise of data subject rights. <\/span><\/p><p><span data-contrast=\"none\"><b>12.3<\/b> For support services that are not included in the service description or are not attributable to misconduct of the Processor and that go beyond the statutory obligations of the Processor, the Processor may claim reasonable remuneration on the basis of a market-standard offer (cf. Section 14).<\/span><\/p><h3><b><span data-contrast=\"none\">13. Remuneration<\/span><\/b><\/h3><p><span data-contrast=\"none\">Any claims for remuneration which the Processor may assert under the foregoing clauses must be reasonable. The billing of the expenditure incurred at the market-standard hourly rates charged by the Processor, on the basis of an offer agreed between the Controller and the Processor prior to the expenditure being incurred, shall be deemed reasonable. <\/span><\/p><h3><b><span data-contrast=\"none\">14. Technical and Organisational Measures for Data Security<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>14.1<\/b> The Processor undertakes vis-\u00e0-vis the Controller to comply with the technical and organisational measures necessary to comply with the applicable data protection provisions. This includes, in particular, the requirements of Art. 32 GDPR. <\/span><\/p><p><span data-contrast=\"none\">14.2 The status of the technical and organisational measures existing at the time of conclusion of the contract is attached as <b>Annex 3 <\/b><\/span><span data-contrast=\"none\"> to this Agreement. The parties agree that, in order to adapt to technical and legal circumstances, amendments to the technical and organisational measures may become necessary. The Processor shall agree material changes which may affect the integrity, confidentiality or availability of the personal data with the Controller in advance. Measures which entail only minor technical or organisational changes and which do not adversely affect the integrity, confidentiality and availability of the personal data may be implemented by the Processor without coordination with the Controller. The Controller may at any time request a current version of the technical and organisational measures taken by the Processor. <\/span><\/p><h3><b><span data-contrast=\"none\">15. Term of the Order<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>15.1<\/b> This DPA shall take effect upon conclusion of the main agreement or upon the Controller&#8217;s acceptance of the Processor&#8217;s General Terms and Conditions in electronic form (Art. 28(9) GDPR) and shall run for the duration of the main agreement existing between the parties<\/span><\/p><p><span data-contrast=\"none\"><b>15.2<\/b> The Controller may terminate the contract at any time without observing a notice period if there is a serious infringement by the Processor of the applicable data protection provisions or of obligations under this Agreement, if the Processor is unable or unwilling to carry out an instruction of the Controller, or if the Processor, in breach of contract, refuses access to the Controller or to the competent supervisory authority.<\/span><\/p><h3><b><span data-contrast=\"none\">16. Termination<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>16.1<\/b> Upon termination of the contract, the Processor shall, at the Controller&#8217;s option, return to the Controller or erase all documents, data and processing or usage results created which have come into its possession and which are connected with the order relationship. The erasure shall be documented in an appropriate manner. <\/span><\/p><p><span data-contrast=\"none\"><b>16.2 <\/b>The Processor may store personal data processed in connection with the order beyond the termination of the contract if and insofar as the Processor is subject to a statutory retention obligation. In such cases, the data may be processed only for the purposes of fulfilling the respective statutory retention obligations. Upon expiry of the retention obligation, the data shall be erased without undue delay. <\/span><\/p><h3><b><span data-contrast=\"none\">17. Final Provisions<\/span><\/b><\/h3><p><span data-contrast=\"none\"><b>17.1<\/b> Should the Controller&#8217;s property at the Processor be jeopardised by measures of third parties (such as by attachment or seizure), by insolvency proceedings or by other events, the Processor shall inform the Controller without undue delay. The Processor shall inform the creditors without undue delay of the fact that the data concerned are data processed on behalf. <\/span><\/p><p><span data-contrast=\"none\"><b>17.2<\/b> Text form (\u00a7 126b BGB) shall apply to ancillary agreements, amendments and supplements to this Agreement; this shall also apply to any amendment of this text form clause.<\/span><\/p><p><span data-contrast=\"none\"><b>17.3<\/b> Should individual parts of this Agreement be invalid, this shall not affect the validity of the remaining provisions of the Agreement.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-99ea323 color-change e-flex e-con-boxed e-con e-parent\" data-id=\"99ea323\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-f6671e3 e-con-full e-flex e-con e-child\" data-id=\"f6671e3\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-9259f26 elementor-widget elementor-widget-text-editor\" data-id=\"9259f26\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h3 aria-level=\"1\"><b><span data-contrast=\"none\">Annex 1 &#8211; Subject Matter of the Order<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335551550\":6,\"335551620\":6,\"335559738\":480,\"335559740\":340}\">&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"none\">The subject matter of the order results from the main agreement (offer together with the annex to the schedule of services and the Processor&#8217;s order confirmation).&nbsp;<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":220,\"335559739\":220}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"none\">Duration: Term of the main agreement plus statutory retention periods. <\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":220,\"335559739\":220}\">&nbsp;<\/span>&nbsp;<\/p>\n<table data-tablestyle=\"MsoNormalTable\" data-tablelook=\"160\" aria-rowcount=\"9\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"none\">Type of Data<\/span><\/b><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"none\">Purpose of the Processing<\/span><\/b><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"none\">Categories of Data Subjects<\/span><\/b><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Name (First Name, Last Name)<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"none\">Email address<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"none\">Phone number (business) \u2013 optional<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Appendix: User Account and Identification When Sending Passwords<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Employees with access to the administration interface<\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Email address,<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"none\">RFID tag number, recharge card number (if applicable) and card name<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Appendix: User Account and Identification When Sending Passwords<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"none\">Employees as Drivers of EVs (Electric Vehicles)<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"none\">Other individuals (guests, subcontractors) who are authorized to drive EVs and regularly use the charging infrastructure<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Last Name, First Name<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"none\">Address (Street, House Number, ZIP Code, City)<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Billing for Charging Sessions Completed<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"none\">Employees as EV Drivers<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"none\">Other individuals (guests, subcontractors) who are authorized to drive EVs and regularly use the charging infrastructure<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Scan of the vehicle registration certificate<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"none\">Account Information:<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"5\" data-aria-level=\"1\"><span data-contrast=\"none\">Account Holder (Last Name, First Name)<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"6\" data-aria-level=\"1\"><span data-contrast=\"none\">IBAN<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Settlement and Clearing of Greenhouse Gas Emission Allowance Trading<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Employees as EV Drivers<\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Data on company vehicles:<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"7\" data-aria-level=\"1\"><span data-contrast=\"none\">License plate number<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"8\" data-aria-level=\"1\"><span data-contrast=\"none\">RFID Tag Number<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"9\" data-aria-level=\"1\"><span data-contrast=\"none\">Optional: Manufacturer, Brand<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Authorizing and Assigning Charging Sessions<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Owners of the client&#8217;s company vehicles<\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Scan of the vehicle registration certificate<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Administration of the Greenhouse Gas Emission Reduction Allowance Trading Program<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Owners of the client&#8217;s company vehicles<\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Charging data:<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"10\" data-aria-level=\"1\"><span data-contrast=\"none\">Charging Station and Connection<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"11\" data-aria-level=\"1\"><span data-contrast=\"none\">RFID tag number of the driver or vehicle<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"12\" data-aria-level=\"1\"><span data-contrast=\"none\">Start and End<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"13\" data-aria-level=\"1\"><span data-contrast=\"none\">Amount of energy charged, charge status, and charging power every 5 minutes during the process<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"14\" data-aria-level=\"1\"><span data-contrast=\"none\">Rate<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Authorizing, Assigning, and Billing Charging Sessions<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"15\" data-aria-level=\"1\"><span data-contrast=\"none\">Employees as EV Drivers<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"16\" data-aria-level=\"1\"><span data-contrast=\"none\">Other individuals (guests, subcontractors) who are authorized to drive EVs and regularly use the charging infrastructure<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"17\" data-aria-level=\"1\"><span data-contrast=\"none\">Owners of the client&#8217;s company vehicles<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Statistical data on usage patterns (pseudonymized):<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"18\" data-aria-level=\"1\"><span data-contrast=\"none\">Use of the Charging Infrastructure\u2014Frequency, Energy Consumption, and Location per User<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Product Improvement<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"19\" data-aria-level=\"1\"><span data-contrast=\"none\">Employees with access to the administration interface<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"20\" data-aria-level=\"1\"><span data-contrast=\"none\">Employees as EV Drivers<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"31\" data-list-defn-props=\"{\"335552541\":1,\"335559685\":720,\"335559991\":360,\"469769226\":\"Symbol\",\"469769242\":[8226],\"469777803\":\"left\",\"469777804\":\"\uf0b7\",\"469777815\":\"hybridMultilevel\"}\" data-aria-posinset=\"21\" data-aria-level=\"1\"><span data-contrast=\"none\">Other individuals (guests, subcontractors) who are authorized to drive EVs and regularly use the charging infrastructure<\/span><span data-ccp-props=\"{\"134233279\":false,\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559685\":315,\"335559739\":80,\"335559740\":240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3 aria-level=\"1\"><b><span data-contrast=\"none\">&nbsp;<\/span><\/b><\/h3>\n<h3 aria-level=\"1\"><b><span data-contrast=\"none\">Annex 2 &#8211; Sub-processors<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335551550\":6,\"335551620\":6,\"335559738\":480,\"335559740\":340}\">&nbsp;<\/span><\/h3>\n<p>The Processor uses, for the processing of data on behalf of the Controller, services of third parties which process data on its behalf (\u201csub-processors\u201d).<span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"none\">These are the following undertaking(s):<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<table data-tablestyle=\"MsoNormalTable\" data-tablelook=\"1536\" aria-rowcount=\"4\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td data-celllook=\"69905\">\n<p><b><span data-contrast=\"none\">Sub-processor<\/span><\/b><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"69905\">\n<p><b><span data-contrast=\"none\">Subject of the&nbsp;<\/span><\/b><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<p><b><span data-contrast=\"none\">engagement<\/span><\/b><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"69905\">\n<p><b><span data-contrast=\"none\">Place of Processing<\/span><\/b><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"69905\">\n<p><b><span data-contrast=\"none\">Data transfer to third countries (legal basis)<\/span><\/b><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6}\">&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L1855 Luxembourg&nbsp;<\/span><span data-ccp-props=\"{\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Cloud Infrastructure and CDN<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Germany \/ EU<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">\/<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"4369\">\n<p>Intercom R&#038;D Unlimited Company <br\/>124 St Stephen&#8217;s Green <br\/>Dublin 2, D02 C628 <br\/>Ireland<span data-ccp-props=\"{\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Support and Live Chat<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Ireland \/ EU<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">\/<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">PostHog Inc., 2261 Market St., #4008, San Francisco, CA 94114, USA (servers in Frankfurt, Germany)<\/span><span data-ccp-props=\"{\"201341983\":1,\"335559738\":80,\"335559739\":160,\"335559740\":300,\"469777462\":[2025],\"469777927\":[0],\"469777928\":[1]}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Product and Usage Analysis for Product Improvement<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">Germany \/ EU<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"none\">\/<\/span><span data-ccp-props=\"{\"335551550\":6,\"335551620\":6,\"335559738\":200,\"335559739\":200}\">&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3><b><span data-contrast=\"none\">&nbsp;<\/span><\/b><\/h3>\n<h3><b><span data-contrast=\"none\">Annex 3 &#8211; Technical and Organisational Measures (TOMs)<\/span><\/b><\/h3>\n<h3 aria-level=\"1\"><strong>1. Introduction<span style=\"font-family: 'Roobert Variable', sans-serif; letter-spacing: 0px; font-size: 26px;\" data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/strong><\/h3>\n<p><span data-contrast=\"auto\">In accordance with Art. 32 GDPR, reev GmbH (\u201creev\u201d) implements appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. In doing so, reev takes into account the state of the art, the costs of implementation as well as the nature, scope, context and purposes of the processing, as well as the likelihood of occurrence and the severity of the risk to the rights and freedoms of natural persons. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">These measures serve to protect personal data against unauthorised or unlawful processing as well as against accidental loss, accidental destruction, alteration, disclosure or unauthorised access. The measures described below apply to the processing of personal data by reev in connection with reev&#8217;s products, services, internal processes and supporting cloud infrastructure, unless otherwise stipulated in a customer-specific agreement. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">reev maintains an information security management system (ISMS) certified to ISO\/IEC 27001. The implementation, monitoring and demonstration of security controls may be supported by appropriate compliance tools, including Vanta. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h3 aria-level=\"2\">&nbsp;<\/h3>\n<h3 aria-level=\"2\"><b><span data-contrast=\"auto\">2. Technical Measures<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/h3>\n<h5 aria-level=\"3\"><b><span data-contrast=\"auto\">2.1 Confidentiality<\/span><\/b><\/h5>\n<h6><strong>Access Control<\/strong><\/h6>\n<p><span data-contrast=\"auto\">Access to information, systems, applications, infrastructure and personal data is restricted to authorised persons and is granted in accordance with business requirements and the principle of least privilege. reev applies a strict need-to-know principle. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Access rights are provisioned, adjusted, reviewed and revoked in accordance with reev&#8217;s Access Control Policy and in line with defined joiner, mover and leaver processes. Access is revoked or adjusted when employees change their role or leave the company. Privileged access is restricted to authorised persons and is subject to additional controls.  <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Authentication&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev uses secure authentication mechanisms to prevent unauthorised access to information systems. Multi-factor authentication (MFA) is required for access to production environments and for further systems, insofar as this is required on a risk basis and according to criticality. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">As far as technically possible, centralised identity and access management, role-based access controls and secure password or authentication requirements are applied.<\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Encryption of Data at Rest&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">Confidential data at rest are protected by strong encryption mechanisms, including AES-256-bit encryption where applicable, in accordance with reev&#8217;s Cryptography Policy. Encryption keys and secrets are managed by means of controlled key management and secrets management mechanisms. Access to encryption keys and secrets is restricted to authorised systems and persons; keys are rotated in accordance with the internal security requirements. <br\/>  <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Encryption in Transit&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">Data transmitted over public networks are protected by means of Transport Layer Security (TLS) and strong cipher suites. Publicly accessible services are configured and regularly reviewed in such a way that secure TLS configurations are maintained. reev aims to ensure that public endpoints meet recognised industry standards for transport encryption.  <\/span><\/p>\n<h6 aria-level=\"4\"><strong>Physical Security&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev implements measures to prevent unauthorised physical access to information processing facilities. Physical access controls, security areas and entry controls are applied in accordance with reev&#8217;s Physical Security Policy. Insofar as infrastructure is hosted with third-party cloud service providers, physical security is covered by the respective provider&#8217;s certified data centre controls and contractual security commitments.  <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Data Separation and Logical Segregation&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">Where applicable, customer data are logically separated in order to prevent unauthorised access between customers, environments and systems. Production, development and test environments are separated from one another; production data are not used in non-production environments unless they are appropriately protected and the use is authorised. <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Pseudonymisation, Masking and Data Minimisation&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">Where appropriate and technically possible, reev applies data minimisation, pseudonymisation, masking, aggregation or access restrictions in order to reduce the disclosure of personal data and to limit the processing to what is necessary for the respective purpose.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h5><b><span data-contrast=\"auto\">2.2 Integrity<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/h5>\n<h6 aria-level=\"4\"><strong>Change Management&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">Material changes to systems, networks, infrastructure and processing facilities are documented, reviewed, tested and approved prior to deployment in the production environment. Changes are tested in environments separate from production, for example in staging or development environments. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Emergency changes are subject to appropriate review and documentation following their implementation. The change management procedures serve to reduce the risk of unauthorised, untested or unintended changes to production systems. <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Secure Development&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev applies secure development principles and engineering standards to software development activities. Development, test, staging and production environments are separated from one another. Access to source code repositories and deployment pipelines is restricted to authorised persons.  <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Security aspects are integrated into the development life cycle, including code reviews, testing, dependency management and secure configuration practices.<\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Logging and Monitoring&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">Production infrastructure and relevant applications are configured to generate logs for security-relevant events, including user authentication events, access to systems, administrative activities, relevant CRUD operations and changes to security settings, as far as technically possible.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Logs are protected against unauthorised access, unauthorised alteration and unauthorised deletion. Logs are retained for a defined period determined by the criticality of the system, statutory requirements, contractual obligations and operational needs. Relevant production logs are stored for at least 30 days, unless a longer retention period applies.  <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Protection of Integrity&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev implements controls intended to protect systems and data against unauthorised alteration, including access restrictions, change management, logging, monitoring, backup procedures and secure deployment processes.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h5><b><span data-contrast=\"auto\">2.3 Availability and Resilience<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/h5>\n<h6 aria-level=\"4\"><strong>Data Backup&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">Backups of relevant systems and databases are carried out daily. Backups are stored separately from production data and protected against unauthorised access. Where applicable, reev uses Cross-Region Replication (CRR) in AWS to support redundancy, resilience and disaster recovery.  <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Backup data are protected by appropriate technical and organisational measures, including access restrictions and encryption where applicable.<\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Recovery Testing&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">The recoverability of backups is tested at least annually in order to validate data integrity, recovery procedures and operational readiness. The results of recovery tests are documented and reviewed; identified issues are addressed by means of appropriate corrective measures. <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Redundancy and Resilience&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">Information processing facilities are implemented with sufficient redundancy in order to meet availability and resilience requirements. reev employs appropriate infrastructure and cloud architecture controls in order to reduce the risk of service interruptions and data loss. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"none\">Personal data processed in the reev platform are, by default, hosted in AWS data centres within the European Union, in particular in the eu-central-1 region, Frankfurt am Main. Insofar as Cross-Region Replication is used, this takes place within the European Union or the European Economic Area. Processing of personal data outside the EU\/EEA takes place only in accordance with the provisions on international transfers described in Section 3.4.  <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Business Continuity and Disaster Recovery&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev maintains business continuity and disaster recovery measures for critical systems and processes. These measures are designed to support the continuous availability of services and the timely restoration of access to personal data in the event of a physical or technical incident in accordance with Art. 32 GDPR. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Recovery procedures and responsibilities are defined and reviewed regularly.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h5 aria-level=\"2\"><b><span data-contrast=\"auto\">2.4 Vulnerability, Patch and Malware Management<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/h5>\n<h6 aria-level=\"4\"><strong>Technical Vulnerability Management&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev obtains information on technical vulnerabilities through vulnerability scans, vendor advisories, dependency monitoring, security advisories and penetration tests. Vulnerabilities are assessed on the basis of severity, exploitability, exposure and potential impact. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Critical vulnerabilities are remediated or mitigated without undue delay on a risk basis. High-risk vulnerabilities are remediated within defined internal time limits, as a rule within 30 days, insofar as this is technically and operationally possible, unless a documented risk-based exception applies. <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Patch Management&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">Security updates are assessed and applied on the basis of risk, severity and system criticality. Patch management procedures are designed to reduce exposure to known vulnerabilities while at the same time maintaining system stability and availability. <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Penetration Tests and Security Assessments&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev carries out penetration tests at least annually and conducts additional security assessments where appropriate, for example following material changes to systems or architecture. Findings are reviewed, prioritised and remediated on a risk basis. <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong>Malware Protection&nbsp;<\/strong><\/h6>\n<p><span data-contrast=\"auto\">Anti-malware and endpoint protection measures are deployed on end devices provided by reev and on relevant e-mail systems. Protection mechanisms are, as far as technically possible, configured to update automatically. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h5 aria-level=\"2\"><b><span data-contrast=\"auto\">2.5 Regular Review, Assessment and Evaluation<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/h5>\n<p><span data-contrast=\"auto\">reev regularly tests, assesses and evaluates the effectiveness of the technical and organisational measures by means of internal reviews, vulnerability assessments, penetration tests, risk assessments, monitoring activities, audits and ISO\/IEC 27001 control reviews. Identified weaknesses are tracked and addressed by means of appropriate corrective measures. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h3 aria-level=\"2\"><b><span data-contrast=\"auto\">3. Organisational Measures<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/h3>\n<h5 aria-level=\"3\"><b><span data-contrast=\"auto\">3.1 Governance and Risk Management<\/span><\/b><\/h5>\n<h6 aria-level=\"4\"><strong><b>ISMS Framework<\/b><br><\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev maintains an information security management system (ISMS) certified to ISO\/IEC 27001. The ISMS defines governance structures, responsibilities, policies, controls, risk management procedures and continuous improvement processes for information security. <\/span><\/p>\n<h6 aria-level=\"4\"><strong><b>Risk Assessment<\/b><br><\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev regularly carries out risk assessments in the area of information security in order to identify threats, vulnerabilities and risks to information assets and personal data. Risk treatment measures are defined, implemented, monitored and reviewed in accordance with the ISMS. <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><span data-contrast=\"auto\"><b>Policy Management<\/b><br><\/span><\/h6>\n<p aria-level=\"4\"><span data-contrast=\"auto\">Information security and data protection policies are reviewed at least annually or in the event of material changes. Policies are communicated to the relevant persons and made available via appropriate internal channels. <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong><b>Classification of Assets and Information<\/b><br><\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev maintains processes for the identification and classification of information assets on the basis of their sensitivity, business importance and security requirements. Appropriate handling requirements are applied in accordance with the classification of the respective information or asset. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h5 aria-level=\"2\"><b><span data-contrast=\"auto\">3.2 Personnel Security<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/h5>\n<h6 aria-level=\"4\"><span data-ccp-props=\"{\"134245418\":true}\"><b>Screening&nbsp;<\/b><br><\/span><\/h6>\n<p><span data-contrast=\"auto\">Insofar as legally permissible and proportionate to the respective role, reev carries out screening prior to the commencement of employment which corresponds to the responsibilities, access rights and risk profile of the position.<\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong><b>Awareness and Training<\/b><br><\/strong><\/h6>\n<p><span data-contrast=\"auto\">All employees receive regular information security training, including training on data protection responsibilities, confidentiality, the secure handling of personal data, phishing awareness, the reporting of security incidents and relevant GDPR obligations. Training takes place at least annually and as part of onboarding. <\/span>&nbsp;<\/p>\n<p aria-level=\"4\"><span data-ccp-props=\"{\"134245418\":true}\"><b><em>Confidentiality Obligations&nbsp;<\/em><\/b><\/span><\/p>\n<p><span data-contrast=\"auto\">Employees, contractors and other persons with access to confidential information or personal data are obliged to enter into confidentiality obligations or non-disclosure agreements. These obligations continue to apply, insofar as legally enforceable, even after termination of the employment or contractual relationship. <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong><b>Acceptable Use and Endpoint Security<\/b><br><\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev defines requirements for the acceptable use of corporate systems, devices and information assets. End devices provided by reev are subject to appropriate security controls, which may include device management, encryption, screen lock requirements, anti-malware protection and update management. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h5 aria-level=\"2\"><b><span data-contrast=\"auto\">3.3 Incident Management<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/h5>\n<h6 aria-level=\"4\"><strong><b>Incident Response Plan<\/b><\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev maintains a formal incident response plan for the identification, reporting, assessment, escalation, containment, investigation and remediation of security incidents. Employees are obliged to report suspected or confirmed security incidents via defined reporting channels. <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong><b>Handling of Personal Data Breaches<\/b><\/strong><\/h6>\n<p><span data-contrast=\"auto\">Insofar as an incident concerns personal data, reev assesses whether the incident constitutes a personal data breach and examines reporting and notification obligations under Art. 33 and Art. 34 GDPR. Insofar as reev acts as a processor, reev notifies the respective controller within seventy-two (72) hours in accordance with Art. 33(2) GDPR and the applicable contractual obligations.  <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Incidents and personal data breaches are documented, including the facts relating to the incident, the effects, the remedial measures taken and the decisions on reporting or notification. Findings from incidents are used to improve security controls and response procedures. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h5 aria-level=\"2\"><b><span data-contrast=\"auto\">3.4 Third-Party Provider and Supplier Management<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/h5>\n<h6 aria-level=\"4\"><strong><b>Supplier Security<\/b><\/strong><span data-ccp-props=\"{\"134245418\":true}\">&nbsp;<\/span><\/h6>\n<p><span data-contrast=\"auto\">Information security and data protection requirements are established and agreed with suppliers on the basis of the nature of the services provided and the risk associated with the processing. Suppliers that process personal data on behalf of reev or of reev&#8217;s customers are subject to appropriate contractual obligations. <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong><b>Data Processing Agreements<\/b><\/strong><\/h6>\n<p><span data-contrast=\"auto\">reev does not transfer personal data to a processor or sub-processor unless appropriate contractual arrangements are in place, including a data processing agreement or equivalent data protection provisions, insofar as this is required under Art. 28 GDPR.<\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><strong><b>Sub-processors<\/b><\/strong><\/h6>\n<p><span data-contrast=\"auto\">Sub-processors are engaged only in accordance with the applicable customer agreements and the requirements of Art. 28 GDPR. Where necessary, the obligations of sub-processors include appropriate data protection, confidentiality, security, support, audit, deletion or return, as well as onward transfer obligations. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"none\">A current list of the sub-processors used by reev is maintained at reev.com\/legal. reev informs customers at least 30 days in advance of intended changes to sub-processors that process personal data of the respective customer, unless a shorter period is required for security, availability or other urgent reasons. Customers may, on legitimate data protection grounds, object to the change within the notice period. In this case, the parties will cooperate in good faith in order to find an appropriate solution.   <\/span>&nbsp;<\/p>\n<h6 aria-level=\"4\"><b>International Transfers<\/b><\/h6>\n<p><span data-contrast=\"auto\">Insofar as personal data are transferred to a country outside the European Economic Area or are accessed from there, reev implements appropriate transfer mechanisms and safeguards in accordance with Chapter V GDPR, for example adequacy decisions, standard contractual clauses and supplementary measures where necessary.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h5 aria-level=\"2\"><b><span data-contrast=\"auto\">3.5 Data Retention and Secure Deletion<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/h5>\n<p><span data-contrast=\"auto\">Personal data are retained only for as long as is necessary for the respective processing purpose or as is required under applicable law, contract or legitimate business needs. Retention and deletion procedures are implemented for relevant systems and data categories. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Upon expiry of applicable retention periods or in the case of valid deletion requests, personal data are deleted, anonymised or otherwise handled in accordance with the applicable legal and contractual requirements, unless further retention is required or permitted by law.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h5 aria-level=\"2\"><b><span data-contrast=\"auto\">3.6 Data Subject Rights and Support of the Controller<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/h5>\n<p><span data-contrast=\"auto\">Insofar as reev acts as a processor, reev supports the controller, as far as possible and taking into account the nature of the processing, in fulfilling obligations in connection with data subject rights under Chapter III GDPR as well as with the security of processing under Art. 32 GDPR, in accordance with the applicable contractual obligations.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h5 aria-level=\"2\"><b><span data-contrast=\"auto\">3.7 Audit, Compliance, and Continuous Improvement<\/span><\/b><span data-ccp-props=\"{\"134245418\":true,\"201341983\":2,\"335559685\":510,\"335559738\":200,\"335559739\":200,\"335559740\":300,\"335559991\":510}\">&nbsp;<\/span><\/h5>\n<p><span data-contrast=\"auto\">reev monitors the effectiveness of its security controls by means of the ISMS, internal reviews, audits, risk assessments, technical assessments and corrective action processes. Security and compliance documentation is maintained in order to demonstrate the implementation of appropriate technical and organisational measures. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">The TOMs are reviewed regularly and updated as needed, particularly in light of changes in legal requirements, technology, the risk landscape, organizational structure, processing activities, or security practices.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Home Data Processing Agreement (DPA) As of July 2026 Disclaimer: Translation of the original document in German. In the event of discrepancy, inconsistency or conflict with the German version (in particular due to translation delays), the German version shall prevailThis Data Processing Agreement (hereinafter the \u201cDPA\u201d) applies between reev GmbH, Sandstra\u00dfe 3, 80335 M\u00fcnchen (hereinafter [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_seopress_titles_title":"Data Processing Agreement (DPA) %%sep%% %%sitetitle%%","_seopress_titles_desc":"reev GmbH - Sandstra\u00dfe 3 - 80335 Munich We operate our websites in accordance with the principles set forth below: We are committed to complying with the statutory provisions on data protection and strive to consistently adhere to the principles of data avoidance and data minimization.","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"Data Processing Agreement (DPA) %%sep%% %%sitetitle%%","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"Data Processing Agreement (DPA) %%sep%% %%sitetitle%%","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"both","_seopress_redirections_param":"","_seopress_redirections_type":301,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"footnotes":""},"class_list":["post-427919","page","type-page","status-publish","hentry"],"translations":{"de":"data-processing-agreement-dpa-reev","en":"data-processing-agreement-dpa-reev","fr":"data-processing-agreement-dpa-reev"},"_links":{"self":[{"href":"https:\/\/reev.com\/en\/wp-json\/wp\/v2\/pages\/427919","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/reev.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/reev.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/reev.com\/en\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/reev.com\/en\/wp-json\/wp\/v2\/comments?post=427919"}],"version-history":[{"count":7,"href":"https:\/\/reev.com\/en\/wp-json\/wp\/v2\/pages\/427919\/revisions"}],"predecessor-version":[{"id":428029,"href":"https:\/\/reev.com\/en\/wp-json\/wp\/v2\/pages\/427919\/revisions\/428029"}],"wp:attachment":[{"href":"https:\/\/reev.com\/en\/wp-json\/wp\/v2\/media?parent=427919"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}