Accordo sul trattamento dei dati
Agreement on the Processing of Personal Data on Behalf of the Controller
(Processing on behalf of the controller pursuant to Article 28 GDPR)
– Annex to the General Terms and Conditions of aysis media GmbH –
This Data Processing Agreement (hereinafter the “DPA”) forms part of the General Terms and Conditions (hereinafter the “GTC”) of aysis media GmbH, Ludwigstraße 8a
97070 Würzburg (hereinafter the “Processor”) and is concluded upon acceptance of the GTC by the Controller.
1. Subject Matter and Duration of the Assignment
(1) The Processor processes personal data on behalf of the Controller.
(2) The subject matter of the assignment arises from the main agreement concluded between the parties (usage agreement for the products tedme and/or pollxpress on the basis of the GTC). The details of the processing are described in Annex 1 “Processing Details”.
(3) The term is governed by the duration of the concluded main agreement. This DPA automatically becomes part of, and supplements, all individual orders. It takes precedence over the data protection provisions of the individual orders.
2. Specification of the Subject Matter of the Assignment
(1) The types of data, the categories of data subjects, and the nature and purpose of the processing of personal data by the Processor for the Controller are specifically described in the GTC, in the respective offers/contracts based thereon, and in Annex 1 “Processing Details”.
(2) The performance of the contractually agreed data processing takes place exclusively in a Member State of the European Union or in another contracting state of the Agreement on the European Economic Area. Any transfer to a third country may only take place if the special requirements of Art. 44 et seq. GDPR are met.
An adequate level of protection may be established as follows:
- by way of an adequacy decision of the Commission (Art. 45(3) GDPR);
- by way of binding corporate rules (Art. 46(2)(b) in conjunction with Art. 47 GDPR);
- by way of standard data protection clauses (Art. 46(2)(c) and (d) GDPR);
- by way of approved codes of conduct (Art. 46(2)(e) in conjunction with Art. 40 GDPR);
- by way of an approved certification mechanism (Art. 46(2)(f) in conjunction with Art. 42 GDPR).
3. Obligations of the Processor
a) Technical and Organizational Measures
(1) The Processor shall establish security pursuant to Art. 28(3)(c), 32 GDPR, in particular in conjunction with Art. 5(1) and (2) GDPR. Overall, the measures to be taken are measures of data security and measures to ensure a level of protection appropriate to the risk with regard to the confidentiality, integrity, availability and resilience of the systems. In doing so, the state of the art, the costs of implementation, and the nature, scope and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons within the meaning of Art. 32(1) GDPR, shall be taken into account. In this respect, the technical and organizational measures set out in Annex 2, to which the Controller agrees, shall apply.
(2) The technical and organizational measures are subject to technical progress and further development. In this respect, the Processor is permitted to implement alternative adequate measures. In doing so, the security level of the specified measures must not be undercut. Material changes shall be documented.
b) Duty to Provide Support
(1) In connection with the Controller’s fulfilment of the rights of data subjects under Art. 12 to 22 GDPR, the Processor shall, to the extent necessary, assist in drawing up the Controller’s record of processing activities as well as in complying with the obligations set out in Articles 32 to 36 GDPR regarding the security of personal data, notification obligations in the event of data breaches, data protection impact assessments and prior consultations, and shall reasonably support the Controller as far as possible. It shall forward the information required for this purpose to the Controller without undue delay in each case.
This includes, among other things:
- a) ensuring an adequate level of protection through technical and organizational measures that take into account the circumstances and purposes of the processing as well as the projected likelihood and severity of a possible infringement of rights due to security vulnerabilities, and that enable the immediate identification of relevant breach events;
- b) the obligation to report personal data breaches to the Controller without undue delay;
- c) the obligation to support the Controller in fulfilling its duty to inform the data subject and, in this context, to make all relevant information available to it without undue delay;
- d) support for the Controller’s data protection impact assessment;
- e) support for the Controller in the context of prior consultations with the supervisory authority.
(2) For support services that are not included in the service description or that are not attributable to misconduct on the part of the Processor and that go beyond the Processor’s statutory obligations, the Processor may claim reasonable remuneration. With regard to the amount of remuneration, reference is made to the corresponding remuneration clause.
c) Processing of Personal Data in the Home or Mobile Office
The Controller consents to the processing of data outside the business premises (e.g. teleworking, working from home, home office, mobile working). The Processor undertakes:
- to support its employees in complying with the required technical and organizational measures on their private premises;
- to appropriately instruct its employees regarding compliance with the technical and organizational measures and other duties of care to be observed when processing data on private premises.
d) Other Obligations of the Processor
(1) The Processor guarantees the written appointment of a data protection officer who carries out their duties in accordance with Art. 38 and 39 GDPR.
The contact details of the Processor’s data protection officer are: Mr Fabian Marterer, SiDIT GmbH, info@sidit.de.
(2) The Processor guarantees compliance with confidentiality pursuant to Art. 28(3) sentence 2 (b), 29, 32(4) GDPR. In carrying out the work, the Processor shall only deploy employees who are bound to confidentiality and who have previously been familiarized with the data protection provisions relevant to them. The Processor and any person subordinate to the Processor who has access to personal data may process such data exclusively in accordance with the Controller’s instructions, including the powers granted under this agreement, unless they are legally obliged to process the data. This confidentiality obligation of the employees shall continue to apply even after termination of their respective employment contract.
(3) The Controller and the Processor shall, upon request, cooperate with the supervisory authority in the performance of its tasks.
(4) The Processor guarantees to inform the Controller without undue delay of any inspections and measures by the supervisory authority insofar as they relate to this assignment. This also applies insofar as a competent authority is investigating the Processor in the course of administrative fine proceedings or criminal proceedings relating to the processing of personal data in the context of the processing on behalf of the Controller.
(5) Insofar as the Controller is, for its part, subject to an inspection by the supervisory authority, to administrative fine or criminal proceedings, to a liability claim by a data subject or a third party, or to any other claim in connection with the processing carried out by the Processor, the Processor shall support the Controller to the best of its ability. For support services that are not included in the service description or that are not attributable to misconduct on the part of the Processor and that go beyond the Processor’s statutory obligations, the Processor may claim reasonable remuneration.
(6) The Processor regularly reviews its internal processes as well as the technical and organizational measures in order to ensure that the processing within its area of responsibility is carried out in accordance with the requirements of the applicable data protection law and that the protection of the rights of the data subject is guaranteed.
4. Obligations and Rights of the Controller
a) Responsibility
(1) The Controller alone is responsible for assessing the lawfulness of the processing pursuant to Art. 6(1) GDPR and for safeguarding the rights of data subjects under Art. 12 to 22 GDPR. Notwithstanding this, the Processor is obliged to forward all such requests to the Controller without undue delay, insofar as they are evidently directed exclusively to the Controller.
(2) Changes to the subject matter of the processing and changes to procedures shall be agreed jointly between the Controller and the Processor and set out in writing or in a documented electronic format.
b) Authority to Issue Instructions
(1) The Processor processes personal data only on the basis of documented instructions from the Controller, unless it is required to process the data under the law of the Member State or under Union law. In such a case, the Processor shall inform the Controller of these legal requirements prior to the processing, unless the law in question prohibits such notification on important grounds of public interest. The Controller instructs the Processor to provide and improve the contractually agreed services, whereby the parties agree that this instruction also includes the anonymization, de-identification or aggregation of personal customer data for the purpose of evaluating, analyzing and improving the services offered.
(2) The Controller shall confirm oral instructions without undue delay (at least in text form). The Controller’s initial instructions are set out in this agreement.
(3) The Processor may not rectify, erase or restrict the processing of the data processed on behalf of the Controller on its own authority, but only in accordance with the Controller’s documented instructions. Insofar as a data subject contacts the Processor directly in this regard, the Processor shall forward this request to the Controller without undue delay.
(4) The Processor may only provide information about personal data from the processing relationship to third parties or to the data subject following prior instruction or consent from the Controller.
(5) The Processor shall inform the Controller without undue delay if it is of the opinion that an instruction violates data protection provisions. The Processor is entitled to suspend the implementation of the relevant instruction until it is confirmed or amended by the Controller.
(6) Copies or duplicates of the data will not be created without the knowledge of the Controller. This does not apply to backup copies, insofar as they are necessary to ensure proper data processing, or to data that is necessary in order to comply with statutory retention obligations.
c) Rights of Control
(1) The Controller has the right, in consultation with the Processor, to carry out inspections regarding compliance with the provisions on data protection and data security as well as the contractual agreements, to an appropriate and necessary extent, or to have them carried out by inspectors to be designated in individual cases. In order to fulfil this right of inspection, the Processor is free to submit to the Controller corresponding audit reports or similar documentation evidencing data-protection-compliant data processing. Insofar as the Controller retains doubts about the data protection compliance of the data processing, it has the right to satisfy itself of the Processor’s compliance with this agreement at the Processor’s place of business by means of spot checks, which must, as a rule, be announced in good time.
(2) The Processor ensures that the Controller can satisfy itself of the Processor’s compliance with its obligations under Art. 28 GDPR. The Processor undertakes to provide the Controller with the necessary information on request and, in particular, to demonstrate the implementation of the technical and organizational measures.
(3) The Processor is entitled to provide evidence of such measures that do not concern only the specific assignment by way of:
- compliance with approved codes of conduct pursuant to Art. 40 GDPR;
- certification under an approved certification procedure pursuant to Art. 42 GDPR;
- current attestations, reports or excerpts of reports from independent bodies (e.g. auditors, internal audit, data protection officer, IT security department, data protection auditors, quality auditors);
- a suitable certification by way of an IT security or data protection audit (e.g. according to BSI baseline protection / IT-Grundschutz).
to be provided.
5. Sub-processing Relationships
(1) Sub-processing relationships within the meaning of this provision are understood to be those services that relate directly to the provision of the main service. This does not include ancillary services that the Processor uses, e.g. telecommunications services or postal/transport services. However, the Processor is obliged, in order to ensure the data protection and data security of the Controller’s data, to take appropriate and legally compliant contractual arrangements and control measures also with regard to outsourced ancillary services.
(2) The outsourcing to sub-processors or the change of an existing sub-processor is permissible, provided that the Processor notifies the Controller of such outsourcing to sub-processors in writing or in text form at least four weeks before the planned change, and the Controller does not object to the planned outsourcing in writing or in text form vis-à-vis the Processor within 2 weeks of receipt of the notification.
(3) By way of derogation from the preceding provision on the change of sub-processors in Section 5(2), the Processor is entitled, in extraordinary cases requiring immediate and short-term action (in particular in the event of an unexpected failure of the existing sub-processor due to illness, insolvency, a serious security incident [e.g. hacking] or comparable events), to carry out a change or the engagement of a new sub-processor without awaiting compliance with the regular notification period.
In these cases, however, the Processor is obliged:
- To inform the Controller without undue delay of the change of sub-processor as soon as it becomes aware of the extraordinary case and this is operationally possible.
- The Processor shall provide the Controller with the following information no later than within five working days after the change: a) the name and contact details of the new sub-processor, b) details of the data processing activities to be carried out by the sub-processor.
- To subsequently grant the Controller the opportunity to object to the change of sub-processor for good cause, in writing or in text form, within two weeks of receipt of the complete information. After expiry of this period, the change shall be deemed approved.
The Processor undertakes to take all measures in the context of the short-term change to ensure the continuity of the data processing and the protection of the personal data. This includes, in particular, a review of the new sub-processor as to its suitability and reliability with regard to the applicable data protection requirements.
(4) The Processor shall conclude a contractual agreement with the sub-processor in accordance with Art. 28(2)-(4) GDPR. If the Controller refuses consent by way of its objection for reasons other than good cause, the Processor may terminate the contract as of the time of the planned engagement of the sub-processor. In the case of engaging sub-processors in a third country, No. 2(2) of this agreement applies.
(5) The Controller consents to the engagement of the sub-processors listed in Annex 3, subject to the condition of a contractual agreement in accordance with Art. 28(2)-(4) GDPR.
(6) The transfer of the Controller’s personal data to the sub-processor and the sub-processor’s initial commencement of activity are only permitted once all the requirements for sub-processing have been met.
6. Erasure and Return of Personal Data
(1) Upon completion of the contractually agreed work, or earlier at the Controller’s request – at the latest upon termination of the service agreement – the Processor shall hand over to the Controller all documents that have come into its possession, all processing and usage results produced, and all data holdings connected with the processing relationship, or shall destroy them in a data-protection-compliant manner following prior consent. The same applies to test and reject material. The erasure log shall be submitted on request. If the Processor incurs costs in handing over or erasing the data, these shall be borne by the Controller.
(2) The Controller shall notify the Processor in text form, subject to a period of one month before the end of the contract, whether the data is to be handed over or erased. If the Processor has not received any instruction by the expiry of this period, it is entitled and obliged to erase the data upon the end of the contract without undue delay, but at the latest within 14 days.
(3) Documentation that serves to demonstrate the contractual and proper data processing shall be retained by the Processor in accordance with the respective retention periods beyond the end of the contract. It may hand this over to the Controller upon the end of the contract in order to discharge itself.
7. Amount of Remuneration for Further Control and Support Measures
Any remuneration claims that the Processor may assert under the preceding clauses must be reasonable. The billing of the effort incurred at the hourly rates usually charged by the Processor is deemed reasonable.
8. Liability and Damages
Within its area of responsibility, the Controller guarantees, in the processing of personal data, the implementation of the obligations arising from the relevant applicable legal provisions.
In principle, the limitations of liability from the main agreement (GTC) apply. The Controller shall indemnify the Processor against all claims asserted by third parties against the Processor due to the infringement of their rights on the basis of the processing of personal data commissioned by the Controller, unless the third party’s claim is based on unlawful processing of the personal data by the Processor. In all other respects, Art. 82 GDPR remains unaffected.
9. Miscellaneous, General Provisions
(1) Should the Controller’s personal data at the Processor be jeopardized by attachment or seizure, by insolvency or composition proceedings, or by other events or measures of third parties, the Processor shall inform the Controller thereof without undue delay. The Processor shall inform all parties responsible in this context without undue delay that authority over the Controller’s personal data lies with the Controller.
(2) The provisions of this agreement shall continue to apply even after termination of the primary service relationship until the complete destruction or return of all of the Controller’s personal data to the Controller.
(3) The Processor reserves the right to amend this DPA at any time, insofar as the amendment is in its legitimate interest and does not unreasonably disadvantage the Controller. This is the case in particular for:
- changes to statutory or regulatory requirements,
- changes in supreme court case law,
- editorial clarifications.
In this case, the Processor shall notify the Controller thereof at the latest four weeks before entry into force and shall provide it with the amended DPA. If no objection is received by the Processor within four weeks of receipt of the notice of amendment, the amended DPA shall be deemed approved. In the event that an objection is received, the Processor shall have an extraordinary right to terminate the DPA and the underlying main agreement, subject to a period of one month.
(4) Should individual parts of this agreement be invalid, this shall not affect the validity of the remainder of this agreement. The parties undertake to replace the invalid provision with a legally permissible provision that comes closest to the purpose of the invalid provision.
Annex 1: Processing Details
Module 1: Interaction Platform tedme / pollxpress
Nature and Purpose of the Processing
The Processor provides the Controller with the web-based interaction platforms „tedme“ (enterprise/managed solution) and „pollxpress“ (self-service solution). Both platforms enable the conduct of interactive events, surveys, votes and elections in real time. In the context of providing and operating these platforms, the Processor processes personal data on behalf of and in accordance with the instructions of the Controller.
The processing includes in particular:
- provision and operation of the platform, including user account management,
- conduct and technical handling of interactive events (surveys, votes, elections, Q&A, chat),
- storage and preparation of event data and results,
- dispatch of system and transactional emails (e.g. invitations, access credentials, result notifications),
- technical support and troubleshooting.
Categories of Personal Data
Within the scope of this module, the following categories of personal data may in particular be processed:
- master data of account holders and users (e.g. surname, first name, organization/company),
- contact data (e.g. email address, telephone number where applicable),
- access data and authentication information (e.g. username, password hash, role and authorization information),
- event and participation data (e.g. participation in surveys/votes, voting results, PIN numbers in elections, voting-share entitlements),
- communication data (e.g. chat histories, questions asked in the Q&A module, comments),
- evaluation and feedback data (e.g. answers in the Controller’s evaluation forms),
- technical usage data (e.g. IP address, timestamps of input, browser information, technical log data),
- any further data category that the Controller has the Processor process within the scope of the contractual relationship (e.g. through freely configurable evaluation forms).
Categories of Data Subjects
- account holders and account users of the Controller (administrators, moderators),
- participants in online events, surveys, votes and elections that the Controller conducts via tedme or pollxpress,
- interested parties and invited persons,
- other categories that the Controller has the Processor process within the scope of the contractual relationship.
Annex 2: Technical and Organizational Measures
The technical and organizational measures of the Processor pursuant to Art. 32(1) GDPR are set out in the separately provided TOM document of aysis media GmbH (as of: 23.04.2026). By accepting the GTC and this DPA, the Controller agrees to the measures described therein.
The TOM document is provided in its respective current version here.
Annex 3: Sub-processors
The Processor engages sub-processors in the course of providing the services. The respective current list of the sub-processors engaged can be accessed at the following link: here.