Data processing agreement
Article 28 GDPR agreement for business customers and resellers
Scope
This agreement applies where CenterView processes personal data on behalf of a business customer for hosting, databases, email, backups or technical support and becomes part of the main contract when the relevant service is booked or accepted.
Processing details
Processing normally lasts for the main contract and necessary wind-down. Its purpose is to provide, transmit, store, secure, restore and administer customer-selected data and applications. Data may include identity, contact, user, communication, content, log, customer, employee and billing data concerning customers, employees, applicants, visitors and communication partners.
Instructions and confidentiality
The customer is responsible for lawfulness and documented instructions. CenterView processes only on instructions unless required by law and uses personnel bound to confidentiality and need-to-know access.
Security measures
Measures include physical and logical access controls, role-based permissions, strong authentication, protected administrative connections, patch and incident management, separation according to architecture, backups and recovery procedures, and periodic risk-based review.
Sub-processors
CenterView may use suitable sub-processors, including IONOS SE for material infrastructure services, under a general authorisation and appropriate contractual obligations. Registrars, registries, certificate authorities and payment providers may act as independent controllers for their core services.
Assistance and incidents
CenterView reasonably assists with data-subject requests, assessments and security obligations and informs the customer without undue delay after becoming aware of a personal-data breach in CenterView's area of responsibility.
Evidence, return and deletion
CenterView provides suitable compliance information and permits proportionate audits. At the end of the contract, data is returned or erased where technically possible unless retention is required; residual copies may remain until rolling backups expire and are not used productively.