Snapshot 34895
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Essentry Inc.
- shall not “share” the personal data, as such term is defined in the
Data Processing Agreement pursuant to Art. CCPA (regardless of whether the CCPA applies) or otherwise
28 (3) GDPR and other applicable law disclose it for targeted advertising purposes;
- shall not retain, use, or disclose any such data outside of the direct
business relationship between the Client and the Contractor, or for
1. General any purpose (including any commercial purpose) other than the
limited business purposes specified in this agreement and as
1.1. Essentry Inc. (hereinafter referred to as the "Contractor") operates systems
permitted by applicable law;
for the digital administration of access management processes and
- shall comply with any restrictions under applicable law on combining
concludes contracts with Clients for the use of the "essentry" system
the personal data that Contractor receives from, or on behalf of,
(hereinafter referred to as "system contracts" or "system contract").
Client with personal data that Contractor receives from, or on behalf
1.2. This agreement (together with its annexes described in more detail below) of, another person or persons, or that Contractor collects from any
on data processing in accordance with Art. 28 GDPR and other applicable other interaction between Contractor and a data subject;
law (hereinafter also referred to as the "Agreement") specifies the legal - shall provide the same level of protection for any personal data
rights and obligations arising for the Contractor and the Client from the subject to the CCPA as is required of businesses under the CCPA,
General Data Protection Regulation (Regulation (EU) 2016/679, and shall promptly inform the Client if the Contractor determines that
hereinafter also referred to as the "GDPR") and other privacy and data it can no longer meet its obligations under the CCPA;
protection laws (such as the California Consumer Privacy Act, as - hereby certifies that it understands the restrictions and obligations
amended, and its regulations (hereinafter also collectively referred to as set forth in this agreement and that it will comply with them.
the “CCPA”)) if the Contractor processes personal data for the Client within
the scope of the system contracts or carries out commissioned
maintenance (hereinafter also referred to as "data processing").
5. Duration of the data processing
1.3. The Contractor acknowledges that the GDPR and other applicable laws 5.1. The term of this agreement depends on the duration of the system
protect the fundamental rights and freedoms of natural persons and in contracts.
particular their right to the protection of personal data and that these 5.2. The agreement ends automatically and without the need for termination if
principles also apply to the Contractor. the Contractor no longer carries out any data processing or commissioned
maintenance for the Client.
2. Definitions 5.3. The right to ordinary termination is - subject to the termination option under
section 5.4 - is excluded. The right to extraordinary termination for good
2.1. The definitions in Art. 4 and Art. 9 GDPR and the following additional
cause in accordance with § 314 BGB remains unaffected.
definitions apply:
5.4. The Client may terminate a system contract, irrespective of any conflicting
2.2. "Commissioned maintenance" means services provided by the Contractor
provisions in the system contract, if the Contractor breaches a statutory
(e.g. care, maintenance or other services on computer programs or
data protection provision or an obligation under this agreement or
technical objects for information processing), during the performance of
breaches a guarantee. In this case, the notice period shall be three (3)
which it cannot be ruled out that the Contractor will gain access to personal
months to the end of the month. Claims of the Contractor due to premature
data for which the Client is responsible.
termination of the contract, in particular claims for damages, are excluded.
2.3. "System Contract" means the respective legal relationship between the
Client and the Contractor based on which the Contractor carries out data
processing or commissioned maintenance for the Client as intended.
6. Place of data processing
2.4. "Subcontractor" means third parties within the meaning of Art. 4 No. 10 6.1. Subject to the following provisions, the data processing may only take
GDPR, which the Contractor uses with the written consent of the Client to place in a member state of the European Union or in another state party to
provide services under the system contract. the Agreement on the European Economic Area.
2.5. Further definitions can be made contextually in the respective clause of 6.2. Any data processing outside a member state of the European Union or
this agreement. outside another state party to the Agreement on the European Economic
Area (hereinafter referred to as "third country") requires the prior written
consent of the Client.
3. Components of the agreement
6.3. Consent to data processing in a third country will not be granted in
3.1. Data processing or commissioned maintenance by the Contractor shall particular if the special requirements of Art. 44 f. GDPR are not
always be carried out based on a system contract between the Contractor permanently fulfilled, in particular if there is no adequate level of protection
and the Client. The system contract is decisive for the subject matter, in the third country or if there are no suitable guarantees to ensure an
duration, type, and purpose of the data processing, as well as for adequate level of protection.
determining the type of personal data and the categories of data subjects
6.4. The Contractor shall ensure at its own expense that an appropriate level
(hereinafter also referred to as "subject matter of the order"). To determine
of protection is ensured in the third country and shall provide evidence of
the subject matter of the order, the Contractor and the Client shall use the
this to the Client when obtaining approval, in particular by:
Annex 1: Subject-matter of the data processing and add it to the
corresponding system contract in a legally binding manner. - an adequacy decision by the EU Commission (Art. 45 (3) GDPR);
- binding internal data protection rules (Art. 46 section 2 lit. b. in
3.2. This agreement contains provisions on data processing and commissioned
conjunction with Art. 47 GDPR);
maintenance that apply to all system contracts concluded between the
- Standard data protection clauses (Art. 46 section 2 lit. c and lit. d
Client and the Contractor. Binding components of this agreement are
GDPR);
- Annex 1: Subject-matter of the data processing - approved codes of conduct (Art. 46 section 2 lit. e in conjunction with
- Annex 2: Security of processing Art. 40 GDPR);
- Annex 3: Contact persons - approved certification mechanisms (Art. 46 section 2 lit. f. in
- Annex 4: Subcontractors conjunction with Art. 42 GDPR); or
- Annex 5: Notification form for data protection breaches - other measures (Art. 46 section 2 lit. a., section 3 lit. a and lit. b
3.3. The provisions of this agreement, including its annexes, shall take GDPR).
precedence over any contradictory provisions of a system contract.
7. Instructions from the Client
4. Principles for data processing
7.1. Notwithstanding binding stipulations within the meaning of section 3.1 of
The Contractor processes personal data exclusively in accordance with the this Agreement, the Contractor acknowledges that the Client alone
system contract, in accordance with this agreement and within the scope of the determines the purposes of the data processing and may also order this
Client's instructions. Without limiting the foregoing restrictions on Contractor’s by means of individual instructions, and that any processing by the
processing of the personal data, the Contractor: Contractor outside the intended purpose or an instruction is unlawful. Art.
28 section 3 lit. a GDPR is decisive for exceptions to this.
- shall not “sell” the personal data, as such term is defined in the CCPA
and similar U.S. state privacy laws;
Data Processing Agreement Ver. 1.6 from 12/23/2024 Page 1 of 8
Essentry Inc.
7.2. Every instruction from the Client obliges the Contractor to carry out, documented measures will form the basis of the respective data
tolerate or refrain from ("actions") every process specified in the instruction processing and will be used as Annex 2: Security of processing to this
(e.g. collection, storage, transmission, deletion or destruction of personal agreement.
data) in accordance with the instructions. The Client's right to issue 10.3. The Contractor is free to prove the suitability of the technical and
instructions includes, in particular, that the Client may lawfully determine organizational measures to be taken - in particular in accordance with Art.
vis-à-vis the Contractor how the system contract is to be implemented in 32 GDPR - by complying with approved rules of conduct in accordance
terms of data protection law, as well as to request order-related information with Art. 40 GDPR or by complying with an approved certification
and to request actions that may serve to fulfill a legal, sovereign or official procedure in accordance with Art. 42 GDPR. Proof can only be provided
requirement to which the Client is subject. (and only for as long as) the Contractor presents the Client with a valid
7.3. Instructions must always be issued in writing (Section 126 BGB) or in text certificate issued by an accredited certification body in accordance with
form (Section 126b BGB). Verbal instructions are only permissible in Art. 43 GDPR for those processing procedures and locations that are
exceptional cases; they must be documented by the Contractor in writing relevant for the processing operations under this Agreement or the
(Section 126 BGB) or text form (Section 126b BGB). The Contractor must corresponding system contract. The Contractor must notify the Client
inform the Client immediately if it is of the opinion that an instruction immediately of any changes to the certificate or its expiry.
violates data protection regulations. The Contractor shall be entitled to 10.4. The submission of the aforementioned certification does not diminish the
suspend the implementation of the corresponding instruction until it is Contractor's responsibility and does not replace the Contractor's obligation
confirmed or amended by the Client. to guarantee that the requirements under this section 10 and the Annex
2: Security of processing within the meaning of Art. 32 GDPR are in
8. Adjustments and further development place as well as maintained and updated.
10.5. To increase the security and further development of the essentry app, the
8.1. When processing personal data, interpreting the requirements of the
Contractor evaluates anonymized usage data. This information cannot be
GDPR and interpreting this Agreement, the applicable recommendations
assigned to any person and the Contractor does not merge this data with
of the Art. 29 Working Party or its successor organization (European Data
other data sources. For this purpose, the Contractor performs the
Protection Board) must be taken into account appropriately.
anonymization on behalf of the Client.
8.2. The Client and the Contractor agree to adapt and amend this Agreement,
10.6. The Contractor is permitted to take and implement a technical measure
including annexes, by mutual agreement and free of charge for the Client
other than one expressly described if the security level of the processing
in the event of changes, adaptations and/or additions to data protection
is thereby maintained or increased, and the measure is documented and
regulations - in particular the GDPR and/or the applicable national
communicated to the Client.
implementation laws, the CCPA, or similar laws.
10.7. The Client shall be entitled at any time to demand compliance with the
obligations and guarantees entered in this Clause in accordance with
9. Duty of confidentiality
section 16 to check. Any breaches of duty identified shall be remedied by
9.1. The Contractor guarantees that it has obligated the persons employed by the Contractor without delay.
it for processing to maintain confidentiality and that it will also comply with
this obligation through organizational precautions, in particular that 11. Subcontractor
personal data will not be processed without authorization, only in
accordance with the order or in accordance with instructions, and that this 11.1. The subcontracting of processing by the Contractor to a subcontractor is
obligation will continue to apply even after the end of their activities (Art. not permitted unless the following conditions are met:
28 section 3 lit. b); Art. 29; Art. 32 section 4 GDPR). The same applies to 11.1.1. The Client has expressly consented to the subcontracting in writing
other confidentiality and/or protection provisions under data protection law, (in this agreement or in a system contract).
insofar as these are relevant to the processing.
11.1.2. The Contractor has carefully selected the subcontractor and has
9.2. Upon request, the Client shall be provided with corresponding evidence given the Client a guarantee that the subcontractor will perform all
free of charge. The Contractor is at liberty to provide evidence by subcontracted services in accordance with all relevant provisions of
complying with approved rules of conduct (Art. 40 GDPR) or by complying this Agreement and the relevant statutory provisions, including,
with an approved certification procedure (Art. 42 GDPR), provided that this where applicable, the GDPR.
shows that the persons involved in the processing in accordance with
11.1.3. The Contractor has ensured through appropriate agreements with
section 9.1 are obliged to maintain confidentiality.
the subcontractor and demonstrated to the Client that the Client can
also exercise all rights to which it is entitled vis-à-vis the Contractor
10. Safety of processing vis-à-vis the subcontractor during the term of the subcontracting; this
also includes rights of inspection of documents and contracts
10.1. The Contractor confirms that it has taken the measures required in its area
relevant to data protection and information about processes relevant
of responsibility in accordance with Art. 32 GDPR. The Contractor
to data protection law.
undertakes to design and update its internal organization accordingly,
taking into account the respective state of the art, the implementation costs 11.2. The processing, and in particular the transfer of personal data to or by the
and the nature, scope and circumstances and purposes of the processing subcontractor, is only permitted (and only for as long as) the conditions set
and the different probability of occurrence and severity of the risk to the out in section 11.1 are demonstrably fulfilled and the Client has not
rights and freedoms of the data subjects, so that they comply with the withdrawn its consent in accordance with section 11.4 has revoked its
special requirements of data protection under the GDPR and ensure the consent.
protection of the rights of the data subjects. In general, the technical and 11.3. Subcontractors approved at the time of conclusion of this agreement
organizational measures (TOM) to be taken include in particular between the Client and the Contractor are listed in Annex 4:
10.1.1. protecting the confidentiality, integrity, availability and resilience of Subcontractors and any addenda thereto shall be made in writing. The
the systems and services in connection with the processing of the right to authorize subcontractors in the system contract remains
data; unaffected.
10.1.2. as appropriate, the encryption of personal data and, where possible, 11.4. The Client may revoke its consent to the use of a subcontractor in justified
its pseudonymization; cases - in particular in the event of a breach of law or other breach of duty.
The Contractor shall immediately cease the subcontracting.
10.1.3. the ability to quickly restore the availability of personal data and
access to it in the event of a physical or technical incident; 11.5. If the Client does not agree to the use of a new subcontractor or revokes
its consent to an already approved subcontractor, both parties have a
10.1.4. the implementation and maintenance of procedures to regularly
special right to terminate the contract and this data processing agreement
review, assess and evaluate the effectiveness of the technical and
with one month's notice.
organizational measures to ensure the security of the processing at
intervals of no longer than twenty-four (24) calendar months.
12. Rights of the data subjects
10.2. The Contractor shall present the measures to which it commits to the Client
correctly, completely, and clearly in advance of the award of the contract, 12.1. The Client is responsible for safeguarding the rights of data subjects in
document them with regard to the specific execution of the contract and accordance with Chapter 3 of the GDPR and other applicable law. The
submit them to the Client for review. If accepted by the Client, the Contractor is only permitted to implement the rights of data subjects in
Data Processing Agreement Ver. 1.6 from 12/23/2024 Page 2 of 8
Essentry Inc.
accordance with the instructions of the Client. However, the Contractor is 14.6. Where required by law, the Contractor is obliged to appoint a data
obliged to fully support the Client in fulfilling requests and claims of data protection officer who can carry out their activities in accordance with Art.
subjects in accordance with Chapter 3 of the GDPR and other applicable 37, 38 GDPR. The contact details of the data protection officer or another
law. contact person for data protection issues - insofar as a data protection
12.2. If data subject rights are asserted directly against the Contractor, the officer is not to be appointed - shall be provided to the Client for the
Contractor must forward the request to the Client without delay. If it is not purpose of direct contact.
possible for the Contractor to identify the personal data of the individual
making the request, the Contractor shall prove the lack of identifiability to 15. Release of personal data
the Client (including, where applicable, in accordance with Art. 11 section
2 GDPR). If requests are not forwarded immediately, the Contractor shall 15.1. The Contractor acknowledges that the Client must be entitled to demand
be liable to the Client for any delays in processing requests from data the surrender of personal data from the Contractor at any time as a result
subjects, considering the processing periods specified in Art. 12 section 3 of its role as controller. The Contractor therefore guarantees the Client that
GDPR or other applicable law, unless the Contractor is not responsible for it has taken technical and organizational measures to be able to fulfill the
the delay. claim for surrender without delay and waives any objections and defenses
against the claim for surrender.
13. Reporting of data protection incidents 15.2. The right to disclosure includes all personal data processed by the
Contractor under the responsibility of the Client, in particular personal data
13.1. The Contractor shall notify the Client in any case in which it becomes transmitted by the Client and personal data that has been changed,
aware of (i) a breach of the protection of personal data by it or the persons created, or generated in the course of the performance of a system
employed by it, (ii) a breach of regulations on the protection of personal contract.
data or (iii) a breach of the provisions made in this Agreement (hereinafter 15.3. Once the Client has confirmed the successful release of the personal data
"Data Protection Incident"). in writing or text form, it must be deleted immediately from the Contractor's
13.2. The notification must be made immediately, at the latest within forty-eight storage media in such a way that it can no longer be reproduced. The
(48) hours of becoming aware of it. Contractor shall guarantee the corresponding deletion of this personal data
13.3. Upon becoming aware of a data protection incident, the Contractor shall on the storage media of any subcontractors. Upon request, the Contractor
immediately take the necessary measures to secure the data and mitigate shall provide the Client with evidence that this deletion has been carried
any adverse effects for the data subjects and the Client. out by means of suitable documents or appropriate insurance. The above
shall apply accordingly if the processing of personal data by the Contractor
13.4. The notification of a data protection incident must - as far as possible - ends, but the Client expressly waives the surrender to the Contractor and
contain all information required by the Client to fulfill its obligations under no agreement to the contrary has been made.
Art. 33 and Art. 34 GDPR; in particular
15.4. The Contractor may store certain personal data in blocked form instead of
13.4.1. a description of the nature of the personal data breach, including, deleting it, as long as and to the extent that the Contractor is subject to
where possible, the categories and approximate number of data mandatory statutory provisions that oblige it to retain it. The lawfulness of
subjects concerned, the categories concerned and the approximate access to blocked data is assessed according to the legal provision on the
number of personal data records concerned; basis of which the personal data had to be blocked.
13.4.2. the name and contact details of the Contractor's data protection 15.5. In the event of the removal or seizure of a storage medium by a third party
officer or a person of the Contractor who can provide information on on which the Client's personal data is stored, or in the event of foreclosure
the matter; of such a storage medium by a third party, the Contractor shall immediately
13.4.3. a description of the likely consequences of the personal data breach; inform both the third party of the fact that the Client's personal data is
13.4.4. a description of the measures already taken and those proposed by located on the data carrier concerned and the Client of the corresponding
the Contractor to address the personal data breach and, where measure. Any legal remedies of the Client against the measures of the
appropriate, measures to mitigate its possible adverse effects. third party shall remain unaffected.
13.5. For reports, please use the form in attached hereto.Annex 5: Notification
form for data protection breaches The Contractor is obliged to document 16. Control rights of the Client
data protection incidents in detail, including their effects and the remedial
16.1. The Client has the right to take reasonable and appropriate steps to (a)
measures taken. The documentation must be made available to the Client
ensure that Contractor is using the personal data consistent with Client’s
without delay.
obligations under applicable law and (b) stop and remediate unauthorized
use of the personal data. During the term of this agreement and until the
14. Obligations of the Contractor to cooperate general limitation period for claims arising from this agreement has
expired, the Client shall have the right to carry out inspections or, in
14.1. With regard to its area of responsibility, the Contractor is obliged to keep
individual cases, to have them carried out by third parties or auditors who
detailed documentation on the processing of personal data and to make
are obliged to maintain confidentiality. In particular, the Client shall have
this available to the Client immediately upon first request. Based on the
the right to satisfy itself of the Contractor's compliance with this Agreement
documentation, the Client must be able to prove the correctness of the
by means of random checks in its business operations during normal
data processing in accordance with Art. 24 section 1 GDPR in a suitable
business hours. The Contractor may assert a claim for remuneration for
manner at any time.
enabling the Client to carry out inspections.
14.2. With regard to its area of responsibility, the Contractor is obliged to provide
16.2. In deviation from section 16.1 the rights of control referred to in this clause
the data and information required for the Client's process register in
shall continue to exist beyond the term of this Agreement and the general
accordance with Art. 30 (1) GDPR.
limitation period to the extent that and for as long as the Contractor
14.3. The Contractor shall support the Client in complying with the obligations processes personal data in accordance with section 15.4 stores personal
set out in Articles 32 to 36 of the GDPR and equivalent requirements in data.
other applicable laws. in particular, those relating to the security of
16.3. This includes the right to enter the property, the business premises and the
personal data, reporting obligations in the event of data breaches, data
locations of the Contractor's information technology systems and to carry
protection impact assessments and prior consultations. For this purpose,
out inspections and tests there or have them carried out, as well as to
the Contractor shall provide the Client with all documents, records and
inspect business documents and stored data and data processing
evidence required for Art. 32 - 36 GDPR and such other applicable laws.
programs, insofar as this is necessary for order control.
14.4. The Client must be informed immediately of any inspections and measures
16.4. As a rule, inspections must be announced with a lead time of fourteen (14)
taken by the supervisory authority or other government authority in relation
days. In urgent cases, the Client may shorten the notice period to 24 hours.
to the Client of the Client’s personal data, including in accordance with Art.
An urgent case exists in particular in the case of inspections by data
58 GDPR. This also applies if a competent authority investigates the
protection supervisory authorities, other sovereign supervisory authorities
Contractor. or in the case of any reportable incidents.
14.5. The Contractor is obliged to regularly check the performance of the 16.5. The Contractor shall ensure that the Client or the auditors commissioned
processing itself for conformity with this agreement. If errors or
by the Client can satisfy themselves that the Contractor is complying with
irregularities are discovered during the inspection, the Client must be
its obligations under Art. 28 GDPR.
informed immediately.
Data Processing Agreement Ver. 1.6 from 12/23/2024 Page 3 of 8
Essentry Inc.
17. Obligations of the Client necessary. If the adjustment is refused by the Contractor or its conclusion
is delayed, the Client may terminate the contract extraordinarily or withhold
17.1. The Client shall be responsible for compliance with the statutory provisions payments to the Contractor, regardless of the legal relationship, until the
applicable to it regarding the protection of personal data. necessary adjustment agreement has been concluded. "Change of
17.2. The Client shall inform the Contractor immediately and in full if it discovers ownership" means any change in control of the Contractor, whether as a
errors or irregularities with regard to data protection regulations when result of the acquisition of voting rights, conversions or agreements. The
checking the processing results. above shall apply accordingly to subcontractors of the Contractor.
17.3. If the Client is subject to the GDPR, the Client is obliged to keep a record 18.2. The partial or complete assignment or transfer of claims, rights and
of processing activities in accordance with Art. 30 GDPR. The Contractor's obligations arising from this agreement by the Contractor is not permitted
obligation to keep its own record of processing activities in accordance with unless the Client has given its prior written consent. § Section 354a HGB
Art. 30 (2) GDPR remains unaffected by this. remains unaffected.
17.4. The Client shall designate a contact person responsible for data protection 18.3. Any amendment to this agreement must be made in writing to be effective.
issues arising within the scope of the contract and provide their contact This also applies to any waiver of the written form requirement itself.
details for the purpose of direct contact. 18.4. The law of the Federal Republic of Germany shall apply to the exclusion
of the UN Convention on Contracts for the International Sale of Goods.
18. Other obligations and provisions 18.5. The place of jurisdiction for all disputes arising from or in connection with
this agreement and data protection-related disputes arising from system
18.1. The Contractor shall inform the Client as soon as a change of ownership,
contracts is Frankfurt am Main. The Client shall also be free to assert any
as defined below, is likely to occur. Insofar as the change of ownership
claims arising from this agreement at the court with subject-matter and
requires an adjustment to this Agreement under the law of the European
local jurisdiction for the Contractor's registered office. Statutory regulations
Union or the Federal Republic of Germany applicable to the Client, the
on exclusive jurisdiction remain unaffected
Contractor shall agree the adjustment with the Client to the extent
2.3. The Contractor shall anonymize and evaluate data from the essentry
Annex 1: Subject-matter of the data processing
platform for the purpose of providing statistical overviews to the Client. This
data is anonymized in accordance with the anonymization method of k-
1. Subject-matter of the data processing anonymity. The k=7 anonymization method is used. This means that 7
different data records of each category of data are required for them to be
1.1. Digital access management: programming, customization, provision, included in the statistical analysis.
1.2. and operation of the software for digital access management. Hosting,
support, and maintenance of the software. Project management and
3. Type of personal data
training.
3.1.1. List of those affected
2. Nature and purpose of processing The following groups of persons are affected by data processing:
2.1. Purpose of processing: Digital access management including identity - Employees of the Client
verification of authorized persons and other persons with temporary - Authorized persons, interested parties, customers, suppliers and
access authorization. service providers of the Client
2.2. Type of processing: 3.1.2. Data categories
- Recording the names and identification features of individuals who The following types or categories of data are subject to collection,
wish to enter a site, building or part of a building of the Client processing and/or use by the Contractor:
- Verification of government issued photo ID documents
- Capture a photograph of the person for comparison with the ID
document
- Recording information on the issue of access media issued to these
persons and assigned access profiles
- Storage of this data for a period specified by the Client
Data type according to
No. Data field name Group of people
deletion concept
001 First name Authorized persons Master data of the authorized persons
002 Surname Authorized persons Master data of the authorized persons
003 Company Authorized persons Master data of the authorized persons
004 Email address Authorized persons Master data of the authorized persons
005 Date of birth (optional, can be deactivated) Authorized persons Master data of the authorized persons
006 ID number (optional, can be deactivated) Authorized persons Master data of the authorized persons
Cut-out photograph of the authorized person from the identification Cut-out photograph of the authorized person from
007 Authorized persons
document the identification document
Photo of the authorized person taken by the self-
008 Photo of the authorized person taken by the self-service kiosk Authorized persons
service kiosk
Users / employees / access
009 First name Employee data
managers
Users / employees / access
010 Surname Employee data
managers
Data Processing Agreement Ver. 1.6 from 12/23/2024 Page 4 of 8
Essentry Inc
Data type according to
No. Data field name Group of people
deletion concept
Users / employees / access
011 Email address Employee data
managers
Users / employees / access
012 Password Employee data
managers
Authorized persons /
013 Start time of the appointment persons responsible for Access data
access
Authorized persons /
014 End time of the appointment persons responsible for Access data
access
Authorized persons /
015 Check-in time persons responsible for Access data
access
Authorized persons /
016 Check-out time persons responsible for Access data
access
Authorized persons /
017 Name of the person responsible for access persons responsible for Access data
access
Authorized persons /
018 Location of the appointment persons responsible for Access data
access
If necessary, further user-defined data fields can be collected, processed and stored as part of the "master data of authorized persons" if the customer's administrator
activates further data in the essentry SaaS platform for querying at the self-service kiosk or the reception dashboard.
Annex 2: Security of processing - HTTPS is used for the connection from the user's browser to the
essentry servers. The specific version of the protocol and the type of
encryption depend on the browser used. The essentry servers only
1. Pseudonymization and encryption of personal data accept secure protocols.
(Art. 32 section 1 lit. a GDPR)
1.1. Pseudonymization: Processing of personal data in such a way that the 2. Measures to protect confidentiality (Art. 32 section 1
personal data can no longer be attributed to a specific data subject without lit. b GDPR)
the use of additional information, provided that this additional information
is kept separately and is subject to technical and organizational measures. 2.1. Access control: Technical and organizational measures for access
control, in particular for the legitimation of authorized persons:
Description of the measures taken:
Description of the measures taken:
- No direct pseudonymization of personal data can take place in order
to fulfill the purpose of the order. - Protection of physical access to data centers through structural
measures and a locking system
- Evaluations and queries for statistical purposes, are carried out
anonymously. - Personal reception of customers and authorized persons
- The application collects pseudonymized usage and traffic data on the - Authorized persons are accompanied or supervised
server side. This information is not merged with the bearer (user) of - Sensitive company areas and rooms in which no employees are
the pseudonym except for provision of the service features that working are locked
require this. Organizational measures:
1.2. Encryption: Use of procedures and algorithms that convert the content of - internal documentation and specifications for contract fulfillment, e.g.
personal data into a non-readable form using digital or electronic codes or internal guidelines and instructions on data security and data
keys. Symmetric and asymmetric encryption techniques can be used: protection
Description of the measures taken: - Internal documentation and guidelines on data protection and data
security
- Encryption of all data "in transit" (during transmission) and "at rest"
2.2. Access control: Technical (password / password protection) and
(stored on the hard disk). Only strong cryptographic methods are
organizational (user master data record) measures with regard to user
used.
identification and authentication:
- The Cloud KMS (Key Management Service) is used to store the keys
Description of the measures taken:
of the encrypted databases. This protects the keys on special
hardware security modules (HSMs). The keys do not leave these - The data processing systems are protected against unauthorized
hardware modules and access to them is fully logged. use by log-in and authorization procedures.
- TLS encryption - Password security includes personalized and automated login
- cloud.google.com/security procedures.
- images.apple.com/business/docs/iOS_Security_Guide.pdf - Length and complexity requirements for passwords.
- android.com/intl/en_en/security-center/
Data Processing Agreement Ver. 1.6 from 12/23/2024 Page 5 of 8
Essentry Inc.
- Access to the essentry SaaS platform via mobile systems and end - Every change to the configuration is first tested on the test systems
devices only takes place via secure and encrypted lines and and changes are saved in log files for traceability. Regular security
connections. scans of the servers are performed. Basic configurations of the
2.3. Access control: Demand-oriented design of the authorization concept communication paths between instances are carried out by defined
and access rights as well as their monitoring and logging: administrators.
Description of the measures taken: 4.2. Availability of the IT systems used
Description of the measures taken:
- Access authorizations for employees to the IT systems are assigned
restrictively. - Reasonable measures for fire protection, power supply, air
- Our employees only receive the authorizations that they actually conditioning, data backup, disaster recovery, etc. have been taken
need for their work. for our IT systems as part of an emergency concept.
- Employee access authorizations to the servers with customer data - The Kubernetes cluster scheduler distributes the instances of the
are restricted to what is absolutely necessary in accordance with the software in such a way that the different instances always run on
principles of need-to-know and least privilege. Developers only have different servers. A hardware defect therefore generally does not
access to test systems on which they can test new features. Only lead to the essentry system becoming unavailable.
tested new features are transferred by an admin to the servers on - The Client's customer data is processed in the Google Cloud.
which essentry is running. Reference is made here to Google's availability and resilience
- essentry servers are protected against hacking attacks by several measures.
defense mechanisms including a firewall. cloud.google.com/compute/
cloud.google.com/storage/
2.4. Separation control: Measures for separate processing (storage,
modification, deletion, transmission) of data with different purposes:
5. Measures to restore the availability of and access to
Description of the measures taken:
personal data in the event of a technical incident (Art.
- Data is stored on Google Cloud IT systems that are logically 32 lit. c GDPR)
separate from data of other Google Cloud customers.
cloud.google.com/security/ 5.1. Recovery / backup systems
Description of the measures taken:
3. Measures to protect integrity (Art. 32 section 1 lit. b
- Appropriate measures for fire protection, power supply, air
GDPR) conditioning, data backup, disaster recovery, etc. have been taken
for our IT systems as part of an emergency concept. A recovery time
3.1. Transfer control: Measures during transportation, transfer and
of 24 hours is guaranteed.
transmission or storage on data carriers (manually or electronically) as well
as during subsequent verification: - The Client's customer data is processed in the Google Cloud. Google
guarantees an availability of over 99.99%. In addition, reference is
Description of the measures taken:
made to the measures taken by Google to restore availability.
- Transport encryption (TLS) is implemented for the transfer of cloud.google.com/compute/
personal data from the respective end device to the server. cloud.google.com/storage/
- A subsequent check of the transfer control can also be carried out
by viewing the log files. 6. Procedure for the regular review, assessment, and
3.2. Input control: Measures to subsequently check whether and by whom evaluation of technical and organizational measures;
data has been entered, changed or removed (deleted): data protection by default (Art. 32 section 1 lit. d
Description of the measures taken: GDPR; Art. 25 section 1 GDPR)
- A subsequent check of the input control can also be carried out by 6.1. Data protection management
viewing the log files.
Description of the measures taken:
4. Availability and resilience of systems and services
- A data protection management system (DPMS) is in use. The DPMS
is provided by the Contractor's data protection officer and operated
(Art. 32 lit. b GDPR) together with the Contractor. Our procedures are regularly reviewed,
4.1. Availability control assessed, and evaluated as part of resubmissions and regular
meetings. Depending on the type of processing, these measures are
Description of the measures taken: carried out after 3, 6 or a maximum of 12 months.
- The data backups of our IT systems are carried out according to a 6.2. Data protection-friendly default settings (Privacy by Default)
binding data backup concept. A backup of the databases is made
Description of the measures taken:
daily between 1:00 am and 3:00 am. It is stored for 30 days and is
encrypted with AES256. - Default settings are protective of data. Client-specific development
is carried out on the instructions of the Client. Data subjects can
- The Client's customer data is processed in the Google Cloud.
obtain information about the use of their data at any time when using
Reference is made here to Google's availability and resilience
the software/app with the help of the data protection declaration.
measures.
cloud.google.com/compute/ - The Client specifies the categories of data to be collected.
cloud.google.com/storage/ 6.3. Order control: Measures (technical / organizational) to delimit the
- The files requiring storage are stored redundantly at different competencies between Client and Contractor:
locations to prevent loss. In addition, certain critical objects are Description of the measures taken:
versioned, which means that the replacement or deletion of a file is
logged and the old file is not lost but remains stored. All stored files - When processing personal data, contracts are concluded with
are encrypted with AES256. subcontractors in accordance with Art. 28 GDPR / EU Model
Clauses.
- In the Google Cloud, computing capacity is automatically increased
in the event of a sharp increase in requests or users.
Data Processing Agreement Ver. 1.6 from 12/23/2024 Page 6 of 8
Essentry Inc.
Annex 3: Contact persons
Responsible and authorized persons of the Client and Contractor. Contractor: Essentry GmbH
Instruction recipient Name Email Phone
CEO Dr. Dennis Lips [email protected] will be announced separately
CTO Christian Böhlke [email protected] will be announced separately
Other functions Name Email Phone
External Data Protection Officer Philipp Rothmann
[email protected] will be announced separately
External Information Security Officer Philipp Rothmann
Client shall inform Contractor of the persons responsible and authorized to issue instructions accordingly.
Annex 4: Subcontractors
Overview of all subcontractors working for the Contractor who directly collect, process and/or use the Client's data.
The following subcontractors work with the consent of the Client:
Subcontracting taker Address Field of activity
Gordon House, Barrow Street
Google Ireland Limited Hosting of the databases and servers in Germany.
Dublin, D04 E5W5, Ireland
Amazon Web Services 38 Avenue John F. Kennedy Sending e-mails and generating name tags for the printer; photo comparison;
EMEA SARL 1855, Luxembourg data processing takes place within the EU
Stanisla-Kist-Str. 14A Management of kiosk devices including the installation of app and system updates, assignment of
Cubefinity GmbH
94330 Aiterhofen customer and location-specific profiles and remote monitoring in the event of problems and other
Product NinjaOne
Deutschland support cases. Data processing and storage takes place in the EU.
375 Beale Street
Suite 300 Sending SMS and (video) telephony service. The subcontractor can only be used if the functionality is
Twilio Inc.
San Francisco explicitly ordered.
CA 94105, USA
Data Processing Agreement Ver. 1.6 from 12/23/2024 Page 7 of 8
Essentry Inc.
Annex 5: Notification form for data protection breaches
____________________________________________
Name (Contractor) Address (Contractor)
____________________________________________
Name (Client) Address (Client)
More detailed description of the contractual relationship concerned:
Period of the incident (date, time):
Description of the data protection incident:
(personal data breach)
Personal data concerned:
(according to data categories)
Number of persons affected (approximate):
Number of data records affected (approximate):
Affected IT systems:
Responsible department / responsible IT department if applicable:
Name and contact details of the data protection officer or other contact point:
Author and date of the message:
Who has already been informed and by whom:
(e.g. data protection officer, data protection supervisory authority, etc.)
Learn about this through (source):
Description of the likely consequences of the data protection incident:
Description of the immediate measures taken by the Contractor to rectify the problem:
Proposal for measures to be taken:
Measures to mitigate possible adverse effects:
Overall risk:
Legally binding confirmation of the correctness and completeness of the above information:
__________________________________________________________________
Place, date Signature Signature (Data Protection Officer)
Data Processing Agreement Ver. 1.6 from 12/23/2024 Page 8 of 8