Data Processing Agreement (DPA)

Agreement on processing on behalf of the controller pursuant to Art. 28 GDPR between the customer (controller) and HUWA MEDIA LLC (processor).

This is a courtesy translation. The German version of this agreement prevails.

§ 1 Subject matter and duration

This agreement governs the processing of personal data by HUWA MEDIA LLC, 2880 West Oakland Park Blvd, 225C, Fort Lauderdale, FL 33311, USA (the “processor”) on behalf of the customer (the “controller”) in the context of using the Set2Sell Cockpit software. It forms part of the service agreement and applies for its entire term.

§ 2 Nature, purpose and scope of processing

Processing comprises storing, managing and analyzing data that the controller enters into Set2Sell Cockpit: in particular contact and lead data (names, email addresses, phone numbers, company data), communication data (emails, call logs, call recordings and transcripts where activated by the controller), appointment and contract data, and usage data of invited team members.

Categories of data subjects are: the controller's prospects and customers, its employees and team members, and other contact persons whose data the controller enters.

§ 3 Right to issue instructions

The processor processes the data solely on documented instructions from the controller. Use of the software and its functions constitutes such instruction. The processor shall inform the controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions.

§ 4 Confidentiality

The processor ensures that persons authorized to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of secrecy.

§ 5 Technical and organizational measures (Art. 32 GDPR)

The processor takes appropriate technical and organizational measures to protect the data, in particular: encryption in transit (TLS) and at rest, data residency in the EU (database in Frankfurt am Main), role-based access control with workspace separation, logging, and regular backups. A current description of the measures and the infrastructure used is available on our security page.

§ 6 Subprocessors

The controller grants general authorization for the use of subprocessors. The current list forms part of this agreement and is available on our security page. The processor informs the controller of intended changes in advance in text form; the controller may object to a change for important data protection reasons within 14 days. The processor imposes data protection obligations on subprocessors that correspond to the obligations of this agreement.

§ 7 Third-country transfers

The processor is established in the USA; in addition, individual subprocessors are established in third countries. Transfers to third countries take place on the basis of the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914, Module 2: controller to processor), which are incorporated by concluding this agreement, and — where applicable — on the basis of the respective provider's certification under the EU-U.S. Data Privacy Framework.

§ 8 Assistance to the controller

The processor assists the controller by appropriate means in responding to data subject requests (Art. 12–23 GDPR), in ensuring security of processing, in data protection impact assessments and in fulfilling notification obligations. Export and deletion functions are available directly in the software.

§ 9 Notification of breaches

The processor notifies the controller of personal data breaches without undue delay after becoming aware of them and provides the information pursuant to Art. 33(3) GDPR insofar as available.

§ 10 Deletion and return

After termination of the service agreement, the processor deletes the data processed on behalf of the controller unless a statutory retention obligation exists. The controller can export its data before the end of the contract using the software's export functions.

§ 11 Evidence and audits

The processor makes available to the controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR. Audits are conducted primarily by providing current documentation and existing audit reports of the infrastructure providers used; further audits are possible to a reasonable extent after prior notice.

§ 12 Final provisions

In the event of conflicts between this agreement and the service agreement, this agreement prevails with regard to data protection. Should individual provisions be invalid, the remainder of the agreement remains in effect.

Questions about this agreement are answered at info@set2sell.io. On request, we provide the DPA as a countersigned document.