Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the DLEGATE Terms of Service and governs the processing of Personal Data by the Provider on behalf of the Customer in connection with the use of the Service.
1. Introduction and Definitions
1.1 Relationship to the Terms of Service
This DPA forms part of the DLEGATE Terms of Service (“Terms of Service”) and applies to all processing of Personal Data carried out by DLEGATE Solutions GmbH on behalf of the Customer connection with the provision of the Service.
For data access, export, and sharing rights under the EU Data Act, the parties additionally rely on the Data Access & Sharing Addendum, which is incorporated into the Terms of Service and prevails for such matters.
1.2 Definitions
For the purpose of this DPA:
"GDPR" means Regulation (EU) 2016/679.
"Controller" and "Processor" have the meanings given to them under the GDPR.
"Personal Data" has the meaning given to it under the GDPR.
"Customer Data" means any data, including Personal Data, submitted to or generated through the Service by or on behalf of the Customer.
"Service", "Customer", "Provider", and "Agreement" have the meanings set out in the Terms of Service.
Capitalised terms not defined in this DPA have the meanings given to them in the Terms of Service.
2. Scope and Exclusions
2.1 Scope of Application
This DPA applies only to processing of Personal Data by the Processor on behalf of the Customer after the Customer has created an account and uses the Service.
Personal Data processed prior to the formation of the Agreement (for example website visits, trial requests, or sign-up forms) is processed by the Processor as an independent Controller and is governed by the Privacy Policy.
2.2 Payment Processing Exclusion
Payment processing for Paid Subscription Plans is carried out directly by an external payment service provider acting as an independent controller under applicable data protection laws. Such processing is outside the scope of this DPA.
The Processor does not process or store payment card data or other payment-related Personal Data of the Customer. The Customer’s relationship with the payment service provider is governed by the provider’s own terms and privacy policy.
3. Subject Matter and Duration
The Processor processes Personal Data solely to provide the contracted services under the Terms of Service.
This DPA enters into force upon the formation of the Agreement and remains in effect for the duration of the Agreement. This DPA continues to apply until all Customer Data processed on behalf of the Customer has been deleted or anonymised in accordance with this DPA and applicable law, except where limited retention is required by law.
4. Nature and Purpose of Processing
The Processor processes Personal Data arising from the Customer’s use of the Service, including video and communication services, session capture and storage, workflow execution, and user account management.
Processing may also occur for security, platform operation, maintenance, and Customer support purposes. All processing is performed strictly in accordance with the Customer’s documented instructions and only to the extent necessary to fulfil the agreed purposes.
Processing operations required to enable Customer Data access, export, portability, and sharing in accordance with the Data Access & Sharing Addendum and the EU Data Act form part of the agreed purposes.
5. Customer Instructions
5.1 Documented Instructions
The Customer’s use of the Service constitutes constitutes the Customer’s general instructions to the Processor for the processing of Personal Data.
Additional instructions may be issued only through the interface or support channels provided by the Processor. The Processor is not obliged to act on instructions that are unlawful, technically infeasible, or outside the scope of the Service and will inform the Customer without undue delay where applicable.
5.2 Legal Requirements
The Processor may process Personal Data where required by Union or Member State law to which it is subject. The Processor will notify the Customer before processing, unless prohibited by law on important grounds of public interest.
Instructions executed by the Customer through the data export, access, and sharing mechanisms described in the Data Access & Sharing Addendum constitute documented instructions under this DPA.
5.3 Suspension for Security or Legal Reasons
The Processor may suspend or restrict processing where Customer Data is reasonably suspected to be unlawful, harmful, or in violation of the Terms of Service. Any such suspension will be limited to the extent necessary to address the issue.
6. Types of Personal Data and Categories of Data Subjects
The Processor may process the following categories of Personal Data:
- User identification and account data
- Video, audio, image and communication content
- Device, connection, and technical metadata
- Workflow-related content
- Information relating to external participants
Data subjects include the Customer’s authorised users, employees, contractors, and other individuals participating in video sessions or workflows initiated by the Customer.
6.1 Free-Tier Eligibility Data
To verify eligibility for the Free-Tier Plan and prevent misuse, the Processor may additionally process:
- Name
- Email address
- Company Name
- Email domain
- Internal account status indicators
Such data is processed solely for eligibility verification and may be retained for the duration of the Customer’s account and up to twelve (12) months after account closure, unless the Customer instructs earlier deletion.
6.2 External Participants
Where the Customer invites third parties to participate in video sessions or workflows, the Customer is responsible for ensuring that such individuals receive all information required under applicable data protection laws.
6.3 Anonymised and Aggregated Data
The Processor may process anonymised or aggregated data derived from the Customer’s use of the Service for analytics, service optimisation, security, and product improvement, provided such data does not identify the Customer or any data subject.
6.4 Payment Data Exclusion
The Processor does not process any payment card information, bank details, or other payment-related personal data. Such data is processed exclusively by the independent payment service provider used for handling paid subscriptions.
7. Roles and Responsibilities
The Customer acts as Controller and determines the purposes and means of processing. The Processor processes Personal Data solely on documented instructions of the Customer.
The Customer is responsible for ensuring the lawfulness of processing, including the existence of a valid legal basis, compliance with information obligations, and the obtaining of consents where required.
The Customer must ensure that Customer Data does not contain unlawful content or categories of data that the Service is not designed to process. The Processor has no obligation to actively monitor Customer Data.
All persons authorised by the Processor to process Personal Data are subject to appropriate confidentiality obligations.
8. Sub-Processors
The Processor may engage sub-processors to support the provision of the Service. The current Sub-Processor List is referenced in the Terms of Service.
The Processor imposes data protection obligations on sub-processors under its control that are no less protective than those in this DPA. For standard infrastructure, the Processor relies on appropriate contractual safeguards and, where applicable, certified compliance frameworks to meet GDPR obligations.
Payment service providers used for subscription billing act as independent controllers and are not considered sub-processors under this DPA.
9. International Data Transfers
Customer data is processed within the EU/EEA unless required for specific services.
Where Personal Data is transferred outside the EU/EEA, such transfers are subject to appropriate safeguards, Standard Contractual Clauses adopted by the European Commission or other lawful transfer mechanisms.
Where the Customer initiates data export or sharing under the Data Access & Sharing Addendum that results in a transfer to a third country or third party, such transfer is deemed to occur on the Customer’s instructions.
10. Security Measures
The Processor implements appropriate technical and organisational measures in accordance with Article 32 GDPR, including measures addressing confidentiality, integrity, availability and resilience of processing systems. A summary of the applicable technical and organizational measures is provided below and constitutes the agreed measures for the purposes of Article 28(3)(c) GDPR.
(a) Confidentiality
- Role-based access control and least-privilege principles
- Strong authentication for administrative access
- Confidentiality obligations for all authorised personnel
- Certified data centre providers with industry-standard physical security
(b) Integrity
- Access restrictions, logging, and change management
- Encryption of Personal Data in transit using modern cryptography
(c) Availability and Resilience
- Resilient cloud infrastructure with redundancy and high availability
- Regular backups and recovery procedures
- Disaster recovery and business continuity processes
(d) Ongoing Evaluation
- Continuous monitoring and internal reviews
- Security testing, vulnerability management, and risk assessments
The Processor may update these measures provided the overall protection level is maintained.
11. Assistance to the Customer
The Processor assists the Customer with compliance obligations under the GDPR, including handling data subject requests, Personal Data breaches, data protection impact assessments, to the extent applicable to the processing performed.
The Processor will also provide reasonable technical assistance to enable Customer Data access and export as described in the Data Access & Sharing Addendum.
12. Audits and Inspections
Upon reasonable request, the Processor will provide evidence of compliance with this DPA, including certifications, attestations, or summaries of internal controls.
On-site audits are not provided. Audit requests must not unreasonably disrupt the Processor’s business operations.
13. Personal Data Breaches and Government Requests
The Processor will notify the Customer without undue delay upon becoming aware of a Personal Data breach affecting Customer Data and will provide information reasonably necessary to allow the Customer to meet its legal obligations.
Where the Processor receives a legally binding request from a public authority for access to Personal Data, it will notify the Customer unless legally prohibited and will challenge requests reasonably believed to be unlawful or disproportionate.
14. Deletion or Return of Data
Upon termination or expiry of the Agreement, Customer Data remains accessible for the duration of the applicable retention or post-termination access period specified in the applicable subscription plan, Terms of Service, or applicable addendum.
During this period, the Customer may export Customer Data in a commonly used, machine-readable format. Reasonable fees may apply for repeated or complex export requests where permitted by law.
After expiry of the applicable retention or access period, Customer Data will be deleted or anonymised, unless retention is required:
- by applicable law,
- for compliance with legal obligations, or
- for the establishment, exercise, or defence of legal claims.
Where User accounts are deactivated during an active Customer relationship, certain system-related metadata, including system-generated identifiers and associated activity records, may continue to be retained in pseudonymised form where technically and operationally necessary to ensure:
- traceability and auditability of historical system events, and
- consistency of Customer records.
Such retained metadata does not include full Customer datasets unless retention is legally required.
Upon termination or expiry of the Customer relationship and deletion of the corresponding Customer Data, any remaining pseudonymised records associated with previously deactivated Users are also deleted, unless retention is required by applicable law.
15. Priority
In case of conflict between this DPA and the Terms of Service, this DPA prevails with respect to the processing of Personal Data.
In case of conflict concerning data access, export, portability, or sharing rights, the Data Access & Sharing Addendum prevails.