Hypatos Data Processing Agreement (DPA) Compliance
Data Processing Agreement
This data processing agreement including all attachments (hereinafter jointly referred to as the "DPA") specifies the data protection obligations of the Parties under the underlying Order Form.
Website analytics with Pearl Diver
We use “Pearl Diver” to allow us to conduct analysis of website visitors. Pearl Diver is a service of Black Pearl Group Limited, Level 1/60 Cuba Street Te Aro, Wellington 6011, NZ, Company Number 4064918.
Pearl Diver uses so-called "cookies" and web beacons. The information generated in relation to the use of this website is transferred by default to a Black Pearl server in the USA and stored there.
Pearl Diver only sets cookies with your consent. On behalf of the operator of this website, Pearl Diver will use this information to analyze your use of the website and to generate reports on website activity and visitors. Pearl Diver also uses this information to provide other services related to the use of the website and the internet to the website operator.
The terms of use of Pearl Diver and information on data protection can be accessed via the following link:
https://pearldiver.io/privacy-policy/
§ 1 Scope of application and definitions
(1) The following provisions shall apply to all data processing services within the meaning of Art. 28 GDPR provided by HYPATOS to Customer on the basis of the Order Form and to all activities in which personal data may be processed by HYPATOS.
(2) Insofar as the term data processing is used in this DPA for the processing of orders, this is generally to be understood as the use of personal data. Data processing means any operation or set of operations carried out with or without the aid of automated processes relating to personal data, such as collection, recording, organisation, sorting, recording, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, comparison or association, limitation, erasure or destruction.
(3) Reference is made to the other definitions in Art. 4 GDPR and in the Order Form.
§ 2 Subject and duration of data processing
(1) HYPATOS shall process personal data on behalf of and in accordance with instructions by Customer.
(2) The subject of this DPA is the digitisation, storage and further processing of documents, for example incoming invoices of Customer within the scope agreed with HYPATOS, in accordance with the Order Form.
(3) The duration of this DPA corresponds to the duration of the Order Form.
§ 3 Type and purpose of data processing
The type and purpose of data processing include the following activities and purposes:
- Training of the AI base models to the specific requirements of Customer during the project phase
- Automated and manual digitisation of documents
- Storage of documents and associated metadata in a document management system
- Implementation of release processes
- Enhancement of document data with posting accounts, cost centers and other attributes
- Provision of payment information in payment lists
- Export of data for further processing in the Customers’ systems
- Providing customer support
§ 4 Categories of data subjects
The categories of persons affected by the handling of personal data under the Order Form can include:
- Employees of Customer
- Customer's suppliers or their employees
- Customers of Customer or their employees
- If applicable, other natural persons whose personal data are contained in the processed documents.
§ 5 Type of Personal Data
(1) The personal data are subject to two categories: personal data of Users (“Personal User Data”) and personal data of persons mentioned in the documents processed by means of the Services (“Personal Document Data”).
(2) The following data types are affected by data processing:
- Person master data, for example name, address (Personal User Data as well as Personal Document Data.)
- Communication data (e.g. telephone, e-mail) (Personal User Data as well as Personal Document Data.)
- Account master data (e.g. bank details) (Personal Document Data)
- Electronic communication data (e.g. IP address, operating system and browser, time and date) (Personal User Data)
- Log data (Personal User Data)
- Where applicable, other personal data of natural persons contained in the documents provided by the Customer (Personal Document Data).
§ 6 Rights and Duties of the Customer
(1) Customer is the data controller within the meaning of Art. 4 No. 7 GDPR.
(2) Customer is entitled to issue instructions on the type, scope and procedure of data processing. Oral instructions shall be confirmed immediately by HYPATOS in writing or in text form at Customer's request.
(3) Insofar as Customer deems it necessary, persons authorized to issue instructions may be named. Customer shall notify HYPATOS of this in text form. In the event that these persons authorized to issue instructions change at Customer, HYPATOS shall be notified thereof in text form, naming the new person in each case.
(4) Customer shall inform HYPATOS immediately if errors or irregularities are detected in connection with the processing of personal data by HYPATOS.
§ 7 Obligations of HYPATOS
(1) Data processing HYPATOS will process the personal data exclusively in accordance with this DPA and/or the underlying Order Form and in accordance with Customer's instructions, unless HYPATOS is legally required to do otherwise. In the latter case, HYPATOS will inform Customer of that legal requirement before processing.
(2) Data Subject Rights
- HYPATOS shall support Customer in fulfilling the rights of the parties concerned, in particular with regard to rectification, restriction of processing and deletion, notification and provision of information, within the scope of its capabilities, insofar as HYPATOS is obliged to do so for compelling legal reasons.
- If HYPATOS collects the personal data specified in this DPA on behalf of Customer and if this data is the subject of a justified claim to data portability pursuant to Art. 20 GDPR and if the person concerned is identified within the meaning of Art. 12 GDPR, HYPATOS shall notify Customer of the fact that the data has been processed on behalf of Customer in a structured, common and machine-readable format within a reasonable time.
- At the instruction of Customer, HYPATOS shall correct, delete or restrict the processing of the personal data on behalf of Customer. The same shall apply if this DPA provides for the correction, deletion or limitation of the processing of data.
- If a data subject contacts HYPATOS directly for the purpose of correcting, deleting or restricting the processing of the personal data, HYPATOS shall forward this request to Customer immediately upon receipt.
(3) Control obligations
- HYPATOS shall ensure by means of appropriate controls that the personal data collected, processed or used on behalf of Customer are processed exclusively in accordance with this DPA and/or the Order Form and/or the corresponding instructions.
- HYPATOS shall set up its operating procedures in such a way that the data which it processes on behalf of Customer are secured to the extent necessary and protected from unauthorised access by third parties.
- HYPATOS confirms that it has appointed a data protection officer and will monitor compliance with data protection and data security regulations, including the data protection officer.
(4) Duty to provide information
- HYPATOS shall immediately draw Customer's attention to any instructions issued by Customer which, in its opinion, violate statutory provisions.
- HYPATOS shall assist Customer in complying with the obligations set out in Articles 32 to 36 GDPR, taking into account the type of processing and the information available to it.
(5) Place of data processing The data processing takes place in principle on the territory of the Federal Republic of Germany or within the European Union or the states of the European Economic Area. Processing in other states is only permitted with the prior consent of the Customer and only if the special requirements of Art. 44, 45, 46 or 49 GDPR are fulfilled.
(6) Deletion of personal data after completion of the order Upon termination of the Order Form, HYPATOS shall delete or destroy all personal data, documents and processing and usage results that have come into its possession and that are connected with the contractual relationship, in accordance with data protection regulations, insofar as the deletion of such data does not conflict with any statutory storage obligations.
§ 8 Control rights of Customer
(1) Customer shall be entitled, after timely prior registration during normal business hours, to ensure compliance with the provisions on data protection and the contractual agreements in the necessary scope itself or by third parties.
(2) HYPATOS shall inform Customer about the implementation of control measures by the supervisory authority, insofar as the measures or data processing which HYPATOS provides for Customer may be affected.
§ 9 Subprocessing relationships
(1) Customer authorizes HYPATOS to make use of further data processors in accordance this § 9. This authorization constitutes a general written approval within the meaning of Art. 28 para. 2 GDPR.
(2) HYPATOS currently cooperates with the subprocessors named in Appendix 2. Customer agrees to their assignment.
(3) HYPATOS shall be entitled to commission further subprocessors or to replace those already commissioned. HYPATOS shall inform Customer in advance of any intended change.
(4) Customer may object to an intended change. The objection to the intended change must be made to HYPATOS within two (2) weeks of receipt of the information about the change.
(5) HYPATOS is obliged to conclude agreements in accordance with Art. 28 para. 4 GDPR with the subprocessors.
§ 10 Technical and Organizational Measures
(1) The technical and organisational measures described in Appendix 1 shall be agreed. HYPATOS may update and modify these measures provided that such updates and/or modifications do not significantly reduce the level of protection and are documented.
(2) HYPATOS shall observe the principles of proper data processing pursuant to Art. 32 in connection with Art. 5 para. 1 GDPR. It is obliged to the contractually agreed and legally prescribed data security measures.
Appendix 1 to DPA
Technical and organizational measures to ensure the security of data processing A. Encryption measures Measures or processes in which a clearly readable text/information is converted into an illegible, i.e. not easily interpretable, character string (ciphertext) with the aid of an encryption procedure (cryptosystem):
- All web traffic transmitted over the Internet between Hypatos and its Customers is encrypted using TLS 1.2+
- Customer data stored at Cloud Infrastructure as a Service (IaaS) providers is encrypted at rest using AES-256
- Hard drives of employees’ devices are encrypted using AES-256
- Emails are encrypted at rest using BitLocker Drive Encryption
- Encryption keys and secrets are stored in secure cloud locations, accessible only by Engineering team members, in accordance with least privilege and need-to-know principles
B. Measures to ensure confidentiality 1. Physical access control Measures physically preventing unauthorised persons from gaining access to IT systems and data processing equipment processing personal data and to confidential files and data carriers:
- Entrance to office facilities only accessible with keycard or PIN-code in combination with transponder system for authorized employees or freelancers and service staff;
- External Security Service regularly controls building and premise;
2. Logical access control Measures to prevent unauthorised persons from processing or using data protected by data protection law.
- Logical access to systems is controlled based on principles of least privilege and need-to-know;
3. Separation requirement Measures to ensure that data collected for different purposes are processed separately and are separate from other data and systems.
C. Measures to safeguard integrity 1. Data integrity Measures to ensure that stored personal data is not damaged by system malfunctions:
- Testing of new releases and patches to verify correctness of changed component;
2. Transmission control Measures to ensure that it is possible to verify and establish to which bodies personal data have been or may be transmitted or made available by means of data transmission facilities.
3. Transport control Measures to ensure that the confidentiality and integrity of personal data are protected when personal data are transmitted and when data media are transported.
4. Input control Measures to ensure that it can be subsequently verified and established whether and by whom personal data have been entered into, modified in or removed from computer systems.
D. Measures to ensure availability and resilience 1. Availability control Measures to ensure that personal data are protected against accidental destruction or loss.
2. Rapid recoverability Measures to ensure the ability to restore rapidly the availability of and access to personal data in the event of a physical or technical incident.
3. Reliability Measures to ensure that all functions of the system are available and that any malfunctions are reported.
E. Data protection through technology design and through data protection-friendly presettings Privacy by Design means translated "data protection through technology design". This means that suitable technical measures are implemented as early as the development of processing operations.
F. Measures for the regular evaluation of the security of data processing 1. Review procedure Measures to ensure that processing complies with data protection regulations and is secure.
- Data protection management and data protection concept
2. Organisational control Measures to ensure that employees are informed and sensitised to the requirements of data protection and that they are committed to compliance with data protection.
3. Order control Measures to ensure that personal data processed on behalf of the Customer can only be processed in accordance with the instructions of the Customer:
Appendix 2 to DPA: Subcontracting relationships pursuant to § 9 of the DPA
HYPATOS currently cooperates with the following subcontractors in the fulfilment of the order:
1. Amazon Web Services
Name/Company: Amazon Web Services EMEA SARL
Function/activity: Cloud Infrastructure as a Service (IaaS) Provider which offers cloud computing services including computing power
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR
2. Microsoft
Name/Company: Microsoft Ireland Operations Limited Function/activity: Processing of customer document email uploads via Microsoft Exchange (part of Microsoft 365) Location of data processing: European Union Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR
3. Google Vision AI
Name/Company: Google Ireland Limited
Function/Activity: Cloud OCR provider, enabling extraction of text from customer-uploaded documents
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR
4. Atlas MongoDB
Name/Company: MongoDB, Inc.
Function/Activity: Managed database service within Hypatos’ AWS environment, ensuring secure and scalable data storage and retrieval.
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR
5. Jira Service Management
Name/Company: Atlassian. Pty Ltd
Function/Activity: Service desk for customer support, processing the data that customers enter and attach to tickets, as well as all information related to such tickets
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR
6. Mailjet
Name/Company: Mailjet SAS
Function/Activity: Email notification dispatch service for emails sent to Customer by Hypatos CloudServices
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR
7. OpenAI API
Name/Company: OpenAI Ireland Limited
Function/Activity: Natural language processing and generation of text-based outputs used for further document processing by Hypatos.
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR
8. LabelYourData
Name/Company: SupportYourApp, Inc. DBA Label Your Data
Function/Activity: Managed data annotation and labelling service provider
Location of data processing: USA
Measures/guarantees to ensure an adequate level of data protection: Certificate according to the EU-US Data Privacy Framework
9. CenterDevice
Name/Company: CenterDevice GmbH
Function/Activity: Cloud document management system (DMS) for GOBD archive service
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR
10. DeepL
Name/Company: DeepL SE
Function/Activity: Provides automated translation services for customer documents in languages other than English
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR
11. Wargitsch
Name/Company: Wargitsch & Comp. AG
Function/Activity: Implementation Partner
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR
12. EY
Name/Company: EY GmbH & Co. KG Wirtschaftsprüfungsgesellschaft
Function/Activity: Implementation Partner
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR
13. KPMG
Name/Company: KPMG Advisory N.V.
Function/Activity: Implementation Partner
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR
August 2024