Hypatos Data Processing Agreement (DPA) Compliance

Data Processing Agreement

This data processing agreement including all attachments (hereinafter jointly referred to as the "DPA") specifies the data protection obligations of the Parties under the underlying Order Form.

Website analytics with Pearl Diver

We use “Pearl Diver” to allow us to conduct analysis of website visitors. Pearl Diver is a service of Black Pearl Group Limited, Level 1/60 Cuba Street Te Aro, Wellington 6011, NZ, Company Number 4064918.

Pearl Diver uses so-called "cookies" and web beacons. The information generated in relation to the use of this website is transferred by default to a Black Pearl server in the USA and stored there.

Pearl Diver only sets cookies with your consent. On behalf of the operator of this website, Pearl Diver will use this information to analyze your use of the website and to generate reports on website activity and visitors. Pearl Diver also uses this information to provide other services related to the use of the website and the internet to the website operator.

The terms of use of Pearl Diver and information on data protection can be accessed via the following link:

https://pearldiver.io/privacy-policy/

§ 1 Scope of application and definitions

(1) The following provisions shall apply to all data processing services within the meaning of Art. 28 GDPR provided by HYPATOS to Customer on the basis of the Order Form and to all activities in which personal data may be processed by HYPATOS.

(2) Insofar as the term data processing is used in this DPA for the processing of orders, this is generally to be understood as the use of personal data. Data processing means any operation or set of operations carried out with or without the aid of automated processes relating to personal data, such as collection, recording, organisation, sorting, recording, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, comparison or association, limitation, erasure or destruction.

(3) Reference is made to the other definitions in Art. 4 GDPR and in the Order Form.

§ 2 Subject and duration of data processing

(1) HYPATOS shall process personal data on behalf of and in accordance with instructions by Customer.

(2) The subject of this DPA is the digitisation, storage and further processing of documents, for example incoming invoices of Customer within the scope agreed with HYPATOS, in accordance with the Order Form.

(3) The duration of this DPA corresponds to the duration of the Order Form.

§ 3 Type and purpose of data processing

The type and purpose of data processing include the following activities and purposes:

§ 4 Categories of data subjects

The categories of persons affected by the handling of personal data under the Order Form can include:

§ 5 Type of Personal Data

(1) The personal data are subject to two categories: personal data of Users (“Personal User Data”) and personal data of persons mentioned in the documents processed by means of the Services (“Personal Document Data”).

(2) The following data types are affected by data processing:

§ 6 Rights and Duties of the Customer

(1) Customer is the data controller within the meaning of Art. 4 No. 7 GDPR.

(2) Customer is entitled to issue instructions on the type, scope and procedure of data processing. Oral instructions shall be confirmed immediately by HYPATOS in writing or in text form at Customer's request.

(3) Insofar as Customer deems it necessary, persons authorized to issue instructions may be named. Customer shall notify HYPATOS of this in text form. In the event that these persons authorized to issue instructions change at Customer, HYPATOS shall be notified thereof in text form, naming the new person in each case.

(4) Customer shall inform HYPATOS immediately if errors or irregularities are detected in connection with the processing of personal data by HYPATOS.

§ 7 Obligations of HYPATOS

(1) Data processing HYPATOS will process the personal data exclusively in accordance with this DPA and/or the underlying Order Form and in accordance with Customer's instructions, unless HYPATOS is legally required to do otherwise. In the latter case, HYPATOS will inform Customer of that legal requirement before processing.

(2) Data Subject Rights

(3) Control obligations

(4) Duty to provide information

(5) Place of data processing The data processing takes place in principle on the territory of the Federal Republic of Germany or within the European Union or the states of the European Economic Area. Processing in other states is only permitted with the prior consent of the Customer and only if the special requirements of Art. 44, 45, 46 or 49 GDPR are fulfilled.

(6) Deletion of personal data after completion of the order Upon termination of the Order Form, HYPATOS shall delete or destroy all personal data, documents and processing and usage results that have come into its possession and that are connected with the contractual relationship, in accordance with data protection regulations, insofar as the deletion of such data does not conflict with any statutory storage obligations.

§ 8 Control rights of Customer

(1) Customer shall be entitled, after timely prior registration during normal business hours, to ensure compliance with the provisions on data protection and the contractual agreements in the necessary scope itself or by third parties.

(2) HYPATOS shall inform Customer about the implementation of control measures by the supervisory authority, insofar as the measures or data processing which HYPATOS provides for Customer may be affected.

§ 9 Subprocessing relationships

(1) Customer authorizes HYPATOS to make use of further data processors in accordance this § 9. This authorization constitutes a general written approval within the meaning of Art. 28 para. 2 GDPR.

(2) HYPATOS currently cooperates with the subprocessors named in Appendix 2. Customer agrees to their assignment.

(3) HYPATOS shall be entitled to commission further subprocessors or to replace those already commissioned. HYPATOS shall inform Customer in advance of any intended change.

(4) Customer may object to an intended change. The objection to the intended change must be made to HYPATOS within two (2) weeks of receipt of the information about the change.

(5) HYPATOS is obliged to conclude agreements in accordance with Art. 28 para. 4 GDPR with the subprocessors.

§ 10 Technical and Organizational Measures

(1) The technical and organisational measures described in Appendix 1 shall be agreed. HYPATOS may update and modify these measures provided that such updates and/or modifications do not significantly reduce the level of protection and are documented.

(2) HYPATOS shall observe the principles of proper data processing pursuant to Art. 32 in connection with Art. 5 para. 1 GDPR. It is obliged to the contractually agreed and legally prescribed data security measures.

Appendix 1 to DPA

Technical and organizational measures to ensure the security of data processing A. Encryption measures Measures or processes in which a clearly readable text/information is converted into an illegible, i.e. not easily interpretable, character string (ciphertext) with the aid of an encryption procedure (cryptosystem):

B. Measures to ensure confidentiality 1. Physical access control Measures physically preventing unauthorised persons from gaining access to IT systems and data processing equipment processing personal data and to confidential files and data carriers:

2. Logical access control Measures to prevent unauthorised persons from processing or using data protected by data protection law.

3. Separation requirement Measures to ensure that data collected for different purposes are processed separately and are separate from other data and systems.

C. Measures to safeguard integrity 1. Data integrity Measures to ensure that stored personal data is not damaged by system malfunctions:

2. Transmission control Measures to ensure that it is possible to verify and establish to which bodies personal data have been or may be transmitted or made available by means of data transmission facilities.

3. Transport control Measures to ensure that the confidentiality and integrity of personal data are protected when personal data are transmitted and when data media are transported.

4. Input control Measures to ensure that it can be subsequently verified and established whether and by whom personal data have been entered into, modified in or removed from computer systems.

D. Measures to ensure availability and resilience 1. Availability control Measures to ensure that personal data are protected against accidental destruction or loss.

2. Rapid recoverability Measures to ensure the ability to restore rapidly the availability of and access to personal data in the event of a physical or technical incident.

3. Reliability Measures to ensure that all functions of the system are available and that any malfunctions are reported.

E. Data protection through technology design and through data protection-friendly presettings Privacy by Design means translated "data protection through technology design". This means that suitable technical measures are implemented as early as the development of processing operations.

F. Measures for the regular evaluation of the security of data processing 1. Review procedure Measures to ensure that processing complies with data protection regulations and is secure.

2. Organisational control Measures to ensure that employees are informed and sensitised to the requirements of data protection and that they are committed to compliance with data protection.

3. Order control Measures to ensure that personal data processed on behalf of the Customer can only be processed in accordance with the instructions of the Customer:

Appendix 2 to DPA: Subcontracting relationships pursuant to § 9 of the DPA

HYPATOS currently cooperates with the following subcontractors in the fulfilment of the order:

1. Amazon Web Services

Name/Company: Amazon Web Services EMEA SARL Function/activity: Cloud Infrastructure as a Service (IaaS) Provider which offers cloud computing services including computing power
Location of data processing: European Union Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR

2. Microsoft

Name/Company: Microsoft Ireland Operations Limited Function/activity: Processing of customer document email uploads via Microsoft Exchange (part of Microsoft 365) Location of data processing: European Union Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR

3. Google Vision AI

Name/Company: Google Ireland Limited Function/Activity: Cloud OCR provider, enabling extraction of text from customer-uploaded documents Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR

4. Atlas MongoDB

Name/Company: MongoDB, Inc. Function/Activity: Managed database service within Hypatos’ AWS environment, ensuring secure and scalable data storage and retrieval.
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR

5. Jira Service Management

Name/Company: Atlassian. Pty Ltd
Function/Activity: Service desk for customer support, processing the data that customers enter and attach to tickets, as well as all information related to such tickets
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR

6. Mailjet

Name/Company: Mailjet SAS
Function/Activity: Email notification dispatch service for emails sent to Customer by Hypatos CloudServices
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR

7. OpenAI API

Name/Company: OpenAI Ireland Limited
Function/Activity: Natural language processing and generation of text-based outputs used for further document processing by Hypatos.
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR

8. LabelYourData

Name/Company: SupportYourApp, Inc. DBA Label Your Data
Function/Activity: Managed data annotation and labelling service provider
Location of data processing: USA
Measures/guarantees to ensure an adequate level of data protection: Certificate according to the EU-US Data Privacy Framework

9. CenterDevice

Name/Company: CenterDevice GmbH
Function/Activity: Cloud document management system (DMS) for GOBD archive service
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR

10. DeepL

Name/Company: DeepL SE
Function/Activity: Provides automated translation services for customer documents in languages other than English
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR

11. Wargitsch

Name/Company: Wargitsch & Comp. AG
Function/Activity: Implementation Partner
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR

12. EY

Name/Company: EY GmbH & Co. KG Wirtschaftsprüfungsgesellschaft
Function/Activity: Implementation Partner
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR

13. KPMG

Name/Company: KPMG Advisory N.V.
Function/Activity: Implementation Partner
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Data Processing Agreement according to Art. 28 GDPR

August 2024