rapidFOX Logo
rapidFOX
Smart Helpdesk
Zur Startseite

Data processing agreement (DPA)

Courtesy translation

This English version is provided for convenience only. The German version is the legally binding one; in the event of any discrepancy, the German text prevails.

As of 10 Sep 2026 · Agreement on the processing of personal data on behalf of a controller pursuant to Art. 28 GDPR. This DPA forms part of the usage contract for rapidFOX.

Recital

A usage contract for the software-as-a-service solution “rapidFOX” (the “Main Contract”) exists between the customer (the “Controller”) and Entracon Projektservice GmbH, Springorumallee 10, 44795 Bochum (the “Processor”). In providing the service, the Processor processes personal data on behalf of and on the instructions of the Controller. This agreement sets out in detail the parties’ data protection rights and obligations pursuant to Art. 28 GDPR.

§ 1 Subject matter and duration

(1) The subject matter of the engagement is the processing of personal data by the Processor for the Controller in connection with the provision and operation of rapidFOX (operation of the application, hosting, storage, maintenance, support).

(2) The duration of this agreement corresponds to the term of the Main Contract. It ends automatically when the Main Contract ends, unless the provisions below (in particular on deletion and return) give rise to obligations beyond that point.

§ 2 Nature, scope and purpose of processing

The nature and purpose of the processing, the type of personal data and the categories of data subjects are set out in Annex 1. Processing takes place exclusively within the European Union or the European Economic Area. Processing in a third country takes place only under the conditions of Art. 44 et seq. GDPR.

§ 3 The Controller’s right to issue instructions

(1) The Processor processes personal data exclusively within the scope of the agreements made and in accordance with the Controller’s documented instructions, unless required to process by law. In such a case, the Processor informs the Controller of those legal requirements before processing, unless the law in question prohibits such notification on important grounds of public interest.

(2) Use of the application by the Controller and its users within the contractually intended functions counts as an instruction. Supplementary or deviating individual instructions must be issued in text form.

(3) If the Processor is of the opinion that an instruction infringes data protection law, it must inform the Controller without undue delay. It is entitled to suspend performance of the instruction concerned until the instruction is confirmed or amended.

§ 4 Obligations of the Processor

  • processing data exclusively on instruction and for the agreed purpose (Art. 28 (3) (a) GDPR);
  • obliging persons authorised to process the data to maintain confidentiality, or ensuring that they are under an appropriate statutory obligation of confidentiality (Art. 28 (3) (b), Art. 29, Art. 32 (4) GDPR);
  • taking and maintaining appropriate technical and organisational measures pursuant to Art. 32 GDPR in accordance with Annex 2;
  • assisting the Controller in responding to requests from data subjects (Art. 12–23 GDPR) by appropriate measures, insofar as possible (Art. 28 (3) (e) GDPR);
  • assisting the Controller in complying with the obligations under Art. 32 to 36 GDPR (security of processing, notification of breaches, data protection impact assessment, prior consultation);
  • informing the Controller without undue delay of inspections and measures by the supervisory authority, insofar as they relate to the processing carried out on the Controller’s behalf;
  • maintaining a record of all categories of processing activities carried out on behalf of the Controller (Art. 30 (2) GDPR).

§ 5 Technical and organisational measures

The Processor takes the technical and organisational measures described in Annex 2. It is entitled to develop and adapt these measures over time, provided the agreed level of protection is not reduced.

§ 6 Sub-processors

(1) The Controller grants the Processor general authorisation to engage further processors (sub-processors). The sub-processors engaged at the time the contract is concluded are listed in Annex 3.

(2) The Processor informs the Controller in advance, with reasonable notice, of intended changes concerning the addition or replacement of sub-processors. The Controller may object to a change on important data protection grounds within the period stated.

(3) The Processor imposes on each sub-processor, by contract, the same data protection obligations as are set out in this agreement (Art. 28 (4) GDPR). Ancillary services that the Processor uses, such as pure telecommunications, maintenance or cleaning services, do not count as sub-processing.

§ 7 Assistance with data subject rights

If a data subject approaches the Processor directly with a request (for example access, rectification, erasure, restriction, data portability, objection), the Processor forwards the request to the Controller without undue delay and assists the Controller – insofar as agreed and technically possible – in fulfilling it. rapidFOX provides the Controller with functions for exporting and deleting data for this purpose.

§ 8 Notification of personal data breaches

The Processor notifies the Controller of any personal data breach affecting the data processed on the Controller’s behalf, without undue delay after becoming aware of it. The notification contains the information required under Art. 33 (3) GDPR insofar as it is available to the Processor. The Processor assists the Controller with its notification and communication obligations under Art. 33 and 34 GDPR.

§ 9 The Controller’s audit rights

(1) The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller (Art. 28 (3) (h) GDPR).

(2) Audits must be carried out with reasonable advance notice, during normal business hours and without disrupting operations. Evidence may also be provided by presenting suitable certifications, attestations or current reports.

§ 10 Deletion and return after termination

After the processing has ended, the Processor deletes – at the Controller’s choice – all personal data or returns it and deletes existing copies, unless Union or Member State law requires storage. For this purpose the Processor allows the Controller to export data for a reasonable period after the contract ends.

§ 11 Accountability and liability

(1) The Controller is responsible for the lawfulness of the data processing and for safeguarding the rights of data subjects (Art. 24 GDPR).

(2) Art. 82 GDPR applies to liability towards third parties. Between the parties, the liability provisions of the Main Contract additionally apply.

§ 12 Final provisions

(1) In the event of contradictions between this DPA and the Main Contract, the provisions of this DPA prevail in matters of data protection. (2) Amendments require text form. (3) German law applies. (4) Should any provision be invalid, the validity of the remaining provisions is unaffected.


Annex 1 – Subject matter, type of data and data subjects

Nature and purpose of the processing

Storing, organising, retrieving, altering, transmitting within the application and deleting personal data for the purpose of operating a help desk and ticketing system (recording, handling and answering support cases, collaboration, documentation).

Type of personal data

  • master and contact data (for example name, email address, telephone number, company);
  • content and communication data (for example ticket content, emails, chat messages, notes, attachments);
  • case and metadata (for example status, priority, timestamps, assignments, time tracking);
  • usage and log data of the agents within the application.

Categories of data subjects

  • the Controller’s end customers and requesters;
  • contact persons recorded in company records;
  • the Controller’s employees and users (agents).

Annex 2 – Technical and organisational measures (Art. 32 GDPR)

Confidentiality

  • physical access control: operation in a data centre with recognised physical security measures (in Germany);
  • system access control: individual user accounts, passwords stored in encrypted form, two-factor authentication, locking on inactivity;
  • data access control: role-based permissions and strict tenant separation, so that each workspace is logically separated and accessible only to authorised users;
  • separation control: separate processing of data belonging to different controllers.

Integrity

  • transfer control: transport encryption (TLS/HTTPS) for all connections;
  • input control: traceability of changes through logging of significant operations.

Availability and resilience

  • regular backups;
  • protective measures against data loss and measures for rapid restoration after an incident;
  • firewalls and restriction of externally reachable services.

Procedures for regular review

  • updating the systems in use (patch management);
  • regular review and improvement of the protective measures;
  • processing only on the basis of documented instructions.

Annex 3 – Approved sub-processors

  • Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany – hosting and data centre and infrastructure services (servers located in Germany).

Further sub-processors are engaged only in accordance with § 6 and with prior notice. The optional AI assistant is processed on infrastructure operated by the Processor itself; no transmission to external AI services takes place.