Data Processing Agreement
This Data Processing Agreement ("DPA") is entered into between the Customer ("Controller") and Sykik [FlexCo i.G.] ("Processor") and forms part of the Sykik Terms of Service or separate written agreement between the parties (the "Main Agreement"). This DPA applies where and to the extent the Processor processes Personal Data on behalf of the Controller under the Main Agreement.
The Terms of Service incorporate the Privacy Policy and the DPA by reference. The measures published on the Security page are Annex III of the DPA. The Imprint is the disclosure required by § 5 ECG and is not part of the agreement.
Definitions
"Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Personal Data Breach," and "Supervisory Authority" shall have the meanings given in Article 4 of the GDPR.
"Sub-Processor" means any processor engaged by the Processor to process Personal Data on behalf of the Controller under this DPA, as listed in Annex II or subsequently approved in accordance with Section 6.
"Standard Contractual Clauses" ("SCCs") means the European Commission's Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 (Commission Implementing Decision (EU) 2021/914 of 4 June 2021).
Subject Matter, Nature, Purpose, and Duration
The subject matter, nature, and purpose of the Processing, the types of Personal Data, and categories of Data Subjects are set out in Annex I.
The Processing shall continue for the term of the Main Agreement or until the Controller instructs the Processor to cease processing and delete all Personal Data.
Processor Obligations
The Processor shall:
- process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or international organisation, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
- ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- take all measures required pursuant to Article 32 GDPR (Security of Processing), and as further described in Annex III (Technical and Organisational Measures);
- respect the conditions referred to in paragraphs 2 and 4 of Article 28 for engaging another processor (see Section 6 of this DPA);
- taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR;
- assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR (security, data breach notification, data protection impact assessment, and prior consultation with the Supervisory Authority), taking into account the nature of processing and the information available to the Processor;
- at the choice of the Controller, delete or return all the Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the Personal Data;
- make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
Controller Obligations
The Controller shall:
- ensure that it has a lawful basis for the Processing of Personal Data under Article 6 GDPR and, where applicable, Article 9 GDPR (special categories of data), and that the Controller's instructions to the Processor comply with all applicable data protection laws;
- ensure that Data Subjects have been provided with all information required under Articles 13 and 14 GDPR, including the identity of the Processor and any Sub-Processors;
- provide the Processor with documented instructions as required under this DPA, and notify the Processor promptly of any changes that affect the Processing.
Personal Data Breach Notification
The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA. The notification shall:
- describe the nature of the Personal Data Breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- communicate the name and contact details of the Data Protection Officer or other contact point where more information can be obtained;
- describe the likely consequences of the Personal Data Breach;
- describe the measures taken or proposed to be taken by the Processor to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach. Where feasible, this notification shall be made within 72 hours of becoming aware.
Sub-Processors
The Controller authorises the Processor to engage the Sub-Processors listed in Annex II. The Processor shall:
- inform the Controller of any intended changes concerning the addition or replacement of Sub-Processors at least 14 days in advance by email to the address registered with the Controller's Sykik account, thereby giving the Controller the opportunity to object to such changes;
- impose data protection obligations on the Sub-Processor that are no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of the GDPR;
- where the Sub-Processor fails to fulfil its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of that Sub-Processor's obligations.
International Data Transfers
The Controller acknowledges that certain Sub-Processors listed in Annex II process data outside the European Economic Area (EEA). Transfers are governed by:
- an adequacy decision of the European Commission pursuant to Article 45(3) GDPR (including the EU-US Data Privacy Framework for certified recipients);
- the Standard Contractual Clauses (Module 2: Controller to Processor and Module 3: Processor to Processor) adopted under Article 46(2)(c) GDPR; or
- binding corporate rules approved under Article 47 GDPR.
The SCCs are incorporated by reference into this DPA. Where the SCCs apply, the Controller is the "data exporter" and the Processor is the "data importer" (or sub-exporter/sub-importer, as appropriate under the onward transfer chain). A Transfer Impact Assessment has been documented and is available on request.
Audit Rights
The Controller may audit the Processor's compliance with this DPA. Audits shall be:
- upon reasonable written notice (minimum 30 days);
- during normal business hours;
- conducted no more than once per calendar year, unless an audit is required by a Supervisory Authority or follows a confirmed Personal Data Breach;
- at the Controller's own cost, including the Processor's reasonable time and expenses in supporting the audit.
The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance. The Controller may appoint an independent auditor, provided the auditor enters into a confidentiality agreement with the Processor.
Liability
Each party's liability arising out of or related to this DPA shall be subject to the limitations and exclusions of liability set out in the Main Agreement. Nothing in this DPA limits either party's liability to a Data Subject or to the extent prohibited by applicable law.
Termination and Data Deletion
This DPA terminates automatically upon termination or expiry of the Main Agreement. Upon termination, the Processor shall, at the Controller's choice:
- delete all Personal Data, except to the extent that EU or Member State law requires ongoing storage; or
- return all Personal Data to the Controller in a common, machine-readable format.
Deletion shall be completed within 30 days of the termination date. Residual copies held in encrypted backups shall be automatically overwritten in accordance with the backup rotation schedule (currently ~35 days). The Processor shall confirm deletion in writing upon the Controller's request.
Governing Law and Jurisdiction
This DPA shall be governed by the law governing the Main Agreement. Any disputes arising from this DPA shall be subject to the jurisdiction of the courts specified in the Main Agreement. Nothing in this DPA affects the rights of Data Subjects to bring claims under the GDPR.
Order of Precedence
In the event of any conflict between this DPA, the Standard Contractual Clauses (where applicable), and the Main Agreement, the following order of precedence applies:
- Standard Contractual Clauses
- This Data Processing Agreement
- The Main Agreement
The Parties
This DPA is entered into by the duly authorised representatives of the parties. It forms part of the Terms of Service, which Customer accepts electronically on creating an account; a countersigned execution copy is available on request.
Annex I — Details of Processing
A. List of Parties
Data Exporter (Controller): As identified in the Main Agreement and the Parties section above.
Data Importer (Processor): Sykik [FlexCo i.G.], [Registered Address], [FN Number].
Data Protection Officer: Hermann Wagner, sykik-privacy@sykik.ai
B. Description of Processing
C. Competent Supervisory Authority
Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, Austria. dsb.gv.at
Annex II — Authorised Sub-Processors
The Controller authorises the following Sub-Processors. The Processor will notify the Controller at least 14 days in advance of any addition or replacement in accordance with Section 6 of this DPA.
Annex III — Technical and Organisational Measures
The Processor maintains the following Technical and Organisational Measures (TOMs) pursuant to Article 32 GDPR, corresponding to those published in the Processor's Privacy Policy (Section 14). These TOMs are also published as a standalone document at sykik.ai/security for transparency during security reviews.
Annex IV — Standard Contractual Clauses (Cross-Reference)
Where transfers are subject to the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the parties agree that:
- Clause 7 (Docking Clause): The optional clause is included.
- Clause 9 (Use of sub-processors): Option 2 (General Written Authorisation) with 14 days' prior notice applies, as set out in Section 6 of this DPA.
- Clause 11 (Redress): The optional language is not included; Data Subjects shall be entitled to redress from the Data Importer or its representatives.
- Clause 17 (Governing Law): The law of Austria shall govern.
- Clause 18 (Choice of Forum and Jurisdiction): Any dispute arising from the SCCs shall be resolved by the competent courts of Vienna, Austria.
- Annexes I-III of this DPA serve as Annexes I, II, and III of the SCCs.
- The competent Supervisory Authority is the Österreichische Datenschutzbehörde.