Passvanta
← All legal texts
Legal NoticePrivacy NoticeCookie PolicyB2B TermsData Processing AgreementSupplier Portal TermsAI and DPP Compliance NoticesNo Withdrawal Right for B2B Customers

Data Processing Agreement

Version 5 September 2026

Article 28 GDPR data processing agreement including technical and organisational measures and approved subprocessors.

This DPA applies between the Customer identified in Passvanta checkout or an Enterprise Order Form, as controller or processor, and Ömer Salmaz, Passvanta, Philippsburger Straße 83a, 68753 Waghäusel, Germany, as processor. It becomes part of the Main Agreement when accepted in checkout or incorporated into an Enterprise Order Form.

1 Subject and duration

Passvanta processes personal data to provide the SaaS platform, administer accounts and permissions, store and structure Customer Content, operate supplier requests, process documents through AI, provide support and security, and export and delete data. Processing lasts for the Main Agreement plus agreed export, deletion and backup periods.

2 Instructions

Passvanta processes data only on documented Customer instructions unless Union or Member State law requires otherwise. The Main Agreement, configuration and documented support instructions are the initial instructions. Passvanta informs the Customer without undue delay if an instruction appears unlawful and may suspend it pending clarification.

3 Confidentiality

Passvanta ensures that authorised persons are bound by confidentiality or an appropriate statutory duty and receive access only as necessary.

4 Security

Passvanta maintains appropriate Article 32 GDPR technical and organisational measures. Annex 2 contains minimum obligations. Passvanta may update them without materially reducing protection.

5 Individual rights

Passvanta forwards requests received directly without undue delay and assists through available technical functions and reasonable organisational support. It does not answer on the Customer's behalf unless law requires it.

6 Personal data breaches

Passvanta informs the Customer without undue delay and, where possible, within 24 hours after becoming aware of a breach affecting entrusted data. The notice includes available information on nature and scope, categories, likely effects, mitigation and contact. Missing information follows without undue delay.

7 Assistance

Taking account of the processing and information available, Passvanta assists with security, notifications, data protection impact assessments and consultations under Articles 32 to 36 GDPR. Extraordinary assistance not caused by Passvanta may be charged after prior agreement where lawful.

8 Subprocessors

The Customer gives general authorisation for Annex 3 subprocessors. Passvanta gives notice as early as possible and generally at least 14 days before an intended addition or replacement, through direct text-form notice or a subscribed register. If an existing platform provider announces a mandatory change on shorter notice, Passvanta informs the Customer without undue delay after receipt and before use where Passvanta controls the start date. The Customer may object for documented privacy reasons. If no reasonable solution exists, it may terminate the affected service before the new provider starts. Passvanta imposes Article 28(4) obligations and remains responsible for subprocessor performance.

9 International transfers

Transfers outside the EEA occur only on documented instruction and under Chapter V GDPR, including an adequacy decision or SCCs. Passvanta documents required transfer assessments and supplementary measures. The mechanism actually used for the relevant account controls where a provider lists alternatives.

10 Evidence and audits

Passvanta provides information necessary to demonstrate compliance. The Customer first uses current certifications, reports and documentation. If objectively insufficient, it may conduct one annual audit and an additional incident-based audit through a confidential independent auditor. Audits require notice, remain relevant and must not compromise security or other customers.

11 Return and deletion

At service end, Passvanta returns or deletes data on instruction unless law requires retention. Exportable data remains retrievable for at least 30 calendar days after transition. Backups remain restricted until scheduled overwrite. Legally retained data is blocked and deleted when the duty ends.

12 Customer duties

The Customer is responsible for lawfulness, transparency, minimisation, accuracy, retention and instructions. It must not use special-category, criminal-conviction or high-risk employee data unless expressly agreed, assessed and technically approved.

13 Priority and liability

This DPA prevails for processing conflicts. Mandatory GDPR liability remains unaffected; the Main Agreement's effective liability rules otherwise govern between the parties.

Annex 1 Processing description

Item Description

Customer Users and administrators; employees and business contacts of customers, suppliers and Individuals service providers; recipients of supplier requests; people whose business details appear in evidence

Identity and contact data; account, role and authentication data; organisation assignment; personal Data elements in product and supplier data; document content and metadata; communications, audit, support and security data; AI inputs and outputs

Special data Not intended. Processing requires a separate written agreement and risk assessment

Purposes Provision, storage, structuring, validation, AI extraction, supplier communications, audit, publication on

Item Description

instruction, support, security, export and deletion

Collection, recording, organisation, storage, alteration, retrieval, consultation, transmission, alignment, Operations restriction, erasure and destruction

Duration Main Agreement term plus export, deletion, backup and legal retention periods

Annex 2 Technical and organisational measures

• Current TLS for external connections and encryption at rest where supported by platform services; secrets and keys are separated from application data. • Tenant separation at organisation and data level, server-side authorisation for every protected access, and explicit Supplier sharing only. • Least-privilege roles, with separate permissions for publication, registry submission, API keys, owner transfer and billing. • Individual accounts, secure password hashes, time-limited sessions, CSRF protection, rate limits and random revocable Supplier tokens; multi-factor authentication for privileged internal access. • Logging of security and compliance actions, tamper protection and limited documented retention. • Dependency updates, vulnerability handling, separate development and production, review of critical changes and controlled secret rotation. • Backup and restoration procedures with tested recoverability, restricted backups and a deletion cycle. • Incident process for detection, containment, evidence preservation, risk assessment, notice and remediation. • Data minimisation, deletion and export functions, retention rules and processes for individual rights and Customer instructions. • DPA and SCC diligence, region selection, vendor change monitoring and transfer impact assessments where required. • Business or API contracts with AI providers, disabled voluntary training on Customer Content, content minimisation and human review for critical results. Release condition: These measures may be described as implemented only after every control has been technically tested, assigned to an owner and documented internally.

Annex 3 Approved subprocessors

Subprocessor Service Location Transfer basis

Vercel, Inc. Web and app hosting USA; account region DPA, SCCs or adequacy decision

DNS, CDN, WAF and Cloudflare, Inc. USA and global network DPA, SCCs or EU-US DPF security

Databricks, Inc. with Neon Database USA; project data region DPA and SCCs; select EU region Platform

Plus Five Five, Inc. Resend Email USA DPA, SCCs and stated EU-US DPF

OpenAI Ireland Limited and Ireland and possible third AI processing DPA; SCCs or adequacy decision affiliated subprocessors countries

France; other locations by Mistral AI SAS AI processing DPA; mechanism by configuration product

Google Cloud EMEA Limited and Ireland and possible third Gemini API Cloud DPA; SCCs or adequacy decision affiliates countries

Domain and email-address IONOS SE Germany; by service DPA where acting as processor administration

Stripe Payments Europe, Limited may act as independent controller for payment functions and is not treated as a subprocessor for all Customer Content. Google Analytics, Google Ads and Meta Platforms Ireland Limited serve Passvanta's own consent-based marketing and are outside Customer processing under this DPA.

Passvanta

Digital Product Passport & EU Product Compliance Platform

Product

CategoriesHow it worksPassportData carriersAPI

Get started

Open dashboardSign in

Legal

Legal NoticePrivacy NoticeCookie PolicyLegal

Passvanta is a product compliance platform. It is not an EU authority, notified body, certification body or the official EU DPP Registry, and software output alone does not guarantee legal conformity.

© 2026 Passvanta. All rights reserved.Digital Product Passport & EU Product Compliance Platform

Cookie Settings

Necessary always active

These storage and access operations are required for sign-in, security, language choice, consent evidence and payment. They cannot be disabled through the banner.

Google Analytics helps us understand website use. It may process online identifiers, device information and usage data. It loads only after consent.

Google Ads and Meta Pixel help measure conversions and build remarketing audiences. They can associate data with Google or Meta accounts and transfer data to third countries. They load only after consent.

Legal NoticePrivacy NoticeCookie Policy