Data Processing Agreement
Version 2026-08-03
This English version is a non-binding convenience translation provided for information purposes only. Solely the German version of this page is legally binding; in the event of any discrepancy, the German version prevails.
1. Parties and subject matter
This agreement applies between the Quickard customer as controller ("customer") and EBS Euchner Büro- und Schulsysteme GmbH as processor ("processor"). It supplements the main Quickard agreement and applies to any processing of personal data on the customer's behalf.
2. Duration, nature and purpose
Processing generally lasts for the term of the main agreement plus any technically or legally required wind-down periods. It covers storing, organizing, retrieving, transmitting, providing, restricting and deleting data to operate digital business cards, contact pages, forms, newsletter features, support and agreed add-on functions.
3. Data and data subjects
Depending on use, contact, professional, profile, content, communication, usage, device, log and support data are processed. Data subjects may include employees, cardholders, prospects, customers, form submitters, newsletter recipients and other persons designated by the customer. Special categories of data may only be processed on the basis of prior documented instructions and suitable safeguards.
4. Instructions and obligations
The processor processes data only on documented instructions, unless a legal obligation requires otherwise. Use and configuration of the service, support requests and written instructions constitute the instruction. Unlawful instructions are flagged. Persons authorized to process data are bound to confidentiality.
5. Support and incidents
The processor reasonably supports the customer with data subject rights, data protection impact assessments, prior consultation and accountability obligations. Breaches of protection of processed personal data are reported without undue delay with the available mandatory information; supplementary information may follow in phases.
6. Technical and organizational measures
- Physical and logical access protection of the operating environment plus role-based, organization-scoped access controls in the application
- Multi-factor authentication for privileged access, secure sessions and regular permission review
- Transport encryption, protected secrets and separated tenant data with Row Level Security
- Logging of security-relevant events, monitoring, error analysis and a defined incident response
- Data backup, recovery procedures and regular availability testing
- Data minimization, defined deletion processes and control of exports and support access
- Confidentiality obligations, data protection and security training for authorized personnel
- Supplier vetting and contractual binding of subprocessors used
The measures are developed further on a risk basis. Material changes may not fall below the agreed level of protection.
7. Subprocessors
The customer grants general authorization for the subprocessors listed below. Intended changes are announced with reasonable notice; objections are possible for an important data protection reason.
- EBS operations and hosting infrastructure: Application operations, database, authentication and file storage. Processing location: Infrastructure administered by the controller; specific location per the current product information.
- Plus Five Five, Inc. (Resend): Delivery of transactional emails. Processing location: USA; third-country transfer only with a safeguard under Art. 44 et seq. GDPR.
- OpenAI Ireland Ltd.: Optional AI assistant Quin, only when used and within the documented scope of instructions. Processing location: EEA; further processing/transfers according to contract and product configuration.
External services that the customer activates or links itself and that act as their own controller are not subprocessors of the processor for this purpose.
8. Transfers to third countries
Processing outside the EEA only takes place where the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision or suitable safeguards including standard contractual clauses and any required supplementary measures.
9. Evidence and audits
The processor provides the information required to demonstrate compliance with its obligations and enables proportionate audits. To protect all customers, suitable certificates, reports and questionnaires are used first; on-site audits take place after reasonable advance notice, under confidentiality and without impairing other clients.
10. Return and deletion
After the service ends, processed data is returned or deleted at the customer's choice, unless a statutory retention obligation applies. Existing backup copies are locked until regular overwriting and are not used productively.
11. Precedence and form
In case of conflict, the data protection provisions of this DPA take precedence for the processing of personal data. Changes and supplementary instructions should be documented in text form. Statutory rights and obligations remain unaffected.
Acceptance
Sign in and reopen this page to log the acceptance with your organization and a timestamp.