DPA / AVV (Template)
Template data processing agreement under Art. 28 GDPR for ROARK GmbH B2B SaaS services.
This document is a template data processing agreement (DPA) pursuant to Art. 28 GDPR for our B2B SaaS services.
Data processing becomes legally binding only after execution of an individual contractual document between the customer (controller) and ROARK GmbH (processor). The individually agreed service description forms part of the DPA and specifies the product- and deployment-specific processing.
The DPA applies only to personal content and business data for which the customer determines the purposes and means. ROARK processes account, access, support, billing and security data for which it determines the purposes and means as a controller; that data is outside the scope of this DPA.
1. Subject matter and duration
- ROARK processes personal data solely on behalf of and under documented instructions from the customer.
- The individually agreed service description identifies the subject matter, nature, purpose and scope of processing and the specific product and deployment. A reference only to “SaaS services” or to a general provider list is not sufficient.
- The term of this DPA corresponds to the processing period stated in the service description and does not exceed the term of the main agreement unless otherwise agreed.
Before processing begins, the service description must specify at least the product and, where relevant, its version, the deployment model, the subject matter, nature and purpose of processing, its duration, the personal data categories and data subject categories actually involved and the specific processing regions for production data, logs, support and backups. It must also identify the subprocessors actually used, including their function, data type, country or region, third-country transfer mechanism and contractual chain, the production-data deletion period, backup interval and retention period, support-access rules and the notification and objection mechanism for subprocessor changes. Items that do not apply must be expressly marked “not applicable”. Language such as “depending on configuration” is sufficient only where the selected configuration is unambiguously recorded in the same service description.
2. Type of data and data subject categories
The personal data categories actually processed and the categories of data subjects are identified exhaustively in the individual service description. General examples or a list of every technically possible category do not replace this specification.
The customer is responsible for ensuring that content entered into the product is covered by its documented instructions, the main agreement and the individual service description.
3. Instructions
- ROARK processes personal data only on documented instructions.
- Verbal instructions must be confirmed in text form without undue delay.
- If ROARK considers an instruction unlawful under data protection law, ROARK will inform the customer without undue delay.
4. Confidentiality and access control
- ROARK ensures that persons involved in processing are bound to confidentiality.
- Access to personal data is limited by role-based and need-to-know principles.
5. Technical and organizational measures (TOMs)
ROARK implements appropriate technical and organizational measures under Art. 32 GDPR, including:
- Physical access, system access and authorization controls
- Tenant separation and role/permission concepts
- Encryption in transit (TLS) and, where applicable, at rest
- Logging of security-relevant events
- Availability safeguards (backups and recovery procedures)
- Regular review and improvement of security measures
6. Subprocessors
The subprocessors actually used for the specific product and deployment are identified in the individual service description with their function, processed data type, processing region and applicable third-country transfer mechanism. Providers that ROARK uses for other products or for its own controller processing do not automatically become subprocessors under this agreement.
ROARK has direct contractual relationships with Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP). These providers are therefore not classified exclusively as subprocessors of Vercel. They become subprocessors under this DPA only where they are actually used for the specific product and deployment and identified as such in the individual service description.
Where Convex is used for the specified product, the individual service description records the processing region as EU West; US East is not used for this processing.
ROARK informs the customer of intended changes to the subprocessors identified in the individual service description according to the notification and objection mechanism specified there. A change to a general website-provider list does not replace this notice.
7. Third-country transfers
- Processing in third countries takes place only where the requirements of Art. 44 et seq. GDPR are met.
- Appropriate safeguards may include Standard Contractual Clauses (SCC) and other lawful transfer mechanisms.
- For Switzerland, the EU adequacy decision applies.
8. Assistance obligations
ROARK supports the customer, to a reasonable extent, with
- data subject rights requests,
- data protection impact assessments,
- supervisory authority consultations,
- compliance with personal data breach notification obligations.
9. Personal data breach notification
- ROARK notifies the customer without undue delay after becoming aware of a personal data breach within the processing relationship.
- The notification includes all information available and required to assess the incident and fulfill legal obligations.
10. Audit and evidence
- Upon request, ROARK provides the customer with information required to demonstrate compliance with Art. 28 GDPR obligations.
- Audits take place with reasonable prior notice, respecting confidentiality, security requirements and uninterrupted operations.
11. Return and deletion after termination
- After termination of processing services, ROARK deletes or returns personal data according to customer instruction, unless statutory retention obligations apply.
- Production data and backups are deleted or overwritten within the periods specified in the individual service description. No general product-independent backup period applies.
12. Liability and order of precedence
- Liability follows the main agreement, to the extent permitted by law.
- In case of conflict, data protection provisions of the DPA prevail over the main agreement.
13. Contact
For DPA-related data protection requests:
ROARK GmbH
Email: datenschutz@roark.at
Phone: +43 660 375 8455