Legal · Article 28 GDPR

Data Processing Agreement

The processing terms that apply when Fairtech Group handles personal data contained in Customer Data on a customer’s behalf.

Publication version18 September 2026 Canonical languageGerman OperatorFairtech Group
ENRIVAQDPApublic trust layer
01Instructions
02Security
03Subprocessors
04Deletion
Language note

The German version is the canonical legal version. This English version is provided for convenience. Where legally permissible and the versions differ, the German version prevails.

This DPA is between the customer and:

Andrii Rzhavin, trading as Fairtech Group
Bartholomäus-Arnoldi-Straße 6
61250 Usingen
Germany
Email: info@fairtech.group

It supplements the ENRIVAQ main agreement and applies where Fairtech Group acts as processor under Article 28 GDPR.

01

1. Subject and duration

Processing covers personal data contained in Customer Data to the extent processed on behalf of the customer.

Duration: main agreement plus export/deletion periods.

02

2. Nature and purpose

Processing may include receipt, storage, structuring, extraction, normalization, classification, validation, technical analysis, AI-assisted processing, derived-content creation, output, backup/logging, deletion and anonymization.

Purpose: provision, administration and security of ENRIVAQ.

03

3. Data categories

ENRIVAQ primarily processes product/catalog data.

Incidental personal data may include business contact/user information and technical security metadata.

Special-category data is not intended.

04

4. Data subjects

Customer users/employees and business contacts at suppliers/partners where lawfully included.

05

5. Instructions

Fairtech Group processes personal data only on documented instructions unless required by law.

The main agreement, DPA, customer configuration and authorized support instructions constitute documented instructions.

06

6. Customer obligations

The customer is responsible for lawfulness, purposes, legal basis, notices, data-subject rights, instructions and minimization.

07

7. Confidentiality

Authorized personnel are bound by confidentiality and access is restricted.

08

8. Security

Fairtech Group maintains Article 32 measures described in Annex 2.

09

9. Subprocessors

The customer grants general written authorization.

Fairtech Group generally provides 30 days’ prior notice of new/replacement Customer Data subprocessors except urgent security/continuity changes.

The customer may object on substantiated privacy grounds.

10

10. Data-subject requests

Fairtech Group assists where technically possible and generally forwards direct Customer Data requests to the customer.

11

11. Breaches

Fairtech Group notifies the customer without undue delay after becoming aware of a Customer Data breach and provides available information regarding nature, affected categories, likely consequences and mitigation.

12

12. DPIA

Reasonable assistance is provided for Articles 35/36 GDPR where required.

13

13. Audits

Fairtech Group provides reasonable compliance information.

Audits should ordinarily begin with documentation/remote evidence; proportionate on-site audits may be used where necessary.

14

14. Return and deletion

Available export may be requested within 30 days after termination.

Working copies are generally deleted/anonymized within up to another 30 days.

Backups expire within 90 days unless lawful retention applies.

15

15. Germany

Customer Data, files, databases, backups and primary application data are stored in Germany under the current operating model.

16

16. International transfers

Restricted transfers are made only under Articles 44 et seq. GDPR using adequacy decisions, EU-US DPF, SCCs and supplementary measures where needed.

17

17. External LLMs

ENRIVAQ uses its own AI/model infrastructure.

Customer Data is not sent to OpenAI, Anthropic or Google for ENRIVAQ AI processing.

Annex 1 — Processing details

Subject: ENRIVAQ and Customer Data.
Duration: contract plus export/deletion periods.
Purposes: enrichment, validation, structured product processing, content generation, storage/output and technical administration.
Special categories: not intended.

Annex 2 — TOMs

  • role-based access;
  • least privilege;
  • MFA for privileged roles;
  • tenant isolation;
  • session management;
  • password hashing;
  • TLS;
  • HSTS;
  • encryption at rest;
  • secret protection/masking;
  • administrative/security logs;
  • encrypted backups;
  • 24 hourly / 14 daily / 8 weekly / 3 monthly rotation;
  • integrity checks;
  • quarterly restore tests;
  • monitoring;
  • patch/dependency management;
  • documented incident response;
  • data minimization;
  • no general-model training using Customer Data without explicit agreement.

Annex 3 — Current Customer Data subprocessors

Hetzner Online GmbH, Germany
Hosting/infrastructure. Primary ENRIVAQ data region: Germany.

Cloudflare, Inc., USA
Network/DNS/CDN/security/DDoS. Connection/security metadata and potentially transient request data depending on routing. Applicable DPA/transfer safeguards.

Stripe and Google Analytics are described in the Privacy Policy and are not automatically Customer Data subprocessors for the core ENRIVAQ processing.

Talk to ENRIVAQ

Request a catalog assessment

Tell us enough to make the next step useful for your catalog.