The German version is the canonical legal version. This English version is provided for convenience. Where legally permissible and the versions differ, the German version prevails.
This DPA is between the customer and:
Andrii Rzhavin, trading as Fairtech Group
Bartholomäus-Arnoldi-Straße 6
61250 Usingen
Germany
Email: info@fairtech.group
It supplements the ENRIVAQ main agreement and applies where Fairtech Group acts as processor under Article 28 GDPR.
1. Subject and duration
Processing covers personal data contained in Customer Data to the extent processed on behalf of the customer.
Duration: main agreement plus export/deletion periods.
2. Nature and purpose
Processing may include receipt, storage, structuring, extraction, normalization, classification, validation, technical analysis, AI-assisted processing, derived-content creation, output, backup/logging, deletion and anonymization.
Purpose: provision, administration and security of ENRIVAQ.
3. Data categories
ENRIVAQ primarily processes product/catalog data.
Incidental personal data may include business contact/user information and technical security metadata.
Special-category data is not intended.
4. Data subjects
Customer users/employees and business contacts at suppliers/partners where lawfully included.
5. Instructions
Fairtech Group processes personal data only on documented instructions unless required by law.
The main agreement, DPA, customer configuration and authorized support instructions constitute documented instructions.
6. Customer obligations
The customer is responsible for lawfulness, purposes, legal basis, notices, data-subject rights, instructions and minimization.
7. Confidentiality
Authorized personnel are bound by confidentiality and access is restricted.
8. Security
Fairtech Group maintains Article 32 measures described in Annex 2.
9. Subprocessors
The customer grants general written authorization.
Fairtech Group generally provides 30 days’ prior notice of new/replacement Customer Data subprocessors except urgent security/continuity changes.
The customer may object on substantiated privacy grounds.
10. Data-subject requests
Fairtech Group assists where technically possible and generally forwards direct Customer Data requests to the customer.
11. Breaches
Fairtech Group notifies the customer without undue delay after becoming aware of a Customer Data breach and provides available information regarding nature, affected categories, likely consequences and mitigation.
12. DPIA
Reasonable assistance is provided for Articles 35/36 GDPR where required.
13. Audits
Fairtech Group provides reasonable compliance information.
Audits should ordinarily begin with documentation/remote evidence; proportionate on-site audits may be used where necessary.
14. Return and deletion
Available export may be requested within 30 days after termination.
Working copies are generally deleted/anonymized within up to another 30 days.
Backups expire within 90 days unless lawful retention applies.
15. Germany
Customer Data, files, databases, backups and primary application data are stored in Germany under the current operating model.
16. International transfers
Restricted transfers are made only under Articles 44 et seq. GDPR using adequacy decisions, EU-US DPF, SCCs and supplementary measures where needed.
17. External LLMs
ENRIVAQ uses its own AI/model infrastructure.
Customer Data is not sent to OpenAI, Anthropic or Google for ENRIVAQ AI processing.
Annex 1 — Processing details
Subject: ENRIVAQ and Customer Data.
Duration: contract plus export/deletion periods.
Purposes: enrichment, validation, structured product processing, content generation, storage/output and technical administration.
Special categories: not intended.
Annex 2 — TOMs
- role-based access;
- least privilege;
- MFA for privileged roles;
- tenant isolation;
- session management;
- password hashing;
- TLS;
- HSTS;
- encryption at rest;
- secret protection/masking;
- administrative/security logs;
- encrypted backups;
- 24 hourly / 14 daily / 8 weekly / 3 monthly rotation;
- integrity checks;
- quarterly restore tests;
- monitoring;
- patch/dependency management;
- documented incident response;
- data minimization;
- no general-model training using Customer Data without explicit agreement.
Annex 3 — Current Customer Data subprocessors
Hetzner Online GmbH, Germany
Hosting/infrastructure. Primary ENRIVAQ data region: Germany.
Cloudflare, Inc., USA
Network/DNS/CDN/security/DDoS. Connection/security metadata and potentially transient request data depending on routing. Applicable DPA/transfer safeguards.
Stripe and Google Analytics are described in the Privacy Policy and are not automatically Customer Data subprocessors for the core ENRIVAQ processing.