Data Processing Agreement (Art. 28 GDPR)
Draft template, version 0.4 (last revised 4 August 2026), for business customers whose use of the service involves personal data in submitted certificates. Download the current draft, complete both parties and return a signed copy to contact@quovalis.eu.
Download the DPA draft (Markdown)
Key parameters of the draft
- Scope: only the processing we perform on your behalf — validation of submitted X.509 certificates against EU trusted lists and storage of the resulting records. Account, billing and audit data we process for our own purposes as controller is described in the Privacy Policy and is not covered by the DPA.
- Categories of data: certificate contents (subject/issuer names, serials, PSD2 attributes) and the derived validation records.
- Instructions: the agreement, the service contract and your use of the API and console constitute the documented instructions; additional instructions in text form.
- Duration:the account lifetime plus the retention windows of the customer’s plan.
- Deletion or return: records are exportable via the API/console at any time before closure, and are returned on documented request within the 7-day grace window after closure; otherwise automated deletion applies (7-day grace window, backups rotate out within at most 31 days).
- Responsibilities: data-subject requests received by us are forwarded to you, not answered by us; you warrant a legal basis for the certificate data you submit and do not submit private keys, credentials, secrets or unrelated personal data.
- Sub-processors: hosting (Hetzner Online GmbH (Germany)); changes announced at least 30 days in advance with a right to object and, if unresolved, to terminate the affected service. Providers used only for our own controller-side processing (such as transactional email) are listed in the Privacy Policy and are not sub-processors under the DPA.
- Breach notice: without undue delay, with the Art. 33(3) minimum content and assistance toward your own 72-hour deadline.
- Audits: primarily via documentation and written answers; on-site with reasonable notice, at cost, once per year absent cause — statutory audit rights unaffected.
- Technical and organisational measures: TLS-only transport, hashed credentials/keys, per-tenant isolation covered by automated tests, append-only audit log, documented retention/erasure automation, encrypted backups with monitored rotation, CI-gated change management, EU/EEA processing.