Loading Optiviera...

DPA

Acuerdo de Procesamiento de Datos (DPA)

v1.0 · 7 de mayo de 2026

DPA conforme al RGPD Art. 28 para el procesamiento de datos personales.

This Data Processing Addendum ("DPA") governs the processing of personal data by Optiviera on behalf of customers in connection with the Optiviera platform and related services. This DPA is intended to satisfy the requirements of Article 28 GDPR.

Company Information

FieldDetails
Company / OwnerA. Kerim Akkis – AkkisTech
ProductOptiviera
Registered AddressFreisinger Str. 1, 28215 Bremen, Germany
Support Contact[email protected]
Legal Contact[email protected]

1. Scope and Applicability

This DPA applies to all personal data processed by Optiviera on behalf of Customers in connection with the Services, including account management, platform access, file storage, backup and restore operations, HR and payroll data, financial records, and related platform operations.

2. Processor Obligations

  • Process personal data only on documented instructions from the Controller
  • Ensure persons authorized to process personal data are bound by confidentiality
  • Implement appropriate technical and organizational security measures (Article 32 GDPR)
  • Respect conditions for engaging subprocessors (Article 28(2) GDPR)
  • Assist the Controller in responding to data subject rights requests
  • Assist the Controller in ensuring compliance with security and breach notification obligations
  • Delete or return all personal data upon termination of the DPA
  • Provide information necessary to demonstrate compliance and cooperate with audits

3. Data Subject Rights

Optiviera assists Customers in fulfilling data subject rights requests where technically feasible. Supported workflows may include access requests, deletion requests, export and portability, and correction requests. Customers remain responsible for responding to data subjects directly.

4. Security Measures

Technical Measures

  • Encryption at rest
  • Encryption in transit (TLS)
  • Access control and authentication
  • Audit logging

Organizational Measures

  • Staff confidentiality obligations
  • Role-based access control
  • Security training
  • Controlled deployment

Availability & Resilience

  • Regular backups
  • Disaster recovery procedures
  • Monitoring and alerting
  • Incident response procedures

5. Subprocessors

Optiviera may engage subprocessors to provide parts of the Services. Customers are provided general authorization for subprocessors. Optiviera will inform Customers of material changes to subprocessors where applicable. Current subprocessors are listed at /legal/subprocessors.

6. International Data Transfers

Where personal data is transferred outside the EEA, Optiviera seeks to implement appropriate safeguards including Standard Contractual Clauses (SCCs) pursuant to GDPR Chapter V, transfer impact assessments, encryption safeguards, and supplementary technical measures where appropriate.

7. Breach Notification

Optiviera will notify Customers without undue delay, and where feasible within 72 hours, upon becoming aware of a personal data breach affecting Customer Data. Notifications will include the nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed to address the breach.

8. Data Deletion and Return

Upon termination or expiry of the agreement, Optiviera will, at the Customer's election, delete or return all Customer Data and delete existing copies unless applicable law requires storage. Customers should export their data before account termination.

Contact

For DPA-related inquiries: [email protected]

For general support: [email protected]

Volver al Centro Legal