QuovalisSign in

Data Processing Agreement (Art. 28 GDPR)

Template, version 2026-08-14-dpa-0.9 (last revised 14 August 2026), for business customers whose use of the service involves personal data in submitted certificates. The agreement is executed electronically at signup: the signup form incorporates it into the contract by reference (Art. 28(9) GDPR — electronic form, no signature needed), and the accepted version is recorded against your account. If your organisation requires a countersigned copy instead, download the current template, complete both parties and return a signed copy to contact@quovalis.eu.

Download the DPA template (Markdown)

Key parameters of the template

  • Scope: only the processing we perform on your behalf — validation of submitted X.509 certificates against EU trusted lists and storage of the resulting records. Account, billing and audit data we process for our own purposes as controller is described in the Privacy Policy and is not covered by the DPA.
  • Categories of data: certificate contents (subject/issuer names, serials, PSD2 attributes) and the derived validation records.
  • Instructions: the agreement, the service contract and your use of the API and console constitute the documented instructions; additional instructions in text form.
  • Duration: the account lifetime plus the retention windows of the customer’s plan.
  • Deletion or return: records are exportable via the API/console at any time before closure, and are returned on documented request within the 7-day grace window after closure; otherwise automated deletion applies (7-day grace window, backups rotate out within at most 31 days).
  • Responsibilities: data-subject requests received by us are forwarded to you, not answered by us; you warrant a legal basis for the certificate data you submit and do not submit private keys, credentials, secrets or unrelated personal data.
  • Sub-processors: hosting (Hetzner Online GmbH (Germany)); changes announced at least 30 days in advance with a right to object and, if unresolved, to terminate the affected service. Providers used only for our own controller-side processing (such as transactional email) are listed in the Privacy Policy and are not sub-processors under the DPA.
  • Breach notice: without undue delay, with the Art. 33(3) minimum content and assistance toward your own 72-hour deadline.
  • Audits: primarily via documentation and written answers; on-site with reasonable notice, at cost, once per year absent cause — statutory audit rights unaffected.
  • Technical and organisational measures: TLS-only transport, hashed credentials/keys, per-tenant isolation covered by automated tests, append-only audit log, documented retention/erasure automation, encrypted backups with monitored rotation and periodically tested restoration, CI-gated change management, EU/EEA processing.

Archived versions

Every version any customer could accept stays available here, unchanged — including the one in force — so the text you agreed to can always be retrieved. Each archived page carries the Markdown template as it stood at that version, which is the agreement itself; the page only summarises it.

  • 2026-08-14-dpa-0.9 (in force)
ContactImprintTermsPrivacyCookiesDPA