The Protocol
  • Home
  • Technical Architecture
  • Attestation Network
  • Governance
  • Join Beta

Data Processing Agreement

According to Article 28 GDPR

📅 Version: 1.0
📋 Date: January 2025
🔒 GDPR Article 28 Compliant

Controller

[Customer Name]

[Address]

[Registration]

(hereinafter "Customer")

Processor

Raphael Jeziorny

The Protocol

Richard-Strauss-Straße 6

83395 Freilassing, Germany

(hereinafter "Provider")

Table of Contents

  • 1. Subject Matter and Duration
  • 2. Nature and Purpose of Processing
  • 3. Type of Personal Data
  • 4. Processor Obligations
  • 5. Technical and Organizational Measures
  • 6. Controller Rights
  • 7. Notification Duties
  • 8. Deletion and Return
  • 9. Liability
  • 10. Miscellaneous
  • Annex 1: Security Measures
  • Annex 2: Sub-processors
§ 1

Subject Matter and Duration

1.1 Subject Matter

Provider processes personal data on behalf of Customer within the provision of "The Protocol" platform services according to the Main Agreement.

1.2 Duration

The duration corresponds to the term of the Main Agreement.

§ 2

Nature and Purpose of Processing

2.1 Nature of Processing

  • Storage of agent metadata
  • Processing of transaction data
  • Identity management (SPIFFE/SPIRE)
  • Log analysis and monitoring
  • Backup and disaster recovery

2.2 Purpose

Provision of infrastructure for autonomous AI agents according to agreed services.

§ 3

Type of Personal Data

3.1 Data Categories

  • Identification data (names, email addresses)
  • Contact data
  • Technical identifiers (IP addresses, DIDs)
  • Transaction data
  • Log data
  • Contract data

3.2 Data Subjects

  • Customer employees
  • Customer's customers
  • Agent operators
  • Other authorized users
§ 4

Processor Obligations

4.1 Instructions

Processor shall process data only on documented instructions from Customer.

4.2 Confidentiality

Processor ensures all personnel are bound by confidentiality per Art. 28(3)(b) GDPR.

4.3 Security of Processing

Processor implements technical and organizational measures per Art. 32 GDPR (see Annex 1).

4.4 Sub-processors

  • Approval required for new sub-processors
  • Current list in Annex 2
  • Same data protection obligations

4.5 Assistance Obligations

Assistance with:

  • Data subject rights (Art. 12-22 GDPR)
  • Data protection impact assessments
  • Data breach notifications
  • Supervisory authority communication
§ 5

Technical and Organizational Measures

5.1 Physical Access Control

  • Secured data centers
  • Access only for authorized personnel
  • Visitor registration

5.2 System Access Control

  • Multi-factor authentication
  • Strong password policies
  • Regular access reviews

5.3 Data Access Control

  • Role-based access control (RBAC)
  • Principle of least privilege
  • Access logging

5.4 Transmission Control

  • Encrypted data transmission (TLS 1.3+)
  • VPN for administrative access
  • Secure API authentication

5.5 Input Control

  • Complete audit logging
  • Immutable log storage
  • Traceability of all changes

5.6 Job Control

  • Clear contractual agreements
  • Documented processing procedures
  • Regular compliance checks

5.7 Availability Control

  • Redundant systems
  • Daily backups
  • Disaster recovery plan
  • DDoS protection

5.8 Separation Control

  • Multi-tenant architecture
  • Logical data separation
  • Separate encryption keys
§ 6

Controller Rights

6.1 Audit Rights

  • Inspection of relevant documents
  • Access to business premises (with notice)
  • Conduct audits
  • Obtain information

6.2 Instruction Rights

  • Issue additional instructions
  • Change processing procedures
  • Deletion instructions
§ 7

Notification Duties

7.1 Data Breaches

  • Immediate notification (max 24 hours)
  • Detailed documentation
  • Support with authority notification

7.2 Changes

  • Technical/organizational changes
  • Key personnel changes
  • Location changes
§ 8

Deletion and Return

After contract termination:

  • Complete deletion of all data
  • Or return at Customer's choice
  • Deletion certificate
  • Exception: Legal retention requirements
§ 9

Liability

  • Liability per Main Agreement
  • Processor liable for sub-processors
  • Damages for breaches
§ 10

Miscellaneous

10.1 Amendments: Written form required

10.2 Severability: Partial invalidity doesn't affect entire agreement

10.3 Governing Law: German law

Annex 1

Technical and Organizational Measures

Encryption

  • AES-256 for data at rest
  • TLS 1.3 for transmission
  • Key management with HSM

Monitoring

  • 24/7 Security Operations Center
  • Intrusion Detection System (IDS)
  • Security Information and Event Management (SIEM)

Incident Response

  • Documented incident response plan
  • 24/7 on-call service
  • Regular drills

Certifications (Planned)

  • ISO 27001
  • SOC 2 Type II
Annex 2

Sub-processors

Name Service Location Purpose
Hetzner Online GmbH Infrastructure Germany Server hosting
Hetzner Online GmbH Backup Services Germany Data backup
Cloudflare, Inc. Content Delivery Global Static content

Need This Agreement?

Download the Data Processing Agreement for your records or to complete with your organization's details.

📄 Download PDF (English) 📄 Download PDF (Deutsch)
Terms of Service Privacy Policy Data Processing Agreement Cookie Policy Risk Notice Enterprise SLA

© 2025 The Protocol | Architected by Raphael Jeziorny

Impressum | Datenschutzerklärung