Data Processing Agreement
Order Processing Agreement
Order Processing Agreement (OPA) in accordance with Art. 28 GDPR
between
Client (Controller) = Client
and
Contractor (Processor) STRYNEX Pte. Ltd. = DIVID-Mengenmeldung
1. Subject and Duration
DIVID-Mengenmeldung processes personal data on behalf of the client for the purpose of conducting the audit in accordance with Section 11 EWKFondsG.
Processing ends with the termination of the business relationship.
2. Nature and Purpose of Processing
- Receipt and preparation of client documents,
- Forwarding to accredited auditors,
- Creation and provision of audit-relevant documents.
3. Type of Data / Data Subjects
- Data types: Contact details (name, email, phone), company data, documents with personal information (e.g., invoices, delivery notes).
- Data subjects: Client contact persons, potentially third parties named in documents.
4. Obligations of DIVID Volume Reporting
DIVID Volume Reporting undertakes to:
- Process data exclusively according to documented instructions from the client,
- Obligate employees to confidentiality,
- Implement appropriate technical and organizational measures (TOMs),
- Report data protection violations without delay,
- Support the client with data subject rights.
5. Sub-processors
DIVID-Mengenmeldung is entitled to engage sub-processors (e.g., accredited auditors, hosting service providers).
These are contractually obligated to comply with the GDPR.
Individual disclosure of sub-processors is not provided.
6. Retention and Deletion
DIVID-Mengenmeldung retains data for as long as necessary for audit purposes, proof obligations, or due to legal requirements.
Deletion only occurs upon explicit instruction from the client, provided there are no conflicting legal obligations or legitimate interests.
7. Obligations of the Client
The client is responsible for the lawfulness of data transmission and ensures that they only provide lawfully collected data to DIVID Volume Reporting.
8. Technical and Organizational Measures (TOMs)
DIVID-Mengenmeldung ensures, among other things:
- Encrypted transmission and storage of data,
- Access control through authorization systems,
- Logging of access,
- Regular security updates and backups.
9. Final Provisions
The OPA is considered concluded in electronic form and does not require a separate signature.
The law of Singapore applies. Compliance with the obligations under Art. 28 GDPR remains unaffected by this.