This English version is provided for convenience. In case of any discrepancy, the German version is legally binding.
Data Processing Agreement (DPA)
Pentalink Consulting GmbH as processor · Customer template · Last updated: June 2026
When this agreement applies
Pentalink concludes this DPA as processor with the customer (controller) whenever Pentalink processes personal data on behalf of the customer – e.g. operation/development of a customer portal, BI/analytics on customer data, automations involving personal data, hosting of customer-related content.
No DPA is required if Pentalink provides pure consulting without access to personal data of third parties or processes only its own/team data.
Two tiers: Customer → Pentalink (this DPA) and Pentalink → sub-processors (their DPAs, see Annex 3).
Data processing agreement pursuant to Art. 28 GDPR
the customer as defined in the Main Agreement – hereinafter the “Controller” –
and
Pentalink Consulting GmbH, Kastanienweg 6a, 18437 Stralsund, registered in the commercial register of the Amtsgericht Stralsund (Local Court of Stralsund) under HRB 22928, represented by its Managing Director Sascha Lübow-Westendorf – hereinafter the “Processor” –
– individually a “Party”, together the “Parties” –
§ 1 Subject matter, duration and specification
(1) The subject matter, nature and purpose of the processing, the type of personal data and the categories of data subjects are set out in Annex 1.
(2) The term of this agreement corresponds to the term of the Main Agreement, unless the following provisions give rise to obligations extending beyond it.
(3) The Processor processes personal data exclusively within the EU/EEA, unless otherwise provided in Annex 1 or § 7 (third country).
§ 2 Controller’s right to issue instructions
(1) The Processor processes personal data exclusively within the scope of the agreements made and on documented instructions from the Controller, unless it is required by law to carry out other processing (Art. 28 (3)(a) GDPR).
(2) Instructions are issued and documented in text form. Oral instructions are confirmed in text form without undue delay.
(3) The Processor shall inform the Controller without undue delay if it considers that an instruction infringes applicable data protection law. It is entitled to suspend the execution of the instruction concerned until it has been confirmed or amended by the Controller.
§ 3 Obligations of the Processor
(1) Confidentiality: The Processor shall engage for the processing only persons who have committed themselves to confidentiality and have been familiarised with the relevant data protection provisions (Art. 28 (3)(b), Art. 29, 32 (4) GDPR).
(2) Security of processing: The Processor complies with the technical and organisational measures pursuant to Art. 32 GDPR; these are described in Annex 2.
(3) Assistance: The Processor shall assist the Controller, to the extent reasonable, in safeguarding the rights of data subjects (Art. 12–23), in data protection impact assessments (Art. 35) and in prior consultation (Art. 36).
(4) Data protection officer / contact person: The Processor designates a contact person for data protection matters (contact: info@pentalink.de).
(5) Demonstration of compliance: The Processor makes available to the Controller the information necessary to demonstrate compliance (Art. 28 (3)(h)).
§ 4 Rights of data subjects
If a data subject contacts the Processor directly with requests for access, rectification, erasure or other claims, the Processor shall forward the request to the Controller without undue delay and shall not respond to it itself unless instructed otherwise.
§ 5 Notification of personal data breaches
The Processor shall notify the Controller of any personal data breach without undue delay, and in any event within 24 hours of becoming aware of it, and shall assist the Controller in fulfilling its obligations under Art. 33, 34 GDPR. The notification shall contain at least the information referred to in Art. 33 (3), insofar as available.
§ 6 Sub-processors
(1) The Controller grants a general authorisation for the engagement of sub-processors. The sub-processors engaged at the time of conclusion of the agreement are listed in Annex 3.
(2) The Processor shall inform the Controller in advance, in text form, of any intended changes (addition/replacement). The Controller may object within 14 days on important grounds relating to data protection law.
(3) The Processor shall impose on sub-processors the same data protection obligations as are set out in this agreement (Art. 28 (4)).
(4) Ancillary services such as telecommunications or maintenance services without a specific connection to the processing activities do not constitute sub-processing.
§ 7 Transfers to third countries
Processing in a third country takes place only if the requirements of Art. 44–49 GDPR are met (adequacy decision, EU standard contractual clauses, Data Privacy Framework where applicable). The sub-processors concerned and the transfer mechanisms are identified in Annex 3.
§ 8 Inspection and audit rights
The Controller is entitled to satisfy itself of compliance with the obligations – primarily by means of the submission of suitable evidence (e.g. certificates, audit reports, self-disclosure). On-site inspections take place after timely prior notice, during business hours and without disrupting operations.
§ 9 Erasure and return
After the end of the processing, the Processor shall, at the Controller’s choice, erase or return all personal data and delete existing copies, unless there is a statutory retention obligation (Art. 28 (3)(g)).
§ 10 Liability and final provisions
(1) Liability is governed by Art. 82 GDPR and otherwise by the provisions of the Main Agreement.
(2) In the event of conflicts between this DPA and the Main Agreement, the provisions of this DPA shall prevail in matters of data protection law.
(3) Amendments must be made in text form. Should any provision be invalid, the validity of the remaining provisions shall remain unaffected.
Annex 1 – Subject matter of the processing
| Subject matter | specified per assignment (e.g. operation of a customer portal, BI analysis, automation) |
|---|---|
| Nature of processing | collection, storage, analysis, transfer (on instruction) |
| Purpose | provision of the services agreed in the Main Agreement |
| Categories of data subjects | specified per assignment (e.g. customers, end users, employees of the Controller) |
| Categories of personal data | specified per assignment (e.g. master data, contact data, usage data) |
| Special categories (Art. 9) | as a rule none – otherwise specified in the individual contract |
| Place of processing | EU/EEA (third country where applicable pursuant to § 7) |
Annex 2 – Technical and organisational measures (Art. 32)
- Physical and system access control: Cloud infrastructure without physical access; access via Google login/SSO, MFA mandatory; firewall protection of the VPS.
- Data access control: Role-based permissions (least privilege), separate tenants/projects, password manager.
- Encryption: TLS 1.2+ in transit, encryption at rest for the services used.
- Pseudonymisation/minimisation: Data minimisation; where possible, pseudonymisation before transfer to AI/analytics sub-processors.
- Availability/recovery: Backups, recovery concept (BCM/IRP).
- Separation control: Tenant separation per customer.
- Review: Regular review of the effectiveness of the measures; sub-processors with C5/ISO 27001/SOC 2 preferred.
Annex 3 – Sub-processors & data tiers
Pursuant to § 6, the Controller grants a general authorisation for the engagement of sub-processors. These are classified into data tier levels according to their protection requirements; this determines which services may be used for each project — from exclusively specially vetted services to more broadly approved solutions for low-sensitivity use cases. Higher tiers are stricter: a solution approved for “High Security” is also permitted in the tiers below it — but not vice versa.
Current list available on request. The specific services used vary by project and tier and are subject to confidentiality. We will provide you with the always up-to-date overview relevant to your tier (provider, purpose, place of processing, DPA status) on request or as part of this annex to your DPA. Your tier is specified in your DPA — if in doubt, our team will be happy to help.
For highly regulated projects, projects close to critical infrastructure (KRITIS) and special categories of data. Only specially vetted services are used; processing preferably in the EU/EEA, third-country transfers only with robust safeguards (SCC/DPF) — or self-hosted on own infrastructure.
Request current sub-processor list →For regular B2B projects involving personal data. Processing in the EU/EEA or by services with a concluded DPA and appropriate safeguards (standard contractual clauses, Data Privacy Framework).
Request current sub-processor list →For low-sensitivity use cases without critical personal data. Third-country services with appropriate safeguards (SCC/DPF) are also permitted here.
Request current sub-processor list →Note: The service providers used to operate this website (hosting, forms) are listed separately in our privacy policy.
← Back to home page