Refocusly - Logo Icon

Data Processing Agreement (DPA) – Refocusly
between
1. NO PARADE (Refocusly), Marvin Eckert – Ankerberg 5, 76344 Eggenstein-Leopoldshafen – Processor
2. [Customer Name], [Street, Number, Postal Code, City] – Controller

1. Definitions
1.1 GDPR: Regulation (EU) 2016/679
1.2 Personal Data, Processing, Controller, Processor, Data Subject as defined in the GDPR
1.3 Customer Data: all personal data provided by the Controller

2. Subject Matter and Duration
2.1 Subject Matter: Processing of Customer Data within the Refocusly platform (Marketing Automation, CRM, Email Marketing, Onboarding)
2.2 Duration: Commences upon signing, terminates with the end of platform usage or at the Controller’s request

3. Obligations and Rights of the Controller
3.1 Right to issue instructions according to Art. 28 Para. 3 lit. a GDPR
3.2 Ensuring lawfulness (consents, legal bases)
3.3 Provision of privacy information to Data Subjects, DPIA if required

4. Obligations of the Processor
4.1 Processing only on documented instructions
4.2 Implementation and maintenance of TOMs as specified in Appendix B
4.3 Support with Data Subject rights (access, rectification, deletion)
4.4 Deletion or return of data as instructed
4.5 Provision of evidence and audit reports upon request

5. Reference to Appendix A (Details of Data Processing)
6. Reference to Appendix B (Technical and Organizational Measures)
7. Reference to Appendix C (Sub-processors)
8. Reference to Appendix D (International Data Transfers)

9. Notification Obligation for Data Breaches
9.1 Without undue delay, at the latest within 24 hours
9.2 Content: Type, scope, affected data categories, countermeasures

10. Support with Data Subject Requests
10.1 Forwarding to the Controller
10.2 Implementation as instructed

11. Audit and Inspection Rights
11.1 Annual audits on-site or remote
11.2 Provision of audit reports and certificates

12. Return and Deletion
12.1 Deletion of all Customer Data within 30 days or return
12.2 Exceptions: legal retention obligations

13. Liability
13.1 Statutory liability
13.2 No liability for indirect damages except in cases of intent or gross negligence
13.3 Liability limited to three times the annual revenue of the affected contract year

14. Final Provisions and Versioning
14.1 Written form requirement for amendments
14.2 Severability clause
14.3 Applicable law: German; Place of jurisdiction: Karlsruhe
14.4 This DPA is an integral part of the main contract between the parties.
14.5 The version valid at the time of use is available at https://refocusly.com/en/dpa. Changes to the DPA will be communicated to the customer in text form at least 30 days before they take effect. If the customer does not object within 14 days, the new version is deemed accepted.

Appendix A – Details of Data Processing
– Purposes of processing (e.g., Email Marketing, CRM, Automated Workflows)
– Categories of personal data (e.g., contact information, interaction data)
– Categories of data subjects (e.g., customers, prospects)

Appendix B – Technical and Organizational Measures
– Encryption of data at rest and in transit
– Access control (two-factor authentication, role-based permissions)
– Availability and backup (regular backups)
– Logging and audits

Appendix C – Sub-processors
– HighLevel Inc., Dallas, USA
– Google LLC, Mountain View, USA
– Amazon Web Services Inc., Seattle, USA
– Twilio Inc., San Francisco, USA
– Stripe Inc., USA

Appendix D – International Data Transfers
– Legal bases (EU Standard Contractual Clauses, UK Addendum)
– Additional protective measures (encryption, access restrictions)
– Brief overview of recipient countries and protective measures