Terms and Conditions and Data Processing Agreement
Last updated: July 2026
Source (German original): https://console.eoscloud.io/de/agb/#inhaltsverzeichnis
Note: This is a convenience translation of the German original (“AGB und Auftragsverarbeitervertrag”). In case of any discrepancy or dispute, the German original version shall prevail.
Table of Contents #
PART A — General Terms and Conditions #
1. Scope, Contracting Parties, Amendment of the Terms #
1.1. These General Terms and Conditions (“Terms”) apply to all contracts for the provision and use of the eos platform between eos GmbH (“eos”) and its customers. The special conditions in the annex apply insofar as the customer obtains the services referred to therein.
1.2. Deviating terms and conditions of the customer shall not apply, even if eos does not expressly object to them. Individual special agreements take precedence over these Terms; this does not apply to pre-formulated contractual terms of the customer.
1.3. The services of eos are directed exclusively at entrepreneurs within the meaning of Section 1 of the Austrian Commercial Code (UGB) and at legal entities under public law. By registering, the customer warrants that it is entering into the contract in the course of its commercial activity.
1.4. For new contracts, the version in effect at the time the contract is concluded shall apply. Amendments vis-à-vis existing customers are permissible in the event of subsequently occurring, unforeseeable changes that eos did not cause and over which it has no influence, in the event of changes in the legal situation, and in the event of gaps that lead to difficulties in performing the contract.
1.5. eos shall communicate amended Terms at least six weeks before they take effect, in text form, stating the reason for and scope of the amendment. If the customer does not object in text form before the amendment takes effect, the amendment shall be deemed accepted; eos will expressly point this out in its communication. In the event of a timely objection, the previous Terms shall continue to apply; either party may then terminate the contract in accordance with Section 10.2.
1.6. Text form is satisfied by letter, email to the address on file, or notification within the eos platform, provided the identity of the person making the statement is recognizable.
2. Registration, User Account and Organizations #
2.1. Use requires registration of a user account. The customer must provide truthful and complete information and update any changes in the platform without undue delay.
2.2. The customer may create organizations and add further users. eos’s contracting party is the legal entity that operates the organization and to which the billing account is assigned. The customer shall ensure that the users it adds are authorized to act as they do; their actions shall be attributed to the customer.
2.3. The assignment and management of roles and access rights within an organization is the sole responsibility of the customer, in particular for administrative roles and access to the audit log.
2.4. The customer must keep its access credentials secret and use the security features offered, such as two-factor authentication. It must inform eos without undue delay if there are indications of a compromise. The customer is responsible for any misuse of its access credentials for which it is at fault.
3. Formation of Contracts, Communication #
3.1. Offers and telephone information are non-binding unless indicated otherwise. The offers and service descriptions published on this website in their respective current version shall be decisive.
3.2. The contract for a paid service is formed when the customer orders the service via the platform and eos confirms the order or begins providing the service.
3.3. eos shall send information regarding ongoing contracts by email to the address on file or within the platform. Access credentials will not be sent by email.
3.4. The customer must ensure that the email address on file is current and able to receive messages. Communications shall be deemed received once they have been sent to this address or made available within the platform.
4. Scope of Services, Availability and Changes #
4.1. eos provides computing, storage and network resources as well as associated management functions. The scope of services results from the respective service description.
4.2. eos shall provide the services with the diligence of a prudent businessperson. In doing so, eos relies on infrastructure operated by third parties; disruptions whose cause lies outside eos’s sphere of influence, in particular disruptions of the internet or cases of force majeure, do not constitute a failure of performance.
4.3. A specific level of availability is owed only insofar as a service level has been separately agreed and paid for. Absent such an agreement, there is no entitlement to a specific level of availability.
4.4. If a service level has been agreed, its terms result from the respective product description. The following shall not be considered unavailability:
- interruptions due to disruptions in the sphere of third parties over which eos has no influence
- interruptions due to force majeure
- announced maintenance windows
- short-term interruptions to avert concrete threats arising from security vulnerabilities
- interruptions attributable to the customer’s configuration or conduct
If an agreed service level is not met, the customer shall receive a credit to its customer account. The credit must be asserted in text form within one month after the end of the affected calendar month and shall amount to no more than 100% of the monthly fee for the affected service. The credit is the customer’s exclusive remedy for failure to meet a service level.
4.5. eos regularly carries out maintenance and service work and, where possible, schedules any associated downtime during periods of low demand.
4.6. Software updates may change the scope and design of the services; this may require the customer to make adjustments to applications it operates. If such a change requires adjustments that are unreasonable for the customer, the customer may terminate the affected contract for cause.
4.7. eos is entitled to have the services owed provided in whole or in part by third parties. Part B, Chapter 8 applies to the engagement of sub-processors.
4.8. The customer selects the processing region within the platform itself. Part B, Sections 1.3 and 1.4 govern this in more detail.
4.9. A change to a plan with a larger scope of services is possible at any time. Upon such a change, the service description in effect at that time shall apply; any ongoing minimum term remains unaffected. Unused prepayments will be credited.
4.10. eos provides support through the support channels made available in the platform, unless otherwise agreed.
5. Trial Period #
5.1. eos may make the platform or individual features available as part of a free trial period. The following provisions take precedence for such services.
5.2. During the trial period, there is no entitlement to any particular availability. Features may be changed, restricted or discontinued at any time.
5.3. Either party may end participation at any time without giving reasons and without notice. eos will inform the customer of the end of the trial period in good time and allow a reasonable period for data backup. After this period expires, the resources operated as part of the trial period and the data contained therein will be deleted.
5.4. During the trial period, the customer will not operate production systems and will not input data whose loss would cause significant damage. eos’s liability for services provided during the trial period is limited to intent.
5.5. Any evaluation of usage behavior beyond error analysis shall take place solely on the basis of separately given consent that may be revoked at any time. Revocation does not lead to exclusion from the trial program. Details are governed by the privacy policy.
6. Fees and Payment Terms #
6.1. Usage-independent fees are payable in advance for the billing period stated in the service description; usage-dependent fees are payable after the end of the billing period.
6.2. All prices are exclusive of value-added tax. Billing takes place in the currency selected in the billing account.
6.3. Payment is made using the payment methods offered in the platform. eos uses external payment service providers for this purpose. A SEPA direct debit mandate that has been granted also applies to newly added bank details and may be revoked at any time.
6.4. Invoices are due within 14 days of receipt, without deduction.
6.5. In the event of default in payment, eos is entitled to charge default interest pursuant to Section 456 of the Austrian Commercial Code (UGB). Section 1333(2) of the Austrian Civil Code (ABGB) applies to collection costs; the lump-sum compensation under Section 458 UGB remains unaffected. eos may pass on the actual costs of returned direct debits caused by the customer.
6.6. If the customer defaults on a non-negligible portion of the fees, eos may, after prior notice and setting a reasonable grace period, restrict or suspend its services. The notice shall include reference to the deletion under Section 10.5.
6.7. If the customer defaults on a non-negligible portion of the remuneration for two consecutive billing periods, or on a monthly fee for more than two months, eos may terminate the contractual relationship for cause with immediate effect.
6.8. The customer may only set off undisputed or legally established counterclaims. The customer has a right of retention only insofar as it is based on the same contractual relationship.
6.9. eos may change prices at the start of a new billing period with six weeks’ notice in text form. The customer may terminate the affected contract for cause as of the effective date of the change. If the customer does not do so within four weeks of receiving the notice, the change shall be deemed approved; eos will expressly point this out.
7. Customer Obligations and Permitted Use #
7.1. The customer is responsible for maintaining adequate backup copies of the data it inputs. Unless expressly agreed as a service, eos does not back up customer content.
7.2. When using the platform, the customer shall comply with the applicable statutory provisions and refrain from any measures that could impair the operation of the platform or its use by other customers. In particular, the following are prohibited:
- the mass sending of unsolicited messages, as well as actions that could result in eos’s address ranges being added to blocklists
- storing and making accessible content whose dissemination violates applicable law, in particular depictions of the sexual abuse of minors, copyrighted content used without authorization, and content that incites terrorism, violence or hatred or violates the Austrian Prohibition Act
- cryptocurrency mining and comparable activities whose economic purpose predominantly consists of converting computing power
- attacks on third-party systems, scanning of third-party networks, distribution of malware, and circumventing the platform’s security measures
- using resources to an extent that significantly exceeds the agreed usage or the usage specified in the service description
7.3. The customer is solely responsible for the legality of the content it inputs and the applications it operates. eos does not conduct a review of content.
7.4. The customer shall notify eos without undue delay, and with meaningful information, of any malfunctions it identifies.
7.5. The customer shall indemnify eos against third-party claims arising from the unlawfulness of content it has input or from a breach of its obligations under this Section 7, including the necessary costs of legal defense.
8. Reports, Suspension and Restrictions #
8.1. eos maintains a contact point at abuse@eoscloud.io for reports of unlawful or abusive content and activity, reviews incoming reports, and takes the necessary measures.
8.2. eos is entitled to suspend the services provided, in whole or in part, if the customer violates Section 7 or there is a concrete suspicion thereof, if this is necessary to avert a significant risk to the security of the platform or third parties, or if there is an official or judicial order to that effect.
8.3. Where possible, eos shall hear the customer before a suspension; where this is not possible due to urgency, eos will inform the customer without undue delay afterward and give it the opportunity to comment. The customer shall receive a statement of reasons for the measure, including the circumstances on which it is based, as well as notice of the possibility to challenge it. The suspension must be lifted as soon as the suspicion is dispelled or the violation is remedied.
9. Data Protection #
9.1. Where eos processes personal data on behalf of the customer, Part B of this document applies. For data that the customer processes on the platform, the customer is the controller within the meaning of the GDPR and shall ensure that it is authorized to process the data and to transfer it to eos.
9.2. The privacy policy at Privacy Policy eos provides information on the processing operations that eos carries out as an independent controller.
9.3. Part B, as Annex 1, is an integral part of these Terms. In the event of conflicts, its provisions shall prevail. Sections 1.4 and 1.5 do not apply to Part B; amendments are governed by Part B, Section 9.2.
9.4. Customers who, for regulatory reasons, require a separately signed data processing agreement will receive one upon request.
10. Contract Term, Termination, Return of Data #
10.1. Contracts are concluded for an indefinite period unless otherwise agreed.
10.2. Contracts for an indefinite period may be terminated by either party with one month’s notice to the end of a month, at the earliest upon expiry of any agreed minimum term. Contracts with a 24-month term are extended by twelve months at a time unless terminated with one month’s notice to the end of the term.
10.3. Where a party has a special right of termination, the contract may be terminated with one month’s notice to the end of a month, regardless of any minimum term.
10.4. Terminations shall be made in text form, in particular via the platform’s termination function. Outside the platform, the identity of the person making the statement must be clearly recognizable; in case of legitimate doubt, eos reserves the right to make further inquiries.
10.5. After termination of the contractual relationship, the customer’s data shall remain available for export for 14 days, unless there is good cause to the contrary. After this period expires, the resources and the data contained therein will be deleted. Deletion from backup copies takes place in accordance with Part B, Section 3.10.
10.6. The right to terminate for cause remains unaffected. Good cause for eos exists in particular if
- the requirements of Section 6.7 are met
- the customer is insolvent, insolvency proceedings have been opened over its assets, or such an application has been dismissed for lack of assets to cover costs
- the customer violates material contractual obligations, in particular Section 7, and fails to remedy the violation without undue delay despite a warning
- there is a serious violation of Section 7.2 that makes continuation unreasonable; in this case, a prior warning is not required
11. Warranty and Liability #
11.1. eos provides warranty in accordance with statutory provisions. The customer must notify eos of defects without undue delay in accordance with Section 377 UGB. The presumption of defectiveness under Section 924 ABGB is excluded.
11.2. eos is not liable for damages resulting from disruptions in technical systems outside its sphere of influence, nor for damages resulting from a breach of the customer’s obligations, in particular the obligation to back up the data it has input. Furthermore, eos is not liable for damages arising from third parties exploiting security vulnerabilities for which no remedy was yet available at the time of the attack.
11.3. eos is liable only for intent and gross negligence. Liability for slight negligence is excluded. Liability for personal injury remains unaffected.
11.4. Liability for loss of profit, indirect damages, consequential damages, business interruption and data loss is excluded to the extent permitted by law. For data loss, eos is liable only to the extent that would have been necessary for restoration had the customer carried out proper and regular data backups.
11.5. eos’s liability is capped at the amount the customer paid to eos for the affected service in the twelve months preceding the event giving rise to the damage. This cap applies per claim and in aggregate for all claims within a calendar year.
11.6. Claims of the customer against eos lapse if not asserted in court within twelve months of becoming aware of the damage and the party liable.
11.7. The limitations in Sections 11.3 to 11.6 do not apply in cases of intent, personal injury, or mandatory statutory liability.
12. Final Provisions #
12.1. Austrian law applies, excluding the UN Convention on Contracts for the International Sale of Goods and the conflict-of-laws rules of private international law.
12.2. The place of performance is eos’s registered seat. The courts with subject-matter jurisdiction for eos’s registered seat shall have exclusive jurisdiction over all disputes.
12.3. Amendments and additions require text form. Sections 1.4, 1.5 and 9.3 remain unaffected.
12.4. Should individual provisions be or become invalid, the validity of the remaining provisions shall remain unaffected.
12.5. The customer may transfer rights and obligations arising from the contractual relationship only with the prior consent of eos. eos is entitled to transfer the contractual relationship to an affiliated company; in this case, the customer has a special right of termination.
Special Conditions for Virtual Servers and Computing Resources #
S1.1. eos provides virtual machines and associated resources. The customer receives administrative access to the systems it operates.
S1.2. The customer is responsible for the configuration, security and updating of the systems and applications it operates, in particular for installing security-relevant updates to the operating system and any software it has installed.
S1.3. The IP addresses assigned to the customer may change for technical reasons. There is no entitlement to the allocation or retention of a particular IP address.
S1.4. If the customer exceeds an included data transfer volume, a fee shall be charged for each additional unit at the rate specified in the service description.
PART B — Data Processing Agreement pursuant to Art. 28 GDPR #
(Annex 1 to the General Terms and Conditions of eos GmbH)
eos GmbH
Feldkirchner Straße 140
9020 Klagenfurt
Austria
FN 663176i
— “Processor” — as data processor under the GDPR
The customer under Part A, Section 2.2 — “Controller” — as controller under the GDPR
Preamble #
This agreement is an integral part of the General Terms and Conditions of eos GmbH and thus of every contract concluded between the Controller and the Processor. It specifies the parties’ data protection obligations for all existing and future contracts, service descriptions and terms of use (together, the “Contracts”) between the Controller and the Processor, and applies to all activities in which employees of the Processor, or persons engaged by the Processor, process personal data (“Data”) of the Controller as controller on its behalf. In all other respects, the provisions and terms of Regulation (EU) 2016/679 (“GDPR”) and the applicable national data protection law governing the Contracts shall apply.
Acceptance takes place as part of registration, together with acceptance of the Terms, in electronic form pursuant to Art. 28(9) GDPR. Customers who require a separately signed version will receive one upon request.
Any references to natural persons apply equally to all genders.
1. Subject Matter, Location and Duration of the Data Processing #
1.1. The subject matter and duration of the engagement, the nature and purpose of the processing, the location of the processing, the categories of data processed, and the categories of data subjects result from the Contracts. The Controller is responsible for the record under Art. 30(1) GDPR, unless the exemption under Art. 30(5) GDPR applies; the Processor is responsible for the record under Art. 30(2) GDPR.
1.2. With the eos platform, the Processor provides the Controller with an infrastructure and management environment. The Controller alone determines what data it inputs, for what purposes it processes such data, and how long it retains it. The Processor does not take note of the content of the data input and processes it only to the extent necessary to provide the agreed services.
1.3. The Controller alone decides on the location of the processing, taking Chapter V GDPR into account. It instructs the Processor, contractually, in text form, or through its own chosen configuration in the eos platform, to carry out the processing within the EU or the EEA, or in regions to be designated by the Controller. The configuration chosen by the Controller constitutes an instruction within the meaning of this agreement.
1.4. The Processor shall inform the Controller of the region and country of processing, as well as the sub-processors engaged pursuant to Chapter 8. For reasons of physical security and the protection of the data of all customers, the Processor will not disclose the exact designation and address of individual data center locations. The parties agree that stating the region, country, and sub-processors is sufficient for assessing the lawfulness of the processing, in particular under Chapter V GDPR.
1.5. The duration of the data processing follows the term of the Contracts, unless further obligations arise from this agreement or by law.
2. Scope of Application and Responsibility #
2.1. The Processor processes Data on behalf of the Controller within the scope of the Contracts. The Controller is solely responsible for compliance with data protection law, in particular for the lawfulness of the processing and of the transfer of data to the Processor.
2.2. The Controller’s instructions are set out in the Contracts and may be amended, supplemented or replaced through configuration in the eos platform and through a statement in text form.
2.3. Processing that the Processor carries out as an independent controller is not the subject of this agreement, in particular the administration of user accounts and organizations, billing, logging for the security of the platform, and the collection of technical operating metrics. The Processor’s privacy policy provides information on this.
3. Obligations of the Processor #
3.1. The Processor processes Data and processing results only within the scope of the engagement and the Controller’s instructions, unless an exception under Art. 28(3)(a) GDPR applies. The Processor shall inform the Controller without undue delay if it considers that an instruction violates applicable law, and may suspend implementation of that instruction until the matter is clarified.
3.2. The Processor undertakes to ensure the security of processing pursuant to Art. 32(1) lit. a to c GDPR and, pursuant to Art. 32(1) lit. d GDPR, to maintain a process for regularly testing the effectiveness of the measures. Details are set out in ANNEX 1. The specific design for a given engagement results from the services agreed in the Contracts. The Processor reserves the right to change the security measures without separate notice, provided the agreed level of protection is not reduced.
3.3. The measures under ANNEX 1 apply group-wide and thus also to the Processor. The infrastructure underlying the operation of the eos platform is operated by the sub-processors named in ANNEX 2. The certifications listed in ANNEX 1 relate to the parts of the corporate group named therein and to data center operations; the Processor itself is not subject to its own certification under these standards.
3.4. The Processor shall ensure that persons involved in the processing are prohibited from unauthorized processing (data secrecy pursuant to Section 6 of the Austrian Data Protection Act, DSG). This obligation continues to apply even after the end of their activity.
3.5. Access by the Processor’s employees to Data input by the Controller shall take place only to the extent necessary to provide the agreed services, to process a support request from the Controller, or to avert a concrete threat to the security of the platform. Such access is logged.
3.6. Within the bounds of its capabilities, the Processor shall support the Controller in fulfilling the rights of data subjects under Chapter III GDPR and in complying with the obligations under Art. 32 to 36 GDPR, within the limits of what is technically and organizationally feasible. The Processor may charge reasonable compensation for support services that go beyond the agreed scope of services.
3.7. The Processor shall notify the Controller without undue delay if it becomes aware of a breach of the protection of the Controller’s Data, take the necessary measures to secure the Data, and coordinate with the Controller without undue delay in this regard.
3.8. The Processor shall rectify or delete the Data covered by the Contracts on the instruction of the Controller, to the extent covered by the scope of the instructions. If deletion in compliance with data protection law is not possible, the Processor shall, upon specific instruction, carry out the compliant destruction of the affected data carriers or return them to the Controller.
3.9. After the end of the contract, Data, data carriers and other materials shall be handed over or deleted at the Controller’s request, analogous to Section 3.8.
3.10. If the Controller deletes Data itself using the functions of the eos platform, such Data will be removed from active systems without undue delay and from regular backup copies within 30 days at the latest. The Controller shall bear any additional costs arising from deviating, non-standard requirements of the Controller that do not result from applicable law or the Contracts.
3.11. In the event a claim is brought against the Controller by a data subject under Art. 82 GDPR, the Processor shall support the Controller in defending against the claim within the bounds of its capabilities.
4. Obligations of the Controller #
4.1. The Controller shall ensure that the processing is carried out in accordance with the principles of Chapter II GDPR, and that the measures under ANNEX 1, together with the measures arising from the Contracts, provide an appropriate level of protection taking into account the nature, scope, circumstances and purposes of the processing as well as the risks to the rights and freedoms of natural persons.
4.2. The Controller is solely responsible for the configuration of the resources it uses, in particular for the choice of processing region, the assignment of roles and access rights, the management of its users’ access credentials, and the backup of the Data input, unless backup has been expressly agreed as a service.
4.3. The Controller shall notify the Processor without undue delay and completely if it identifies errors or irregularities relating to data protection provisions.
4.4. Section 3.11 applies mutatis mutandis in the event a claim is brought against the Controller under Art. 82 GDPR.
5. Data Protection Officer and Contact #
5.1. Data protection queries may be sent at any time by email to data-protection@anexia-it.com. The corporate group to which the Processor belongs has appointed a joint data protection officer pursuant to Art. 37(2) GDPR, who serves as the primary point of contact for the Controller on data protection matters. Name and contact details are published and kept up to date on the corporate website.
5.2. The Controller shall designate one or more contact persons for data protection matters to the Processor.
6. Requests from Data Subjects #
6.1. If a data subject contacts the Processor with a request under Chapter III GDPR, the Processor shall refer the data subject to the Controller, where an assignment is possible, and forward the request without undue delay. The Processor shall support the Controller in fulfilling data subject requests within the bounds of its capabilities and on the Controller’s instructions.
6.2. The Processor shall not be liable if the data subject’s request is not answered, not answered correctly, or not answered in time by the Controller.
7. Means of Proof and Inspection Rights #
7.1. The Processor shall demonstrate compliance with the obligations set out in this agreement upon the Controller’s request, using appropriate means. This may include:
- the updated record of technical and organizational measures (ANNEX 1)
- data protection certifications, where available
- reports on security reviews conducted, where available and provided that their disclosure does not compromise the security of the platform
7.2. The parties agree that the means of proof under Section 7.1 will generally satisfy the Controller’s control and inspection rights. Where these demonstrably prove insufficient in an individual case, the Controller may request an inspection. Such an inspection must be announced with at least four weeks’ notice, is limited to one occasion per calendar year, and is limited to the subject matter not covered by the means of proof. The Processor may request reasonable compensation for the resulting personnel effort. Since the Processor does not operate its own data center locations, inspections of the physical infrastructure are governed by the rules of the respective sub-processor pursuant to ANNEX 2.
7.3. The Processor may make inspections conditional upon the signing of a confidentiality agreement concerning internal company information, the data of other customers, and the measures implemented. If the appointed auditor is in a competitive relationship with the Processor, the Processor has a right of objection; in this case, the Controller agrees to the appointment of an independent external auditor by the Processor, whose report shall be made available to the Controller.
7.4. Mandatory rights under the GDPR take precedence over the provisions of this chapter in the event of any conflict.
7.5. If a supervisory authority carries out an ad hoc inspection, a confidentiality agreement under Section 7.3 is not required, provided the authority is already subject to a statutory duty of confidentiality with penalties for breach.
8. Sub-Processors #
8.1. The Controller consents to processing by the companies named in ANNEX 2 as sub-processors, to the extent necessary for the provision of services. This includes, in particular, the companies that provide the underlying infrastructure. The Processor shall impose all statutory and contractual data protection obligations on such sub-processors in full. For the companies within the corporate group, “Corporate Binding Rules” exist as a binding written legal instrument, together with a group-wide data protection policy and a data protection management system.
8.2. The Controller grants the Processor general written authorization pursuant to Art. 28(2) GDPR to engage or replace sub-processors. The Processor shall inform the Controller at least 30 days before the change takes effect, by notice to the email address on file in the user account and by updating ANNEX 2. The Controller may object within this period on data protection grounds. If no agreement is reached, the Controller may terminate the affected service for cause as of the effective date of the change.
8.3. A sub-processor relationship exists where the Processor engages further companies to provide all or part of a service and personal data of the Controller is processed in the process; this also includes the operation of the infrastructure. This does not include subordinate ancillary services where the activity does not involve the processing of the Controller’s personal data (e.g., telecommunications, postal or cleaning services, security services).
9. Information Obligations, Amendments, Choice of Law #
9.1. If the Controller’s Data held by the Processor is endangered by seizure, attachment, insolvency proceedings, or other measures by third parties, the Processor shall inform the Controller without undue delay and shall point out to those involved that authority over the Data lies exclusively with the Controller.
9.2. Amendments to this agreement are permissible only to the extent necessary to adapt to changed legal requirements or decisions of supervisory authorities, and provided the level of protection is not reduced. The Processor shall provide notice at least six weeks before the amendment takes effect, in text form. Sections 1.4 and 1.5 of the Terms do not apply; Section 8.2 remains unaffected.
9.3. In the event of conflicts relating to data protection, the provisions of this agreement take precedence over the Terms and the other Contracts. The invalidity of individual provisions does not affect the validity of the remainder.
9.4. Austrian law applies.
10. Liability #
The Controller and the Processor are liable to data subjects under Art. 82 GDPR. In the internal relationship between the parties, the liability provisions of the General Terms and Conditions apply in addition.
11. Confidentiality #
Both parties shall treat the contents of this agreement as confidential. Excepted from this are statutory disclosure obligations toward authorities and in proceedings, as well as disclosure to persons bound by confidentiality, auditors, sub-processors and affiliated companies.
ANNEX 1 to the DPA — Technical and Organizational Measures #
As of: January 2026
This document supplements the data processing agreement concluded between the Controller and the Processor pursuant to Art. 28 GDPR.
The technical and organizational measures are implemented by Anexia in accordance with Art. 32 GDPR. They are continuously improved as feasible and in line with the state of the art, and brought to a higher level of security and protection.
Confidentiality #
Access Control (Physical) #
Measures suitable for preventing unauthorized persons from gaining physical access to data processing facilities where personal data is processed or used.
| Technical Measures | Organizational Measures |
|---|---|
| Alarm system | Key management / register |
| Automatic access control system | Reception / front desk / security personnel |
| Biometric access control for the data center | Visitor log / visitor register |
| Chip cards / transponder systems | Staff / visitor badges |
| Manual locking system | Visitors accompanied by staff |
| Doors with exterior door handles | Care taken in selecting security personnel |
| Doorbell system with camera, video surveillance of entrances | Care taken in selecting cleaning services |
Access Control (Systems) #
Measures suitable for preventing data processing systems from being used by unauthorized persons.
| Technical Measures | Organizational Measures |
|---|---|
| Login with username and strong password | |
| Anti-virus software – servers | |
| Anti-virus software – clients | |
| Anti-virus software – mobile devices | Managing user permissions on a need-to-know basis |
| Firewalls with intrusion detection / intrusion prevention systems (IDS/IPS) | Centralized creation of user profiles |
| Use of VPN for remote access | User and password policies |
| Encryption of data carriers | Application of state-of-the-art security measures for remote work |
| Encryption of smartphones | Restricted use of administrative user accounts |
| Automatic desktop lock | Access regulations for office locations and data centers |
| Encryption of hard drives on notebooks / tablets / smartphones | |
| Two-factor authentication for data center operations and critical systems |
Access Control (Data) #
Measures ensuring that persons authorized to use a data processing system can access only the data covered by their access authorization, and that personal data cannot be read, copied, altered or removed without authorization during processing, use, or after storage.
| Technical Measures | Organizational Measures |
|---|---|
| Centralized user and permissions management | Use of authorization concepts |
| Encryption of data at rest and data in transit | Minimal number of administrators |
| Logging and monitoring | Management of user rights by administrators |
| Policy for cryptographic procedures |
Segregation Control #
Measures ensuring that data collected for different purposes can be processed separately.
| Technical Measures | Organizational Measures |
|---|---|
| Separation of production and test environments | |
| Physical separation (systems / databases / data carriers) | |
| Multi-tenancy capability of relevant applications | Definition of database permissions |
| VLAN segmentation of networks | Defined requirements for development environments |
| Customer systems logically separated | Defined requirements for conducting tests in software development |
| Staging of development, test and production environments |
Integrity #
Transfer Control and Input Control #
Measures ensuring that personal data cannot be read, copied, altered or removed without authorization during electronic transmission or input, or during its transport or storage, and that it is possible to verify and establish to which entities a transfer is intended.
| Technical Measures | Organizational Measures |
|---|---|
| Use of VPN | |
| Logging of access and retrievals | Implementation of the need-to-know principle |
| Provision via encrypted connections such as SFTP, HTTPS, secure cloud storage | Policy for cryptographic procedures |
| Technical logging of the input, modification and deletion of data |
Availability and Resilience #
Availability Control #
Measures ensuring that personal data is protected against destruction or loss.
| Technical Measures | Organizational Measures |
|---|---|
| Fire and smoke detection systems | |
| Fire extinguishers in the server room | |
| Server room monitoring of temperature and humidity | |
| Air-conditioned server room | Existing contingency planning |
| UPS system and emergency power for the data center | Regular maintenance and testing of air conditioning, fire suppression systems, batteries and diesel generators |
| Protective power strips in the server room | Disaster recovery plans |
| RAID system / disk mirroring | Disaster recovery tests |
| Video surveillance of the server room | |
| Use of protective programs against malware | |
| High-availability systems for critical systems |
Recoverability #
Measures enabling the availability of personal data and access to it to be restored quickly in the event of a physical or technical incident.
| Technical Measures | Organizational Measures |
|---|---|
| Backup monitoring and reporting | Recovery concept |
| Recoverability using automation tools | Control of the backup process |
| Backup concept based on criticality and customer requirements | Regular data restoration testing and logging of results |
| Storage of backup media in a secure location outside the server room |
Process for Regular Review, Assessment and Evaluation #
Data Protection Management #
| Technical Measures | Organizational Measures |
|---|---|
| Central documentation of all data protection rules, with technical access for staff | Data protection management system implemented |
| Annual review of the adequacy of the TOMs | Information security management system implemented |
Incident Response Management #
Support in responding to security incidents, as well as a data breach process.
| Technical Measures | Organizational Measures |
|---|---|
| Documented procedure for handling security and data protection incidents | |
| Central reporting channel for security incidents and data breaches | Documentation of security incidents and data breaches via ticketing system |
| Extensive logging and monitoring for forensic investigations | Defined roles and responsibilities within the organization |
| Training and awareness programs for staff |
Privacy-Friendly Default Settings #
“Privacy by design” / “privacy by default” pursuant to Art. 25(2) GDPR.
| Technical Measures | Organizational Measures |
|---|---|
| Documented requirements for “privacy by design / default” are in place | |
| Application of privacy-friendly default settings in standard and custom software | Requirements for secure software development are defined |
Sub-Processor Control #
Measures ensuring that personal data processed on behalf of the controller is processed only in accordance with the controller’s instructions.
| Technical Measures | Organizational Measures |
|---|---|
| Supplier assessments are conducted on a risk basis | |
| Prior review of the security measures taken by the contractor and their documentation | |
| Monitoring of remote access by external parties, e.g., in the context of remote support | Selection of the contractor based on defined criteria |
| Monitoring of subcontractors based on the principles and using the technologies described in the preceding chapters | Conclusion of the necessary data processing agreement |
| Group-wide framework agreement on data processing | |
| Regular review of the contractor and its level of protection |
ANNEX 2 to the DPA — Sub-Processors #
Version 1.0 – As of: July 2026
The following sub-processors are listed, whose engagement the Controller approves pursuant to Section 8.1 of the Data Processing Agreement.
| Company | Registered Office | Country | Service |
|---|---|---|---|
| Anexia Cloud Solutions GmbH | Klagenfurt | Austria | Operation of the underlying infrastructure, data center services, operation of monitoring and error-analysis systems |
| Anexia Cloud Solutions GmbH | Karlsruhe | Germany | Operation of the underlying infrastructure, data center services, operation of monitoring and error-analysis systems |
All of the above-named companies belong to the corporate group to which the Processor also belongs. The “Corporate Binding Rules” referred to in Section 8.1 of the agreement, as well as the group-wide framework agreement on data protection and data processing, apply to them.
Third-country transfer: All of the above-named sub-processors are based within the European Union. No transfer of the Controller’s personal data to countries outside the EU or the EEA takes place as part of the data processing, unless you configure a server location outside the European Union via the eos platform.
The Processor will provide notice of any intended amendments to this annex in accordance with Section 8.2 of the agreement, at least 30 days before they take effect.