1. Subject matter and duration
The subject matter is the processing of personal data by the processor when providing Vallion. The duration corresponds to the term of the main contract.
2. Nature and purpose of processing
Storing and processing account, organization, product and notification data to monitor vulnerabilities and prepare notifications under CRA Art. 14.
3. Types of personal data
- Names and business email addresses of users
- Sign-in and session data
- IP addresses and user agents in the audit log
- Contact details in notifications, where entered by the customer
4. Categories of data subjects
- Employees and agents of the customer who use Vallion
- Contact persons the customer names in notifications or notes
5. Obligations of the processor
- Processing only on documented instructions from the controller (Art. 28(3)(a) GDPR)
- Confidentiality commitments of authorised persons (point (b))
- Technical and organisational measures under Art. 32 GDPR (point (c))
- Engaging subprocessors only in accordance with section 6 (point (d))
- Assistance with data subject requests (point (e))
- Assistance with the obligations under Art. 32 to 36 GDPR (point (f))
- Deletion or return of data after the end of the contract (point (g))
- Providing evidence and allowing audits (point (h))
6. Subprocessors
The list of subprocessors will be attached before launch: [Annex 1: subprocessors]. The processor informs the controller in advance of intended changes; the controller may object.
7. Notification of personal data breaches
The processor notifies personal data breaches without undue delay after becoming aware of them, at the latest within [set period], and assists the controller with its obligations under Art. 33 and Art. 34 GDPR.
8. Technical and organisational measures
The measures are described in Annex 2. Already implemented in the application are, among others:
- Tenant isolation: every record belongs to one organization, every query is filtered server-side
- Access control with roles (owner, admin, member) and hashed API keys
- Tamper-evident, hash-chained audit log
- Encryption in transit via TLS provided by the hosting environment
- Redaction of secrets in operational logs
- Backup and restore: [set]
9. Term and termination
The agreement ends with the main contract. After termination, the data is deleted or returned at the controller’s choice, unless a retention obligation applies.
The German version of this page is authoritative; this translation is provided for convenience.