Data Processing Agreement
Version 1.0 · in force since September 8, 2026
This is a translation. In case of discrepancy, the German version governs.
This agreement under Art. 28 GDPR supplements the terms and conditions. It applies as soon as and to the extent that the Provider processes personal data on behalf of the customer. Within the scope of its subject matter it prevails over the terms and conditions.
§ 1 Roles
The customer is the controller; the Provider — AS4 Holding GmbH, Reklewskigasse 19A/2, 1230 Wien, VAT ID ATU82919512 — is the processor.
For the processing of public charging infrastructure data the Provider is the controller in its own right; that data is not personal data and is not the subject of this agreement. What the Provider processes under its own responsibility is set out in the privacy notice.
§ 2 Subject matter, nature and purpose
| | | |---|---| | Subject matter | provision of the analyses, interfaces and portal functions agreed in the contract | | Nature | collection, storage, retrieval, transmission to the customer, deletion | | Purpose | operation of the customer's access and performance of the contract | | Duration | for the term of the main contract, plus the periods under § 9 |
§ 3 Data subjects and categories of data
Only the data required for access and billing is processed:
- Employees of the customer with portal access: login identifier, name, business e-mail address, role, times of login and action, log of activity within their own account - Billing contacts: name, billing address, VAT ID
No special categories under Art. 9 GDPR. No location data of natural persons. No profiling of employees.
§ 4 Instructions
The Provider processes only on documented instructions from the customer. The main contract, this agreement and the settings the customer makes in the portal constitute instructions. Further instructions require text form.
If the Provider considers an instruction unlawful, it will say so and may suspend execution until the matter is resolved.
Where the Provider processes on the basis of a legal obligation under Union or member state law, it informs the customer beforehand — unless that same law prohibits the notification.
§ 5 Confidentiality
All persons handling the data are bound to confidentiality; the obligation survives the end of their engagement. Access is limited to those persons who need it for their task.
Impersonation — accessing a customer account for support purposes — is possible only with a ticket number, a time limit and a log entry. The customer sees those entries in their own log.
§ 6 Technical and organisational measures
The measures under Art. 32 GDPR are described in a separate document, available on request. As at the date of this version they include in particular:
- Encryption in transit (TLS 1.2+) and at rest - Tenant separation at the database level (row-level security), verified by automated tests on every deployment - Multi-factor authentication required for all administrative access - Logging without personal content; an automated check searches the logs for names, addresses and identifiers - Continuous availability measurement, daily backup, verified restore - Processing exclusively within the European Union
The Provider may develop the measures further; the level of protection must not fall.
§ 7 Sub-processors
The customer gives general authorisation for the use of sub-processors. The Provider keeps a current list with name, seat, service and place of processing and provides it on request.
Before a change or an addition, the customer is informed in text form at least 30 days in advance. The customer may object within 14 days; if the objection cannot be resolved, the customer may terminate the main contract extraordinarily with effect from the changeover.
The Provider binds every sub-processor to the same obligations and is liable for them as for its own conduct.
§ 8 Assistance to the customer
The Provider assists the customer with
- requests from data subjects (Art. 15 to 22) — access and export are available as self-service in the portal, - the data protection impact assessment and prior consultation (Art. 35, 36), - notification of personal data breaches.
The Provider notifies the customer of a breach without delay, at the latest within 24 hours of becoming aware — stating the nature of the incident, the categories of data affected, the estimated scope, the measures taken and a contact. The period is shorter than the 72 hours under Art. 33 because the customer has to meet that deadline themselves.
§ 9 Deletion and return
After the main contract ends, the data remains available for export for 30 days. It is then deleted, including copies in backups after their retention period.
Excepted is what must be retained by law — in particular invoices for seven years under § 132 BAO. That data is blocked and processed solely to meet the retention obligation.
Deletion is logged; the log is provided on request.
§ 10 Evidence and audit
The Provider demonstrates compliance on request, primarily through self-declaration, current documentation and available audit reports.
Where that is not sufficient, the customer may once a year — and on cause in the event of a specific breach — carry out an audit, or have one carried out by an auditor bound to secrecy who is not a competitor of the Provider. The audit is announced with reasonable notice and must not impair operations.
§ 11 Third countries
No processing takes place outside the European Union. Should it become necessary, it will take place only on the basis of an adequacy decision or standard contractual clauses together with a transfer impact assessment, and the customer will be informed in advance under § 7.
§ 12 Liability
Art. 82 GDPR applies. The liability limitations of the main contract do not apply to claims by data subjects nor to fines under Art. 83.
Terms and Conditions · Consumer information · Service Level Agreement · Seal terms of use · Legal notice