Data Processing Agreement
1. Scope of application and contracting partners
These General Terms and Conditions for Commissioned Processing under Art. 28 para. 3 GDPR (the "GTC-OPC") set out in concrete terms the data protection obligations arising from a service contract between the party responsible for the data (gender-neutral, the "Customer") and CitationBooster.com, represented by the person or group shown on legal notice (gender-neutral, the "Supplier"; together with the Customer, the "Parties").
2. Subject and scope of commissioned processing
2.1. Delivering the services under the Provider's Terms of Use (the "Main Agreement") requires the Supplier to handle personal data for which the Customer is the controller under data protection law ("Customer Data"). This agreement sets out the Parties' data protection obligations and rights regarding the Supplier's use of Customer Data to perform the services under the Main Agreement.
2.2. The Supplier processes Customer Data on the Customer's behalf and in line with the Customer's instructions, as processing within the meaning of Art. 28 GDPR. The Customer remains the controller under data protection law.
2.3. The Supplier processes Customer Data in the manner, to the extent, and for the purpose set out in Annex 1 (“Subject-Matter of the Processing“); processing covers only the types of personal data and categories of data subjects listed there. Processing runs for the term of the Main Agreement.
2.4. The Supplier may anonymize or aggregate Customer Data so that individual data subjects can no longer be identified, and use it in that form to design, develop, optimize, and deliver the services agreed under the Main Agreement as needed. The Parties agree that data anonymized or aggregated to that standard is no longer "Customer Data" for purposes of this agreement.
2.5. Where data protection law permits it — through a statutory basis or the data subject's consent — the Supplier may process and use Customer Data for its own purposes as a controller. This agreement does not govern that processing.
2.6. The Supplier processes Customer Data within the EU or another EEA state as a rule. Processing outside the EEA remains permitted under this agreement if the Supplier notifies the Customer in advance of the place of processing, and either Art. 44 to 48 GDPR are satisfied or an exception under Art. 49 GDPR applies.
3. Right of the Customer to issue instructions
3.1. The Supplier processes Customer Data as instructed by the Customer, unless legally required to act otherwise — in which case the Supplier will tell the Customer about that legal requirement before processing, unless the law bars such disclosure on important public-interest grounds.
3.2. As a rule, the Customer's instructions are fully set out and documented in this agreement's own provisions. Any individual instruction that departs from those provisions, or adds requirements, needs the Supplier's consent and must follow the Main Agreement's change request procedure, which documents the instruction and allocates any resulting extra cost to the Customer.
3.3. The Supplier will process Customer Data as instructed by the Customer. Where the Supplier considers an instruction to breach this agreement or applicable data protection law, it may — after notifying the Customer — suspend carrying it out until the Customer confirms it. The Parties agree that responsibility for the instructions themselves rests solely with the Customer.
4. Legal Responsibility of the Customer
4.1. As between the Parties, the Customer alone is responsible for the lawfulness of processing Customer Data and for safeguarding data subjects' rights. Where a third party brings a claim against the Supplier over Customer Data processed under this agreement, the Customer will indemnify the Supplier against it on first demand.
4.2. The Customer is responsible for delivering Customer Data to the Supplier in time to perform the services under the Main Agreement, and for that data's quality. If, in reviewing the Supplier's output, the Customer finds errors or irregularities relative to data protection law or its own instructions, it will tell the Supplier immediately and in full.
4.3. On request, the Customer will give the Supplier the information listed in Art. 30 para. 2 GDPR, to the extent the Supplier does not already have it.
4.4. Where the Supplier must supply information to a government body or person about processing Customer Data, or otherwise cooperate with such a body, the Customer will help the Supplier meet that information or cooperation obligation on first request.
5. Requirements for personnel
The Supplier binds everyone it involves in processing Customer Data to confidentiality regarding that processing.
6. Security of processing
6.1. In line with Art. 32 GDPR, the Supplier applies technical and organizational measures appropriate to the risk, taking into account the state of the art, implementation cost, and the nature, scope, context and purposes of processing Customer Data, as well as how likely and severe the risk to data subjects' rights and freedoms is.
6.2. The Supplier may change its technical and organizational measures — including those detailed in Annex 2 ("Technical and Organizational Measures") — during the term of this agreement, provided they continue to meet the statutory requirements.
7. Engagement of further processors
7.1. The Customer gives the Supplier a general authorization to engage further processors for processing Customer Data. Annex 3 (“Sub-processors“) lists the further processors engaged as of this agreement's conclusion. As a rule, no separate authorization is needed for service providers examining or maintaining data processing procedures or systems, or providing other ancillary services, even where they cannot be excluded from accessing Customer Data — provided the Supplier takes reasonable steps to protect its confidentiality.
7.2. The Supplier will notify the Customer before engaging or replacing a further processor. The Customer may object to a specific engagement, but only for important reasons it can substantiate to the Supplier. If the Customer does not object within 14 days of notice, its right to object to that engagement lapses. Should the Customer object, the Supplier may terminate the Main Agreement and this agreement on 3 months' notice.
7.3. The Supplier's agreement with any further processor must impose on it the same obligations the Supplier bears under this agreement. The Parties agree this is satisfied where that contract provides an equivalent level of protection, or imposes the obligations of Art. 28 para. 3 GDPR on the further processor.
7.4. This Section 7 also applies where a further processor sits in a third country, subject to Section 2.6. The Customer authorizes the Supplier to enter into an agreement with such a processor on the Customer's behalf, based on the standard contractual clauses for transferring personal data to third-country processors under the European Commission's Implementing Decision (EU) 2021/914 of 4 June 2021. The Customer will cooperate as needed to satisfy the requirements of Art. 49 GDPR.
8. Data subjects’ rights
8.1. Through reasonable technical and organizational measures, the Supplier will help the Customer meet its obligation to respond to data subjects exercising their rights.
8.2. If a data subject sends a rights request straight to the Supplier, the Supplier will pass it on to the Customer promptly.
8.3. Where the Customer does not already have it and cannot obtain it itself, the Supplier will give the Customer information about the stored Customer Data, the recipients to whom the Supplier discloses it under instruction, and the purpose of storing it.
8.4. To a reasonable and necessary extent, and against reimbursement of the Supplier's documented expenses and costs, the Supplier will let the Customer correct, delete, or restrict further processing of Customer Data — or, on the Customer's instruction, do so itself where the Customer cannot.
8.5. Where a data subject has a right to data portability against the Customer over Customer Data under Art. 20 GDPR, and the Customer cannot obtain that data elsewhere, the Supplier will help — to a reasonable and necessary extent, against reimbursement of its documented expenses and costs — hand it over in a structured, commonly used, machine-readable format.
9. Notification and support obligations of the Supplier
9.1. Where a Customer Data security breach triggers a statutory notification duty for the Customer (notably under Art. 33, 34 GDPR), the Supplier will promptly tell the Customer of any reportable event within its own area of responsibility, and — at the Customer's request, to a reasonable and necessary extent, against reimbursement of its documented expenses and costs — help the Customer meet that notification duty.
9.2. To a reasonable and necessary extent, against reimbursement of its documented expenses and costs, the Supplier will help the Customer carry out data protection impact assessments and, where needed, any resulting consultation with the supervisory authority under Art. 35, 36 GDPR.
10. Deletion of Customer Data
10.1. On termination of this agreement, the Supplier will delete Customer Data unless the law requires it to keep storing it.
10.2. The Supplier may retain records evidencing that Customer Data was processed properly and accurately even after this agreement ends.
11. Evidence and audits
11.1. On the Customer's request, the Supplier will provide all information it has available that is needed to demonstrate compliance with its obligations under this agreement.
11.2. The Customer may audit the Supplier's compliance with this agreement, including how the technical and organizational measures are implemented, and including on-site inspections.
11.3. To carry out an inspection under Section 11.2, the Customer may, after giving timely advance notice under Section 11.5 and at its own cost, access the Supplier's premises where Customer Data is processed during normal business hours (Monday to Friday, 10 a.m. to 3 p.m., excluding public holidays at the Supplier's registered office) — without disrupting business operations and while keeping the Supplier's business and trade secrets strictly confidential.
11.4. At its own discretion, and having regard to the Customer's legal obligations, the Supplier may withhold information that is sensitive to its business or whose disclosure would breach a statutory or contractual duty. The Customer has no right to access data about the Supplier’s other customers, cost information, quality-control or contract-management reports, or any other confidential Supplier data not directly relevant to the agreed audit purpose.
11.5. The Customer will give the Supplier timely notice — normally at least two weeks — of everything relevant to how the audit will be carried out. The Customer may run one audit per calendar year; further audits require prior consultation with the Supplier and reimbursement of its costs.
11.6. Where the Customer has a third party carry out the audit, it will bind that third party in writing to the same obligations Section 11 imposes on the Customer toward the Supplier, and to secrecy and confidentiality — unless the third party is already bound by a professional duty of secrecy. On the Supplier's request, the Customer will promptly provide the commitment agreements signed with that third party. The Customer may not engage any competitor of the Supplier to conduct the audit.
11.7. Instead of an inspection, the Supplier may, at its discretion, demonstrate compliance by producing a suitable, current opinion or report from an independent body (e.g. an auditor, audit department, data protection officer, IT security department, or data protection or quality auditors), or a fitting IT-security or data-protection certification – such as under BSI-Grundschutz – (an “audit report”), provided that report lets the Customer properly satisfy itself of compliance with the contractual obligations.
12. Contract term and termination
This agreement's term and termination follow the term and termination provisions of the Main Agreement. Terminating the Main Agreement automatically ends this agreement too; this agreement cannot be terminated on its own.
13. Liability
13.1. The Supplier's liability under this agreement is governed by the disclaimers and liability limits set out in the Main Agreement. Where a third party brings a claim against the Supplier that stems from the Customer's culpable breach of this agreement or of its own obligations as controller under data protection law, the Customer will indemnify and hold the Supplier harmless against that claim on first demand.
13.2. The Customer will, on first demand, indemnify the Supplier against any fine imposed on the Supplier, to the extent that fine reflects the Customer's share of responsibility for the underlying infringement.
14. Final provisions
14.1. The Main Agreement determines the governing law.
14.2. The Main Agreement determines the place of jurisdiction.
14.3. If this agreement conflicts with other arrangements between the Parties, in particular the Main Agreement, this agreement's provisions control.
14.4. Should any individual provision of this agreement be or become ineffective, or should the agreement contain a gap, the remaining provisions stay in force. The Parties will replace the ineffective provision with a lawful one that comes as close as possible to its intended purpose while satisfying Art. 28 GDPR.
14.5. This Order Processing Agreement forms part of the Main Agreement and takes effect once the Main Agreement is concluded.
Annex 1: Subject-Matter of the Processing
- Purposes of Processing
This Data Processing Agreement covers processing the Customer's personal data for the following purposes:
- Software-as-a-Service (SaaS)
- Types and Categories of Data
The types and categories of personal data processed under this DPA include:
- Master / Inventory data
- Contact information
- Content data
- Contract details
- Location data (these values are imprecise and cannot be used to identify a specific address or household)
- Log data
- Meta / communication data
- Performance and behavioral data
- Emails
- Referrer URL
Categories of data subjects
The categories of data subjects affected by processing under this DPA include:
- Website visitors
- Software users
Annex 2: Technical and Organizational Measures (TOMs)
Processing, and the Data processed, receive a level of protection appropriate to the risk to affected data subjects' interests, fundamental rights and freedoms. In particular, the protection goals of confidentiality, integrity and availability of the systems and services, and their resilience, are weighed against the nature, extent, circumstances and purposes of the Processing, so that appropriate technical and organizational measures durably mitigate the risk.
Aside from workstation computers and mobile devices, the company maintains no data processing systems on its own business premises.
Electronic Access Control
Electronic access controls prevent unauthorized persons from accessing systems, data processing equipment, or procedures — including merely the possibility of exploiting, using, or observing them.
A password policy sets minimum length and complexity requirements in line with the state of the art and applicable security standards.
Every data processing system is password-protected.
As a rule, passwords are never stored in plain text and are transmitted only hashed or encrypted.
Password management software is in use.
Hardware firewall(s) protect the network.
Internal Access Control (permissions for user rights of access to and amendment of data)
Internal access controls ensure that anyone authorized to use a data processing system can reach only the Data their access authorization covers, and that personal data cannot be read, copied, altered or removed without authorization during Processing. Input controls further ensure it can later be checked and established whether, and by whom, Data was entered, altered, removed, or otherwise processed in a data processing system.
A rights-and-roles (authorization) concept limits access to personal data to a group of people chosen by need, and only to the extent necessary.
That authorization concept is reviewed regularly, at reasonable intervals and whenever an incident calls for it (e.g. a breach of access restrictions), and updated as needed.
Document shredders in use (minimum security level 3, protection class 2)
Entries, changes and deletions of the Customer's individual Data are logged.
An authorization concept is established and applied.
Data media are stored securely.
Transmission Control
Transmission controls ensure the Data cannot be read, copied, altered or deleted by unauthorized persons during electronic transmission, transport, or storage on data carriers, and that it can be verified and established which bodies personal data is meant to be transmitted to via data transmission equipment.
Remote access to internal systems (e.g. for remote maintenance) goes through encrypted channels (e.g. VPN).
Data transfer is encrypted (e.g. email encryption, TLS/SSL-encrypted internet connections, SFTP for file transfer).
Data storage is encrypted (e.g. file encryption to the AES-256 standard).
Adherence to Instructions, Purpose Limitation and Separation Control
Measures ensure Data processed on the Customer's behalf is processed only per the Customer's instructions, that Data collected for different purposes is kept separate, and that Data is not merged, combined, or otherwise jointly processed contrary to those instructions.
The Data is processed physically apart from data belonging to the Processor's other processing operations.
Production and test data are kept strictly separate, in different systems; production systems run separately and independently from development and test systems.
Safeguarding the Integrity and Availability of Data and the Resilience of Processing Systems
Measures protect personal data against accidental destruction or loss and allow it to be restored quickly in an emergency.
Server systems and services run under an appropriate, reliable and controlled backup-and-recovery concept.
Data backups are kept at a secure, off-site location.
Annex 3: Sub-Processors
The Processor uses the following sub-processors to process data on the Client's behalf:
Company Name, Address, Purpose
- Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, CDN and security
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, Hosting
- Stripe Payments Europe, Limited, The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland, Payment processing