Data Processing Agreement
Last updated: 2026-10-01
This is a convenience translation. The German version is legally binding.
Under Art. 28 GDPR and Art. 9 Swiss DPA. Part of the Terms of Service; applies upon conclusion of the contract without a separate signature.
1. Parties and subject matter
This agreement is concluded between the customer as controller and EAS International, Klybeckstr. 141, 4057 Basel, Schweiz as processor (the Provider). Representative of the Provider in the EU under Art. 27 GDPR: Urs Zimmermann, Eichacker 2, 79418 Schliengen, Germany.
Its subject is the processing of personal data that the customer enters into or collects through Batteriepass Online. Nature, purpose, data types and categories of data subjects are described in Annex 1. The agreement applies for the term of the service contract including the read-only phase and any archive hosting under section 8 of the Terms.
2. Instructions
The Provider processes the data exclusively within the scope of the service contract and on documented instructions of the customer. The customer issues instructions by using the functions of the software (such as publishing a passport, assigning access levels, sending a supplier request, exporting, deleting) and in text form to info@batteriepass-online.eu. Instructions beyond the agreed scope are treated as change requests and may be charged separately.
If the Provider considers an instruction unlawful, it informs the customer without delay and may suspend execution until confirmation.
Making passport content available to the public, to persons with a legitimate interest and to authorities takes place in accordance with Regulation (EU) 2023/1542 in the configuration chosen by the customer and is deemed an instruction of the customer.
3. Obligations of the Provider
- Confidentiality: all persons involved in processing are bound to confidentiality. Customer data is accessed only where necessary for operation, support or troubleshooting.
- Security: the Provider implements the technical and organisational measures in Annex 3 and adapts them to the state of the art without lowering the level of protection.
- Assistance: the Provider assists the customer with the means of the software (export, rectification, deletion, access log) in fulfilling data subject rights and in data protection impact assessments and consultations with the supervisory authority, to the extent the information is held by the Provider.
- Notification: the Provider notifies the customer of personal data breaches affecting customer data without undue delay, at the latest within 48 hours of becoming aware, to the e-mail address stored in the account, with the information available under Art. 33(3) GDPR.
- Data subject requests: if data subjects contact the Provider directly, it forwards the request to the customer without a substantive answer of its own, insofar as the request relates to customer data.
- Evidence: on request, the Provider makes available the information necessary to demonstrate compliance with this agreement, in particular a description of the measures in Annex 3 and reports on security incidents.
- Deletion: after the end of processing the Provider deletes the data in accordance with section 8 of the Terms unless a statutory retention obligation exists. For published battery passports the statutory obligation to keep them available under Art. 77(8) Regulation (EU) 2023/1542 counts as a retention obligation.
4. Audit rights of the customer
The customer may verify compliance with this agreement once a year and where there is a specific reason. Verification is carried out primarily by reviewing documentation, reports and confirmations of sub-processors. An on-site audit is possible after notice with a reasonable period (at least 14 days) during normal business hours, provided it does not endanger the data of other customers. For audits exceeding one per year or not prompted by an incident the Provider may charge the resulting effort at a reasonable rate.
5. Sub-processors
The customer consents to the use of the sub-processors listed in Annex 2. The Provider binds them to data protection obligations equivalent to those agreed here.
The Provider informs the customer of intended changes (addition or replacement) at least 30 days in advance by e-mail. The customer may object within this period for important data protection reasons. In case of objection either party may terminate the service contract with effect from the date of the change; section 8 of the Terms remains unaffected.
6. Processing in third countries
Data is stored on servers in Germany. The Provider is established in Switzerland, for which an adequacy decision of the European Commission exists; access from Switzerland is therefore permitted. Processing in other third countries takes place only with the customer’s consent and on the basis of appropriate safeguards under Chapter V GDPR.
7. Obligations of the customer
The customer is responsible for the lawfulness of the processing, in particular for the legal basis for publishing information on natural persons in passports, for informing data subjects and for the lawfulness of contacting suppliers and applicants. It assigns access levels and access grants on its own responsibility and checks that the data made accessible through the software complies with legal requirements.
The customer designates in the account an e-mail address reachable for data protection matters and keeps it up to date.
8. Liability, term, final provisions
Section 11 of the Terms applies to liability; Art. 82 GDPR remains unaffected. This agreement ends with the service contract but continues as long as the Provider keeps customer data available under section 8 of the Terms. Otherwise the final provisions of the Terms apply. In case of conflict between this agreement and the Terms, this agreement prevails for data protection matters.
Annex 1 – Subject of processing
- Nature and purpose: hosting, storage, display, export and transmission of battery passport content and related documents; sending e-mails on behalf of the customer (supplier requests, access decisions); logging access to protected content; provision of the API and webhooks.
- Types of data: names, functions and contact details of contact persons of the customer, its suppliers and of applicants for access grants (e-mail address, organisation, role, purpose, supporting documents); content of passport fields and documents insofar as they contain information on natural persons (such as the responsible person of the economic operator, signatories of declarations of conformity); access logs (truncated hashed IP address, user agent, time, access level); data submitted by the customer to the API.
- Categories of data subjects: employees and contact persons of the customer, its suppliers and business partners; persons requesting access to protected passport content (authorities, repair and recycling operators, purchasers); visitors of public passport pages.
- Special categories (Art. 9 GDPR) are not subject to processing; the customer does not enter such data into the software.
Annex 2 – Sub-processors
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany – data centre services (servers, database, document storage, backups) in Falkenstein and Nuremberg.
- STRATO GmbH, Otto-Ostrowski-Str. 7, 10249 Berlin, Germany – sending e-mails on behalf of the customer.
- Stripe Payments Europe Ltd., Dublin, Ireland, processes the customer’s payment data as an independent controller and is not a sub-processor for customer data within the meaning of this agreement.
Annex 3 – Technical and organisational measures
- Physical and system access: servers in ISO 27001 certified Hetzner data centres; administration only via key-based SSH and a private network; the database is not reachable from the public internet.
- Data access: role-based permissions (owner, editor, viewer) per organisation; tenant separation at database level via the organisation ID in every query; access levels for passport content (public, legitimate interest, authority) are enforced server-side in a single filter function.
- Authentication: passwords as scrypt hashes; sessions with random tokens in the database, 30 days; e-mail verification before write access; limits on login, registration and reset attempts; API keys stored only as hashes.
- Transmission: TLS for all connections; Content Security Policy; signed webhooks (HMAC) with encrypted stored secrets.
- Integrity: every publication of a passport creates a version with a hash chain (previous hash); audit log of all writing actions; nothing is physically deleted before the contractual periods have expired.
- Availability: daily backup of database and document storage with at least 30 days retention at a second location; regular restore tests; availability monitoring.
- Separation: production data separated from development and test environments; passports in the Pilot plan are marked as test data.
- Organisation: data minimisation built into the software (only fields required for the passport); security review for every change of the service; incident documentation; regular updates of system components.