Data Processing Agreement
Processing of personal data on behalf of our business customers under Art. 28 GDPR.
Version 2026-07-25 · Last updated: July 25, 2026
1. Subject Matter and Roles
This DPA governs the processing of personal data by Fesk e.U., Mariahilfer Straße 136, 1150 Vienna, Austria ("Processor") on behalf of the customer ("Controller") in connection with the use of the Fesk platform ("the Service"). For this data the Controller is responsible within the meaning of Art. 4(7) GDPR and the Processor acts within the meaning of Art. 4(8) GDPR. For the Processor's own account and billing data, Fesk is itself the controller (see our Privacy Policy).
2. Duration
This DPA applies for the term of the main contract. Processing ends with the termination of the main contract, subject to the deletion and return obligations in section 10.
3. Nature and Purpose of Processing
The Processor processes personal data solely to provide the Service: hosting, storage, display, transmission, and, where enabled by the Controller, AI-assisted processing of support tickets, comments, attachments, and related metadata. The nature and purpose are further described in the Terms and Privacy Policy.
Where the Controller makes public forms available on which persons without an account can submit requests, the Controller undertakes to configure, before publishing them, a privacy notice or a link to its privacy policy (Art. 13 GDPR). The Processor withholds the technical activation of such forms until this information is provided and logs the version shown to the data subject.
4. Type of Personal Data and Categories of Data Subjects
Types of personal data: identity and contact data, the content of support tickets and comments, attachments, and usage/communication metadata submitted by or on behalf of the Controller.
Categories of data subjects: the Controller's staff and authorized users, and the Controller's own customers or end users who submit or are referenced in support requests.
5. Obligations of the Processor
The Processor shall:
- process personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by Union or Member State law (Art. 28(3)(a) GDPR);
- ensure that persons authorized to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b));
- implement the technical and organizational measures set out in Annex 2 (Art. 32);
- respect the conditions for engaging sub-processors set out in section 7;
- assist the Controller, taking into account the nature of processing, in fulfilling its obligation to respond to data subject requests (Art. 12–23) by appropriate technical and organizational measures;
- assist the Controller in ensuring compliance with Art. 32–36 (security, breach notification, data protection impact assessments);
- make available to the Controller all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits (section 9);
- inform the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
5a. Notification of Personal Data Breaches
The Processor shall notify the Controller of any personal data breach affecting the Controller's data without undue delay after becoming aware of it, and in any event within 24 hours (Art. 33(2) GDPR). The initial notification shall include, to the extent known, the nature and time of the breach, the systems affected, the categories and approximate number of data subjects and records concerned, the likely consequences, the containment and remedial measures taken or proposed, and a named contact point for further information. Where not all details are available at the time of the initial notification, the Processor shall provide the missing information without undue delay and submit a final report after remediation.
The Processor shall assist the Controller in fulfilling the Controller's own notification and communication obligations under Art. 33 and Art. 34 GDPR. Notification to the data protection authority and communication to affected data subjects are made by the Controller, unless expressly agreed otherwise. Notifications are sent to the security contact address held in the account, which the Controller keeps current.
6. Instructions
The main contract, this DPA, and the configuration choices made by the Controller in the Service (e.g. configuring AI workflow steps to act autonomously) constitute the Controller's documented instructions. Additional instructions must be issued in text form. The Processor will not use the personal data for its own purposes; in particular, ticket and knowledge-base content is not used to train AI models.
6a. EU AI Act, Role Allocation
Fesk provides an AI system within the meaning of Regulation (EU) 2024/1689 ("EU AI Act") as part of the Service. For the purposes of that Regulation, Fesk is the Provider and the Controller is the Deployer insofar as it activates and uses the AI features of the Service toward its own end users. The obligations below apply from the respective statutory date of application of the Regulation and only insofar as the activated AI features fall within its scope; the transparency obligations under Art. 50 apply from 2 August 2026. The Controller shall fulfil the deployer obligations under the EU AI Act (in particular Art. 26 and Art. 50(4)), and Fesk shall support the Controller by marking AI-generated outputs, making technical documentation available, and providing configuration options for the AI's degree of autonomy. Further details are set out in section 11b of the Terms.
7. Sub-Processors
The Controller grants general written authorization for the engagement of sub-processors. The Processor currently engages the sub-processors listed in Annex 1. The Processor shall impose data protection obligations on each sub-processor that are equivalent to those in this DPA. The Processor shall inform the Controller of any intended change concerning the addition or replacement of sub-processors at least 14 days in advance, giving the Controller the opportunity to object on reasonable data protection grounds. If the parties cannot reach agreement, the Controller may terminate the affected services.
7a. Customer-Initiated Transfers to Third-Party Services
The Service enables the Controller to export data to third-party systems it designates (in particular webhooks, REST connectors, Slack, message queues) and to connect its own email mailboxes (e.g. Gmail, Microsoft 365, its own IMAP/SMTP server). Activating and configuring these features constitutes a documented instruction of the Controller. The recipients of these transfers are not sub-processors of the Processor; the Controller is solely responsible for the legal basis, the choice of recipients, and the safeguards required under Chapter V GDPR toward those recipients. The Processor logs the activation, modification, and deactivation of these configurations.
Where the Controller or an authorized user signs in through an external identity provider (single sign-on with Google or Microsoft), that identity provider acts as an independent controller with respect to the processing that takes place in its own account; its processing is governed by its own privacy policy.
8. International Data Transfers
The Controller selects the deployment region of its workspace at registration; this choice constitutes a documented instruction within the meaning of Art. 28(3)(a) GDPR, including with regard to any associated transfer to a third country. The Processor publishes, on its GDPR page, the country and the applicable transfer instrument (European Economic Area, adequacy decision, or Standard Contractual Clauses) for the selectable regions.
Where the Controller enables the AI features, AI processing takes place within the selected deployment region; no personal data is transmitted to an external AI provider.
Where a sub-processor processes personal data outside the European Economic Area, the Processor ensures appropriate safeguards under Chapter V GDPR. For regions without an adequacy decision, transfers are made on the basis of the Standard Contractual Clauses of Implementing Decision (EU) 2021/914 (Module 3), supplemented by the technical and organizational measures set out in Annex 2. For regions with an adequacy decision (e.g. the EU-US Data Privacy Framework for certified US organizations), the Processor relies on that decision. The Processor makes available, on request, the information necessary for the Controller to carry out a Transfer Impact Assessment. The Controller may restrict its workspace to regions within the European Economic Area.
9. Audit Rights
The Processor shall, upon reasonable prior notice, make available to the Controller the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. Audits shall be conducted during regular business hours, without disrupting operations, and subject to confidentiality. The Processor may satisfy audit requests by providing current certifications, audit reports, or a documented summary of its technical and organizational measures.
10. Deletion and Return
Upon termination of the main contract, the Processor shall, at the choice of the Controller, delete or return all personal data processed on behalf of the Controller and delete existing copies, unless Union or Member State law requires storage. Personal data is removed from or anonymized in production systems within 30 days; backup copies are overwritten or deleted within the rolling backup cycle (up to a further 30 days). Statutory retention obligations (in particular § 132 BAO and § 212 UGB for billing records) remain unaffected.
11. Liability
Liability under this DPA is governed by the liability provisions of the Terms. Mandatory liability under Art. 82 GDPR remains unaffected.
12. Order of Precedence
In the event of conflict between this DPA and the Terms, this DPA prevails with regard to data protection matters. The contract language is German; in case of conflict, the German version of this DPA prevails.
Annex 1, Sub-Processors
The Processor currently engages the following sub-processors:
| Sub-processor | Purpose | Location / transfer instrument | |---|---|---| | Amazon Web Services EMEA SARL, Luxembourg | Hosting, storage, operation, email delivery, and authentication (including Cognito Hosted UI) | region selected by the Controller; for regions outside the EEA, Standard Contractual Clauses (Implementing Decision (EU) 2021/914) | | Stripe Payments Europe, Ltd., Ireland | Payment processing | EU / USA (Standard Contractual Clauses or EU-US Data Privacy Framework) |
Not sub-processors, and to be considered separately, are: integrations initiated by you as the Controller (connected email mailboxes, connectors such as webhooks, Slack, REST endpoints), external identity providers used for single sign-on (Google, Microsoft — each an independent controller), and the push delivery services of the browser used by your users. The full recipient and role overview is published on our GDPR page.
Annex 2, Technical and Organizational Measures (Art. 32 GDPR)
Confidentiality
- Role-based access control (RBAC) on all protected endpoints; access to production systems restricted to authorized personnel
- Encryption in transit (TLS 1.2+) and encryption at rest for sensitive data
- Authentication safeguards: email verification, time-limited tokens, registration abuse protection
Integrity
- Parameterized database access to prevent injection
- CSRF protection on all state-changing requests; Content Security Policy enforced in production
- Audit logging of authentication and administrative events
Availability and Resilience
- Hardened, regularly patched infrastructure with health monitoring and alerting
- Automated daily backups on a rolling basis (up to 30 days), then automatically overwritten or deleted
Procedures for Regular Review
- Regular security reviews based on recognized web application standards
- Dependency scanning for known vulnerabilities
A detailed description is available on our Security page.