Data Processing Agreement
Pursuant to Art. 28 GDPR — template for Neurohain implementation clients
This is the template, not the signed agreement. The binding DPA is completed with the Controller's details and signed by both parties before go-live. The highlighted fields are filled in individually.
Parties
Controller (Art. 4 (7) GDPR):
Company, address, represented by
Processor (Art. 4 (8) GDPR):
Neurohain, Amparo Iglesias Gordillo, 40211 Düsseldorf, Germany
Email: info@neurohain.com
1. Subject Matter and Duration
1.1 This agreement specifies the data protection obligations of the parties arising from the underlying main contract on the design, installation and operation of a Neurohain system.
1.2 Processing takes place solely within the scope of the main contract and on the Controller's documented instructions.
1.3 The term matches the term of the main contract and ends automatically with it.
2. Nature, Scope and Purpose of Processing
2.1 Starting point: the system runs in the Controller's own infrastructure — on the Controller's server, with the Controller's accounts and API keys. Personal data of the Controller's end customers is not copied to, stored on, or processed on Neurohain's own systems.
2.2 Processing within the meaning of this agreement occurs because Neurohain holds technical access to that infrastructure in order to provide the operating service, and may in doing so view, modify or delete personal data.
2.3 Purpose: operation, monitoring, error correction, adaptation and further development of the system.
2.4 Nature of processing: viewing, reading, correcting, deleting and configuring in the course of operation and support.
Categories of data subjects
- The Controller's customers and prospects
- The Controller's staff, insofar as they use the system
Categories of personal data
- Master data (name, form of address)
- Contact data (telephone, mobile, email address)
- Appointment data (date, time, type, status)
- Communication content (message histories via WhatsApp, SMS or email)
- System usage and log data
- further categories to be added per project
Special categories under Art. 9 GDPR are not processed unless expressly and separately agreed. Note for veterinary practices: data about animals is not health data within the meaning of Art. 9 GDPR, but data about their owners may be personal data.
3. The Controller's Right to Issue Instructions
3.1 Neurohain processes personal data solely on the Controller's documented instructions, including with regard to transfers to third countries, unless required to do so by law.
3.2 Instructions are given in text form. Oral instructions must be confirmed in text form without undue delay.
3.3 Neurohain informs the Controller without undue delay if, in its opinion, an instruction infringes data protection law, and may suspend the instruction concerned until it is confirmed or amended.
4. Neurohain's Obligations
4.1 Confidentiality: all persons involved in the processing are bound to confidentiality.
4.2 Security of processing: Neurohain implements the technical and organisational measures described in Annex 1 pursuant to Art. 32 GDPR.
4.3 Assistance: Neurohain assists the Controller, within reason, in responding to data subject requests (Art. 12–23 GDPR), in data protection impact assessments (Art. 35 GDPR) and in prior consultation (Art. 36 GDPR).
4.4 Personal data breaches: Neurohain notifies the Controller of any personal data breach without undue delay and at the latest within 24 hours of becoming aware of it, with all information available to it. The obligation to notify the supervisory authority under Art. 33 GDPR rests with the Controller.
4.5 Data subject requests: if a data subject contacts Neurohain directly, Neurohain forwards the request to the Controller without undue delay and does not answer it itself.
4.6 Data protection contact: info@neurohain.com. A data protection officer is not required under § 38 BDSG; the Controller will be informed if that changes.
5. Sub-processors
5.1 The Controller grants general authorisation for the engagement of the sub-processors listed in Annex 2.
5.2 Neurohain informs the Controller of intended changes in text form with 30 days' notice. The Controller may object within that period. Where a justified objection makes performance impossible, both parties have a special right of termination.
5.3 Neurohain binds sub-processors to a level of data protection equivalent to this agreement.
5.4 Important clarification: services which the Controller uses under its own accounts and in its own name — in particular hosting providers, Meta / WhatsApp Business, Google and AI providers — are not sub-processors of Neurohain. The Controller is itself the contracting party towards those providers and concludes the necessary agreements directly with them. Neurohain assists with the set-up.
6. Third Country Transfers
6.1 Processing by Neurohain takes place exclusively within the EU/EEA.
6.2 Insofar as the Controller uses services that transfer data to third countries (such as Meta or US-based AI providers), this occurs on the basis of the Controller's own agreements with those providers and under its own responsibility. Neurohain points this out to the Controller before go-live.
7. Audit Rights
7.1 The Controller may satisfy itself of compliance with this agreement, in particular by requesting information and by inspecting the access rights recorded in its own administration.
7.2 On-site audits are possible following prior notice with reasonable lead time and during normal business hours, without unreasonably disrupting operations.
8. Deletion and Return on Termination
8.1 As the data remains in the Controller's infrastructure, no return of data sets by Neurohain is required.
8.2 On termination Neurohain's technical access is revoked. Any copies held by Neurohain (for example in support tickets or local working files) are deleted, unless a statutory retention obligation applies.
8.3 On request, Neurohain confirms the deletion in text form.
9. Liability
Art. 82 GDPR applies. In all other respects the liability provisions of the main contract apply.
Annex 1 — Technical and Organisational Measures (Art. 32 GDPR)
Physical access control: Neurohain's working devices are kept in non-public premises and locked when unattended. No own server rooms are operated.
System access control: access exclusively via individual, named accounts, never through shared credentials. Two-factor authentication wherever the respective service offers it. Passwords are managed in a password manager and are never sent by email or messenger.
Data access control: permissions follow the principle of least privilege, limited to what is necessary for operation and support. No access to data sets not required for the service.
Control stays with the Controller: the access is granted by the Controller and can be revoked by the Controller at any time from its own administration, without Neurohain's involvement.
Transmission control: encrypted connections (TLS/HTTPS, SSH) for all access. No transmission of personal data over unencrypted channels.
Separation control: each Controller runs its own instance in its own infrastructure. Commingling of different Controllers' data is excluded by design.
Availability and resilience: monitoring of system operation. Backup arrangements as agreed in the main contract; backups reside in the Controller's infrastructure.
Review: the measures are reviewed at least annually and whenever material changes occur.
As of 19 August 2026. System-side logging of access is not currently in place and is deliberately not claimed here; it is in preparation and will be added once implemented.
Annex 2 — Sub-processors
| Sub-processor | Service | Place of processing |
|---|---|---|
| None in the standard case. The system runs entirely in the Controller's infrastructure and under the Controller's own accounts. Neurohain engages no sub-processors of its own that would have access to the Controller's personal data. | ||
| add per project | e.g. own server, own AI access | EU / EEA |
If, exceptionally, Neurohain provides its own infrastructure or its own access in a specific project, that provider must be added here before go-live.
Version of 19 August 2026