Data processing agreement (DPA)
Version 1.0 · Last updated: 17 July 2026 · Annex to the main agreement · Convenience translation; the German AVV governs
Parties and incorporation
This DPA is concluded between the customer identified in the offer as controller (“Customer”) and Zaina Jaber, trading as “Televora”, Löher Weg 20, 51545 Waldbröl, Germany, as processor (“Processor”). It applies once accepted by the Customer in text form or during onboarding and supplements the main agreement.
Where Televora processes data for its own purposes, such as contract, billing, abuse-prevention or its own security data, Televora is a controller for that processing and the privacy policy applies.
1. Subject matter, duration, nature and purpose
The subject matter is the hosting, storage, organisation, conversion, delivery, support, backup and deletion of data processed by the Customer in the digital signage platform, including the admin dashboard, players, media, schedules, integrations and telemetry. Processing lasts for the term of the main agreement, including agreed export, return and deletion periods.
Operations may include collection, recording, organisation, storage, adaptation, retrieval, transmission, provision, restriction and deletion. Processing generally takes place in the EU/EEA region identified in the subprocessor register.
2. Data and data subjects
- Data types: names, business contact details, user and role information, pseudonymous IDs, login/session and security data, IP/device/browser data, screen status and telemetry, usage and playback logs, support data, uploaded media and metadata, schedules, integration data, prompts and AI output.
- Optional special-category data: only on documented instruction may media or integration data contain health data or other data under Article 9 GDPR. The Customer must explicitly configure and minimise such use and ensure a legal basis.
- Data subjects: the Customer's employees and contractors, its customers, patients, visitors, depicted persons, contacts and other persons whose data the Customer provides.
3. Instructions and responsibility
Televora processes data only on documented instructions from the Customer, including regarding third-country transfers, unless Union or Member State law requires processing. In that case Televora informs the Customer in advance where the law permits. The main agreement, product configuration, API calls and support instructions constitute documented instructions.
If Televora considers an instruction to violate data protection law, it informs the Customer immediately and may suspend execution until the instruction is confirmed or changed. The Customer is responsible for lawfulness, transparency, legal bases, notices to data subjects and data minimisation.
4. Televora obligations
- Confidentiality commitments and appropriate privacy/security training for all persons authorised to access the data;
- implementation and regular assessment of the measures in Annex 1;
- assistance with data-subject rights, data protection impact assessments, consultations and evidence under Articles 28–36 GDPR, taking into account the nature of processing and information available;
- no direct response to data subjects without instructions, except where legally required;
- provision of information necessary to demonstrate compliance and cooperation with reasonable audits.
5. Security and personal data breaches
Televora implements risk-appropriate measures under Article 32 GDPR. A personal data breach affecting commissioned data is reported to the Customer without undue delay after becoming aware of it, using the Customer's registered security address. Where available, the report includes its nature and scope, affected categories, likely consequences, measures taken and a contact. Missing information is supplied without undue delay.
A report does not constitute an admission of breach of duty. The Customer decides on notifications to authorities and data subjects where it is the controller.
6. Subprocessors
The Customer grants general authorisation for the subprocessors listed in the current register. Televora gives at least 30 days' notice of an intended material change. The Customer may object within 14 days for demonstrable data-protection reasons. If the parties cannot find a reasonable solution, either party may terminate the affected service for cause.
Televora contractually binds subprocessors to substantially equivalent data protection obligations and remains responsible to the Customer for their performance.
7. Third-country transfers
Televora initiates third-country transfers only on instruction, on the basis of an adequacy decision or appropriate safeguards under Article 46 GDPR. Where standard contractual clauses are required, the then-current EU standard contractual clauses are incorporated together with a transfer impact assessment and supplementary measures. Details are set out in the subprocessor register.
8. Audits
The Customer may audit once per year and additionally following a relevant incident. Current certificates, reports, questionnaires and remote evidence are used first. On-site audits require at least 14 days' notice, take place during business hours, must not affect other customers and are subject to confidentiality. The Customer bears reasonable costs unless the audit identifies a material Televora violation.
9. Return and deletion
When the service ends, Televora returns commissioned data in an available common format at the Customer's choice and then deletes it unless statutory retention is required. The retrieval period is at least 30 calendar days after the transition period is complete. Production data is then deleted; encrypted backups are overwritten during the regular documented backup cycle and remain blocked until then. Data subject to statutory retention is stored separately and used only for the required purpose.
10. Liability and final provisions
Article 82 GDPR applies to liability, supplemented internally by the valid liability provisions of the main agreement. Changes to this DPA require text form. For conflicts concerning data protection, this DPA takes precedence over the main agreement.
Annex 1 – Technical and organisational measures
- Physical/access control: controlled data centres; individual accounts; role- and tenant-based permissions; strong password policies; administrative MFA as a binding production target.
- Transmission: TLS for external connections; encrypted administrative access; short-lived or revocable device and session tokens.
- Storage: encrypted disks/backups in the production architecture; separate tenant identifiers; private object storage and authorised delivery.
- Integrity and availability: input validation, security-event logging, monitoring, backups, recovery and emergency procedures; local player caches.
- Tenant isolation: tenant scoping in the database and API, with permission checks before media, export and screen access.
- Development and operations: separate environments and secrets as a production requirement, patch/vulnerability management, dependency review, incident and permission processes.
- Data protection: data minimisation, defined deletion periods, instruction control, subprocessor review and procedures for data-subject requests.
Specific availability, RPO/RTO or certification values are owed only where promised in the offer. Televora may replace measures in line with the state of the art provided the level of protection does not decrease.