Data Processing Agreement (DPA)
As of: 4 May 2026 — Version 1.4 · per Art. 28 GDPR
1. Contracting Parties
Controller: the Customer using the HOVIGuard service under the Terms of Service.
Processor:
Ing. Dipl.-Ing. (FH) Karl J. Pilz, sole proprietorship
Sagmüllerweg 8, 5081 Anif-Niederalm, Salzburg, Austria
VAT-ID: ATU 66845907
Data protection email: datenschutz@hoviguard.eu
2. Subject Matter and Duration of Processing
HOVIGuard processes personal data exclusively on behalf of the Customer for the operation of the AI Security and Governance Gateway. Processing covers:
- Receiving, security-checking and forwarding user prompts to AI models
- Content inspection (PII detection, content safety using Qwen3Guard, NSFW filter)
- Management of user accounts, roles and access rights within the tenant
- Storage of conversations, uploaded files and configurations
- Token and usage metering for billing
- Audit logging for compliance evidence
Processing starts upon registration of the tenant and ends with deletion of the tenant account. After contract end, all personal data is deleted within 30 days, unless statutory retention obligations apply (§ 132 BAO, 7 years), in which case data is pseudonymised/blocked.
3. Nature and Purpose of Processing
See the German master version (§3 — Art und Zweck der Verarbeitung) for the full table of processing activities.
4. Types of Personal Data
- Master data: name, business email, language
- Access data: Argon2id password hash, session tokens, optional 2FA seeds
- Usage data: prompt content, AI responses, token consumption, model selection
- File content: documents and images uploaded by end users, plus metadata
- Communication data: IP address (pseudonymised after 7 days), user-agent, device ID
- Billing data: company/billing address, VAT-ID, Stripe customer ID, tokenised payment instruments (no card numbers)
- Audit data: action logs, security decisions, policy violations
5. Categories of Data Subjects
- Employees and agents of the Customer registered as end users of the tenant
- Persons whose data may be contained in prompts or uploaded files (third parties)
- Billing and contract contacts of the Customer
6. Obligations of HOVIGuard (Processor)
Bound by documented instructions; written confidentiality of staff (Art. 28(3)(b), Art. 29 GDPR); TOMs per Annex A; sub-processor list per Annex B with 30 days' prior change notice; assistance with data subject rights, DPIAs and breach notifications; data export and deletion within 30 days after contract end; Art. 30(2) records.
7. Obligations of the Customer (Controller)
Lawful basis vis-à-vis own end users; tenant configuration of security and content policies; observance of retention; Art. 13/14 information of own end users; ensure no Art. 9 special categories without legal basis; prompt notification of breaches involving HOVIGuard.
8. Audit Rights
Self-service audit log access at any time; one free TOM report per calendar year; on-site or remote audit once per year with 30 days' notice (Customer cost unless triggered by a substantiated breach); third-party certificates accepted in lieu.
9. Third-Country Transfers (Schrems II)
Primary processing within EU/EEA. Third-country transfers limited to the technical minimum and listed in Annex B (Stripe USA via SCCs Modules 1+2 + EU-US DPF; xAI USA via SCCs Module 2 with EU region enforcement and zero retention).
A Transfer Impact Assessment (EDPB Recommendations 01/2020) has been performed. Mitigations: tokenisation, TLS 1.3 + AES-256, no AI conversation content sent to Stripe, xAI processing forced to EU region (eu-west-1) with contractual zero retention, IP pseudonymisation after 7 days, complaint rights with the Austrian DPA and the US Data Protection Review Court (EO 14086).
AI inference and image generation run exclusively on EU-hosted endpoints. Non-EU models are blocked at catalogue level.
10. No Training on Customer Data
Prompts and responses are not used for training or fine-tuning by HOVIGuard or any sub-processor. Eden AI is contractually configured for zero retention. Direct routes (e.g. xAI Grok) only via enterprise/zero-retention endpoints.
11. Tenant Isolation
Strict logical separation by tenant_id, separate MinIO buckets per tenant, application row-level filters, tenant-specific policies, alerting on cross-tenant attempts.
12. Personal Data Breaches (Art. 33/34 GDPR)
HOVIGuard notifies the Customer of any personal data breach without undue delay, in any case within 72 hours of becoming aware of it, in text form. Target: ≤ 24 hours on business-day detection; on weekend/holiday detections up to 48–72 hours. The notification contains all Art. 33(3) GDPR information available and is updated continuously. Process per legal/INCIDENT_RESPONSE_PLAYBOOK.md.
13. Liability
Per Art. 82 GDPR. Contractual liability limited as agreed in §10 of the Terms of Service. Statutory liability for intent, gross negligence and under the GDPR remains unaffected.
14. Conclusion of Contract, Validity, Form
Standard tenants (self-service, Pro plan): acceptance of the Terms of Service constitutes acceptance of this DPA. Current version at hoviguard.eu/en/avv.
Enterprise tenants: separately signable PDF (handwritten or qualified electronic signature) on request via datenschutz@hoviguard.eu.
Order of precedence: in case of conflict between Terms of Service, Privacy Policy and this DPA, the DPA prevails on data processing matters.
Amendments with 30 days' prior notice; material amendments to the Customer's detriment trigger an extraordinary right of termination.
Form: text form (email) suffices for special instructions, audit requests, terminations and objections.
Final: Austrian law, Salzburg jurisdiction. Supervisory authority: Austrian Data Protection Authority (DSB), Barichgasse 40-42, 1030 Vienna.
A. Annex A — TOMs (overview)
See German version §A — Anhang A. Full description in legal/TOMS.md.
B. Annex B — Sub-processors
| # | Sub-processor | Location | Purpose | Third-country safeguard |
|---|---|---|---|---|
| 1 | Hetzner Online GmbH ¹ | Falkenstein, DE 🇩🇪 | Server hosting (GEX44) | EU — no third country |
| 2 | Eden AI SAS | Lyon, FR 🇫🇷 | AI model gateway (EU routing enforced) | EU — no third country |
| 3 | xAI, Inc. | USA 🇺🇸 (EU region eu-west-1) | Direct Grok API (image/video/text) | SCCs Module 2, zero retention |
| 4 | Neue Medien Münnich GmbH (All-Inkl) | Friedersdorf, DE 🇩🇪 | Transactional email (SMTP) | EU — no third country |
| 5 | Stripe Payments Europe Ltd. | Dublin, IE 🇮🇪 (parent USA) | Payment processing | SCCs Modules 1+2 + EU-US DPF |
C. Annex C — Standard Instructions
See German version §C — Anhang C. Standard instructions deemed issued by the Customer upon DPA acceptance.
D. Annex D — Change History
v1.0 (2026-03-23) initial; v1.1 (2026-05-04) Schrems II / TIA section, explicit acceptance clause, Annexes A–D; v1.2 (2026-05-04) removed Cloudflare again (not actually used in operations); v1.3 (2026-05-04) added xAI, Inc. as 3rd sub-processor (direct Grok API, EU region enforced, zero retention, SCCs Module 2); v1.4 (2026-05-04) counsel re-review findings: §12 breach-notification window relaxed from 24h to 72h target 24h; §14.1 acceptance clause reinforced with notice of separate Stripe-checkout checkbox in Q3 2026; Annex B footnote ¹ refined (personal-union Karl Pilz, economic-substance doctrine).
Frequently asked questions about the DPA
What is a DPA?+
A Data Processing Agreement (DPA) regulates per Art. 28 GDPR the obligations between the controller (customer) and the processor (HOVIGuard) — including bindingness to instructions, sub-processors, technical and organisational measures (TOMs), audit rights and third-country safeguards.
When is the DPA concluded?+
For standard tenants, the DPA is deemed accepted upon acceptance of the Terms of Service during registration/checkout (see §14.1). The current version is available online at hoviguard.eu/en/avv. Enterprise customers may request a separately signable PDF version.
How do I receive a signable version?+
By email to datenschutz@hoviguard.eu with subject DPA PDF Request. We typically provide a PDF version with original or qualified electronic signature.
Who are the current sub-processors?+
Hetzner Online GmbH (hosting, DE), Eden AI SAS (AI gateway, FR), xAI Inc. (direct Grok endpoint, US region eu-west-1 with zero retention), Neue Medien Münnich GmbH (SMTP, DE) and Stripe Payments Europe Ltd. (payments, IE). Details including third-country safeguards are in Annex B of the DPA.
How are changes to the sub-processor list communicated?+
Addition or replacement of a sub-processor is notified with 30 days' prior notice in text form to the admin address registered in the tenant. Within this period you have a right to object and an extraordinary right of termination.
What audit rights do I have?+
Self-service audit logs in the admin dashboard at any time; one TOM report per calendar year free of charge on request; one on-site or remote audit per year with 30 days' notice (during business hours). Details in §8 of the DPA.
