Back to Home

Data Processing Agreement

Last Updated: 1st January 2026

1. Definitions

"Data Controller" means the entity which determines the purposes and means of the Processing of Personal Data. In this context, the Customer is the Data Controller.
"Data Processor" means the entity which Processes Personal Data on behalf of the Data Controller. In this context, Assetoc is the Data Processor.

2. Processing of Personal Data

Assetoc shall only process Personal Data on behalf of and in accordance with Customer's documented instructions. Assetoc shall treat Personal Data as Confidential Information and shall only process Personal Data as necessary to provide the Services.

3. Security Measures

Assetoc shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing.

4. Sub-processors

Customer generally authorizes the engagement of Sub-processors by Assetoc. Assetoc shall notify Customer of any intended changes concerning the addition or replacement of Sub-processors.

5. Data Subject Rights

Taking into account the nature of the processing, Assetoc shall assist the Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests for exercising the data subject's rights laid down in the GDPR or other applicable data protection laws.