Data Processing Agreement under Article 28 GDPR.
Last updated: January 1, 2026
This DPA is part of the Terms of Service between Wysor IT Solutions UG (haftungsbeschränkt) ("Processor") and the Customer ("Controller").
This DPA applies when Wysor processes personal data on behalf of the Customer. The Customer is the Controller; Wysor is the Processor.
The Customer ensures it has lawful basis to provide data to Wysor and that its instructions comply with applicable law.
Wysor will:
Wysor may use subprocessors listed at wysor.io/subprocessors. We notify customers before adding new subprocessors. Customers may object within 14 days.
Data is processed in the EU. For non-EU subprocessors, EU Standard Contractual Clauses apply.
Wysor maintains appropriate technical and organizational measures including encryption, access controls, and monitoring.
Wysor notifies the Customer within 48 hours of becoming aware of a personal data breach.
Wysor assists the Customer in responding to data subject requests (access, deletion, portability, etc.).
Wysor provides information needed for compliance verification. Audits require 30 days notice.
Upon termination, Wysor deletes or returns all personal data at Customer's choice, unless retention is legally required.
Subject to the limitations in the Terms of Service.
German law. Jurisdiction: Hamburg, Germany.
Wysor IT Solutions UG (haftungsbeschränkt) c/o Postflex #9898, Emsdettener Str. 10, 48268 Greven, Germany Email: [email protected]
Last Updated: January 1, 2026