{"id":23428,"date":"2026-06-01T08:32:12","date_gmt":"2026-06-01T06:32:12","guid":{"rendered":"https:\/\/www.e-signature.eu\/?page_id=23428"},"modified":"2026-06-01T08:32:12","modified_gmt":"2026-06-01T06:32:12","slug":"dpa","status":"publish","type":"page","link":"https:\/\/www.e-signature.eu\/de\/dpa\/","title":{"rendered":"Data Processing Agreement"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"23428\" class=\"elementor elementor-23428 elementor-23427\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-66670a53 e-flex e-con-boxed e-con e-parent\" data-id=\"66670a53\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-18e5bfe0 elementor-widget elementor-widget-text-editor\" data-id=\"18e5bfe0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\n\n\n<div style=\"max-width:860px;margin:0 auto;padding:0 20px 60px 20px;font-family:Arial,Helvetica,sans-serif;color:#212121;line-height:1.7;\">\n\n  \n  <div style=\"background:#4B0082;border-radius:8px;padding:40px 40px 36px 40px;margin-bottom:40px;\">\n    <div style=\"font-size:13px;color:rgba(255,255,255,0.7);letter-spacing:2px;text-transform:uppercase;margin-bottom:8px;\">VisitOnWeb srl \u2014 e-Signature.eu<\/div>\n    <h1 style=\"font-size:28px;font-weight:700;color:#ffffff;margin:0 0 8px 0;line-height:1.2;\">Data Processing Agreement<\/h1>\n    <div style=\"font-size:14px;color:rgba(255,255,255,0.8);margin:0;\">Pursuant to Article 28 of Regulation (EU) 2016\/679 (GDPR) &nbsp;\u00b7&nbsp; Version 1.0 &nbsp;\u00b7&nbsp; June 2026<\/div>\n  <\/div>\n\n  \n  <div style=\"background:#EDE7F6;border-left:4px solid #4B0082;border-radius:0 6px 6px 0;padding:18px 22px;margin-bottom:40px;\">\n    <div style=\"font-size:13px;font-weight:700;color:#4B0082;text-transform:uppercase;letter-spacing:1px;margin-bottom:6px;\">Applicability<\/div>\n    <p style=\"margin:0;font-size:14px;color:#333;line-height:1.6;\">This DPA is incorporated by reference into the <a href=\"https:\/\/www.e-signature.eu\/en\/terms-and-conditions\/\" style=\"color:#4B0082;font-weight:600;\">General Terms and Conditions<\/a> of e-Signature.eu. Acceptance of the General Terms and Conditions \u2014 whether by account creation, first order, or continued use of the platform \u2014 constitutes full acceptance of this DPA. Clients requiring a bilaterally signed copy may contact <a href=\"mailto:contact@e-signature.eu\" style=\"color:#4B0082;font-weight:600;\">contact@e-signature.eu<\/a>.<\/p>\n  <\/div>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Parties<\/h2>\n  <p style=\"font-size:15px;color:#333;margin:0 0 12px 0;\">This DPA applies to any entity (the <strong>&#8220;Data Controller&#8221;<\/strong>) using the e-Signature.eu platform operated by VisitOnWeb srl, BE 0894 404 534, 42 Avenue L\u00e9on Houyoux, 1160 Brussels, Belgium (the <strong>&#8220;Data Processor&#8221;<\/strong>).<\/p>\n  <p style=\"font-size:15px;color:#333;margin:0 0 32px 0;\">Clients requiring a bilaterally executed version of this DPA with their entity details formally recorded may contact <a href=\"mailto:contact@e-signature.eu\" style=\"color:#4B0082;font-weight:600;\">contact@e-signature.eu<\/a>.<\/p>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Preamble<\/h2>\n  <p style=\"font-size:15px;color:#333;margin:0 0 12px 0;\">This Data Processing Agreement (&#8220;DPA&#8221;) governs the processing of personal data by the Data Processor on behalf of the Data Controller in connection with the Electronic Signature Services provided through e-Signature.eu.<\/p>\n  <p style=\"font-size:15px;color:#333;margin:0 0 24px 0;\">This DPA is concluded in accordance with Article 28 of Regulation (EU) 2016\/679 (GDPR) and forms part of the contractual relationship established by the acceptance of the General Terms and Conditions of e-Signature.eu.<\/p>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Article 1 \u2014 Definitions<\/h2>\n  <p style=\"font-size:15px;color:#333;margin:0 0 10px 0;\"><strong>1.1<\/strong> &nbsp;&#8220;Personal Data&#8221; \u2014 any information relating to an identified or identifiable natural person processed in connection with the Electronic Signature Services.<\/p>\n  <p style=\"font-size:15px;color:#333;margin:0 0 10px 0;\"><strong>1.2<\/strong> &nbsp;&#8220;Electronic Signature Services&#8221; \u2014 electronic signature services provided through e-Signature.eu, relying on eIDAS-compliant Trust Service Providers.<\/p>\n  <p style=\"font-size:15px;color:#333;margin:0 0 24px 0;\"><strong>1.3<\/strong> &nbsp;&#8220;Sub-processor&#8221; \u2014 any third-party processor engaged by the Data Processor to process Personal Data on its behalf.<\/p>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Article 2 \u2014 Scope and Purpose<\/h2>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">2.1 &nbsp;Subject matter<\/h3>\n  <p style=\"font-size:15px;color:#333;margin:0 0 16px 0;\">The Data Processor processes Personal Data on behalf of the Data Controller solely for the purpose of providing Electronic Signature Services as ordered by the Data Controller through the e-Signature.eu platform.<\/p>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">2.2 &nbsp;Duration<\/h3>\n  <p style=\"font-size:15px;color:#333;margin:0 0 16px 0;\">This DPA remains in force for the duration of the service relationship and survives termination until all Personal Data has been returned or deleted in accordance with Article 9.<\/p>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">2.3 &nbsp;Nature of processing<\/h3>\n  <p style=\"font-size:15px;color:#333;margin:0 0 10px 0;\">Processing activities include:<\/p>\n  <ul style=\"margin:0 0 24px 0;padding-left:24px;\">\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Collection of signers&#8217; identification and contact data for the purpose of sending signature requests<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Transmission of identification data to qualified Trust Service Providers for identity verification and signature issuance<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Storage of signed documents for a maximum period of <strong>thirty (30) days<\/strong> from the date of signature, for the sole purpose of enabling download by the Data Controller<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Permanent and automatic deletion of documents upon expiry of the 30-day period, or upon manual deletion by the Data Controller, whichever occurs first<\/li>\n  <\/ul>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Article 3 \u2014 Categories of Data and Data Subjects<\/h2>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">3.1 &nbsp;Personal Data processed may include:<\/h3>\n  <ul style=\"margin:0 0 16px 0;padding-left:24px;\">\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Identity data: name, first name, date of birth, ID document references<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Contact data: email address, phone number<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Electronic identification data: credentials used for identity verification (method-dependent)<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Signature metadata: IP address, timestamp, device information, audit trail elements<\/li>\n  <\/ul>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">3.2 &nbsp;Categories of data subjects<\/h3>\n  <p style=\"font-size:15px;color:#333;margin:0 0 24px 0;\">Individuals designated by the Data Controller as signatories, including employees, contractors, clients, or any other natural persons authorised by the Data Controller to sign documents electronically.<\/p>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Article 4 \u2014 Obligations of the Data Processor<\/h2>\n  <p style=\"font-size:15px;color:#333;margin:0 0 10px 0;\">The Data Processor shall:<\/p>\n  <ul style=\"margin:0 0 24px 0;padding-left:24px;\">\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Process Personal Data only on documented instructions from the Data Controller, unless required to do so by EU or Member State law<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Ensure that persons authorised to process Personal Data are subject to confidentiality obligations<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Implement appropriate technical and organisational measures as described in Article 5<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Assist the Data Controller in responding to data subject rights requests under Chapter III GDPR<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Assist the Data Controller in ensuring compliance with Articles 32 to 36 GDPR<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">At the Data Controller&#8217;s choice, delete or return all Personal Data upon termination of services<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Make available all information reasonably necessary to demonstrate compliance with Article 28 GDPR<\/li>\n  <\/ul>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Article 5 \u2014 Security Measures<\/h2>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">5.1 &nbsp;Technical measures<\/h3>\n  <ul style=\"margin:0 0 16px 0;padding-left:24px;\">\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">SSL\/TLS encryption for all data transmissions between users and the platform<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Encrypted storage of documents and associated audit trails<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Secure API connections with qualified Trust Service Providers<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Application of security updates within 30 days (critical patches within 72 hours)<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Multi-factor authentication (MFA) for all administrative access<\/li>\n  <\/ul>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">5.2 &nbsp;Organisational measures<\/h3>\n  <ul style=\"margin:0 0 16px 0;padding-left:24px;\">\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Access control and least-privilege authorisation procedures<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Ongoing security awareness for all persons with access to personal data<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Documented incident response procedures<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Quarterly review of access rights to critical systems<\/li>\n  <\/ul>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">5.3 &nbsp;Sub-processor security<\/h3>\n  <p style=\"font-size:15px;color:#333;margin:0 0 24px 0;\">The Data Processor relies additionally on security measures implemented by its Sub-processors. All Trust Service Providers are eIDAS-qualified and supervised by competent European national authorities.<\/p>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Article 6 \u2014 Sub-processors<\/h2>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">6.1 &nbsp;General authorisation<\/h3>\n  <p style=\"font-size:15px;color:#333;margin:0 0 16px 0;\">The Data Controller grants the Data Processor general authorisation to engage Sub-processors, subject to the conditions of this Article.<\/p>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 12px 0;\">6.2 &nbsp;Current Sub-processors<\/h3>\n\n  \n  <div style=\"overflow-x:auto;margin-bottom:16px;\">\n    <table style=\"width:100%;border-collapse:collapse;font-size:13px;\">\n      <thead>\n        <tr style=\"background:#4B0082;\">\n          <th style=\"text-align:left;padding:10px 12px;color:#fff;font-weight:700;border:1px solid #4B0082;\">Sub-processor<\/th>\n          <th style=\"text-align:left;padding:10px 12px;color:#fff;font-weight:700;border:1px solid #4B0082;\">Role<\/th>\n          <th style=\"text-align:left;padding:10px 12px;color:#fff;font-weight:700;border:1px solid #4B0082;\">Location<\/th>\n          <th style=\"text-align:left;padding:10px 12px;color:#fff;font-weight:700;border:1px solid #4B0082;\">Scope<\/th>\n        <\/tr>\n      <\/thead>\n      <tbody>\n        <tr style=\"background:#ffffff;\">\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">eID Easy O\u00dc (Estonia)<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">Signature engine &amp; TSP aggregator<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">EU \u2014 Estonia<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">All signature methods<\/td>\n        <\/tr>\n        <tr style=\"background:#F5F5F5;\">\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">itsme\u00ae \/ Belgian Mobile ID SA (Belgium)<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">QES \u2014 identity verification<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">EU \u2014 Belgium<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">itsme\u00ae signers only<\/td>\n        <\/tr>\n        <tr style=\"background:#ffffff;\">\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">Evrotrust Technologies AD (Bulgaria)<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">QES \u2014 identity verification<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">EU \u2014 Bulgaria<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">Evrotrust signers only<\/td>\n        <\/tr>\n        <tr style=\"background:#F5F5F5;\">\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">Veriff O\u00dc (Estonia)<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">AES \u2014 identity verification<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">EU\/EEA *<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">Veriff signers only<\/td>\n        <\/tr>\n        <tr style=\"background:#ffffff;\">\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">Mollie B.V. (Netherlands)<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">Payment processing<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">EU \u2014 Netherlands<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">Billing data only<\/td>\n        <\/tr>\n        <tr style=\"background:#F5F5F5;\">\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">CloudConvert GmbH (Germany)<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">File conversion<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">EU \u2014 Germany<\/td>\n          <td style=\"padding:9px 12px;border:1px solid #ddd;color:#333;\">Upload conversion only<\/td>\n        <\/tr>\n      <\/tbody>\n    <\/table>\n  <\/div>\n\n  <div style=\"background:#EDE7F6;border-left:4px solid #4B0082;border-radius:0 6px 6px 0;padding:14px 18px;margin-bottom:24px;\">\n    <p style=\"margin:0;font-size:13px;color:#333;line-height:1.6;\">* Veriff processes identity verification data within the EU\/EEA. For detailed information on Veriff&#8217;s data infrastructure, refer to eID Easy&#8217;s documentation, as eID Easy is the contracting party with Veriff.<\/p>\n  <\/div>\n\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">6.3 &nbsp;Sub-processor obligations<\/h3>\n  <p style=\"font-size:15px;color:#333;margin:0 0 16px 0;\">The Data Processor ensures that Sub-processors are bound by contracts imposing equivalent data protection obligations as set out in this DPA.<\/p>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">6.4 &nbsp;Changes to Sub-processors<\/h3>\n  <p style=\"font-size:15px;color:#333;margin:0 0 24px 0;\">The Data Processor shall inform the Data Controller of any intended addition or replacement of Sub-processors at least 30 days in advance. The Data Controller may object on reasonable grounds within 15 days of notification. Absence of objection within that period constitutes acceptance.<\/p>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Article 7 \u2014 Data Location<\/h2>\n  <p style=\"font-size:15px;color:#333;margin:0 0 12px 0;\">Personal Data is processed and stored within the European Union or the European Economic Area by VisitOnWeb srl and its Sub-processors, subject to the qualification in Article 6.2 regarding Veriff.<\/p>\n  <p style=\"font-size:15px;color:#333;margin:0 0 24px 0;\">No transfer of Personal Data outside the EU\/EEA is made by VisitOnWeb srl. To the extent that any Sub-processor may process data outside the EU\/EEA, such transfers are subject to appropriate safeguards under Chapter V GDPR.<\/p>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Article 8 \u2014 Data Breach Notification<\/h2>\n  <p style=\"font-size:15px;color:#333;margin:0 0 12px 0;\">The Data Processor shall notify the Data Controller without undue delay and no later than <strong>72 hours<\/strong> after becoming aware of a personal data breach likely to result in a risk to the rights and freedoms of natural persons.<\/p>\n  <p style=\"font-size:15px;color:#333;margin:0 0 10px 0;\">Such notification shall include, to the extent available at the time:<\/p>\n  <ul style=\"margin:0 0 24px 0;padding-left:24px;\">\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">The nature of the breach and categories of data affected<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">The approximate number of data subjects concerned<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">The likely consequences of the breach<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Measures taken or proposed to address the breach and mitigate its effects<\/li>\n  <\/ul>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Article 9 \u2014 Return or Deletion of Data<\/h2>\n  <p style=\"font-size:15px;color:#333;margin:0 0 12px 0;\">Upon termination of services, the Data Processor shall, at the Data Controller&#8217;s written choice:<\/p>\n  <ul style=\"margin:0 0 12px 0;padding-left:24px;\">\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Return all Personal Data in a commonly used electronic format; or<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Securely delete all Personal Data and provide written confirmation of deletion<\/li>\n  <\/ul>\n  <p style=\"font-size:15px;color:#333;margin:0 0 12px 0;\">Signed documents and associated audit trails are automatically and permanently deleted 30 days after the date of signature, or upon manual deletion by the Data Controller, whichever occurs first.<\/p>\n  <p style=\"font-size:15px;color:#333;margin:0 0 24px 0;\">Data may be retained beyond these periods only where required by applicable EU or Member State law (including Belgian accounting and tax obligations applicable to the Data Processor).<\/p>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Article 10 \u2014 Audit and Compliance Demonstration<\/h2>\n  <p style=\"font-size:15px;color:#333;margin:0 0 12px 0;\">The Data Processor shall make available to the Data Controller all information reasonably necessary to demonstrate compliance with this DPA and with Article 28 GDPR, including this DPA, applicable security documentation, and the current list of Sub-processors.<\/p>\n  <p style=\"font-size:15px;color:#333;margin:0 0 10px 0;\">Where the Data Controller requires additional assurance, it may mandate an independent auditor, subject to:<\/p>\n  <ul style=\"margin:0 0 12px 0;padding-left:24px;\">\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">At least 30 days&#8217; prior written notice<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Audit conducted during normal business hours without unreasonably disrupting operations<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Costs borne by the Data Controller<\/li>\n    <li style=\"font-size:15px;color:#333;margin-bottom:6px;\">Auditor bound by appropriate confidentiality obligations<\/li>\n  <\/ul>\n  <div style=\"background:#EDE7F6;border-left:4px solid #4B0082;border-radius:0 6px 6px 0;padding:14px 18px;margin-bottom:24px;\">\n    <p style=\"margin:0;font-size:13px;color:#333;line-height:1.6;\">Given the size of the Data Processor&#8217;s organisation, audit requests will be accommodated primarily through document review and written responses. On-site audits require mutual agreement and reasonable advance planning.<\/p>\n  <\/div>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Article 11 \u2014 Liability<\/h2>\n  <p style=\"font-size:15px;color:#333;margin:0 0 12px 0;\">Each Party shall be liable for damages caused by processing that infringes GDPR, in accordance with Articles 82\u201384 GDPR.<\/p>\n  <p style=\"font-size:15px;color:#333;margin:0 0 12px 0;\">The Data Processor&#8217;s liability to the Data Controller under this DPA is limited to direct damages and shall not exceed the total fees paid by the Data Controller in the twelve (12) months preceding the event giving rise to the claim.<\/p>\n  <p style=\"font-size:15px;color:#333;margin:0 0 24px 0;\">This limitation does not apply in cases of wilful misconduct or gross negligence.<\/p>\n\n  \n  <h2 style=\"font-size:18px;font-weight:700;color:#4B0082;border-bottom:2px solid #4B0082;padding-bottom:8px;margin:40px 0 16px 0;\">Article 12 \u2014 Miscellaneous<\/h2>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">12.1 &nbsp;Governing law and jurisdiction<\/h3>\n  <p style=\"font-size:15px;color:#333;margin:0 0 16px 0;\">This DPA is governed by Belgian law and the GDPR. Any dispute arising from this DPA shall be subject to the exclusive jurisdiction of the courts of Brussels, Belgium.<\/p>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">12.2 &nbsp;Relationship to General Terms and Conditions<\/h3>\n  <p style=\"font-size:15px;color:#333;margin:0 0 12px 0;\">This DPA is published at <strong>https:\/\/www.e-signature.eu\/dpa\/<\/strong> and is incorporated by reference into the General Terms and Conditions of e-Signature.eu. Acceptance of the General Terms and Conditions \u2014 whether by account creation, first order, or continued use of the platform \u2014 constitutes full acceptance of this DPA.<\/p>\n  <p style=\"font-size:15px;color:#333;margin:0 0 12px 0;\">In the event of conflict between this DPA and the General Terms and Conditions on matters of data protection, this DPA shall prevail.<\/p>\n  <p style=\"font-size:15px;color:#333;margin:0 0 16px 0;\">Clients requiring a bilaterally signed copy of this DPA may contact <a href=\"mailto:contact@e-signature.eu\" style=\"color:#4B0082;font-weight:600;\">contact@e-signature.eu<\/a>. The Data Processor will provide a countersigned version upon request, without modification to the standard terms unless otherwise agreed in writing.<\/p>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">12.3 &nbsp;Amendments<\/h3>\n  <p style=\"font-size:15px;color:#333;margin:0 0 16px 0;\">The Data Processor reserves the right to update this DPA to reflect changes in applicable law or Sub-processor arrangements, with 30 days&#8217; prior notice published on this page.<\/p>\n  <h3 style=\"font-size:15px;font-weight:700;color:#212121;margin:0 0 8px 0;\">12.4 &nbsp;Severability<\/h3>\n  <p style=\"font-size:15px;color:#333;margin:0 0 32px 0;\">If any provision of this DPA is found invalid or unenforceable, the remaining provisions shall continue in full force and effect.<\/p>\n\n  \n  <div style=\"margin-top:40px;padding-top:20px;border-top:1px solid #eee;display:flex;justify-content:space-between;flex-wrap:wrap;gap:8px;\">\n    <div style=\"font-size:12px;color:#999;\">Version 1.0 \u2014 June 2026<\/div>\n    <div style=\"font-size:12px;color:#999;\">VisitOnWeb srl \u2014 BE 0894 404 534 \u2014 <a href=\"mailto:contact@e-signature.eu\" style=\"color:#4B0082;\">contact@e-signature.eu<\/a><\/div>\n  <\/div>\n\n<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>VisitOnWeb srl \u2014 e-Signature.eu Data Processing Agreement Pursuant to Article 28 of Regulation (EU) 2016\/679 (GDPR) &nbsp;\u00b7&nbsp; Version 1.0 &nbsp;\u00b7&nbsp;&#8230;<\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-23428","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.e-signature.eu\/de\/wp-json\/wp\/v2\/pages\/23428","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.e-signature.eu\/de\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.e-signature.eu\/de\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.e-signature.eu\/de\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.e-signature.eu\/de\/wp-json\/wp\/v2\/comments?post=23428"}],"version-history":[{"count":2,"href":"https:\/\/www.e-signature.eu\/de\/wp-json\/wp\/v2\/pages\/23428\/revisions"}],"predecessor-version":[{"id":23441,"href":"https:\/\/www.e-signature.eu\/de\/wp-json\/wp\/v2\/pages\/23428\/revisions\/23441"}],"wp:attachment":[{"href":"https:\/\/www.e-signature.eu\/de\/wp-json\/wp\/v2\/media?parent=23428"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}