Introduction
This DPA forms part of the agreement between MIXCONIX.COM SRL (CUI: RO 31654250), with registered office at Str. Brândușelor 74, Green Centre, Brașov, Romania ("Processor" or "Mixconix"), and the customer identified in the Order Form ("Controller" or "Customer"). It governs processing of Personal Data in connection with Mixconix applications on SAP Business Technology Platform (SAP BTP).
1. Definitions
- Applicable Data Protection Law: GDPR and applicable local data protection laws.
- GDPR: Regulation (EU) 2016/679.
- Personal Data, Processing, Controller, Processor, Data Subject, Personal Data Breach, Supervisory Authority: As defined in GDPR.
- Sub-processor: Third parties engaged by Processor to process Personal Data on behalf of Controller.
- Services: Mixconix applications and related support, maintenance, and professional services.
2. Roles of the Parties
Controller determines purposes and means of Processing. Processor processes Personal Data only on documented instructions from Controller regarding data categories, purposes, retention, and transfers.
3. Duration
This DPA applies for the Agreement term and any period during which Processor retains Personal Data on behalf of Controller, including limited retention for evidence, audit, or legal obligations.
4. Nature and Purpose of Processing
- Providing and operating Mixconix applications within SAP BTP and customer environments.
- Validating business partner data via external APIs (e.g., VIES, OpenIBAN, credit agencies); scanning and processing data via connected devices; monitoring and analytics.
- Providing customer support, troubleshooting, monitoring, and security (logs, backups).
- Improving and maintaining Services, strictly as instructed, without combining Controller data with other clients' data.
5. Categories of Data and Data Subjects
Data Subjects: Customer personnel and business partners (suppliers, customers, contractors).
Personal Data categories:
- Identification and professional data (name, role)
- Contact data (email, phone)
- VAT numbers
- IBAN
- Address
- Technical/usage data (logs, IP, device/browser)
6. Processor Obligations
Processor shall:
- Process Personal Data only on documented Controller instructions, including transfers.
- Ensure authorized persons are bound by confidentiality obligations.
- Implement and maintain appropriate technical and organisational measures (TOMs) per Annex II, including access controls, encryption in transit, vulnerability management, logging/monitoring, backup and recovery.
- Assist Controller with Data Subject requests and GDPR Articles 32–36 compliance.
- Notify Controller without undue delay upon awareness of Personal Data Breach with timely information to support notifications.
- At Controller's choice, delete or return all Personal Data after Services end; delete copies unless legally required.
- Make available information necessary to demonstrate DPA compliance; allow audits per Section 11.
7. Sub-processors
Controller authorizes Processor to engage Sub-processors listed in Annex III and additional Sub-processors for hosting or delivery, provided Processor:
- (a) imposes data protection terms no less protective than this DPA;
- (b) remains liable for Sub-processor performance;
- (c) provides advance notice of changes, allowing Controller to object on reasonable grounds.
8. International Data Transfers
Where Processing involves transfers outside EEA/UK to countries without adequacy decisions, Processor ensures appropriate safeguards under GDPR Chapter V, including European Commission Standard Contractual Clauses (SCCs) (Module 2: Controller-to-Processor and/or Module 3: Processor-to-Processor), supplemented by transfer impact assessments and additional measures where required.
9. Security Measures
Processor implements security measures appropriate to risk as described in Annex II. Mixconix operates under certified Quality Management System (ISO 9001) and Information Security Management System (ISO/IEC 27001). Certification evidence available upon request.
10. Personal Data Breach Notification
- Notify Controller without undue delay upon breach awareness.
- Provide breach details: nature, categories and approximate number of affected Data Subjects and records, likely consequences, and proposed remedial measures.
- Cooperate in fulfilling Supervisory Authority and Data Subject notification obligations.
11. Audits and Certifications
Upon reasonable prior notice and no more than once per 12 months (unless required by Supervisory Authority or following breach), Controller may conduct audits limited to materials verifying DPA compliance. Audits minimize disruption and preserve confidentiality and security. Processor may satisfy audit requests via recent certifications, audit summaries, or equivalent assurances.
12. Assistance and Records
Processor maintains Processing activity records and shall, upon request, provide reasonable assistance to Controller in demonstrating Applicable Data Protection Law compliance.
13. Data Deletion and Return
Within 30 days after Agreement termination (or agreed period), Processor shall, at Controller's option, securely delete or return Personal Data and delete copies, unless legal retention is required.
14. Confidentiality
Processor ensures authorized Processing persons are subject to appropriate confidentiality obligations and receive regular data protection and information security training.
15. Liability
Parties' DPA liability is governed by limitations and exclusions in the underlying Agreement, to maximum extent permitted by law.
16. Miscellaneous
Invalid provisions do not affect remaining provisions. DPA prevails over Agreement regarding data protection matters. Governed by Romania laws and Brașov competent courts unless otherwise agreed.
Annex I — Description of Processing Activities
| Controller | As per Order Form |
| Processor | MIXCONIX.COM SRL (CUI: RO 31654250), Str. Brândușelor 74, Green Centre, Brașov, Romania; contact: office@mixconix.com |
| Subject matter | Business data processing within Mixconix applications |
| Duration | Agreement term plus limited retention per Section 13 |
| Nature and purpose | Mixconix application provision; external API validations and integrations; support and security operations |
| Types of Personal Data | Identification/professional data; contact data; VAT numbers; IBAN; address; technical/usage data (logs, IP) |
| Categories of Data Subjects | Customer personnel and business partners (suppliers, customers) |
Annex II — Technical and Organisational Measures (TOMs)
- Access control: Role-based access; least privilege; MFA for privileged accounts.
- Data protection: Encryption in transit (TLS); encryption at rest where platform-supported; secure key management.
- Application security: Secure SDLC; code review; dependency scanning; vulnerability and patch management.
- Operations: Change management; logging and monitoring; alerting; regular backups and recovery testing.
- Network security: Segmentation; firewalling; WAF/DoS protections where applicable.
- Supplier risk: DPAs with Sub-processors; SCCs for transfers; periodic vendor reviews.
- Business continuity: Documented incident response; disaster recovery plans; regular exercises.
- Data minimization & retention: Log retention and data purging aligned with Controller instructions.
- Employee measures: Confidentiality agreements; security and privacy training; onboarding/offboarding controls.
Annex III — Authorised Sub-processors
The following Sub-processors are engaged by MIXCONIX.COM SRL for Mixconix Services, or may be engaged depending on deployment model and region. Mixconix provides advance notice of changes; Controller may object on reasonable grounds within the notice period.
The current list of Sub-processors is available upon request from office@mixconix.com and is maintained as a living document.
Annex IV — Cross-Border Transfers and Standard Contractual Clauses (SCCs)
A. Incorporation and Scope
SCCs Incorporated. Where required by GDPR Article 46, the Parties agree that the European Commission's Standard Contractual Clauses of 4 June 2021 (Commission Implementing Decision (EU) 2021/914) are incorporated by reference as follows:
- Module 2 (Controller → Processor) for transfers from Controller (data exporter) in EEA/UK/CH to Processor (data importer) in third countries without adequacy decisions.
- Module 3 (Processor → Sub-processor) for onward transfers from Processor (exporter) to Sub-processor (importer) in such third countries.
Annex Mapping. DPA's Annex I serves as SCC Annex I (Description of transfer); Annex II serves as SCC Annex II (TOMs); Annex III serves as SCC Annex III (Sub-processor list).
Precedence. In case of conflict between this DPA and the SCCs, the SCCs prevail to the extent of the conflict (SCCs, Clause 5).
B. Parties and Roles
- Data exporter (Module 2): The Controller identified in Annex I.
- Data importer (Module 2): MIXCONIX.COM SRL (Processor).
- Data exporter (Module 3): MIXCONIX.COM SRL (Processor).
- Data importer (Module 3): The Sub-processor identified in Annex III.
C. Docking Clause (SCCs, Clause 7)
The Parties enable Clause 7 (Docking): additional controllers/processors may accede to the SCCs by executing an adherence document referencing this DPA and Annexes.
D. Description of Transfer (SCCs, Annex I(A)–(C))
Elements required by SCCs Annex I(A)–(C) are set out in DPA Annex I by reference, including: exporter/importer identities and contacts, categories of data subjects and data, frequency, nature and purpose of processing, processing duration and retention, and competent supervisory authority.
E. Technical and Organisational Measures (SCCs, Annex II)
The importer implements TOMs described in DPA Annex II (encryption in transit (TLS 1.2+), encryption at rest where platform-supported, key management, access control/MFA, logging & monitoring, secure development, BCM/backup, third-party due diligence, privacy by design). For Module 3, each Sub-processor must implement TOMs not less protective than Annex II.
F. Sub-processor Authorisation (SCCs, Clause 9)
- General authorisation applies. Current Sub-processors are listed in Annex III.
- The importer will notify exporter of intended Sub-processor changes (additions/replacements) at least 10 business days before engagement via standard notice channel (email to contact in Annex I).
- Exporter may object on reasonable data-protection grounds; Parties will discuss in good faith. If unresolved within reasonable period, exporter may suspend/terminate affected processing (without penalty) and receive prorated refund for prepaid unused fees for impacted functionality.
G. Local Laws & Government Access Requests (SCCs, Clauses 14–15)
- Transfer Impact Assessment (TIA). The importer has assessed, to best knowledge and experience, destination country laws relevant to Clause 14. The importer will re-assess periodically or upon material change.
- Transparency & Challenge. If the importer receives legally binding public authority requests for personal data:
- It will notify the exporter without undue delay (unless legally prohibited) and seek to lift any prohibition.
- It will review request legality and challenge where reasonable.
- It will disclose only minimum strictly required data and keep records.
- It will provide aggregate transparency reporting where permitted (request counts).
- Supplementary Measures. The importer maintains encryption in transit, access controls, data minimisation, and logging, and will apply additional case-by-case measures where needed to maintain essentially equivalent protection.
H. Data Subject Rights & Redress (SCCs, Clauses 10–12)
The importer will assist the exporter in handling data-subject requests and complaints per SCCs and GDPR. Third-party beneficiary rights under SCCs are upheld; copies of SCCs may be provided to data subjects on request with commercially sensitive information redacted.
I. Supervisory Authority, Governing Law & Forum (SCCs, Clauses 13, 17–18)
- Supervisory Authority (Clause 13). The competent authority is the authority of the exporter's main EU establishment; where exporter is established in Romania, the competent authority is ANSPDCP (Romanian Supervisory Authority).
- Governing Law (Clause 17). The Parties select the laws of Romania (an EU Member State allowing third-party beneficiary rights).
- Jurisdiction (Clause 18). Disputes shall be brought before Romania courts; the courts of Brașov have jurisdiction where appropriate and permitted.
J. UK and Switzerland Add-ons
- United Kingdom. For transfers subject to UK GDPR, the Parties incorporate the ICO International Data Transfer Addendum (IDTA) Addendum to the EU SCCs (version B.1.0 or latest).
- Part 1 Tables: (i) Parties & contacts per DPA Annex I; (ii) Selected SCCs: EU 2021/914, Module 2 and/or 3; (iii) Appendix information: DPA Annexes I–III; (iv) Mandatory Clauses per ICO template.
- Governing law & courts (UK): England and Wales.
- Switzerland. For transfers subject to Swiss FADP, the Parties incorporate the SCCs with adaptations: references to "EU GDPR" include the Swiss FADP; references to "competent supervisory authority" include the Swiss FDPIC; jurisdiction is Switzerland per Clause 18.
K. Return/Deletion & Termination
Upon SCCs-governed processing termination, the importer will delete or return personal data at exporter's choice within 30 days, unless legally required. Backups are overwritten on next scheduled cycle.
L. Copies and Access to SCCs
The Parties will make current SCC copies (including this Annex and referenced Annexes I–III) available to supervisory authorities upon request. Data subjects may receive copies on request, with confidential information redactions.
M. Conflicts
If DPA terms (including other annexes) conflict with incorporated SCCs, the SCCs control. If UK Addendum or Swiss adaptations conflict with SCCs, the local addendum/adaptation controls for the respective transfer.
DPA questions? Contact office@mixconix.com.