How to use this DPA
Parties & Roles
This Data Processing Agreement ("DPA") is entered into between 3B Data GmbH, Lena-Christ-Str. 2, 82031 Grünwald, Germany ("kwery", "Processor") and the business customer ("Customer", "Controller") that uses the Services.
Customer acts as Controller within the meaning of Art. 4(7) GDPR with respect to any personal data submitted to or generated through the Services. kwery acts as Processor within the meaning of Art. 4(8) GDPR and processes such personal data only on the documented instructions of the Controller.
Subject Matter, Duration & Purpose
- Subject matter: Provision of kwery's pricing-data APIs and related Services as described in the Documentation and any applicable Order Form.
- Duration: For the term of Customer's subscription to the Services and any post-termination return or deletion period.
- Nature & purpose: Hosting, transmission, storage, retrieval, logging, and support related to Customer's use of the Services.
- Documented instructions: The Terms of Service, this DPA, any Order Form, and Customer's lawful in-product configurations constitute Customer's documented processing instructions.
Categories of Data & Data Subjects
kwery does not require Customer to submit personal data in order to use the Services. Where personal data is nevertheless processed, the following typically applies:
- Categories of data subjects: Customer's authorized users, administrators, and developers; any other natural persons whose data Customer chooses to submit.
- Categories of personal data: Account identifiers (name, business email, role), authentication and API key metadata, support communications, usage and request logs, IP addresses, and audit data.
- Special categories: kwery does not intentionally process special categories of personal data (Art. 9 GDPR). Customer shall not submit such data through the Services.
Processor Obligations
- Process personal data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by Union or Member State law;
- Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation;
- Implement and maintain the technical and organizational measures described in Section 7;
- Assist Customer, taking into account the nature of the processing, in fulfilling its obligations to respond to data subject requests (Section 8) and to meet its obligations under Art. 32–36 GDPR;
- Make available to Customer all information necessary to demonstrate compliance with Art. 28 GDPR;
- Immediately inform Customer if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
Sub-processors
Customer grants kwery a general authorization to engage sub-processors for the performance of the Services, subject to the conditions of Art. 28(2) and (4) GDPR. The current list is published at kwery.co/subprocessors and forms part of this DPA.
kwery shall notify Customer of any intended addition or replacement of sub-processors at least thirty (30) days in advance, by updating the sub-processor page and, where Customer has subscribed to notifications, by email. Customer may object on reasonable data protection grounds within that period; if the parties cannot agree on a solution, Customer may terminate the affected Services with pro-rata refund of pre-paid fees.
kwery imposes on each sub-processor data protection obligations no less protective than those set out in this DPA and remains liable to Customer for the performance of each sub-processor's obligations.
International Transfers
Personal data processed under this DPA is primarily stored and processed within the European Economic Area. Where personal data is transferred to a third country that has not been recognized by the European Commission as providing an adequate level of protection, the parties rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (Controller-to-Processor), incorporated into this DPA by reference, supplemented by appropriate technical and organizational safeguards.
Technical & Organizational Measures
kwery implements and maintains appropriate technical and organizational measures pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit (TLS 1.2+) and at rest;
- Role-based access control with least-privilege principles and multi-factor authentication for administrative access;
- Network segmentation, firewalling, and continuous security monitoring;
- Audit logging of administrative and security-relevant events;
- Regular backups with tested restoration procedures and documented retention windows;
- Vulnerability management, dependency scanning, and periodic security review of changes;
- Incident response procedures including defined roles, escalation paths, and post-incident review;
- Confidentiality undertakings and security training for all personnel with access to personal data.
kwery may update these measures from time to time, provided the level of protection is not materially decreased. The current technical and organizational measures form Annex II to this DPA and are available on request.
Data Subject Requests
Taking into account the nature of the processing, kwery shall assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling its obligation to respond to requests for exercising data subject rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection).
If a data subject contacts kwery directly with a request relating to Customer's personal data, kwery shall, without responding substantively, forward the request to Customer without undue delay.
Personal Data Breach Notification
kwery shall notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware, of a personal data breach affecting Customer's personal data. The notification shall, to the extent known at the time, include the nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed to address the breach and mitigate its possible adverse effects.
kwery shall reasonably cooperate with Customer in the investigation, mitigation, and remediation of any such incident.
Audit Rights
kwery shall make available to Customer information reasonably necessary to demonstrate compliance with Art. 28 GDPR, including third-party audit reports, security certifications, and written responses to security questionnaires.
Customer may, no more than once per calendar year and on at least thirty (30) days' prior written notice, request an audit of kwery's compliance with this DPA. Audits shall be conducted during business hours, in a manner that does not disrupt kwery's operations, and subject to confidentiality. kwery may satisfy the audit obligation by providing the results of an independent third-party audit covering the requested scope.
Return & Deletion
On termination of the Services, kwery shall, at Customer's choice, delete or return all personal data processed on Customer's behalf and delete existing copies, unless Union or Member State law requires further storage. Routine backups containing such personal data shall be deleted in accordance with kwery's standard retention cycle and remain protected by this DPA until deletion.
Liability
Liability under this DPA is governed by the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits either party's statutory liability under Art. 82 GDPR.
Effective Date & Versioning
This DPA becomes effective upon Customer's acceptance of the Terms of Service or first use of the Services, whichever occurs first. kwery may update this DPA from time to time to reflect legal, regulatory, or operational changes. Material changes will be communicated with at least thirty (30) days' notice via email or the kwery dashboard.
3B Data GmbH
Lena-Christ-Str. 2
82031 Grünwald, Germany
Data Protection Officer: dsb@kwery.co
Sub-processors list: kwery.co/subprocessors