savien Legal
Data Processing Agreement (DPA)
Data processing agreement pursuant to Art. 28 GDPR.
- Document ID
- dpa/en
- Version / Updated
- 2026-09-16
- Effective from
- 16 September 2026
- Contact
- privacy@savien.io
- SHA-256
- 24166b6e77354d58315e5fe183c0f6f9f109b468dd4a078158aeb72e71e43749
Last updated: 2026-09-16
This DPA applies between the respective customer as controller and Davis Gabriels Kalnozols, trading under the business name “savien”, Meierberger Str. 14, 31737 Rinteln, Germany (“savien”), as processor.
This DPA is incorporated only by express acceptance for a specific organisation by its owner or a person with demonstrable authority to represent it. Registration, invitation, connection or use alone does not constitute acceptance of this DPA.
1. Subject Matter and Duration
The subject matter of processing is the provision, operation, maintenance, support and security of savien as B2B SaaS.
The duration of processing corresponds to the term of the main agreement. After contract end, personal data is returned or deleted at the controller's choice in accordance with Section 13.
2. Role Allocation
The customer is controller for personal data that it or its users process in savien for their own B2B processes. The customer determines the purposes and means of such processing.
savien processes such customer personal data as processor unless it acts as controller for specific processing.
savien remains controller for its own contract, billing, security, website, support and operational data. These processing activities are described in the Privacy Policy and are not subject to this DPA.
3. Nature and Purpose of Processing
Processing is carried out for:
- Providing platform functions.
- Storing and displaying customer data.
- Authentication and permission checks.
- Communication between merchants, suppliers and employees.
- Document and file management.
- Email and in-app notifications.
- Billing, support, error analysis, security, backups and misuse prevention.
- Optional third-party integrations activated by the customer.
- Export, portability, return and deletion of customer data under the contract, GDPR and, where applicable, the EU Data Act.
4. Categories of Data Subjects
- Users and employees of the customer.
- Merchants, suppliers and their contact persons.
- Invited users and business partners.
- Support contacts.
- Other persons whose data the customer enters or uploads to savien.
5. Categories of Personal Data
- Names, company assignment, roles and permissions.
- Email addresses, telephone numbers, business addresses.
- Authentication and session data.
- Order, delivery, item, catalogue, price, shipment and return data.
- Comments, documents, files and metadata.
- Notification and communication data.
- Integration data such as BillBee credentials and SKU mappings.
- Usage, security, error and audit data.
Special categories of personal data under Art. 9 GDPR and data under Art. 10 GDPR are not intended. The customer undertakes not to process such data in savien without prior agreement and appropriate safeguards.
6. Customer Instructions
We process personal data only on documented customer instructions unless a legal obligation requires otherwise. Instructions arise from the main agreement, this DPA, settings in the application and documented individual instructions.
Instructions must be issued in text form or through the application. Oral instructions must be confirmed in text form without undue delay.
If we consider an instruction unlawful, we will inform the customer to the extent legally permissible. We may suspend an obviously unlawful instruction until it is confirmed, modified or withdrawn.
7. Confidentiality
We bind all persons with access to personal data to confidentiality unless they are already subject to a statutory confidentiality obligation.
8. Technical and Organisational Measures
We implement appropriate technical and organisational measures pursuant to Art. 32 GDPR. The contractual TOM annex and security overview are accessible before contract formation. The TOM annex describes the agreed standard; confidential operational evidence is provided under section 14.
The applicable TOM annex and Subprocessor List are recorded and stored together with the DPA by document ID, version and content hash upon acceptance. We may replace measures with measures that are at least equivalent. The agreed security level must not be reduced. Individual additional requirements require a separate agreement before the affected processing begins.
9. Subprocessors
The customer grants general authorisation to use subprocessors. The current Subprocessor List is permanently available.
We will notify the customer at least 30 calendar days before the intended use of a new or replacement subprocessor.
The customer may object within that period for important data protection reasons. We assess the objection and reasonable alternatives. If the objection cannot be resolved, the customer may terminate the specifically affected service before the new subprocessor is used.
If an unforeseeable security or legal requirement or a provider failure requires a faster change, we obtain the customer's separate express authorisation before use. Without that authorisation, no new subprocessor is used before the agreed information and objection procedure has completed. Necessary temporary safeguards are communicated to the customer without undue delay.
We conclude agreements with subprocessors that meet Art. 28 GDPR requirements. Subprocessors may use further subprocessors where contractually secured and provided for in their provider structure.
10. Third-Country Transfers
Transfers to third countries occur only where GDPR requirements are met, in particular by:
- Adequacy decision under Art. 45 GDPR.
- EU Standard Contractual Clauses under Art. 46 GDPR.
- Additional safeguards where required.
- EU-US Data Privacy Framework where applicable and the provider is certified.
Where Standard Contractual Clauses are required, they apply additionally. Mandatory SCC provisions prevail in case of conflict.
11. Customer Assistance
We reasonably assist the customer with:
- Data subject requests.
- Deletion, access, rectification and export requests.
- Security of processing.
- Reporting and investigating personal data breaches.
- Data protection impact assessments and prior consultation where the processing by savien is affected.
- Return, portability and deletion of customer data after contract end.
The customer remains responsible for legal assessment and communication with data subjects or supervisory authorities where it is controller. Assistance beyond standard functions and reasonable cooperation may be separately charged where legally permissible.
12. Personal Data Breaches
If we become aware of a personal data breach affecting customer data, we will inform the customer without undue delay in accordance with Art. 33 GDPR.
The notification will include, where available:
- Nature of the incident.
- Affected data and person categories.
- Approximate number of affected persons and records, where known.
- Possible consequences.
- Measures taken or proposed.
- Contact point for follow-up questions.
We will take reasonable measures to investigate, contain and prevent similar incidents.
13. Return and Deletion
After contract end, the controller chooses whether customer personal data is returned or deleted. The choice may be exercised before contract end or within 30 days after our request, in text form or through the function provided for that purpose.
If return is chosen, we provide the data in an appropriate, structured and commonly used format through a secure transfer channel. Return is not conditional on the technical availability of a standard export function. After confirmed return, we delete the copies held by us.
If deletion is chosen, we delete or anonymise active customer personal data and confirm completion. In either case, data may be retained only to the extent and for as long as a statutory retention obligation requires; such data is restricted and not processed for other purposes.
Backup copies are blocked from further use after the choice and overwritten or deleted in the regular backup cycle, no later than 90 days. If a backup is restored within that period, the return or deletion instruction is reapplied before the restored system is released.
14. Evidence and Audits
Upon request, we provide appropriate evidence of compliance with this DPA, such as TOM descriptions, subprocessor information, security documentation or certificates where available.
We enable and contribute to audits, including inspections, by the customer or its appointed auditor under Art. 28(3)(h) GDPR. Scope, timing and protection of other customers are reasonably coordinated. Document reviews or remote audits may be used if they fulfil the audit purpose; they do not exclude necessary inspections. Where there are concrete indications of non-compliance or an authority requests an audit, coordination must not delay necessary checks.
Costs of external or customer-specific audits are borne by the customer where legally permissible and unless otherwise agreed.
15. International Customer Use
If the customer uses savien for persons, companies or data outside Germany or the EU/EEA, the customer remains responsible for additional local privacy, information and transfer obligations to the extent it determines such use.
16. Order of Precedence
In case of conflicts between the main agreement and this DPA, this DPA prevails for data protection matters. Mandatory statutory requirements and applicable EU Standard Contractual Clauses remain unaffected.
17. Acceptance, Organisation and Version Evidence
Acceptance applies only to the organisation identified in the acceptance process. It may be given only by the owner or a person whose authority to represent the organisation has been confirmed and recorded.
The acceptance record contains at least the document ID, version, content hash, language, timestamp, organisation, user, authority role and authority confirmation. The accepted version and its annexes remain permanently available to the organisation so that the agreed terms can be fully reconstructed.