Appearance
WebAccess/DMP Data Processing Agreement
Personal Data Processing Terms for WebAccess/DMP
| Provider | Advantech Czech s.r.o. |
| Effective date | Upon valid acceptance or incorporation |
Contractual effect. This DPA governs Processing of Customer Personal Data by Advantech on behalf of the Customer in connection with WebAccess/DMP. It becomes binding through the acceptance or incorporation mechanism in Clauses 1.4 and 14.1.
1. Status, Purpose and Incorporation
1.1 This WebAccess/DMP Data Processing Agreement (DPA) forms part of the contractual package governing the Service. It becomes legally binding when the Customer validly accepts it under Clause 1.4 or when it is expressly incorporated into an executed Agreement.
1.2 This DPA is between Advantech Czech s.r.o., identification number 24148661, with its registered office at Sokolská 71, Kerhartice, 562 04 Ústí nad Orlicí, Czech Republic (Advantech), and the natural or legal person, public authority, agency or other body accepting or incorporating this DPA (Customer). The Customer's legal form, sector, size or commercial status does not by itself determine whether this DPA applies; applicability depends on the actual Processing and roles under Clauses 1.3 and 3.
1.3 This DPA supplements the applicable agreement governing the subscription (Agreement), the WebAccess/DMP End User License Agreement (EULA) and the WebAccess/DMP SaaS Service Description (Service Description). It applies only to Processing of Customer Personal Data by Advantech on behalf of the Customer in connection with the Service.
1.4 The DPA may be accepted at activation of a subscription or applicable Company context, including a Root Company where a Company Hierarchy is used, through the clickwrap process in Schedule 4. The EULA, this DPA and the Service Description must each be separately linked by title and accepted as one contractual package. The DPA may also be incorporated through an executed Agreement.
1.5 This DPA does not govern Processing for which Advantech determines the purposes and essential means as an independent Controller, including limited corporate administration, billing-contact, legal-compliance or direct relationship data, to the extent such Processing is described in an applicable privacy notice and not performed on the Customer's behalf.
2. Definitions
2.1 Company means a logically separated organizational and tenant context in the Service. It is a product and tenant term and does not describe or restrict the Customer's legal form. Root Company, Parent Company, Child Company and Company Hierarchy have the meanings given in the EULA and Service Description.
2.2 Customer Personal Data means Personal Data Processed by Advantech on behalf of the Customer through the Service, including data within a Root Company, Parent Company, Child Company or the Company Hierarchy, but excluding data for which Advantech acts as an independent Controller under Clause 1.5.
2.3 Controller, Processor, Processing, Personal Data, Personal Data Breach and Data Subject have the meanings in Regulation (EU) 2016/679 (GDPR). Subprocessor means a processor engaged by Advantech to Process Customer Personal Data on behalf of the Customer.
2.4 Applicable Data Protection Law means the GDPR and other Union or Member State personal-data law applicable to the relevant Processing. Where another law applies, the parties will interpret this DPA to give effect to the mandatory requirements of that law without reducing GDPR protections where the GDPR applies.
2.5 Documented Instructions means the Customer's instructions in the accepted Agreement, EULA, DPA and Service Description, the Customer's authorized configuration and use of the Service, authorized portal or API actions, and additional written instructions accepted by Advantech.
2.6 Authorized User means a natural person permitted to use the Service through an assigned user account. User account means an interactive login account assigned to a natural person. Service account means a non-human API/login account used for automation or integration. A user account or service account is not a Company or contractual party.
3. Factual Roles and Company Hierarchy
3.1 The parties do not fix a single role regardless of circumstances. For each Processing activity, the parties' roles follow the actual Processing chain: (a) where the Customer determines the purposes and means, the Customer acts as Controller and Advantech as Processor; or (b) where the Customer Processes Personal Data on behalf of a Child Customer or other upstream Controller, the Customer acts as Processor and Advantech as Subprocessor.
3.2 A Root Company, Parent Company or Child Company label does not by itself determine a party's legal role. The actual purposes, essential means, documented instructions, contracts and permissions control. Different Processing activities within one Company Hierarchy may have different role allocations.
3.3 Where the Customer is a Processor, the Customer represents that the upstream Controller has authorized the Customer to engage Advantech, that the Customer may issue the relevant instructions, and that the Customer has imposed and will maintain the required downstream and upstream data-protection terms. References in this DPA to the Customer's rights or instructions include the rights or instructions the Customer validly exercises for the upstream Controller.
3.4 Placement in a Company Hierarchy does not grant the Root Company, a Parent Company or their users automatic access to a Child Company's operational or personal data. Access requires an explicit Company-level assignment and appropriate permissions. An authorized user or service-account action within an assigned Company is treated as a Customer instruction within that authorization.
3.5 The Customer is responsible for the lawfulness, transparency, accuracy and minimization of Customer Personal Data; for selecting appropriate Service settings and permissions; and for ensuring that its instructions and downstream use comply with Applicable Data Protection Law.
4. Processing on Documented Instructions
4.1 Advantech shall Process Customer Personal Data only on Documented Instructions, including instructions concerning transfers, unless Union or Member State law requires otherwise. In that case, Advantech shall inform the Customer of the legal requirement before Processing unless the law prohibits that information on important grounds of public interest.
4.2 If Advantech considers that an instruction infringes Applicable Data Protection Law, it shall inform the Customer without undue delay and may suspend the affected Processing until the instruction is clarified, modified or confirmed on a lawful basis. Advantech is not required to perform an instruction that is technically unsupported, outside the Service scope or unlawful; the parties may agree a separate professional service where appropriate.
4.3 Advantech shall not sell Customer Personal Data or use it for its own advertising, customer profiling or unrelated product analytics. Anonymous or aggregate data that no longer identifies a person may be used only as permitted by Applicable Data Protection Law and the accepted documents.
5. Confidentiality and Personnel
5.1 Advantech shall ensure that persons authorized to Process Customer Personal Data are bound by an appropriate statutory or contractual confidentiality obligation and access the data only to the extent necessary for their assigned duties.
5.2 Advantech shall apply role-based access and least-privilege principles to support and operational access. Support access is limited to troubleshooting incidents and maintaining service operations as further described in the Service Description and current public WebAccess/DMP data-transparency documentation.
5.3 Advantech shall provide relevant privacy and information-security awareness to personnel whose duties include Processing Customer Personal Data.
6. Security of Processing
6.1 Taking into account the state of the art, implementation costs and the nature, scope, context and purposes of Processing, as well as the risks to Data Subjects, Advantech shall implement and maintain appropriate technical and organizational measures as required by Article 32 GDPR. The current baseline is described in Schedule 2 and the Service Description.
6.2 Advantech may update the measures to reflect technical progress, threats, legal requirements and service changes, provided that the update does not materially reduce the overall protection of Customer Personal Data. Material changes to data region, retention or handling are subject to the notice provisions in this DPA and the Service Description.
6.3 The Customer shall secure its user accounts, service accounts, credentials, integrations, endpoints, devices and networks; configure appropriate Company roles and permissions; apply least privilege; and maintain any Customer-controlled copies or exports.
6.4 This DPA does not create an availability percentage, service credit, security-response time, recovery time objective (RTO), recovery point objective (RPO) or cross-region disaster-recovery commitment. Any such commitment must be expressly stated in an executed Agreement, SLA Addendum or accepted Service Description provision.
7. Personal Data Breach
7.1 Advantech shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice will be made through the registered security, privacy or contractual contact route available to Advantech.
7.2 To the extent information is available, the notice shall describe the nature of the breach, affected categories of Data Subjects and Personal Data, likely consequences, measures taken or proposed, and a contact point. Advantech may provide information in phases where it cannot be supplied at the same time.
7.3 Advantech shall take reasonable steps to contain, investigate and remediate the breach and shall reasonably cooperate with the Customer. The Customer remains responsible for deciding whether and how to notify an upstream Controller, Data Subjects or a supervisory authority, unless Applicable Data Protection Law requires Advantech to notify directly.
7.4 A notification or cooperation under this Clause is not an admission of fault or liability.
8. Subprocessors
8.1 The Customer grants Advantech general written authorization to engage Subprocessors for the specific activities necessary to provide the Service, subject to this Clause and Schedule 3.
8.2 Advantech shall maintain an up-to-date Subprocessor list and give reasonable advance notice through the registered Customer contact route of an intended addition or replacement that will Process Customer Personal Data. The notice shall identify the Subprocessor's function and location and provide a reasonable period for an objection based on legitimate data-protection grounds.
8.3 If the Customer objects on legitimate grounds, the parties shall work in good faith toward a reasonable solution. If no solution is available, the Customer may discontinue the affected optional feature or terminate the affected Processing in accordance with the Agreement. An objection does not permit the Customer to withhold unrelated fees or require an unsupported architecture.
8.4 Advantech shall impose on each Subprocessor, by written agreement, the same data-protection obligations as apply to the relevant Processing under this DPA, including appropriate security measures. Advantech remains responsible for the Subprocessor's performance to the extent required by Article 28(4) GDPR.
8.5 The initial Subprocessor list is set out in Schedule 3. Advantech may add or replace Subprocessors only in accordance with Clauses 8.2 to 8.4.
9. Data Location and International Transfers
9.1 The current public WebAccess/DMP Data Transparency Notice states that data is stored in AWS cloud infrastructure in the Frankfurt region, Germany (EU), and is not transferred outside the EU. The Service Description records the same current service baseline.
9.2 Advantech shall not store Customer Personal Data outside the agreed location or make a restricted transfer outside the EU/EEA unless the transfer is authorized by the accepted documents or a Documented Instruction and is supported by a lawful Chapter V GDPR mechanism, including an adequacy decision, binding corporate rules or applicable standard contractual clauses, together with supplementary measures where required.
9.3 Where remote access from a third country constitutes a transfer under Applicable Data Protection Law, it is subject to the same requirements. Advantech shall provide information reasonably necessary for the Customer's transfer assessment.
9.4 A proposed material change to the storage region or transfer position is subject to advance notice. If the change requires a new transfer mechanism or materially changes risk, the parties shall complete the required documentation before the affected transfer begins, except where mandatory law requires otherwise.
10. Data Subject Requests
10.1 Taking into account the nature of the Processing, Advantech shall assist the Customer by appropriate technical and organizational measures, insofar as possible, to fulfill the Customer's obligation to respond to requests for access, rectification, erasure, restriction, portability, objection or other applicable Data Subject rights.
10.2 If Advantech receives a request relating to Customer Personal Data, it shall refer the requester to the Customer or forward the request to the Customer where reasonably possible, unless law prohibits it. Advantech shall not independently determine the merits of the request except where required by law.
10.3 The Customer shall use available Company administration, API and export functions where they can fulfill the request. Bespoke assistance outside standard Service functions may be handled as a professional service where permitted by law and agreed in advance.
11. Compliance, DPIA and Authority Assistance
11.1 Taking into account the nature of Processing and the information available to Advantech, Advantech shall reasonably assist the Customer with compliance under Articles 32 to 36 GDPR, including security assessments, Personal Data Breach obligations, data protection impact assessments and prior consultation with a supervisory authority.
11.2 Advantech shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. The Customer remains responsible for its own records of processing, lawful basis, transparency, risk decisions and communications with its upstream Controller or supervisory authority.
11.3 If a supervisory authority lawfully requests information or cooperation concerning Customer Personal Data, each party shall notify and cooperate with the other to the extent legally permitted.
12. Return, Export and Deletion
12.1 During the subscription, the Customer may retrieve data through the available portal, API and export functions described in the Service Description and product documentation. The standard Service does not imply a bespoke export format or migration service.
12.2 On expiry or termination of the affected Service, Company or Company Hierarchy, and at the Customer's choice where Article 28 GDPR applies, Advantech shall return or make available for export the Customer Personal Data and delete remaining copies, unless Union or Member State law requires retention. The applicable offboarding process, export availability and operational deletion sequence are governed by the Agreement and Service Description.
12.3 Deletion from backups may occur through the ordinary backup rotation and secure deletion process, provided the retained backup data remains protected and is not restored for ordinary Processing. If restored for recovery, the deletion instruction shall be reapplied.
12.4 The current Service Description and public Data Transparency Notice specify service-specific retention periods, including the current positions for configuration data, monitoring and telemetry history, and recent monitoring values. Those specific documented periods control unless a valid instruction, law or separate agreement requires otherwise.
13. Information and Audits
13.1 Advantech shall make available information reasonably necessary to demonstrate compliance with this DPA, which may include relevant policies, descriptions of controls, current certifications, independent reports or questionnaire responses that Advantech is lawfully permitted to disclose.
13.2 If that information is not sufficient, the Customer or an independent auditor mandated by the Customer may conduct an audit, including an inspection, subject to reasonable advance notice, confidentiality, normal business hours, protection of other customers, and measures preventing disruption or security compromise. The auditor must not be a competitor of Advantech and must have appropriate expertise.
13.3 Unless required by a supervisory authority, following a Personal Data Breach or based on reasonable evidence of material non-compliance, an on-site audit may be limited to once in any twelve-month period. The Customer bears its audit costs and Advantech's reasonable incremental costs where permitted by law, without restricting a mandatory audit right.
13.4 The parties shall promptly discuss audit findings. Advantech shall address verified material non-compliance within a reasonable period proportionate to risk.
14. Term, Changes and Acceptance
14.1 This DPA begins when validly accepted or incorporated and continues while Advantech Processes Customer Personal Data on the Customer's behalf. Clauses that by their nature must survive continue until the relevant Customer Personal Data is deleted or returned.
14.2 Advantech may update this DPA to reflect changes in law, regulatory guidance, security requirements, Subprocessors or the Service. Advantech shall make the revised text available before its effective date through the registered Customer contact route or acceptance workflow.
14.3 A material change to the parties' data-protection rights or obligations shall be presented for renewed affirmative acceptance where required by the Agreement or Applicable Data Protection Law, or incorporated into an executed Agreement. The acceptance record shall confirm that the Customer accepted the DPA and identify the accepting User, the applicable Company and the UTC timestamp.
14.4 A change to the EULA, DPA or Service Description does not silently change the accepted text of the other documents. The acceptance interface shall identify and link all three documents in the package.
15. Liability and Order of Precedence
15.1 Each party's liability arising from this DPA is subject to the exclusions and limitations in the executed Agreement and EULA, except to the extent liability cannot lawfully be limited or excluded. This DPA does not create a separate or additional liability cap, indemnity, service credit or warranty.
15.2 In the event of conflict, this DPA controls for Processing of Customer Personal Data; the Service Description controls the technical and operational service scope; the EULA controls authorization, intellectual property, prohibited use, disclaimers and the general liability framework; and an executed Agreement controls to the extent it expressly identifies a conflicting provision. The more specific term controls within its assigned subject matter.
15.3 If the parties execute standard contractual clauses or another mandatory transfer instrument, that instrument controls for the restricted transfer to the extent of an unavoidable conflict.
16. General
16.1 Notices under this DPA shall use the contractual, privacy or security contacts maintained for the subscription or applicable Company context, including a Root Company where a Company Hierarchy is used. Each party shall keep its contact information current.
16.2 If a provision is invalid or unenforceable, it shall be limited or severed to the minimum extent necessary and the remaining provisions remain effective. Failure to enforce a provision is not a waiver.
16.3 The governing law and jurisdiction stated in the executed Agreement or EULA apply to this DPA, subject to mandatory rights of Data Subjects and competent supervisory authorities.
16.4 This DPA is effective and binding when accepted or incorporated as stated in Clauses 1.4 and 14.1.
Schedule 1 — Processing Details
| Field | Processing description |
|---|---|
| Subject matter | Provision, operation, security, support, maintenance, administration and lawful billing/reconciliation of the WebAccess/DMP SaaS Service and ordered options for the Customer's Company context, including any Company Hierarchy used by the Customer. |
| Duration | For the subscription term and any documented offboarding, return, legal-retention and deletion period, subject to Clause 12. |
| Nature and purpose | Collection, receipt, organization, hosting, storage, retrieval, consultation, use, transmission, backup, support access, restriction, export and deletion as needed to provide, secure and support the Service on Documented Instructions. |
| Frequency | Continuous or episodic according to Customer use of the portal, API, device-management channels, support process and ordered options. |
| Data Subjects | The Customer where the Customer is a natural person; Authorized Users and service administrators; Customer and Child Customer personnel, contractors and contacts; persons identifiable in support content or Customer-provided content; and individuals associated with managed-device telemetry, communications or location data where enabled. |
| Personal Data | Names, contact details, user/login identifiers, roles, permissions and authentication metadata; Company identifiers and hierarchy relationships; audit/activity metadata; device identity and configuration data; operational telemetry, status, session, connectivity, performance, measurement, location and communication data where enabled; support communications and Customer-provided content; and limited Hierarchy Billing Data where it identifies a person. |
| Special categories | The standard Service is not designed to require special-category data under Article 9 GDPR or criminal-offence data under Article 10 GDPR. The Customer shall not intentionally submit such data unless the parties first document the need, lawful basis and appropriate safeguards. |
| Instructions | The accepted Agreement, EULA, DPA and Service Description; authorized Company, portal and API configuration/actions; valid support requests; and additional written instructions accepted by Advantech. |
| Current retention baseline | Configuration data while the relevant Company context exists; monitoring and telemetry history for 90 days; most recent monitoring values for 24 months; user/contact and other data according to the subscription, accepted documents and legal obligations. The Service Description and current Data Transparency Notice control the detailed baseline. |
| Controller rights and obligations | The Customer retains the rights and obligations of the Controller or, where it acts as Processor, the valid delegated rights and obligations of its upstream Controller, including lawful instructions, transparency, Data Subject response, security choices and termination/deletion decisions. |
Schedule 2 — Technical and Organizational Measures
| Control area | Current baseline |
|---|---|
| Governance | Information-security governance, assigned responsibilities, risk assessment, internal policies, personnel awareness and incident handling. Company-level ISO/IEC 27001 and NIS2 statements are described in the Service Description; they are not a separate SLA. |
| Transport protection | HTTPS and TLS-protected external communication. The current public Security Statement specifies TLS 1.3 and mutual PKI for supported server-to-device authentication. |
| Identity and access | OIDC/OAuth2 where supported, role-based and Company-scoped permissions, least privilege, MFA availability for user access, and separately managed service accounts for authenticated API automation. |
| Company separation | Logical separation of Company data in the multi-tenant service. Company Hierarchy placement alone does not grant access; operational access requires explicit Company assignment and permissions. |
| Network and application controls | Controlled service access points, web application firewall protection for exposed web interfaces, supported device-certificate authentication and operational monitoring of the Advantech-controlled environment. |
| Credentials | Salted password hashes and standardized user-management practices as stated in the current public Security Statement. The Customer remains responsible for its credentials, service-account secrets and endpoints. |
| Logging and audit | Audit records for supported administrative and operational changes, subject to the available product retention and export functions. The current public notice states that support access itself is not logged, while modifications or changes to Customer data are logged. |
| Backup and recovery | Automated regular database and platform backups and recovery processes within the service environment. No contractual RTO, RPO, cross-region recovery or service credit is created by this DPA. |
| Secure development | Security education, security-driven design, input validation and access-control criteria, automated scanning, manual review, internal security audits and targeted specialist testing where appropriate, as described in the current public Security Statement. |
| Data location | AWS cloud infrastructure in the Frankfurt region, Germany (EU), under the current documented service baseline. |
| Confidentiality and support | Confidentiality obligations, role-based support access for troubleshooting and service operations, and access limited to authorized personnel with a business need. |
| Change control | Risk-based review of material changes to security, data region, retention or handling, with the notice and change-control provisions in this DPA and the Service Description. |
Schedule 3 — Subprocessors and Authorization
S3.1 The Customer provides general written authorization under Clause 8. The initial Subprocessor list is set out below and is updated only in accordance with Clauses 8.2 to 8.4.
| Subprocessor | Function | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, hosting, storage, network and backup support for the Service | Frankfurt region, Germany (EU) |
S3.2 Advantech shall maintain the current list in this DPA or at a stable legal-document location made available through the registered Customer contact route. Additions and replacements follow Clause 8.
Schedule 4 — Clickwrap Acceptance and Evidence
S4.1 Trigger. The acceptance workflow runs before activation of a paid subscription or applicable Company context, including a Root Company where a Company Hierarchy is used. It must be completed by an authenticated natural-person User who is the Customer or has authority to bind the Customer. A service account is not eligible to perform legal acceptance.
S4.2 Required UI statement. 'By activating the Service, I confirm that I am the Customer or am authorized to bind the Customer, and accept the WebAccess/DMP EULA, WebAccess/DMP Data Processing Agreement, and WebAccess/DMP SaaS Service Description available through the links below.'
S4.3 Presentation. Use one unticked required checkbox, one activation/acceptance button and three equally prominent links. Each link must show the document title and provide the full text before acceptance. The currently applicable documents shall remain available for download afterwards. Activation remains blocked until the checkbox is selected and the acceptance write succeeds.
| Backend field | Evidence to retain |
|---|---|
acceptance_event_id | Unique, immutable event identifier. |
company_id / root_company_id where applicable | Identifier of the Company context to which acceptance applies and, where a Company Hierarchy is used, the contracting Root Company. |
user_id | Identifier of the authenticated natural-person User who accepted, including the authority/role context at the time. |
accepted_at_utc | Server-side UTC timestamp of successful acceptance. |
documents | Confirmation that the EULA, DPA and Service Description were accepted, identified by document type only. |
result | Successful acceptance and subsequent subscription or applicable Company activation result; failed or abandoned attempts must not activate the Service. |
S4.4 Scope. Acceptance for the subscription or applicable Company context binds the contracting Customer. Where a Company Hierarchy is used, acceptance for the Root Company binds the Customer for the associated Company Hierarchy. A Child Company does not separately accept Advantech's DPA unless it becomes a direct contracting Customer or a separate Agreement requires it. The Customer remains responsible for any required downstream Controller/Processor terms with Child Customers.
S4.5 Document changes. A material document update that requires renewed acceptance must generate a new acceptance event and must not overwrite the historical event. The acceptance record need only record the acceptance event, the accepting User, the applicable Company, the UTC timestamp and the types of documents accepted. This DPA does not require the backend to retain historical document copies, snapshots, content hashes or version identifiers.
S4.6 Retention and access. Acceptance event records shall be retained for the subscription term and any longer period reasonably necessary to comply with applicable law or to establish, exercise or defend legal claims. Access shall be restricted to authorized personnel with a business need.
