Data processing agreement (DPA)
Annex 1 to the nisd2.eu terms. Agreement under Art. 28 GDPR between you as controller and us as processor.
Version of 5 oktober 2026
This agreement applies between the customer as controller and Kardashev Catalyst UG (haftungsbeschränkt) as processor (Annex I) to every processing of personal data the processor carries out on the customer's behalf when the hosted platform nisd2.eu is used.
The parties agree the standard contractual clauses between controllers and processors in the annex to Commission Implementing Decision (EU) 2021/915 of 4 June 2021 (OJ L 199, 7.6.2021, p. 18). By this reference they become part of this agreement in their official wording. Annexes I to IV below are their annexes.
In Clause 1, Option 1 (Art. 28(3) and (4) GDPR) is chosen, and in Clause 7.7 Option 2 (general written authorisation) with a period of 30 days. The optional Clause 5 (docking clause) is not agreed.
Under Clause 4, the standard contractual clauses prevail over the terms and every other agreement between the parties.
The agreement is concluded when the terms, of which it is Annex 1, are accepted. When ordering the annual licence, the customer confirms it at the order button; the version, time and person are stored. Art. 28(9) GDPR allows an electronic form.
Customers without an annual licence conclude the agreement by an email to contact@nisd2.eu in which they accept it. On request, every customer also receives the agreement as a signed PDF.
The customer gives its general authorisation for the sub-processors in Annex IV. If the processor intends to add or replace a sub-processor, it informs the person who holds the customer's account by email at least 30 days in advance.
The customer may object within that period. If the processor cannot refrain from the change for this customer, the customer may terminate the annual licence as of the day of the change; the processor refunds fees paid in advance for the time after that pro rata.
The customer gives instructions by using the platform and in text form to contact@nisd2.eu.
The agreement applies as long as the processor processes data for the customer. When an annual licence ends, the account and its data remain (terms B10), and with them this agreement.
After termination, the customer chooses between deletion and return under Clause 10(d), by email to contact@nisd2.eu. Return is a copy of the data in a common, machine-readable format. The processor certifies deletion in text form. The platform does not yet offer self-service for either; the processor carries out both on request.
Liability follows A7 of the terms. Art. 82 GDPR is not affected.
Annexes to the standard contractual clauses
Controller: the customer, with the company name, address and VAT number from its order. The contact person is the person who holds the account. The stored acceptance (version, time, person), which the customer sees under Billing, takes the place of signature and date.
Processor: Kardashev Catalyst UG (haftungsbeschränkt), Trierer Str. 6, 50676 Köln, Germany, represented by its managing director Simon Orzel. Data protection contact: contact@nisd2.eu. Signature and date: by providing this agreement in the version stated above.
Categories of data subjects: users of the account (employees and agents of the customer). Persons the customer names in the platform: employees, members of management, contact persons for information security, data protection and reporting, participants in training and exercises, owners of risks, assets and measures. Contact persons at suppliers and service providers, including persons who answer through the supplier portal.
Categories of personal data: account data (name, email, phone, job title, role, language, password only as a bcrypt hash, times of login and verification). Content data (names, job titles and contact details in forms, responsibilities, sign-offs with name, role and time, training records and certificates, free text and incident descriptions, uploaded evidence documents). Log data (audit log with user, action, time, IP address, user agent and the submitted values).
Sensitive data: the platform is not designed for special categories of personal data under Art. 9 GDPR and does not ask for them. If the customer enters such data in free text or documents, the measures in Annex III apply to them.
Nature of the processing: storing, displaying, changing, exporting, sending by email and deleting in the operation of the platform.
Purpose: providing the platform with which the customer organises and documents its NIS 2 duties; sending notifications.
Duration: for as long as the customer uses the platform, until deletion or return under section 4.
Processing by sub-processors: subject matter, nature and duration are set out in Annex IV; the duration is that of this agreement.
The measures under Art. 32 GDPR are described on the TOMs page, in the version that applied at acceptance. It lists only what is implemented in the code and in operation. The main points:
Encryption: TLS for every connection to the platform. Uploaded files and archived invoices are stored in AWS S3 with server-side encryption (AES256), set on every upload. The application does not additionally encrypt the database.
Access and permissions: login with email and password (bcrypt, cost factor 12, address confirmed by a one-time code) or with Google. There is no second factor for the password route. Sessions end after eight hours. Four roles (Admin, Reviewer, Legal Reviewer, Member). Customers are separated in the application: every query filters on the company ID of the session.
Input control: every change made through the platform is logged with user, action, time, IP address, user agent and the input values; only selected operations also store the previous value. Sign-offs form a chain of SHA-256 checksums.
Assistance (Clauses 8 and 9): the customer can view, change and delete data in the platform itself. The processor notifies the customer of data subject requests and personal data breaches without undue delay, to the person who holds the account.
Hetzner Online GmbH, Germany: operation of the application servers and the database, and so of all data in Annex II.
Amazon Web Services EMEA SARL, Luxembourg: file storage in AWS S3 in an EU region (evidence documents, training certificates, certificates from the supplier portal).
Resend, Inc., USA: sending the platform's emails (recipient, subject, content, attachments). Transfer to the USA based on the EU standard contractual clauses under Art. 46 GDPR.
Google Ireland Limited, Ireland: sign-in with Google, only for users who choose that route.
Qonto (invoicing) and the EU VAT check (VIES) are not sub-processors: they process only billing data for which the processor is itself responsible. The privacy policy covers that.