Data Processing Agreement
Preamble
This Data Processing Agreement governs the data protection obligations of ScanKit.io c/o Martin Stämmler, Am Bartelskamp 16, D-38553 Wasbüttel (hereinafter referred to as "ScanKit.io" or "Contractor"), towards the client ("Client") in connection with the use of ScanKit.io’s API and SDK services.
1. Subject, Duration of the Assignment, Type and Purpose of Processing, Type of Data, Categories of Affected Parties
The subject and duration of the assignment, the type and purpose of the processing, the type of data, and the categories of affected parties are derived from the terms of service or the main contract. This agreement remains valid until the main contract is terminated and the obligations in Section 10 of this agreement are fulfilled.
2. Security of Processing
ScanKit.io ensures compliance with the technical and organizational measures as required by Art. 5(1) and Art. 32 GDPR. These measures are designed to protect personal data from unauthorized access, loss, or destruction and are outlined in Attachment 1.
Regular reviews of internal processes and technical measures are conducted to ensure compliance with data protection laws and to safeguard the rights of data subjects.
3. Correction, Deletion, and Restriction of Data
ScanKit.io processes, corrects, deletes, or restricts data only upon the Client’s instructions. If a data subject requests corrections, deletions, or restrictions directly from ScanKit.io, the request will be forwarded to the Client immediately.
ScanKit.io will assist the Client in fulfilling statutory obligations related to the rights of data subjects, including the right to access, rectify, or delete personal data.
4. Duties of the Contractor
ScanKit.io ensures compliance with the following obligations:
- Appointing a data protection officer, as required by law.
- Ensuring all employees with access to personal data are bound by confidentiality agreements.
- Facilitating inspections by supervisory authorities and assisting the Client during such inspections.
- Promptly notifying the Client of any data protection-related inquiries or investigations by supervisory authorities.
- Assisting the Client in ensuring the security of processing under Art. 32 GDPR.
- Supporting the Client with data protection impact assessments under Art. 35 GDPR.
- Assisting with notifications of data breaches under Art. 33 and Art. 34 GDPR.
5. Subcontracting
ScanKit.io may use subcontractors to fulfill its obligations under this agreement. All subcontracting arrangements will comply with data protection requirements. ScanKit.io will inform the Client of any intended changes to subcontractors, providing an opportunity for objection.
Subcontracting outside the EU/EEA requires prior written approval from the Client and must comply with Art. 44-49 GDPR.
The current list of subprocessors is set out in Attachment 3.
6. Location of Processing
Data processing by ScanKit.io is restricted to the EU/EEA. Transfers outside these regions require compliance with Art. 44 ff. GDPR and prior written consent from the Client.
7. Client’s Audit Rights
The Client may conduct inspections of ScanKit.io’s premises during business hours with at least four business days' notice. ScanKit.io will provide necessary support to verify compliance with technical and organizational measures as outlined in this agreement.
8. Notifications of Data Protection Breaches
ScanKit.io will notify the Client immediately upon discovering a data protection breach or suspected breach. The notification will include details of the breach, its impact, and corrective actions taken. If required, ScanKit.io will assist the Client in notifying supervisory authorities and affected individuals.
9. Instruction Authority of the Client
ScanKit.io processes data solely based on the Client’s instructions as outlined in the main contract. Changes to the processing scope must be agreed upon and documented. ScanKit.io will notify the Client if it believes an instruction violates data protection laws and may suspend processing until the issue is resolved.
10. Deletion after Contract Termination
Upon contract termination, ScanKit.io will delete or return all personal data as instructed by the Client, unless retention is required by law. Backup copies necessary for compliance or proper processing may be retained securely until their lawful retention period expires.
Attachment 1: Technical and Organizational Measures
1. Protective Measures and Risk Assessment
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, the contractor must implement suitable technical and organizational measures to ensure an appropriate level of protection.
2. Pseudonymization and Encryption
These measures may include, among other things, the pseudonymization and encryption of personal data, as far as such means are possible in light of the purposes of processing.
3. Objective of the Measures
The measures are intended to ensure:
- The confidentiality, integrity, availability, and resilience of the systems and services related to processing are continuously maintained.
- The availability of personal data and access to them can be quickly restored in the event of a physical or technical incident.
4. Risk Assessment and Measures
After a risk assessment, the contractor must take measures to ensure the security of data in the following areas:
Access Control
Denying access to processing facilities with which the processing is conducted to unauthorized persons. Measures include:
- Access control systems (e.g., magnetic cards, central key management).
- Clear assignment of permissions for building and server room access.
- Video surveillance of sensitive areas, including server rooms.
- Locking offices and cabinets when unattended.
- Regulations for visitor access, including badges and escorting.
Data Carrier Control
Prevention of unauthorized reading, copying, modifying, or deleting of data carriers. Measures include:
- Secure password procedures, including regular password changes and length requirements.
- Automatic computer lockout after inactivity.
- Encryption of sensitive data carriers.
- Remote wiping capabilities for mobile devices.
Storage Control
Prevention of unauthorized input, access, modification, or deletion of stored personal data.
User Control
Prevention of unauthorized system access or data processing through transmission facilities.
Transfer Control
Ensuring that data transmissions are secure and can be traced. Measures include:
- Data encryption during transfer (e.g., VPN, HTTPS).
- Prohibiting the use of unauthorized hardware or software for data transmission.
- Guidelines for secure handling of physical data carriers.
Input Control
Ensuring that it is possible to determine who entered, modified, or deleted data. Measures include:
- Access to systems only via secure login procedures.
- Manual logout when leaving workstations.
- Audit logs to track system changes and user actions.
Recoverability
Ensuring the restoration of systems and data in case of a malfunction or breach.
Data Integrity
Ensuring that personal data is protected against corruption or unauthorized alteration.
Availability Control
Ensuring data is protected against destruction or loss. Measures include:
- Regular backups and testing of recovery processes.
- Antivirus software and firewalls maintained to current standards.
- Protection against environmental risks (e.g., fire, water damage).
- Emergency response plans, including power supply systems (UPS).
Separability
Ensuring that data collected for different purposes can be processed separately. Measures include:
- Logical separation of data sets.
- Strict access controls for data with different purposes.
Review and Training on IT Security
Ensuring regular assessment of measures and IT security training for all relevant personnel. Measures include:
- Regular training for employees and IT administrators on data security practices.
- Security awareness programs and internal documentation for staff.
- Incident response plans for handling security breaches or unusual activity.
Attachment 2: Data Protection Specifications
Scope, Nature, and Purpose of the Planned Collection
ScanKit.io provides B2B solutions for seamless document scanning and processing through its API and SDK. The platform enables businesses to integrate document scanning features into their workflows, automatically extract relevant data (e.g., metadata, OCR text, and classifications), and securely process and share documents. The primary purpose of data processing is to enhance document management efficiency for businesses.
Type of Data
1. Personal Data:
- First name, Last name
- Email address
2. Document Information:
- Uploaded PDF files
- Scanned images of documents
3. When using the scanning feature:
- Automatic image processing (trimming, filtering, and optimizing document photos)
- Creation of scanned document images in various resolutions
- Text extraction using Optical Character Recognition (OCR)
4. Metadata for documents (extracted or created by users):
- Document type
- Tags / Labels
- Creation date
- Payment information (e.g., extracted from invoices)
- Calendar information (e.g., extracted from invitations)
- Sender and recipient details (name and address from letters)
5. Communication Data:
- User comments or chat messages related to documents
- Chatbot-generated responses for document inquiries
6. Server Log Data:
- IP address
- Date and time of access
- Requested URL
- Device type (e.g., Desktop, Mobile)
- Browser type
- Language settings
Affected Parties
Customers and users of the ScanKit API and SDK services.
Attachment 3: Subprocessors
Under Section 5 of this agreement, the Client authorises the following subprocessors. The list reflects the processing activities described in Section 1 and is updated when changes occur; intended changes are communicated under Section 5.
| Subprocessor | Purpose | Region | Document content? |
|---|---|---|---|
| Heroku (Salesforce) | App hosting + processing (Heroku runs on AWS) | EU (Ireland, eu-west-1) | Yes — transient (in-memory) |
| Amazon Web Services (AWS) | Image processing (Lambda) and object storage for scanner logos (S3) | EU (Frankfurt, eu-central-1) | Yes — transient image processing; storage holds logos only |
| Google (Google Analytics 4) | Website analytics | EU/US | No — website usage data only, no documents |
| Hotjar | Website behaviour analytics | EU/US | No — website usage data only, no documents |
| Stripe | Payment processing (credit packs) | EU/US | No — payment data only |
| Sentry | Error monitoring | EU (de.sentry.io) | No — technical error details only, no documents |
ScanKit.io remains responsible to the Client for the performance of its subprocessors.