Skip to content
← Back to home

Data processing agreement

Pursuant to Art. 28 GDPR between the customer (controller) and Campaiva (processor)

Last updated: 7/25/2026

Data Processing Agreement (DPA)

Pursuant to Art. 28(3) GDPR — last updated July 2026. The German version is authoritative.

  • Parties/subject: the customer (controller) and Campaiva, owner Florian Bassiouni, Hannover, Germany (processor); becomes part of the service contract upon acceptance at registration. Processing solely to operate the platform features used by the controller (CRM, email/SMS campaigns, social publishing, landing pages, ad campaigns, AI content, telephony if enabled).
  • Data/subjects: contact, master, communication, usage and interaction data of the controller's contacts, leads, recipients, landing-page visitors and staff. Special categories (Art. 9) are out of scope and must not be submitted.
  • Instructions & confidentiality: processing only on documented instructions (platform configuration counts as instruction); authorized persons bound to confidentiality; unlawful instructions flagged.
  • Security (Art. 32): TLS 1.2+/1.3 in transit, AES-256 at rest, enforced per-tenant row-level security, RBAC + 2FA, audit logs, daily encrypted and restore-tested backups, SPF/DKIM/DMARC, EU hosting (Hetzner), PII scrubbing in error reports, encrypted third-party tokens.
  • Sub-processors: general authorization for the listed sub-processors (Hetzner, IONOS, Stripe, Sentry, OpenAI, Anthropic, Google, HeyGen, ElevenLabs, seven, Placetel — current list at campaiva.com/trust); 30 days' advance notice of changes with a right to object for good data-protection cause. Services the controller connects itself (Google, Meta, LinkedIn, Microsoft 365, Shopify accounts; own SMTP; BYO-key AI) are recipients on the controller's instruction, not sub-processors.
  • Transfers: EU by default; third-country transfers under SCCs and/or the EU-US Data Privacy Framework; copies of safeguards on request.
  • Support & breach notice: assistance with data-subject rights (self-service tools) and Art. 32–36 duties; personal-data breaches notified without undue delay, normally within 24 hours, with Art. 33(3) details.
  • Deletion: 30-day export window after contract end, then deletion (statutory retention excepted); backup copies overwritten in the regular cycle.
  • Audits: information and audit rights (Art. 28(3)(h)) — documentation first; on-site audits with ≥14 days' notice during business hours.
  • Liability/misc.: Art. 82 GDPR; internal liability per the Terms; German law; this DPA prevails over the Terms in data-protection matters.
Data processing agreement