← Back to home
Data processing agreement
Pursuant to Art. 28 GDPR between the customer (controller) and Campaiva (processor)
Last updated: 7/25/2026
Data Processing Agreement (DPA)
Pursuant to Art. 28(3) GDPR — last updated July 2026. The German version is authoritative.
- Parties/subject: the customer (controller) and Campaiva, owner Florian Bassiouni, Hannover, Germany (processor); becomes part of the service contract upon acceptance at registration. Processing solely to operate the platform features used by the controller (CRM, email/SMS campaigns, social publishing, landing pages, ad campaigns, AI content, telephony if enabled).
- Data/subjects: contact, master, communication, usage and interaction data of the controller's contacts, leads, recipients, landing-page visitors and staff. Special categories (Art. 9) are out of scope and must not be submitted.
- Instructions & confidentiality: processing only on documented instructions (platform configuration counts as instruction); authorized persons bound to confidentiality; unlawful instructions flagged.
- Security (Art. 32): TLS 1.2+/1.3 in transit, AES-256 at rest, enforced per-tenant row-level security, RBAC + 2FA, audit logs, daily encrypted and restore-tested backups, SPF/DKIM/DMARC, EU hosting (Hetzner), PII scrubbing in error reports, encrypted third-party tokens.
- Sub-processors: general authorization for the listed sub-processors (Hetzner, IONOS, Stripe, Sentry, OpenAI, Anthropic, Google, HeyGen, ElevenLabs, seven, Placetel — current list at campaiva.com/trust); 30 days' advance notice of changes with a right to object for good data-protection cause. Services the controller connects itself (Google, Meta, LinkedIn, Microsoft 365, Shopify accounts; own SMTP; BYO-key AI) are recipients on the controller's instruction, not sub-processors.
- Transfers: EU by default; third-country transfers under SCCs and/or the EU-US Data Privacy Framework; copies of safeguards on request.
- Support & breach notice: assistance with data-subject rights (self-service tools) and Art. 32–36 duties; personal-data breaches notified without undue delay, normally within 24 hours, with Art. 33(3) details.
- Deletion: 30-day export window after contract end, then deletion (statutory retention excepted); backup copies overwritten in the regular cycle.
- Audits: information and audit rights (Art. 28(3)(h)) — documentation first; on-site audits with ≥14 days' notice during business hours.
- Liability/misc.: Art. 82 GDPR; internal liability per the Terms; German law; this DPA prevails over the Terms in data-protection matters.