Data Processing Agreement

Last updated: 23 August 2026

This Data Processing Agreement (“DPA”) forms part of the agreement for services between the Customer (“Controller”) and DOW MEDIA SRL, operating the DirektSupport service (“Processor”), where DirektSupport processes Personal Data on behalf of the Customer.

This DPA is intended to satisfy the requirements of Article 28 of Regulation (EU) 2016/679 — General Data Protection Regulation (“GDPR”).

Where DirektSupport does not process Personal Data on behalf of the Customer, this DPA does not apply to that processing relationship.

1. Parties

Controller

The Customer purchasing or receiving DirektSupport services, where that Customer determines the purposes and means of processing Personal Data.

The Customer’s identification and contact information is the information supplied in the relevant:

  • service order;
  • support request;
  • quotation;
  • contract;
  • customer account;
  • invoice.

Processor

DOW MEDIA SRL
Strada Johann Heinrich Pestalozzi, Nr. 3-5
Timișoara, Romania
European Union

Trade Register: J35/3199/03.11.2004
VAT / Tax ID: RO16906010

Privacy and administrative contact:

office@direktsupport.eu

Technical support:

help@direktsupport.eu

2. Relationship Between the Parties

The Customer acts as the Controller of Personal Data processed within its websites, applications, servers and infrastructure.

DOW MEDIA SRL acts as a Processor where DirektSupport processes that Personal Data solely to provide technical services on the Customer’s behalf and according to the Customer’s instructions.

Depending on the service, these activities may include:

  • Linux server administration;
  • server troubleshooting;
  • hosting control panel administration;
  • WordPress support;
  • database administration;
  • email server administration;
  • server migration;
  • backup and recovery;
  • security investigation;
  • malware removal;
  • infrastructure maintenance;
  • emergency technical support.

DirektSupport does not determine the purposes for which the Customer collects or otherwise processes Personal Data.

3. Scope of Processing

The subject matter of processing is the provision of technical and infrastructure services requested by the Controller.

Processing may occur only to the extent reasonably necessary to provide those services.

The exact scope depends on the Customer’s infrastructure and the technical work requested.

4. Duration of Processing

Processing under this DPA continues for the period during which DirektSupport provides services requiring access to Personal Data on behalf of the Controller.

For one-time interventions, processing will generally end after the requested technical service has been completed and temporary access is no longer required.

For ongoing server management, processing may continue for the duration of the management agreement.

Certain information may be retained afterwards where required by law or where necessary for legitimate contractual, security or legal purposes.

5. Nature of Processing

Depending on the requested service, processing may include:

  • access;
  • viewing;
  • storage;
  • organisation;
  • retrieval;
  • copying;
  • transmission;
  • backup;
  • restoration;
  • migration;
  • alteration;
  • troubleshooting;
  • deletion;

of Personal Data where technically necessary to provide the requested service.

DirektSupport does not intentionally access Customer data that is unrelated to the technical task.

6. Purpose of Processing

Personal Data is processed only for purposes necessary to provide the agreed technical services.

Examples include:

  • diagnosing server problems;
  • restoring unavailable services;
  • administering Linux systems;
  • troubleshooting websites;
  • migrating data between servers;
  • restoring backups;
  • investigating security incidents;
  • administering databases;
  • administering email infrastructure;
  • maintaining production systems.

DirektSupport will not use Personal Data processed on behalf of the Controller for unrelated advertising, profiling or marketing purposes.

7. Categories of Data Subjects

Depending on the Customer’s systems, Personal Data may relate to:

  • the Customer’s employees;
  • customers;
  • prospective customers;
  • suppliers;
  • contractors;
  • website users;
  • registered website users;
  • newsletter subscribers;
  • email users;
  • application users;
  • business contacts;
  • other individuals whose Personal Data is stored within Customer infrastructure.

The Controller determines which categories of data subjects are present within its systems.

8. Categories of Personal Data

Depending on the infrastructure being administered, Personal Data may include:

  • names;
  • email addresses;
  • telephone numbers;
  • postal addresses;
  • IP addresses;
  • account identifiers;
  • usernames;
  • website account information;
  • transaction information;
  • customer records;
  • application data;
  • email data;
  • server logs;
  • access logs;
  • database records;
  • technical identifiers.

DirektSupport does not require the Controller to provide categories of Personal Data that are unnecessary for the requested technical work.

9. Special Categories of Personal Data

The Customer should inform DirektSupport where it knows that the requested services are likely to involve substantial processing of special categories of Personal Data under Article 9 GDPR or other particularly sensitive information.

Such data may include information concerning:

  • health;
  • racial or ethnic origin;
  • religious or philosophical beliefs;
  • political opinions;
  • trade union membership;
  • genetic information;
  • biometric information used for identification;
  • sex life or sexual orientation.

Where processing necessarily involves sensitive data, access will be limited to what is technically required for the agreed service and appropriate additional safeguards may be applied.

The European Commission’s Article 28 clauses specifically require additional restrictions or safeguards where sensitive data is processed. (EUR-Lex)

10. Processing Only on Documented Instructions

DirektSupport shall process Personal Data only on documented instructions from the Controller, including instructions contained in:

  • support requests;
  • emails;
  • service orders;
  • quotations;
  • contracts;
  • authorised technical communications.

This includes transfers of Personal Data unless processing is required by European Union or Member State law.

If DirektSupport believes that an instruction infringes applicable data protection law, we will inform the Controller unless prohibited by law.

11. Controller Responsibilities

The Controller is responsible for:

  • determining the purposes and legal basis of its processing;
  • complying with applicable data protection law;
  • providing appropriate privacy information to data subjects;
  • ensuring Personal Data is collected lawfully;
  • determining appropriate retention periods;
  • ensuring that instructions given to DirektSupport are lawful;
  • ensuring that DirektSupport is authorised to access the systems submitted for support.

The Controller remains responsible for the Personal Data contained within its infrastructure.

12. Confidentiality

DirektSupport shall ensure that persons authorised to process Personal Data on behalf of the Controller are subject to appropriate confidentiality obligations.

Access to Customer infrastructure shall be limited to persons who require it for:

  • providing the service;
  • managing the service;
  • troubleshooting;
  • security;
  • compliance.

The Commission’s Article 28 clauses likewise require authorised personnel to access data only where necessary and to be bound by confidentiality. (EUR-Lex)

13. Security of Processing

DirektSupport shall implement appropriate technical and organisational measures having regard to:

  • the nature of the processing;
  • available technology;
  • implementation costs;
  • the likelihood and severity of risks to individuals;
  • the infrastructure being administered.

Measures may include, where appropriate:

  • restricted administrative access;
  • unique administrative accounts;
  • SSH key authentication;
  • strong authentication;
  • encrypted HTTPS and SSH connections;
  • firewall restrictions;
  • access logging;
  • security updates;
  • operating system hardening;
  • password protection;
  • temporary credentials;
  • limited credential retention;
  • backup procedures;
  • malware investigation;
  • secure deletion of temporary working data.

The exact measures depend on the services being performed and the Customer’s infrastructure.

Article 28 contractual arrangements must describe technical and organisational security measures, and the Commission specifically states that these should be described concretely rather than merely generically. (EUR-Lex)

14. Customer Infrastructure Security

Many security controls remain under the Controller’s authority because the infrastructure remains in the Controller’s own account.

Depending on the agreed service, the Controller may remain responsible for decisions concerning:

  • hosting provider;
  • infrastructure architecture;
  • user accounts;
  • application access;
  • application security;
  • retention policies;
  • business continuity requirements;
  • software licences;
  • third-party applications.

DirektSupport may make recommendations, but measures outside the agreed service scope remain the Controller’s responsibility.

15. Administrative Credentials

The Controller may provide DirektSupport with credentials necessary to perform technical work.

These may include:

  • SSH access;
  • root or sudo access;
  • hosting control panel access;
  • WordPress administration;
  • DNS management;
  • Cloudflare;
  • hosting provider consoles.

Where practical, DirektSupport recommends:

  • temporary credentials;
  • SSH keys;
  • restricted access;
  • revocation of access following one-time interventions.

Customers should not send private SSH keys or passwords in an initial support request unless an appropriate secure method has been agreed.

16. Sub-processors

The Controller grants DirektSupport general authorisation to engage sub-processors where reasonably necessary to provide or support the services.

A sub-processor may be used for functions such as:

  • infrastructure hosting;
  • secure communications;
  • support systems;
  • backup infrastructure;
  • technical service delivery.

Where a sub-processor processes Personal Data on behalf of the Controller, DirektSupport shall impose data protection obligations that provide substantially equivalent protection to those applicable under this DPA.

DirektSupport remains responsible for the performance of its obligations under this DPA where processing is delegated to a sub-processor.

Article 28 permits general authorisation for sub-processors provided that the Controller is informed of intended additions or replacements and has an opportunity to object. Sub-processors must also be contractually subject to substantially the same data protection obligations. (EUR-Lex)

17. Changes to Sub-processors

Where a new sub-processor will materially process Customer Personal Data on behalf of DirektSupport, we will provide reasonable advance information concerning the intended change where required by GDPR.

The Controller may raise reasonable data protection objections.

The parties will attempt in good faith to resolve any legitimate objection.

Where an objection cannot reasonably be resolved and use of that sub-processor is necessary to provide the relevant service, either party may discontinue the affected service subject to the applicable contractual conditions.

18. Infrastructure Providers Selected by the Customer

A hosting provider directly selected and contracted by the Controller is not automatically a sub-processor appointed by DirektSupport.

For example, if the Controller maintains its own account with:

  • Hetzner;
  • OVHcloud;
  • Netcup;
  • Contabo;
  • IONOS;
  • Scaleway;
  • DigitalOcean;
  • Vultr;

that provider generally has its own contractual and data protection relationship with the Controller.

DirektSupport’s administrative access to that infrastructure does not transfer ownership or control of the provider account to DirektSupport.

19. International Transfers

DirektSupport shall not transfer Personal Data processed on behalf of the Controller to a country outside the European Economic Area except:

  • on documented instructions from the Controller;
  • where required by applicable law;
  • where an appropriate GDPR transfer mechanism applies.

Possible safeguards may include:

  • an adequacy decision;
  • Standard Contractual Clauses;
  • another transfer mechanism permitted by Chapter V GDPR.

The Commission’s standard Article 28 clauses expressly state that transfers to third countries must follow documented instructions and comply with Chapter V GDPR; an ordinary DPA by itself does not automatically satisfy international-transfer requirements. (EUR-Lex)

20. Data Subject Requests

Taking into account the nature of the processing, DirektSupport shall provide reasonable assistance to the Controller where technically possible in responding to requests concerning:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • portability;
  • objection.

If DirektSupport receives a request directly from a data subject concerning Personal Data processed solely on behalf of the Controller, we will normally direct that person to the relevant Controller.

DirektSupport will not independently respond to such a request on the Controller’s behalf unless authorised or legally required to do so.

21. Data Protection Impact Assessments

Where reasonably required by Article 35 or 36 GDPR, DirektSupport shall provide information available to it that is reasonably necessary to assist the Controller with:

  • a Data Protection Impact Assessment;
  • consultation with a supervisory authority.

The Controller remains responsible for determining whether a DPIA or prior consultation is required.

The Commission’s Article 28 clauses specifically include assistance with DPIAs and prior consultation among processor obligations. (EUR-Lex)

22. Personal Data Breaches

If DirektSupport becomes aware of a Personal Data Breach affecting Personal Data processed by DirektSupport on behalf of the Controller, DirektSupport shall notify the Controller without undue delay.

Where information is available, the notification may include:

  • the nature of the incident;
  • categories of data affected;
  • approximate number of affected data subjects or records, where known;
  • likely consequences;
  • measures taken or proposed;
  • relevant contact information.

Information may be provided in stages where complete details are not immediately available.

This follows the Commission’s Article 28 clauses, which require processors to notify controllers without undue delay and provide available information necessary for the controller’s GDPR breach obligations. (EUR-Lex)

23. Controller Breach Notifications

The Controller remains responsible for determining whether an incident must be:

  • reported to a supervisory authority;
  • communicated to affected data subjects;
  • documented internally.

DirektSupport shall provide reasonable assistance using information available to it where the incident relates to processing covered by this DPA.

24. Security Incidents on Customer Infrastructure

Not every compromised server constitutes a Personal Data Breach.

DirektSupport may discover incidents including:

  • malware;
  • compromised WordPress installations;
  • stolen SSH access;
  • suspicious processes;
  • malicious scripts;
  • spam activity.

Where such an incident appears to involve unauthorised access to Personal Data, we will inform the Controller so that the Controller can assess its GDPR obligations.

DirektSupport does not make the Controller’s regulatory notification decision on its behalf unless separately contracted and legally appropriate.

25. Return or Deletion of Personal Data

Following termination of processing, at the Controller’s choice and where technically applicable, DirektSupport shall:

  • return relevant Personal Data to the Controller; or
  • delete Personal Data processed on behalf of the Controller;

unless continued retention is required by European Union or Member State law.

This obligation does not necessarily require deletion of:

  • information that DirektSupport processes independently as Controller for accounting or contractual purposes;
  • legally required records;
  • information contained in technical records that must lawfully be retained.

Until Customer Personal Data is returned or deleted, the protections of this DPA continue to apply.

Return or deletion after termination is one of the express requirements in the Commission’s Article 28 clauses. (EUR-Lex)

26. Backups

Where Personal Data is contained in backup systems, immediate selective deletion may not always be technically possible without compromising the integrity of the backup.

Where applicable:

  • backup copies will remain protected;
  • they will not be restored for unrelated purposes;
  • they will be overwritten or deleted according to the applicable backup retention cycle unless longer retention is legally required.

The Controller remains responsible for specifying any particular retention requirements applicable to its data.

27. Audit & Compliance Information

DirektSupport shall make available information reasonably necessary to demonstrate compliance with its obligations under Article 28 GDPR.

Where required, the Controller may conduct or appoint an independent auditor to conduct an audit concerning processing covered by this DPA.

Unless there is evidence of material non-compliance or a security incident requiring urgent review:

  • audits should be conducted with reasonable advance notice;
  • audits should occur during reasonable business hours;
  • audits should avoid unnecessary disruption;
  • auditors should be subject to confidentiality obligations.

DirektSupport may satisfy reasonable information requests through documentation, policies, technical information or equivalent evidence where this is sufficient.

The Commission’s Article 28 clauses require processors to provide necessary compliance information and permit and contribute to audits at reasonable intervals or where there are indications of non-compliance. (EUR-Lex)

28. Audit Costs

Each party normally bears its own costs associated with routine compliance requests.

Where a Customer requests an unusually extensive on-site audit or technical assistance beyond ordinary compliance obligations, reasonable associated costs may be charged where permitted by law and agreed in advance.

This does not limit the Controller’s mandatory audit rights under GDPR.

29. Supervisory Authorities

DirektSupport shall cooperate with competent data protection supervisory authorities where required by applicable law.

Relevant documentation concerning processing under this DPA may be made available to a competent supervisory authority where legally required.

30. Records and Accountability

DirektSupport shall maintain records required of processors under applicable data protection law.

The Controller remains responsible for its own GDPR accountability obligations and records of processing activities.

31. Liability

Liability between the parties concerning this DPA is subject to:

  • GDPR;
  • applicable mandatory law;
  • the DirektSupport Terms of Service;
  • any separately agreed contract.

Nothing in this DPA excludes liability that cannot legally be excluded or limited.

This DPA does not reduce the rights available to data subjects under GDPR.

32. Term and Termination

This DPA becomes effective when:

  • the Controller and DirektSupport enter into a service relationship; and
  • DirektSupport begins processing Personal Data on behalf of the Controller.

It remains effective for as long as DirektSupport processes such Personal Data.

Termination of the underlying service agreement also terminates this DPA once applicable return, deletion and legal retention obligations have been completed.

33. Conflict With Other Agreements

This DPA supplements the DirektSupport Terms of Service and any applicable quotation or service agreement.

If there is a conflict concerning the processing of Personal Data:

this DPA takes precedence for data protection matters, unless the parties have entered into another written data processing agreement expressly intended to replace it.

A separately signed customer-specific DPA may therefore replace this standard DPA.

34. Governing Law

This DPA is governed by the laws of Romania and applicable European Union law, including GDPR.

For business relationships, disputes shall be subject to the competent courts in Timișoara, Romania, unless another arrangement is agreed in writing or mandatory law requires otherwise.

Annex I — Parties

Controller

Name: Customer purchasing DirektSupport services
Address: As provided in the Customer’s billing or contractual information
Contact: As provided in the Customer account, service request or contract
Role: Controller

Processor

DOW MEDIA SRL
Strada Johann Heinrich Pestalozzi, Nr. 3-5
Timișoara, Romania
European Union

Trade Register: J35/3199/03.11.2004
VAT / Tax ID: RO16906010

Contact: office@direktsupport.eu
Role: Processor

Annex II — Description of Processing

Subject matter:
Technical administration, support, maintenance, troubleshooting, security, backup, migration and recovery of Customer infrastructure.

Nature of processing:
Access, consultation, organisation, storage, backup, migration, restoration, alteration and deletion where technically necessary.

Purpose:
Provision of the technical services requested by the Controller.

Duration:
For the duration of the relevant service relationship and any limited period reasonably required afterwards for completion, security, legal or contractual obligations.

Categories of data subjects may include:

  • customers;
  • employees;
  • website users;
  • application users;
  • business contacts;
  • subscribers;
  • email users;
  • suppliers.

Categories of Personal Data may include:

  • identity information;
  • contact information;
  • online identifiers;
  • IP addresses;
  • account information;
  • website data;
  • application data;
  • email data;
  • server logs;
  • transaction information.

Sensitive data:
Not specifically requested by DirektSupport, but may incidentally be present in Customer infrastructure depending on the Controller’s business.

Annex III — Technical and Organisational Measures

Depending on the service and infrastructure, DirektSupport may apply measures including:

Access Control

  • administrative access limited to authorised personnel;
  • use of unique administrative credentials where practical;
  • restricted root or sudo access;
  • temporary access for one-time interventions where appropriate.

Authentication

  • SSH key authentication where appropriate;
  • strong passwords where passwords are required;
  • multi-factor authentication where supported and appropriate.

Transmission Security

Administrative connections generally use encrypted protocols such as:

  • SSH;
  • HTTPS;
  • TLS.

Unencrypted administrative access is avoided where suitable secure alternatives exist.

Network Security

Depending on the server:

  • provider firewall;
  • UFW;
  • iptables;
  • nftables;
  • Fail2Ban;
  • source-IP restrictions.

System Security

Where included in the service:

  • operating system security updates;
  • service updates;
  • removal or restriction of unnecessary services;
  • SSH hardening;
  • application security review.

Logging

Depending on the infrastructure:

  • SSH logs;
  • authentication logs;
  • web server logs;
  • system logs;
  • application logs;
  • firewall logs.

Logs may be reviewed for troubleshooting and security purposes.

Credentials

Credentials are accessed only where technically necessary.

Customers are encouraged to:

  • provide temporary access;
  • use SSH keys;
  • revoke temporary access after completion;
  • rotate credentials following sensitive incidents.

Backups & Recovery

Where backup services are part of the agreed service:

  • scheduled backups;
  • independent backup locations;
  • defined retention;
  • restoration procedures;
  • backup-status monitoring where included.

Data Minimisation

DirektSupport aims to access only data necessary to perform the technical service.

Customer content is not intentionally inspected where it is irrelevant to the requested task.

Annex IV — Sub-processors

The Controller provides general authorisation for DirektSupport to use sub-processors in accordance with Section 16 of this DPA.

Where a third party materially processes Customer Personal Data on behalf of DirektSupport, information concerning that sub-processor will be provided where required by GDPR.

Infrastructure providers directly contracted and controlled by the Customer are not automatically considered DirektSupport sub-processors.

Acceptance

This DPA forms part of the contractual relationship between the Controller and DOW MEDIA SRL where DirektSupport processes Personal Data on behalf of the Controller.

It may be accepted:

  • as part of the DirektSupport Terms of Service;
  • through an electronic service order;
  • through a separately executed agreement;
  • through another written or electronic contractual mechanism.

A customer-specific signed DPA may be provided where required for a particular business relationship.