Legal
Data Processing Agreement
Interim draft · Version 1.0 · June 2026 · AnnexPass OÜ
This Data Processing Agreement ("DPA") is intended to form part of the agreement between AnnexPass OÜ ("Processor") and the customer ("Controller") for the provision of AnnexPass software services under Regulation (EU) 2016/679 (GDPR).
1. Subject matter and duration
Processor processes personal data on behalf of Controller in connection with battery passport compliance workflows, supplier due diligence, document storage, and related audit trails. Processing continues for the term of the services agreement and for any retention period required by that agreement or by law.
2. Nature and purpose
Processing is limited to hosting, storage, retrieval, transmission, and display of Controller data within the AnnexPass workspace, including optional AI-assisted document extraction where Controllers enable that feature.
3. Categories of data subjects
- Controller employees and contractors with workspace accounts
- Supplier contacts invited through token links
- External auditors granted time-limited read access
4. Categories of personal data
- Account identifiers (name, work email, role)
- Supplier contact information
- Uploaded compliance documents that may contain personal data
- Audit trail metadata (actor, timestamp, action)
5. Controller instructions
Processor processes personal data only on documented instructions from Controller, including configuration of the workspace, unless required to do otherwise by Union or Member State law. In that case Processor will inform Controller before processing, unless the law prohibits such notice.
6. Security measures
Processor implements appropriate technical and organisational measures as described on the Trust centre, including access controls, encryption in transit, audit logging, and environment separation for production systems. A final security annex will be attached before commercial signature.
7. Subprocessors
Controller authorises use of subprocessors listed on the Trust centre. Processor will notify Controller of material changes with a reasonable advance period before the change takes effect, so Controller may object on reasonable grounds related to data protection.
8. International transfers
Customer data is intended to be processed and stored within the European Economic Area unless otherwise agreed in writing. Any transfer outside the EEA will use an approved transfer mechanism under GDPR Chapter V.
9. Assistance and breach notice
Processor will assist Controller, taking into account the nature of processing, with data subject requests, DPIAs, and supervisory authority inquiries. Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data.
10. Return and deletion
On termination of services, Processor will delete or return personal data at Controller's choice, except where retention is required by law. Residual backups are purged on the backup rotation schedule disclosed in the final agreement.
11. Contact
Privacy inquiries: privacy@annexpass.com. Commercial terms remain governed by the customer agreement once executed.
AnnexPass (AnnexPass OÜ) provides software tools to support compliance workflows. Customers remain the economic operator responsible for regulatory compliance. Not legal advice.