Data Processing Agreement
Last updated September 8, 2026
This Data Processing Agreement (the "DPA") forms part of, and is subject to, the agreement for the provision of the Zentrum24 Academy compliance-training platform between the parties (the "Principal Agreement"). It is entered into between:
- Zentrum24 LLC, a company with registered address at 1621 Central Ave, Cheyenne, Wyoming 82001, USA ("Zentrum24 Academy", the "Processor"); and
- the customer identified in the Principal Agreement and in Annex I (the "Customer", the "Controller").
Zentrum24 Academy and the Customer are each a "party" and together the "parties". This DPA reflects the parties' agreement on the processing of Personal Data in connection with the Zentrum24 Academy multi-tenant Software-as-a-Service compliance learning management system used to manage role-based training assignments, SCORM courses, quizzes, 21 CFR Part 11 electronic signatures, a tamper-evident audit trail, and completion certificates (the "Service").
1. Definitions and interpretation
1.1 "Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including Regulation (EU) 2016/679 (the "GDPR"), the GDPR as retained in United Kingdom law (the "UK GDPR") together with the UK Data Protection Act 2018, and, where applicable, the Swiss Federal Act on Data Protection.
1.2 The terms "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "processing", "special categories of personal data", and "supervisory authority" have the meanings given in the GDPR.
1.3 "Sub-processor" means any third party engaged by Zentrum24 Academy (or by another sub-processor of Zentrum24 Academy) to process Personal Data on behalf of the Customer under this DPA.
1.4 "SCCs" means the standard contractual clauses for the transfer of personal data to third countries set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, together with the UK International Data Transfer Addendum and any applicable Swiss amendments, as further described in Section 12.
1.5 In the event of any conflict between this DPA and the Principal Agreement in relation to the processing of Personal Data, this DPA prevails. In the event of any conflict between this DPA and the SCCs, the SCCs prevail.
2. Subject-matter, duration, nature and purpose of processing
2.1 Roles. The Customer is the Controller and Zentrum24 Academy is the Processor in respect of the Personal Data processed to provide the Service. Where Zentrum24 Academy processes limited Personal Data as an independent controller for its own legitimate business purposes (for example, account administration, billing, security, fraud prevention, and product improvement using aggregated or de-identified data), it does so in accordance with its privacy notice and applicable Data Protection Law, and such processing is outside the scope of this DPA.
2.2 Subject-matter. The subject-matter of the processing is the delivery, operation, support, and security of the Service on behalf of the Customer.
2.3 Duration. Zentrum24 Academy will process Personal Data for the term of the Principal Agreement and for the additional period contemplated by Section 10 (deletion and return), unless a longer retention period is required by applicable law.
2.4 Nature and purpose. The nature and purpose of the processing are to host and operate a compliance-training learning management system, including: creating and administering tenant accounts and user records; assigning and tracking role-based training; delivering SCORM courses and quizzes; capturing completion status, scores, and 21 CFR Part 11 electronic signatures; generating completion certificates; maintaining a tamper-evident, hash-chained audit trail; and providing security, monitoring, backup, and support.
2.5 The categories of Data Subjects and Personal Data, and further details of the processing, are set out in Annex I.
3. Processing only on documented instructions
3.1 Zentrum24 Academy will process Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by European Union or Member State law to which Zentrum24 Academy is subject; in such a case, Zentrum24 Academy will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
3.2 The Principal Agreement, this DPA (including its Annexes), and the Customer's authorised use and configuration of the Service constitute the Customer's complete and documented instructions. Additional or different instructions must be agreed in writing and may be subject to adjustments to fees or scope.
3.3 Zentrum24 Academy will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law. Zentrum24 Academy is not obliged to carry out a legal assessment of the Customer's instructions and this Section 3.3 is without prejudice to the parties' respective obligations under Data Protection Law.
4. Confidentiality
4.1 Zentrum24 Academy will ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.2 Zentrum24 Academy will limit access to Personal Data to personnel who need access to perform Zentrum24 Academy's obligations under the Principal Agreement, and will ensure such personnel receive appropriate data-protection and security training.
5. Security of processing (Article 32)
5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of natural persons, Zentrum24 Academy will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures in force as at the effective date are described in Annex II.
5.2 Zentrum24 Academy may update or modify the measures in Annex II from time to time, provided that such updates do not materially reduce the overall level of security of the Service.
5.3 The Customer is responsible for the secure use of the Service within its control, including configuring role-based access, enforcing multi-factor authentication and password policy where offered, managing its administrators and users, and promptly deactivating credentials for users who no longer require access.
6. Sub-processors
6.1 General authorisation. The Customer grants Zentrum24 Academy general authorisation to engage Sub-processors to process Personal Data, subject to this Section 6. The Sub-processors authorised as at the effective date are listed in Annex III.
6.2 Flow-down. Where Zentrum24 Academy engages a Sub-processor, it will do so by way of a written contract that imposes data-protection obligations that are substantially the same as, and no less protective than, those set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. Zentrum24 Academy remains fully liable to the Customer for the performance of each Sub-processor's obligations.
6.3 Change notice and objection. Zentrum24 Academy will give the Customer prior written notice (which may be given by email or through the Service or Zentrum24 Academy's sub-processor page) of any intended addition or replacement of a Sub-processor, giving the Customer a reasonable opportunity — at least [30] days before the new Sub-processor begins processing Personal Data — to object on reasonable data-protection grounds. If the Customer objects, the parties will work in good faith to resolve the objection. If no resolution is reached, the Customer may, as its sole and exclusive remedy, terminate the affected part of the Service in accordance with the Principal Agreement.
7. Assistance with Data Subject requests
7.1 Taking into account the nature of the processing, Zentrum24 Academy will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in the fulfilment of the Customer's obligation to respond to requests to exercise Data Subject rights under Chapter III of the GDPR (including rights of access, rectification, erasure, restriction, data portability, and objection).
7.2 Zentrum24 Academy will provide self-service functionality within the Service enabling the Customer to access, correct, export, and delete Personal Data. Where a Data Subject request cannot be fulfilled through such functionality, Zentrum24 Academy will provide reasonable additional assistance at the Customer's request.
7.3 If Zentrum24 Academy receives a request directly from a Data Subject relating to Personal Data processed under this DPA, Zentrum24 Academy will, unless legally prohibited, promptly inform the Customer and will not respond to the request itself except on the Customer's documented instructions or as required by applicable law.
8. Assistance with Articles 32 to 36
8.1 Taking into account the nature of processing and the information available to Zentrum24 Academy, Zentrum24 Academy will assist the Customer in ensuring compliance with the Customer's obligations under Articles 32 to 36 of the GDPR, namely security of processing, notification of Personal Data Breaches to the supervisory authority and to Data Subjects, data protection impact assessments, and prior consultation with the supervisory authority.
8.2 Such assistance may include making available the security information in Annex II, this DPA, and other documentation reasonably necessary for the Customer to carry out a data protection impact assessment and, where required, prior consultation.
9. Personal Data Breach notification
9.1 Zentrum24 Academy will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.
9.2 The notification will, to the extent known and insofar as reasonably possible, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where the information cannot be provided at the same time, it may be provided in phases without undue further delay.
9.3 Zentrum24 Academy's notification of, or response to, a Personal Data Breach will not be construed as an acknowledgement by Zentrum24 Academy of any fault or liability. The Customer remains responsible for its own notification obligations to supervisory authorities and Data Subjects.
10. Deletion and return on termination
10.1 At the choice of the Customer, Zentrum24 Academy will delete or return all Personal Data to the Customer after the end of the provision of the Service, and delete existing copies, unless European Union or Member State law requires storage of the Personal Data.
10.2 The Customer may export its Personal Data (including training records, electronic-signature manifests, audit-trail entries, and certificates) using the Service's export functionality during the term and for a period of [30] days after termination or expiry (the "retrieval period"). After the retrieval period, Zentrum24 Academy will delete Personal Data within [90] days, subject to Section 10.3.
10.3 Zentrum24 Academy may retain Personal Data to the extent, and for the period, required by applicable law (including records that must be preserved to support the integrity of a 21 CFR Part 11 / EU Annex 11 audit trail), and Personal Data residing in routine encrypted backups will be deleted in accordance with Zentrum24 Academy's backup rotation schedule. During any such extended retention, the obligations of this DPA continue to apply and the Personal Data will remain subject to the security measures in Annex II and will only be processed as necessary for the retention purpose.
10.4 On the Customer's written request, Zentrum24 Academy will certify in writing that it has complied with this Section 10.
11. Audits and information
11.1 Zentrum24 Academy will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
11.2 To satisfy the requirements of Section 11.1, Zentrum24 Academy may make available its then-current security documentation, third-party audit reports, certifications, and responses to reasonable written security questionnaires.
11.3 Where the information made available under Section 11.2 is insufficient, the Customer may, on reasonable prior written notice of at least [30] days and no more than once per twelve-month period (unless required following a Personal Data Breach or by a supervisory authority), conduct an audit during normal business hours. Audits must be conducted in a manner that minimises disruption, must respect the confidentiality and security of Zentrum24 Academy's other customers and its multi-tenant environment, must not include access to other customers' data or to any penetration testing of production systems without Zentrum24 Academy's prior written consent, and the auditor must enter into a confidentiality undertaking acceptable to Zentrum24 Academy. Each party bears its own costs, save that the Customer bears Zentrum24 Academy's reasonable costs where the audit reveals no material non-compliance.
12. International transfers
12.1 The Service is hosted on Vercel (application hosting) and Supabase (managed PostgreSQL database and object storage), with primary processing in the the United States (AWS us-east-1 (Northern Virginia, United States)); Zentrum24 Academy is established in the United States. Accordingly, the provision of the Service may involve the transfer of Personal Data to, and processing in, the United States and other countries in which Zentrum24 Academy or its Sub-processors operate.
12.2 Where the processing of Personal Data subject to the GDPR or UK GDPR involves a transfer to a country that is not the subject of an adequacy decision, the parties agree that such transfer is governed by the SCCs, which are hereby incorporated into this DPA by reference and completed as follows:
- Module. Module Two (Controller to Processor) applies where the Customer is a controller and Zentrum24 Academy is a processor. Module Three (Processor to Processor) applies in respect of onward transfers to Sub-processors.
- Docking clause (Clause 7). The optional docking clause applies.
- General authorisation (Clause 9(a), Option 2). The general Sub-processor authorisation in Section 6 applies, with the time period specified in Section 6.3.
- Redress and governing law/forum (Clauses 11, 17, 18). The optional redress clause does not apply; the governing law and forum are those of an EU Member State that allows for third-party beneficiary rights, namely Ireland.
- Annexes. Annex I to this DPA populates Annexes I.A and I.B of the SCCs; the competent supervisory authority (Annex I.C) is identified in Annex I; Annex II to this DPA populates Annex II of the SCCs; and Annex III to this DPA populates the list of Sub-processors.
12.3 United Kingdom. For transfers subject to the UK GDPR, the SCCs apply as varied and supplemented by the UK International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018, which is incorporated by reference and completed using the corresponding information in this DPA and its Annexes.
12.4 Switzerland. For transfers subject to the Swiss Federal Act on Data Protection, the SCCs apply with the amendments necessary to give effect to Swiss law (including references to the Swiss Federal Data Protection and Information Commissioner and to Swiss law), as published by the Swiss authority.
12.5 Where and to the extent Zentrum24 Academy participates in an approved transfer framework recognised as providing an adequate level of protection (for example, the EU-U.S. Data Privacy Framework and its UK and Swiss extensions), the parties may rely on such framework as an alternative transfer mechanism for transfers to the United States.
12.6 If the transfer mechanism relied upon is invalidated, superseded, or ceases to provide a valid basis for transfer, the parties will work together in good faith to implement an alternative lawful transfer mechanism without undue delay.
13. Liability
13.1 Each party's liability arising out of or in connection with this DPA and the SCCs, whether in contract, tort (including negligence), or otherwise, is subject to the aggregate limitations of liability and exclusions agreed in the Principal Agreement, and any reference in those limitations to the liability of a party will mean the aggregate liability of that party under the Principal Agreement and this DPA together.
13.2 Nothing in this DPA limits or excludes either party's liability where it cannot be limited or excluded under applicable law, including liability of a Data Subject's right to compensation under Article 82 of the GDPR, or the rights of Data Subjects under the SCCs.
13.3 As between the parties, and without prejudice to the rights of Data Subjects or supervisory authorities, liability for administrative fines, claims, or damages arising from a party's own breach of its obligations under Data Protection Law will be allocated according to each party's responsibility for the harm caused, taking into account the roles of Controller and Processor.
14. General
14.1 Term. This DPA takes effect on the effective date of the Principal Agreement (or, if later, the date it is last signed) and continues for as long as Zentrum24 Academy processes Personal Data on behalf of the Customer.
14.2 Governing law and jurisdiction. Except where Data Protection Law or the SCCs require otherwise, this DPA is governed by, and construed in accordance with, the laws of State of Wyoming, USA, and the courts identified in the Principal Agreement have exclusive jurisdiction.
14.3 Severance and survival. If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect. Provisions that by their nature should survive termination will survive.
14.4 Data protection contact. Data-protection queries relating to this DPA may be directed to Zentrum24 Academy at contact@zentrum24.com.
Annex I — Description of processing
A. List of parties
Data exporter (Controller): the Customer identified in the Principal Agreement.
- Name and address: (to be completed by the Customer) / (to be completed by the Customer).
- Contact person, position and details: (to be completed by the Customer).
- Activities relevant to the data transferred: use of the Zentrum24 Academy Service to administer and record compliance training for its workforce.
- Role: Controller.
Data importer (Processor): Zentrum24 LLC
- Name and address: Zentrum24 LLC, 1621 Central Ave, Cheyenne, Wyoming 82001, USA.
- Contact person, position and details: contact@zentrum24.com.
- Activities relevant to the data transferred: provision, operation, support, and security of the Zentrum24 Academy compliance-training platform.
- Role: Processor.
B. Description of processing
Categories of Data Subjects. The Customer's personnel and other individuals whose training the Customer administers through the Service, including:
- the Customer's employees, trainees, and workers assigned to compliance training;
- the Customer's administrators, authors, managers, and learners who hold Service accounts;
- contractors, temporary staff, or other authorised users the Customer chooses to enrol.
Categories of Personal Data.
- Account data: organisation name and subscription plan.
- User identity and profile data: full name, work email address, optional employee identifier, assigned role (tenant admin / author / manager / learner), and authentication data (hashed password, TOTP multi-factor secret and backup codes, and SSO identifiers where SAML/SCIM is used).
- Training records: course and quiz assignments, completion status, scores, 21 CFR Part 11 electronic-signature records (signer identity, meaning of signature, and timestamp), and completion certificates.
- Audit and security logs: IP address, user-agent, timestamps, and event metadata recorded in the tamper-evident, hash-chained audit trail.
Special categories of Personal Data. The Service is not designed or intended to process special categories of personal data (Article 9) or criminal-conviction data (Article 10). The Customer must not upload such data except free-text content it chooses to enter; if it does, the Customer is responsible for ensuring a lawful basis and any additional safeguards.
Frequency of processing. Continuous, for the duration of the Principal Agreement.
Nature and purpose of processing. As described in Section 2 of this DPA — hosting and operating a compliance-training learning management system, including assignment and tracking of training, delivery of SCORM courses and quizzes, capture of scores and electronic signatures, generation of certificates, maintenance of an audit trail, and provision of security, backup, monitoring, and support.
Retention period. For the term of the Principal Agreement plus the periods described in Section 10, and thereafter only as required by applicable law (for example, to preserve regulated training and audit-trail records).
Transfers to Sub-processors. Subject-matter, nature, and duration of processing by Sub-processors are as set out in Annex III.
C. Competent supervisory authority
The competent supervisory authority is the authority of the EU Member State in which the Customer, or its EU representative, is established, or otherwise as determined under Clause 13 of the SCCs: the Irish Data Protection Commission. For UK transfers, the competent authority is the UK Information Commissioner's Office; for Swiss transfers, the Swiss Federal Data Protection and Information Commissioner.
Annex II — Technical and organisational security measures
The following measures are implemented and maintained by Zentrum24 Academy as at the effective date. They may be updated in accordance with Section 5.2. This Annex also completes Annex II of the SCCs.
1. Tenant isolation and access control
- Hard multi-tenant isolation enforced at the database layer using PostgreSQL row-level security (RLS), with the application connecting through a dedicated non-superuser role that cannot bypass RLS policies.
- Role-based access control (RBAC) across four application roles — tenant admin, author, manager, and learner — restricting functionality and data access on a least-privilege basis.
- Stateless session management using signed JWTs stored in httpOnly cookies with idle-timeout expiry.
2. Authentication and secret management
- Multi-factor authentication (MFA) via time-based one-time passwords (TOTP) with recovery backup codes.
- Password protection using bcrypt hashing with configurable complexity requirements, password history, and account lockout on repeated failed attempts.
- Enterprise identity federation through SAML single sign-on and SCIM user provisioning (available on the Pro tier).
- Secret protection using KMS-style envelope encryption for stored MFA and SSO secrets.
3. Encryption
- Encryption in transit using TLS for connections to and within the Service.
- Encryption at rest for the managed PostgreSQL database and for object storage (private buckets with server-side encryption), provided by Supabase.
4. Integrity, audit, and electronic records
- Tamper-evident, hash-chained audit log providing a verifiable, append-only record of security- and compliance-relevant events.
- 21 CFR Part 11-compliant electronic signatures capturing signer identity, the meaning of the signature, and a trusted timestamp, consistent with EU Annex 11 expectations.
5. Availability, resilience, and infrastructure security
- Hosting on Vercel (managed serverless application hosting behind a global edge network), with a managed PostgreSQL database and private, encrypted object storage provided by Supabase; rate-limiting state is maintained in the PostgreSQL database. Primary hosting region: AWS us-east-1 (Northern Virginia, United States).
- Managed backups of the database with encryption at rest and a defined rotation schedule.
- Per-tenant and per-user rate limiting to protect availability and mitigate abuse.
- Transactional email delivered via Resend (Resend, Inc.), with a direct SMTP transport available as a fallback.
6. Organisational measures
- Confidentiality obligations imposed on personnel authorised to process Personal Data, together with data-protection and security training.
- Least-privilege administrative access to production systems, limited to personnel who require it to operate and support the Service.
- Sub-processor governance through written contracts imposing data-protection obligations no less protective than those in this DPA (Section 6).
- Error monitoring configured to limit the capture of Personal Data (structured application logs retained by the hosting platform; no third-party error-monitoring service is installed).
7. Standards referenced
The Service and its controls are designed with reference to 21 CFR Part 11, EU Annex 11, ICH Q9, GAMP 5, SCORM 1.2/2004, and GDPR/UK-GDPR. References to standards describe design intent and are not, by themselves, a warranty of certification or of any particular customer's regulatory compliance.
Annex III — List of authorised Sub-processors
As at the effective date, Zentrum24 Academy engages the following Sub-processors. This list may change in accordance with Section 6.3.
- Vercel Inc. — application hosting and content delivery. Processing location: the United States. Nature: serving the application and processing request traffic.
- Supabase — managed PostgreSQL database and private, encrypted object storage. Processing location: the United States. Nature: storage of Service data, including account, user, training-record, and audit data.
- Stripe, Inc. — payment processing and subscription billing. Processing location: United States. Nature: processing of Customer account and billing contact data; Stripe does not process learner training records.
- Email / SMTP provider (not yet selected) — transactional email delivery. Processing location: United States. Nature: delivery of Service notifications containing user name and email address. This sub-processor will be identified here before launch.
Signatures
By signing the Principal Agreement, or by separately executing this DPA, each party agrees to be bound by this DPA. Each party warrants that the individual signing on its behalf is duly authorised to do so.
For Zentrum24 LLC (Processor): Name: Anselme Metoudou; Title: Chief Executive Officer / Managing Member; Date: on execution; Signature: ____________________.
For the Customer (Controller): Name: ____________________; Title: ____________________; Date: ____________________; Signature: ____________________.