Legal · GDPR Art. 28

Data Processing Agreement

How ExpertSlides processes personal data on your behalf as a processor, the safeguards we apply, and the sub-processors we rely on.

1Parties and Scope

This Data Processing Agreement ("DPA") forms part of, and is subject to, the Terms of Service between you ("Controller") and ES Solutions GmbH ("Processor," "ExpertSlides," "we," "our," or "us"). It governs the processing of personal data carried out by the Processor on behalf of the Controller in connection with the ExpertSlides AI presentation services.

This DPA reflects the parties' agreement with respect to the processing of personal data in accordance with Article 28 of the General Data Protection Regulation (GDPR). Where the Controller acts on behalf of its own customers, it confirms it is authorized to instruct the Processor on their behalf.

ES Solutions GmbH
Am Rausch 2
63571 Gelnhausen, Germany

2Definitions

Terms such as "Personal Data," "Processing," "Controller," "Processor," "Sub-Processor," "Data Subject," and "Supervisory Authority" have the meanings given to them in the GDPR. "Applicable Data Protection Law" means the GDPR and any national implementing legislation, including the German Federal Data Protection Act (BDSG).

3Subject Matter and Duration

The subject matter of the processing is the provision of the ExpertSlides services as described in the Terms of Service. The Processor processes personal data only for the duration of the agreement and for as long as required to provide the services or to comply with legal retention obligations.

  • Duration: for the term of the underlying Terms of Service, plus any period required for return or deletion of data.
  • Frequency: continuous, for as long as the Controller uses the services.

4Nature, Purpose and Data Categories

The Processor processes personal data to generate, store, and export AI presentations and related content at the instruction of the Controller. The following categories apply:

Categories of Data Subjects

  • The Controller's account users and authorized team members.
  • Individuals whose personal data is contained in content the Controller submits for processing.

Categories of Personal Data

  • Account & Profile: name, email, and password.
  • User Content: any text, documents, or images submitted to generate presentations, which may contain personal data.
  • Technical Data: IP address, browser type, device information, and access times.

The Controller is responsible for ensuring that no special categories of personal data (Art. 9 GDPR) are submitted unless expressly agreed in writing.

5Obligations of the Processor

The Processor undertakes to:

  • Process personal data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by law.
  • Ensure that persons authorized to process personal data are bound by confidentiality.
  • Implement appropriate technical and organizational measures pursuant to Art. 32 GDPR.
  • Respect the conditions for engaging sub-processors set out in this DPA.
  • Assist the Controller in fulfilling its obligations to respond to data subject requests and to ensure security, breach notification, and data protection impact assessments.
  • At the Controller's choice, delete or return all personal data after the end of the provision of services.
  • Make available all information necessary to demonstrate compliance and allow for audits.

6Obligations of the Controller

The Controller is responsible for:

  • Ensuring it has a valid legal basis for the processing it instructs.
  • Providing instructions that comply with Applicable Data Protection Law.
  • Ensuring the accuracy and lawfulness of the personal data it submits.
  • Obtaining any necessary consents or notices from its own data subjects.

7Sub-Processors

The Controller grants the Processor general authorization to engage sub-processors to provide the services. The Processor remains fully liable for the performance of its sub-processors and ensures each is bound by data protection obligations equivalent to those in this DPA. We will inform the Controller of any intended changes and give an opportunity to object on reasonable grounds. Current sub-processors include:

Cloud Infrastructure

Hosting and storage providers such as Amazon Web Services and Google Cloud.

AI Model Providers

Providers that generate presentation content from anonymized or pseudonymized input data.

Payment Processing

Secure payment providers such as Stripe and PayPal. Full card details are not stored on our servers.

Communication

Email service providers used for transactional and marketing messages.

8Technical and Organizational Measures

In accordance with Art. 32 GDPR, the Processor maintains appropriate technical and organizational measures to protect personal data, including:

  • Encryption of data in transit and at rest where appropriate.
  • Access controls, role-based permissions, and authentication safeguards.
  • Network security, monitoring, and protection against unauthorized access.
  • Regular backups and resilience measures to ensure availability.
  • Recognized security and compliance standards, including ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, and CSA STAR.
  • Procedures for regularly testing and evaluating the effectiveness of these measures.

9Assistance and Data Subject Rights

Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling its obligation to respond to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability, and objection. Where the Processor receives such a request directly, it will refer the data subject to the Controller.

10Personal Data Breaches

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data. The notification will describe, to the extent available, the nature of the breach, the likely consequences, and the measures taken or proposed to address it, so the Controller can meet its own notification obligations under Art. 33 and 34 GDPR.

11International Data Transfers

Where personal data is processed outside the European Economic Area (in particular in the USA), the Processor ensures an adequate level of protection through the EU-U.S. Data Privacy Framework or the Standard Contractual Clauses (SCCs) approved by the European Commission, together with any supplementary measures required.

12Audits and Inspections

The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. Audits will be conducted with reasonable prior notice, during normal business hours, and in a manner that does not unreasonably disrupt the Processor's operations. Where available, certifications and audit reports may be provided to satisfy audit requests.

13Return and Deletion of Data

Upon termination of the services, and at the Controller's choice, the Processor will delete or return all personal data and delete existing copies, unless storage is required by Union or Member State law. Standard deletion follows the Processor's retention schedule, and payment-related data may be retained as required by German commercial and tax law (typically 6 to 10 years).

14Liability and Final Provisions

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. This DPA is governed by the laws of the Federal Republic of Germany, and the courts of Hanau, Germany, have exclusive jurisdiction over any disputes. If any provision of this DPA is found to be invalid, the remaining provisions remain in full force, and the parties will replace the invalid provision with a valid one that reflects its intent. In the event of a conflict between this DPA and the Terms of Service regarding data protection, this DPA prevails.

15Contact

For any questions regarding this Data Processing Agreement or to submit a signed copy, please reach out to our support team:

ES Solutions GmbH
Am Rausch 2, 63571 Gelnhausen, Germany
Contact Our Support Today