Data processing agreement (template)

Version 1.0 in force from 13.08.2026 last updated 13.08.2026

This template applies to commissioned studies: a company (agency, institute, client) has a participant panel measured through NeuroScreen. In that case the client is the controller and NeuroScreen is the processor. For the platform's own tests the reverse applies — there we are the controller and the Privacy Policy governs.

The agreement must be concluded before the first measurement. No commissioned study may start without it. Fields to be completed are marked […].

Data processing agreement under Art. 28 GDPR

between

[Client company]
[Street, postcode, city, country]
represented by: [name]
— hereinafter the "Controller"

and

Adam Koch
Weißensteinstr. 44, 58093 Hagen, Germany
E-mail: info@advena-partners.com
— hereinafter the "Processor"

§ 1 Subject matter, duration and roles

  1. The subject matter is the processing of personal data by the Processor on behalf of the Controller in providing the service "measurement of a participant panel via the NeuroScreen platform" under the main contract / quotation of [date].
  2. The Controller alone determines the purposes and means of processing. The Processor collects and processes the data exclusively on instructions.
  3. This agreement starts on signature and ends when the main contract ends. The Controller may terminate it at any time without notice; the consequence is the end of processing and the procedure under § 10.
  4. Details of the nature, scope, purpose, types of data and categories of data subjects are set out in Annex 1.

§ 2 Instructions

  1. The Processor processes the data only on documented instructions from the Controller, including with regard to transfers to third countries — unless required to do so by Union or Member State law. In that case the Processor informs the Controller before processing, unless the law prohibits this on important grounds of public interest.
  2. Instructions are given in text form. Oral instructions must be confirmed in text form without delay. The persons authorised to give instructions are named in Annex 1.
  3. If the Processor considers an instruction unlawful, it informs the Controller without delay and may suspend execution until the instruction is confirmed or amended.
  4. If the Processor processes data for its own purposes contrary to instructions, it becomes a controller in respect of that processing (Art. 28 (10) GDPR).

§ 3 Special categories of personal data

  1. The processing includes EEG recordings — health data within the meaning of Art. 9 GDPR. Both parties treat them with correspondingly heightened care.
  2. The Controller ensures that valid explicit consent under Art. 9 (2) (a) GDPR exists for every participating person before the measurement begins, and that data subjects have been informed of the purpose, the recipients and how to withdraw. The Processor provides the consent screen of the invitation link for this purpose; responsibility for the lawfulness of the consent remains with the Controller.
  3. The Processor points out, and the Controller acknowledges, that NeuroScreen is not a medical device and provides no diagnoses. Results must not be presented to participants as a medical statement.
  4. Separation from the normative database: data from commissioned studies does not feed into the NeuroScreen comparison or normative database and is not analysed for the Processor's own purposes. Any use beyond the commission requires a separate written agreement and separate consent from the data subjects.

§ 4 Confidentiality

  1. The Processor uses only persons who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The obligation survives the end of their activity.
  2. Access follows the least-privilege principle and is limited to persons who need it for operation or analysis.

§ 5 Technical and organisational measures

  1. The Processor implements the measures described in Annex 2 under Art. 32 GDPR and maintains them for the term of the agreement.
  2. The measures may evolve provided the level of protection is not reduced. Material changes are documented and communicated on request.

§ 6 Sub-processors

  1. The Controller gives general authorisation for the engagement of the sub-processors listed in Annex 3.
  2. The Processor notifies any intended change — addition or replacement — in text form at least four weeks in advance. The Controller may object within two weeks on important grounds relating to data protection. If the objection cannot be resolved, the Controller may terminate the main contract for cause.
  3. The Processor imposes on sub-processors data protection obligations equivalent to those in this agreement and remains liable for their conduct as for its own.
  4. Ancillary services (telecommunications, post, cleaning, manufacturer maintenance) do not constitute sub-processing; appropriate safeguards are nevertheless applied.

§ 7 Assistance with data subject rights

  1. The Processor assists the Controller by appropriate technical and organisational measures in fulfilling requests under Art. 15–22 GDPR.
  2. If a data subject approaches the Processor directly, the Processor forwards the request without delay and does not answer it itself.
  3. Requests for access, rectification, erasure and restriction are implemented only on instruction. Participants are identified by the e-mail address used for the invitation.

§ 8 Personal data breaches

  1. The Processor notifies the Controller of any personal data breach without undue delay and at the latest within 24 hours of becoming aware of it, in text form, to the address given in Annex 1.
  2. The notification contains, as far as known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
  3. The Processor assists the Controller with its obligations under Art. 33 and 34 GDPR. Notifications to supervisory authorities and data subjects are made by the Controller.

§ 9 Assistance with impact assessment and consultation

The Processor assists the Controller with data protection impact assessments (Art. 35 GDPR) and prior consultations (Art. 36 GDPR), taking into account the nature of the processing and the information available to it. Because health data is processed on a larger scale, an impact assessment is regularly required.

§ 10 Erasure and return

  1. On completion of the study, and at the latest on termination of this agreement, the Processor erases all data processed on behalf of the Controller or returns it at the Controller's choice — within 30 days of the corresponding instruction.
  2. Return is made in a common, machine-readable format.
  3. Encrypted backups expire within the relevant backup cycle, after 90 days at the latest; until then they remain locked and are not processed.
  4. Documentation serving as evidence of proper processing may be retained beyond the end of the agreement for the applicable retention periods. Erasure is confirmed in text form on request.

§ 11 Evidence and audits

  1. The Processor demonstrates compliance with its obligations under Art. 28 GDPR — primarily by an up-to-date self-assessment, the description of measures in Annex 2, or certificates and audit reports of its sub-processors.
  2. Where this evidence is insufficient, the Processor allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it who is not a competitor of the Processor. Audits must be announced with reasonable notice (as a rule two weeks), take place on working days during business hours and must not unreasonably disrupt operations.
  3. The Processor informs the Controller without delay if it considers that an instruction infringes data protection law.

§ 12 Liability

Art. 82 GDPR applies. As between the parties, liability follows statutory rules; limitations of liability in the main contract remain unaffected insofar as they do not restrict claims of data subjects.

§ 13 Final provisions

  1. Amendments and supplements require text form; this also applies to any waiver of this form requirement.
  2. In case of conflict, this agreement prevails over the main contract in matters of data protection.
  3. German law applies. The place of jurisdiction is, as far as permissible, the Processor's place of business.
  4. If any provision is invalid, the remainder of the agreement remains effective.
Place, date — ControllerPlace, date — Processor
[…][…]
Name, position, signatureAdam Koch

Annex 1 — Description of the processing

Subject matterMeasurement of brain signals (EEG) of panel participants while a film designated by the Controller is played, together with analysis and provision of the results.
Purpose[e.g. testing the attentional impact of a commercial]
DurationTerm of the main contract; erasure under § 10.
Nature of processingCollection, storage, structuring, analysis, transmission to the Controller, erasure.
Categories of data subjectsPanel participants invited by the Controller (with or without a user account).
Types of data — generalE-mail address as identifier; optionally age band and sex; session metadata (film and film version, start, duration, browser and device type, reasons for abandonment); IP address and browser identification in technical logs.
Types of data — special categories (Art. 9)Raw EEG data (four channels, 256 values/s), signal quality per electrode, time and synchronisation markers, derived measures and reports.
Place of processingExclusively data centres in Germany (see Annex 3). No third-country transfer except the support access in e-mail delivery named in Annex 3, based on standard contractual clauses.
Persons authorised to instruct[name, position, e-mail]
Breach notification address (§ 8)[Controller's e-mail]
Processor contactAdam Koch, info@advena-partners.com, +49 2334 4937304

Annex 2 — Technical and organisational measures (Art. 32 GDPR)

ConfidentialityPhysical access: hoster data centres with access control, video surveillance and logging. System access: personal accounts, no shared credentials, multi-factor authentication for administrative access, user sign-in via single-use, short-lived links instead of passwords. Data access: role model on a least-privilege basis; separation of identity data and measurement data; measurement data stored under a participant identifier rather than a name (pseudonymisation).
IntegrityTransport exclusively over TLS (HTTPS/WSS). Checksums (SHA-256) for every recording; an append-only, hash-chained audit log of changes and access; optional cryptographic timestamps proving that a recording was created at a given time and not altered afterwards.
Availability and resilienceRegular, encrypted backups; separate storage of backups; restore tests; monitoring of services and time synchronisation; malware scanning of uploaded files before acceptance.
ReproducibilityVersioning of film, marker list and analysis pipeline; completed sessions remain bound to the version valid at the time of measurement so that results stay reproducible.
SeparationSeparate database and separate storage per study; commissioned studies are technically separated from the platform's normative database (§ 3 (4)).
Data minimisationYear of birth instead of full date of birth; optional details remain optional; short retention for technical logs.
ReviewRegular review of measures, updating of dependencies, evaluation of logs when anomalies appear.

Annex 3 — Approved sub-processors

CompanyServicePlace of processing
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany Servers, database and object storage (hosting of the application and measurement data) Germany
Zoho Corporation B.V., Beneluxlaan 4B, 3527 HS Utrecht, Netherlands E-mail delivery (invitations, sign-in links, notifications) EU (European data centre); exceptional support access from a third country based on the EU standard contractual clauses

Further sub-processors are notified under the procedure in § 6 (2).