{"id":4823,"date":"2023-06-02T12:27:47","date_gmt":"2023-06-02T10:27:47","guid":{"rendered":"https:\/\/behaviorquant.com\/?page_id=4823"},"modified":"2026-07-16T17:44:50","modified_gmt":"2026-07-16T15:44:50","slug":"dpa","status":"publish","type":"page","link":"https:\/\/behaviorquant.com\/en\/dpa\/","title":{"rendered":"DPA"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"4823\" class=\"elementor elementor-4823\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7fc25df e-flex e-con-boxed e-con e-parent\" data-id=\"7fc25df\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;gradient&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-b724dea e-con-full e-flex e-con e-child\" data-id=\"b724dea\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-adde97e e-con-full e-flex e-con e-child\" data-id=\"adde97e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-c043550 e-con-full e-flex e-con e-child\" data-id=\"c043550\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8c17c1c elementor-nav-menu--dropdown-none elementor-widget elementor-widget-nav-menu\" data-id=\"8c17c1c\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;layout&quot;:&quot;vertical&quot;,&quot;submenu_icon&quot;:{&quot;value&quot;:&quot;&lt;svg aria-hidden=\\&quot;true\\&quot; class=\\&quot;e-font-icon-svg e-fas-caret-down\\&quot; viewBox=\\&quot;0 0 320 512\\&quot; xmlns=\\&quot;http:\\\/\\\/www.w3.org\\\/2000\\\/svg\\&quot;&gt;&lt;path d=\\&quot;M31.3 192h257.3c17.8 0 26.7 21.5 14.1 34.1L174.1 354.8c-7.8 7.8-20.5 7.8-28.3 0L17.2 226.1C4.6 213.5 13.5 192 31.3 192z\\&quot;&gt;&lt;\\\/path&gt;&lt;\\\/svg&gt;&quot;,&quot;library&quot;:&quot;fa-solid&quot;}}\" data-widget_type=\"nav-menu.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t<nav aria-label=\"Menu\" class=\"elementor-nav-menu--main elementor-nav-menu__container elementor-nav-menu--layout-vertical e--pointer-none\">\n\t\t\t\t<ul id=\"menu-1-8c17c1c\" class=\"elementor-nav-menu sm-vertical\"><li class=\"menu-item menu-item-type-post_type menu-item-object-page menu-item-19608\"><a href=\"https:\/\/behaviorquant.com\/en\/terms\/\" class=\"elementor-item\">General Terms<\/a><\/li>\n<li class=\"menu-item menu-item-type-post_type menu-item-object-page menu-item-19609\"><a href=\"https:\/\/behaviorquant.com\/en\/dpa\/\" class=\"elementor-item\">Data Processing Agreement<\/a><\/li>\n<li class=\"menu-item menu-item-type-post_type menu-item-object-page menu-item-19610\"><a href=\"https:\/\/behaviorquant.com\/en\/privacy\/\" class=\"elementor-item\">Privacy Policy BQ Applications<\/a><\/li>\n<li class=\"menu-item menu-item-type-post_type menu-item-object-page menu-item-privacy-policy menu-item-19611\"><a rel=\"privacy-policy\" href=\"https:\/\/behaviorquant.com\/en\/privacy-protection\/\" class=\"elementor-item\">Privacy Policy BQ Website<\/a><\/li>\n<\/ul>\t\t\t<\/nav>\n\t\t\t\t\t\t<nav class=\"elementor-nav-menu--dropdown elementor-nav-menu__container\" aria-hidden=\"true\">\n\t\t\t\t<ul id=\"menu-2-8c17c1c\" class=\"elementor-nav-menu sm-vertical\"><li class=\"menu-item menu-item-type-post_type menu-item-object-page menu-item-19608\"><a href=\"https:\/\/behaviorquant.com\/en\/terms\/\" class=\"elementor-item\" tabindex=\"-1\">General Terms<\/a><\/li>\n<li class=\"menu-item menu-item-type-post_type menu-item-object-page menu-item-19609\"><a href=\"https:\/\/behaviorquant.com\/en\/dpa\/\" class=\"elementor-item\" tabindex=\"-1\">Data Processing Agreement<\/a><\/li>\n<li class=\"menu-item menu-item-type-post_type menu-item-object-page menu-item-19610\"><a href=\"https:\/\/behaviorquant.com\/en\/privacy\/\" class=\"elementor-item\" tabindex=\"-1\">Privacy Policy BQ Applications<\/a><\/li>\n<li class=\"menu-item menu-item-type-post_type menu-item-object-page menu-item-privacy-policy menu-item-19611\"><a rel=\"privacy-policy\" href=\"https:\/\/behaviorquant.com\/en\/privacy-protection\/\" class=\"elementor-item\" tabindex=\"-1\">Privacy Policy BQ Website<\/a><\/li>\n<\/ul>\t\t\t<\/nav>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-32fb7b4 e-con-full e-flex e-con e-child\" data-id=\"32fb7b4\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-735ac02 elementor-widget elementor-widget-text-editor\" data-id=\"735ac02\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Data Processing Agreement (DPA)<br \/><\/strong><\/p><p>If Behaviorquant processes data on your behalf, it does so on the basis of the Data Processing Agreement below, the terms of which you have confirmed by accepting the <a href=\"https:\/\/behaviorquant.com\/en\/terms\">Behaviorquant Terms of Use<\/a>.<\/p><p><em>Last modified: August 28, 2022<\/em><\/p><p><strong>1. Preamble<\/strong><br \/>1.1. Behaviorquant as the Processor (hereinafter referred to as the &#8220;Processor&#8221;) has undertaken to provide the data processing services described below to you as the Controller (hereinafter referred to as \u201cController\u201d). This contract is to be understood as a supplement to the <a href=\"https:\/\/behaviorquant.com\/en\/terms\">Behaviorquant Terms of Use<\/a> and specifies the obligations of the Parties regarding data protection that arise from the existing Behaviorquant Terms of Use regarding data processing described in detail. For the purposes of this Agreement, the definitions of terms in the General Data Protection Regulation (Regulation (EU) 2016\/679) shall apply.<\/p><p><strong>2. Subject Matter of this Agreement<\/strong><br \/>2.1. The object of the service provision by the Processor for the Controller is the use of data of the Controller for the use of the BQ Software provided by the Processor. The software enables an objective behavioral analysis of decision makers in the finance and investment sector. This generates algorithmically and on the basis of an automated dialogue from science-based stimuli (e.g. questions, tasks and scenarios) feature profiles and behavioral predictions of the users as well as recommendations for decision support and behavior optimization. In this context, the scope, nature and purpose of the data processing are limited to the use of the data categories listed under point 2.2. Special categories of data pursuant to Articles 9 and 10 of the GDPR may only be processed in the systems of the Processor with the written consent of the Controller.<\/p><p>2.2. The following categories of data are processed:<br \/>First name, last name, e-mail address, risk attitudes, perceptions and attitudes towards market and investment issues, personality, interests and values, decision-making and information processing style, behavior in investment simulations and amount of fictitious investments, behavioral and cognitive information processing and biases, sentiment and risk assessments about the money and financial markets, response behavior, sociodemographic and firmographic characteristics on gender, age, educational and professional background, professional position, length of work experience, country of occupation, company type and size.<\/p><p>2.3. The following categories of data subjects will be subject to the processing:<br \/>Clients, employees, investment target employees.<\/p><p>2.4. The processing of data by the Processor shall generally take place within the European Union or in another contracting state of the Agreement on the European Economic Area (EEA). The Processor is nevertheless permitted to process data outside the EEA in compliance with the provisions of this Agreement if it informs the Controller in advance of the location of the data processing and the requirements of Articles 44 &#8211; 48 of the GDPR are met or an exception pursuant to Article 49 of the GDPR applies. The Controller acknowledges that the Processor may also agree with sub-processors on processing outside the EEA, provided that such processing is carried out under the conditions of Art. 44 &#8211; 48 of the GDPR or an exception pursuant to Art. 49 of the GDPR exists.<\/p><p><strong>3. Duration of the Agreement<\/strong><br \/>3.1. The term of this Agreement shall be governed by and shall correspond to the term of the respective main agreement, unless the provisions of this agreement give rise to obligations exceeding the aforesaid term.<\/p><p><strong>4. Duties of the Processor<\/strong><br \/>4.1. Right to issue instructions<br \/>The Processor shall not make any decision on its own responsibility regarding the way in which the Controller&#8217;s data is used. The Processor shall use data and processing results exclusively within the scope of the Controller&#8217;s order and on the basis of documented written instructions and shall return them exclusively to the Controller or shall only carry out transfers on the basis of the Controller&#8217;s written order. If, in the opinion of the Processor, a written instruction from the Controller violates data protection law, the Processor shall comply with its legal obligation to warn the Controller. The Controller must have issued a written order to use the data provided for the Controller&#8217;s own purposes (see Section 4.10.).<\/p><p>4.2. Official order<br \/>If the Processor is requested to release data of the Controller on the basis of an official order, the Processor must &#8211; if legally permissible &#8211; inform the Controller immediately and refer the authorities to the Controller.<\/p><p>4.3. Confidentiality<br \/>The Processor declares that all persons entrusted with data processing have been obligated to maintain data secrecy and confidentiality or that they are subject to an appropriate legal obligation of confidentiality. In particular, the confidentiality obligation of the person entrusted with the Data Processing shall remain in force even after the termination of his\/her activity and leaving the Processor. <br \/>The confidentiality obligation shall also apply to legal entities and partnerships.<\/p><p>4.4. Data Security<br \/>The Processor shall take sufficient security measures pursuant to Art 28 (3) lit c and Art 32 of the GDPR, in particular in connection with Art 5 (1) of the GDPR, in order to prevent data from being used improperly or made accessible to third parties without authorization. The measures to be taken are data security measures and measures to ensure a level of protection appropriate to the risk with regard to confidentiality, integrity, availability and resilience of the systems. The state of the art, the implementation costs and the type, scope and purposes of the processing shall be taken into account. The Processor shall take all necessary measures to ensure the security of the Processing pursuant to Art 32 (1) of the GDPR. Technical and organizational measures to be taken by the Processor in principle are listed in <a href=\"https:\/\/behaviorquant.com\/en\/dpa\/#tom\">Appendix 1<\/a>, for example.<\/p><p>4.5. Data subject rights<br \/>The Processor shall implement the technical and organizational measures to enable the Controller to fulfill the rights of the Data Subjects under Chapter III of the GDPR (information, access, rectification and erasure, data portability, objection as well as automated decision-making in individual cases) at any time within the statutory period and shall provide the Controller with all information necessary for this purpose. If a corresponding request is addressed to the Processor and the Processor indicates that the Applicant mistakenly considers it to be the Controller of the data application it operates, the Processor shall forward the request to the Controller without undue delay and notify the Applicant thereof.<\/p><p>4.6. Review<br \/>The Controller shall have the right to inspect and control at any time, including through third parties commissioned by it, the processing of the data provided by it. This shall also include the right of the Controller to carry out inspections (by the Controller itself or by an auditor appointed by it) at the premises of the Processor. The Processor shall provide the Controller with any information necessary to monitor compliance with this Agreement.<\/p><p>4.7. Support<br \/>The Processor shall support the Controller by taking appropriate technical or organizational measures to comply with the obligations set out in Art 32 to 36 GDPR (data security measures, notifications of personal data breaches to the supervisory authority, notification of the person affected by a personal data breach, data protection impact assessment, prior consultation).<\/p><p>4.8. Data protection impact assessment<br \/>In particular, the Processor shall, upon request of the Controller, assist the Controller in ensuring compliance with all obligations of the Controller in relation to data protection impact assessments and prior consultation, including the obligations of the Controller under Articles 35 and 36 of the GDPR, where the Controller does not otherwise have access to the relevant information and such information is available to the Processor. The Processor shall provide the Controller with appropriate assistance in cooperating with the Supervisory Authority in the performance of its tasks.<\/p><p>4.9. Processing directory <br \/>The Processor shall maintain a processing directory for the present commissioned processing in accordance with Art 30 GDPR.<\/p><p>4.10. Return of personal data<br \/>Within three months after the termination of this Agreement, the Processor shall either hand over to the Controller or destroy on the Controller&#8217;s behalf all Processing Results and documents containing Data. The right to choose in this respect shall be incumbent on the Controller. If the Processor processes the data in a special technical format, the Processor is obliged to hand over the data after the termination of this Agreement either in this format or, at the request of the Controller, in the format in which it received the data from the Controller or in another common format. The only exceptions are those personal data that are subject to an obligation to store personal data under Union law or by law.<br \/>The processor is entitled, even after termination of the contract, to further process the data in anonymized form for future product developments and product enhancements as well as for the improvement of algorithms and machine learning processes. In the event of further processing by the Processor, all user data shall be anonymized by the Processor to such an extent that it cannot be attributed to either the responsible party or the Users.<\/p><p><strong>5. Sub-Processors<\/strong><br \/>5.1. The Controller hereby authorizes in a general manner the use of sub-processors by the Processor. The additional processors currently used by the Processor are listed in <a href=\"https:\/\/behaviorquant.com\/en\/dpa\/#sub\">Appendix 2<\/a>. In general, contractual relationships with service providers that have as their object the testing or maintenance of data processing procedures or systems by other bodies or other ancillary services, even if access to data cannot be ruled out in the process, are not subject to approval, as long as the Processor makes appropriate arrangements to protect the confidentiality of the data.<\/p><p>5.2. The Processor shall inform the Controller of any intended changes regarding the involvement or replacement of additional processors. In individual cases, the Controller shall have the right to object to the commissioning of a potential additional processor. An objection may only be raised by the Controller for good cause to be proven to the Processor. If the Controller does not raise an objection within 14 days of receipt of the notification, its right to object with regard to the corresponding commissioning shall expire. If the Controller raises an objection, the Processor shall be entitled to terminate the main agreement and this agreement with a notice period of 3 months.<\/p><p>5.3. If the Processor uses another sub-processor to carry out certain processing activities on behalf of the Controller, the Processor shall impose the same data protection obligations on this sub-processor by way of a contract. The parties agree that this requirement is met if the contract has a level of protection corresponding to this contract or if the additional processor is subject to the obligations set out in Art. 28(3) GDPR.<\/p><p>5.4. Subject to the requirements of Section 2.4 of this agreement, the provisions in this Section 5. shall also apply if an additional processor in a third country is engaged. The Controller hereby authorizes the Processor, on behalf of the Controller, to enter into a contract with the additional processor incorporating the EU Standard Contractual Clauses for the transfer of personal data to processors in third countries of 4.6.2021. The Controller agrees to cooperate to the extent necessary in fulfilling the requirements pursuant to Art. 49 GDPR.<\/p><p><strong>6. Miscellaneous<\/strong><br \/>6.1. There are no verbal ancillary agreements to this order processing contract. Amendments or supplements to this contract must be made in writing. This shall also apply to any waiver of the written form requirement.<\/p><p>6.2. Should any provision of this contract be invalid or ineffective, it shall be replaced by a provision that comes as close as possible in its result to the invalid or ineffective provision. The remaining provisions shall remain unaffected.<\/p><p>6.3. This contract shall be governed by Austrian law to the exclusion of its conflict of law rules and the UN Convention on Contracts for the International Sale of Goods. All disputes arising from or in connection with this contract shall be decided exclusively by the Commercial Court of Vienna.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e07e854 elementor-widget elementor-widget-spacer\" data-id=\"e07e854\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bc32265 elementor-widget elementor-widget-menu-anchor\" data-id=\"bc32265\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"menu-anchor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-menu-anchor\" id=\"tom\"><\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-13a5f89 elementor-widget elementor-widget-text-editor\" data-id=\"13a5f89\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p style=\"text-align: center;\"><strong>Appendix 1: Technical and organizational measures<\/strong><\/p><p>Within its area of responsibility, the Processor shall take the following technical and organizational measures when collecting, processing and using Customer Personal Data.<\/p><p><strong>1. Preventive security measures &#8211; measures to prevent a successful attack<br \/>1.1. Technical measures<\/strong><br \/><span style=\"text-decoration: underline;\">Logical access control<\/span><br \/>Access authorizations are assigned according to the &#8220;need-to-know&#8221; principle.<br \/><span style=\"text-decoration: underline;\">Authentication<\/span><br \/>All access to personal data is granted only after successful authentication.<br \/><span style=\"text-decoration: underline;\">Password security<\/span><br \/>If passwords are used for authentication, they are at least eight characters long. Passwords are stored exclusively in encrypted form. Two-factor authentication is used for security-critical applications.<br \/><span style=\"text-decoration: underline;\">Encryption during transmission<\/span><br \/>Personal data is encrypted during transmission over the Internet.<br \/><span style=\"text-decoration: underline;\">Encryption of mobile devices<\/span><br \/>Mobile devices and mobile data carriers are encrypted, at least to the extent that sensitive data is stored on these devices.<br \/><span style=\"text-decoration: underline;\">Network security<\/span><br \/>A firewall is used to separate the internal network from the Internet and &#8211; as far as possible &#8211; block incoming network traffic.<br \/><span style=\"text-decoration: underline;\">Measures against malware<\/span><br \/>Anti-virus software is used on all systems wherever possible. All incoming emails are automatically scanned for malware.<br \/><span style=\"text-decoration: underline;\">Management of security vulnerabilities<\/span><br \/>As far as possible, automatic installation of security updates is activated on all devices.<\/p><p><strong>1.2. Organizational measures<\/strong><br \/><span style=\"text-decoration: underline;\">Clear responsibilities<\/span><br \/>Internal responsibilities for data security issues are defined.<br \/><span style=\"text-decoration: underline;\">Obligation of employees to maintain confidentiality<\/span><br \/>Employees are obligated to maintain confidentiality beyond the duration of their employment. In particular, they are obliged to disclose personal data to third parties only on the express instruction of a superior.<br \/><span style=\"text-decoration: underline;\">Training and information measures<\/span><br \/>Employees are trained on data security issues (internally or externally) and appropriately informed about data security issues (e.g. password security).<br \/><span style=\"text-decoration: underline;\">Orderly termination of employment<\/span><br \/>Upon termination of employment, all accounts of the departing employee shall be blocked immediately and all keys of the departing employee shall be removed.<br \/><span style=\"text-decoration: underline;\">Management of computer hardware<\/span><br \/>Records are kept of which employees have been assigned which terminal devices (e.g. PC, laptop, cell phone).<br \/><span style=\"text-decoration: underline;\">Input control<\/span><br \/>Procedures are in place to control the accuracy of personal data entered.<br \/><span style=\"text-decoration: underline;\">No duplication of user accounts<\/span><br \/>Each user has his or her own user account. Sharing of user accounts is prohibited.<br \/><span style=\"text-decoration: underline;\">No unnecessary use of administrative accounts<\/span><br \/>User accounts with administrative rights are used only in exceptional cases &#8211; regular use of IT systems is done without administrative rights.<br \/><span style=\"text-decoration: underline;\">Selection of service providers<\/span><br \/>When selecting service providers, the level of data security offered by the service provider is taken into account. The use of a service provider that is to be classified as a processor is only carried out after the conclusion of a processing contract.<br \/><span style=\"text-decoration: underline;\">Secure data disposal<\/span><br \/>Paper containing personal data is always shredded or handed over to an external service provider for secure destruction. Data carriers are completely overwritten or physically destroyed before disposal so that the data stored on them cannot be recovered.<\/p><p><strong>1.3. Physical measures<\/strong><br \/><span style=\"text-decoration: underline;\">Physical access control<\/span><br \/>Persons from outside the company are only allowed to enter the company premises if accompanied by a person from the company.<br \/><span style=\"text-decoration: underline;\">Key management<\/span><br \/>Keys that allow access to the company premises or parts thereof are only issued to particularly trustworthy persons and only to the extent that and for as long as these persons actually require their own key.<\/p><p><strong>2. Detectives security measures &#8211; measures to detect an attack<br \/>2.1. Technical measures<\/strong><br \/><span style=\"text-decoration: underline;\">Scans for malware<\/span><br \/>Regular scans for malware (anti-virus scans) are performed to identify malware that has already compromised an IT system.<br \/><span style=\"text-decoration: underline;\">Automatic checking of log files<\/span><br \/>Insofar as the security log files of several systems are collected centrally on one system, an automated evaluation of the log files is performed in order to identify possible security breaches.<\/p><p><strong>2.2. Organizational measures<\/strong><br \/><span style=\"text-decoration: underline;\">Detection of security breaches by employees<\/span><br \/>All employees are instructed on how to recognize and report security breaches (e.g., computer hardware that can no longer be found, reports from anti-virus software).<br \/><span style=\"text-decoration: underline;\">Reporting systems<\/span><br \/>Technical procedures are in place to enable employees to report anomalies and irregularities in technical systems to the appropriate persons.<br \/><span style=\"text-decoration: underline;\">Audits<\/span><br \/>Regular audits are carried out (e.g., checking whether all critical security updates have been installed). In particular, regular audits are carried out of the access and access authorizations granted (which employee is assigned which user account with which access rights; which persons have which keys).<br \/><span style=\"text-decoration: underline;\">Manual checking of log files<\/span><br \/>If log files are kept (e.g., of unsuccessful authentication attempts), they are checked at regular intervals.<\/p><p><strong>3. Reactive security measures &#8211; measures to respond to an attack<\/strong><br \/><strong>3.1. Technical measures<\/strong><br \/><span style=\"text-decoration: underline;\">Data backup<\/span><br \/>Data backups are made regularly and stored securely.<br \/><span style=\"text-decoration: underline;\">Data recovery concept<\/span><br \/>A concept for the rapid recovery of data backups has been developed in order to restore regular operations promptly after a security breach.<br \/><span style=\"text-decoration: underline;\">Automatic removal of malware<\/span><br \/>The anti-virus software used has the function of automatically removing malware.<\/p><p><strong>3.2. Organizational measures<\/strong><br \/><span style=\"text-decoration: underline;\">Obligation to notify employees<\/span><br \/>All employees are instructed to report security breaches immediately to a previously defined internal office or person.<br \/><span style=\"text-decoration: underline;\">Reporting obligation for external service providers<\/span><br \/>All service providers are provided with contact information for reporting security breaches.<br \/><span style=\"text-decoration: underline;\">Reporting obligation for responding to security breaches<\/span><br \/>An appropriate process shall be in place to ensure that security breaches can be reported to the Data Protection Authority within 72 hours of becoming aware of the security breach. In particular, all employees shall be provided with the emergency telephone numbers of the persons to be involved (e.g., emergency telephone number for IT support).<\/p><p><strong>4. Deterrent security measures &#8211; measures to mitigate attacker motivation<\/strong><br \/><strong>4.1. Technical measures<\/strong><br \/><span style=\"text-decoration: underline;\">Automatic alerts<\/span><br \/>Users receive automatic warnings in case of risky IT usage (e.g. by the web browser if an encrypted website does not use a correct SSL\/TLS certificate).<\/p><p><strong>4.2. Organizational measures<\/strong><br \/><span style=\"text-decoration: underline;\">Sanctions in case of attacks by own employees<\/span><br \/>All employees are informed that attacks on the company&#8217;s own IT systems will not be tolerated and may have serious consequences under labor law.<br \/><span style=\"text-decoration: underline;\">Logging of accesses<\/span><br \/>Access to applications, in particular the entry, deletion and modification of data, is logged.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f14f2ab elementor-widget elementor-widget-spacer\" data-id=\"f14f2ab\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8c8f4ad elementor-widget elementor-widget-menu-anchor\" data-id=\"8c8f4ad\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"menu-anchor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-menu-anchor\" id=\"sub\"><\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cd91156 elementor-widget elementor-widget-spacer\" data-id=\"cd91156\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-abe27fd elementor-widget elementor-widget-text-editor\" data-id=\"abe27fd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p style=\"text-align: center;\"><strong>Appendix 2: List of Sub-Processors<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-027ff4c elementor-widget elementor-widget-spacer\" data-id=\"027ff4c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bed69dc elementor-widget elementor-widget-text-editor\" data-id=\"bed69dc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<table><tbody><tr><td width=\"151\"><p>Sub-Processor<\/p><\/td><td width=\"123\"><p>Product<\/p><\/td><td width=\"198\"><p>Use \/ Service<\/p><\/td><td width=\"132\"><p>Data Center Location<\/p><\/td><\/tr><tr><td width=\"151\"><p>Google (US)<\/p><\/td><td width=\"123\"><p>Google Cloud Platform<\/p><\/td><td width=\"198\"><p>Hosting infrastructure<\/p><\/td><td width=\"132\"><p>EU (NL)<\/p><\/td><\/tr><tr><td width=\"151\"><p>Google (US)<\/p><\/td><td width=\"123\"><p>Google reCAPTCHA<\/p><\/td><td width=\"198\"><p>Spam protection for form entries (Website only)<\/p><\/td><td width=\"132\"><p>US<\/p><\/td><\/tr><tr><td width=\"151\"><p>Hotjar (MLT)<\/p><\/td><td width=\"123\"><p>Hotjar<\/p><\/td><td width=\"198\"><p>Online behavior analysis<\/p><\/td><td width=\"132\"><p>EU<\/p><\/td><\/tr><tr><td width=\"151\"><p>Hubspot (US)<\/p><\/td><td width=\"123\"><p>Hubspot<\/p><\/td><td width=\"198\"><p>CRM, marketing<\/p><\/td><td width=\"132\"><p>EU (D)<\/p><\/td><\/tr><tr><td width=\"151\"><p>Microsoft (US)<\/p><\/td><td width=\"123\"><p>Microsoft 365<\/p><\/td><td width=\"198\"><p>Documentation, collaboration<\/p><\/td><td width=\"132\"><p>EU \/ EFTA<\/p><\/td><\/tr><tr><td width=\"151\"><p>Mailjet (F)<\/p><\/td><td width=\"123\"><p>Mailjet<\/p><\/td><td width=\"198\"><p>Mail infrastructure<\/p><\/td><td width=\"132\"><p>EU<\/p><\/td><\/tr><tr><td width=\"151\"><p>OpenAI OpCo (US)<\/p><\/td><td width=\"123\"><p>OpenAI API<\/p><\/td><td width=\"198\"><p>AI-powered advisory recommendations<\/p><\/td><td width=\"132\"><p>US<\/p><\/td><\/tr><tr><td width=\"151\"><p>Stripe, Inc. (US)<\/p><\/td><td width=\"123\"><p>Stripe<\/p><\/td><td width=\"198\"><p>Payment processing<\/p><\/td><td width=\"132\"><p>EU (IRL) \/ US<\/p><\/td><\/tr><tr><td width=\"151\"><p>Typeform, S.L. (ES)<\/p><\/td><td width=\"123\"><p>Typeform<\/p><\/td><td width=\"198\"><p>Online surveys<\/p><\/td><td width=\"132\"><p>EU<\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Data Processing Agreement (DPA) If Behaviorquant processes data on your behalf, it does so on the basis of the Data Processing Agreement below, the terms of which you have confirmed by accepting the Behaviorquant Terms of Use. Last modified: August 28, 2022 1. Preamble1.1. Behaviorquant as the Processor (hereinafter referred to as the &#8220;Processor&#8221;) has [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"content-type":"","footnotes":""},"class_list":["post-4823","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/behaviorquant.com\/en\/wp-json\/wp\/v2\/pages\/4823","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/behaviorquant.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/behaviorquant.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/behaviorquant.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/behaviorquant.com\/en\/wp-json\/wp\/v2\/comments?post=4823"}],"version-history":[{"count":6,"href":"https:\/\/behaviorquant.com\/en\/wp-json\/wp\/v2\/pages\/4823\/revisions"}],"predecessor-version":[{"id":25775,"href":"https:\/\/behaviorquant.com\/en\/wp-json\/wp\/v2\/pages\/4823\/revisions\/25775"}],"wp:attachment":[{"href":"https:\/\/behaviorquant.com\/en\/wp-json\/wp\/v2\/media?parent=4823"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}