Auftragsverarbeitungsvertrag (AVV)
Last updated: 13 August 2026
Important notice
This Data Processing Agreement (Auftragsverarbeitungsvertrag) is a practical draft for AssetObserve and must be reviewed by qualified legal counsel before it is offered to a customer for signature. It is structured around the elements required by Article 28(3) GDPR, but it has not been reviewed against the final legal entity, hosting arrangement, subprocessor list, or target markets.
Parties
Controller: the customer organization that operates an AssetObserve workspace, as named in the corresponding order or account record.
Processor: AssetObserve
Hofmannstr. 31b
81379 Munich
Germany
This agreement supplements the AssetObserve Terms and Conditions. Where the two conflict on the processing of personal data, this agreement prevails.
Subject matter, nature and purpose of the processing
The processor operates AssetObserve, a software-as-a-service platform for authorized IT asset inventory, discovery coverage planning, vulnerability and risk findings, compliance reporting, and agent telemetry. Personal data is processed only in order to provide, secure, support, and bill that service on the controller's instructions.
Duration of the processing
Processing lasts for the term of the controller's subscription, plus the deletion and return period described below.
Categories of data subjects
- Users of the controller's workspace, including owners, administrators, operators, viewers, and auditors
- Employees and contractors of the controller whose devices, accounts, or directory records appear in scan results
- Contact persons the controller records for support, billing, or partner relationships
Types of personal data
- Account data: name, business email address, password hash, assigned role, multi-factor and session records, audit log entries
- Inventory data that can identify a person directly or indirectly: hostnames, IP and MAC addresses, logged-in usernames, directory account names and group memberships, device serial numbers, and any assigned-owner or note field the controller fills in
- Support data: ticket content and correspondence submitted by the controller
- Billing data: billing contact, billing address, VAT identification number, invoice records
- Technical logs: request metadata, IP addresses, and error reports
Special categories of personal data under Article 9 GDPR are not required by the service and must not be entered into free-text fields.
Instructions of the controller
The processor processes personal data only on documented instructions from the controller. Those instructions are given through the configuration of the workspace, the scan targets and credentials the controller supplies, the controller's use of the product functions, and any further written instruction. The processor informs the controller without undue delay if, in its opinion, an instruction infringes applicable data protection law.
Confidentiality
The processor ensures that persons authorized to process personal data are bound by an appropriate obligation of confidentiality and have received data protection instruction.
Security of processing
The processor implements the technical and organizational measures required by Article 32 GDPR. Those measures are described in the separate Technical and Organizational Measures document, which forms an annex to this agreement. Measures may be updated over time provided the level of protection is not reduced.
Subprocessors
The controller grants general written authorization for the use of subprocessors. The subprocessors engaged at any time are published in the separate Subprocessor List. The processor informs the controller of any intended addition or replacement of a subprocessor with at least 30 days' notice, and the controller may object on reasonable data protection grounds within that period. Each subprocessor is bound by data protection obligations equivalent to those in this agreement, and the processor remains fully liable to the controller for its performance.
Assistance to the controller
Taking into account the nature of the processing and the information available to it, the processor assists the controller with:
- responding to requests from data subjects exercising their rights under Chapter III GDPR
- the security of processing, the notification of personal data breaches, and data protection impact assessments and prior consultations under Articles 32 to 36 GDPR
The workspace provides self-service export and deletion functions that the controller may use to satisfy access and erasure requests directly.
Personal data breaches
The processor notifies the controller without undue delay after becoming aware of a personal data breach affecting the controller's personal data, and provides the information reasonably available to it so that the controller can meet its own notification obligations.
Deletion and return
On termination of the subscription, the processor deletes or returns the controller's personal data at the controller's choice and deletes existing copies, unless applicable law requires continued storage. Workspace export and workspace deletion functions are available in the product. Data held in backups is removed in line with the documented backup rotation period rather than immediately.
Audits
The processor makes available to the controller the information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates. The processor may first offer current certifications, audit reports, or a written questionnaire response, and may charge a reasonable fee for on-site audits beyond one per calendar year.
International transfers
Personal data is processed in [processing_location]. Where a subprocessor processes personal data outside the European Economic Area, the transfer is based on an adequacy decision or on Standard Contractual Clauses together with any supplementary measures the transfer situation requires.
Liability
Liability follows the AssetObserve Terms and Conditions together with the mandatory allocation of responsibility under Article 82 GDPR.
Placeholder notice
Complete the parties, the processing location, the subprocessor notice period, and the audit terms, and confirm the referenced Technical and Organizational Measures and Subprocessor List, before this agreement is signed with a customer. This draft is not legal advice.
Contact: contact@assetobserve.com