Back to Legal

Legal

Data Protection Addendum - EU

Data Protection Addendum for processing subject to GDPR and EU Data Protection Laws.

Last updated:

This EU Data Protection Addendum (“DPA”) governs the processing of personal data by Unipie, Inc. dba Minoa, 1401 21st St., Suite 5305, Sacramento, CA 95811, USA (“Unipie”) on behalf of the customer identified in an Order Form that references the Unipie General Terms and Conditions (“Customer”, “Controller”), and forms part of the agreement between them consisting of the Order Form and the General Terms and Conditions (the “Agreement”). By executing the Order Form, Customer agrees to the terms of this DPA, which is effective as of the Effective Date of the Order Form; no separate signature is required for this DPA to be binding. This version is dated October 6, 2026; previous versions are available in the archive at https://www.minoa.io/legal/.

This DPA applies to the extent that Unipie processes Personal Data on behalf of the Customer in the course of providing the Services, where such processing is subject to the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, or equivalent legislation.

Capitalized terms not otherwise defined in this DPA shall have the meanings given to them in the Agreement. The Parties agree that the terms and conditions of this DPA shall govern the processing of Customer Personal Data and shall prevail over any conflicting provisions in the Agreement with respect to such processing.

1. Definitions

1.1 In this DPA, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:

1.1.1 “Applicable Laws and Regulations” shall mean EU Data Protection Laws and/or US Privacy Laws as applicable.

1.1.2 "Authorised Subprocessors" means (a) those Subprocessors set out in Annex 4 (Authorised Subprocessors); and (b) any additional Subprocessors consented to in writing by the Customer in accordance with section 6.1;

1.1.3 “Consumer” shall have the meaning set forth under the US Privacy Laws, as applicable.

1.1.4 “Data Controller” and “Controller” shall have the same meaning as in the EU Data Protection Laws respectively under the US Privacy Laws and also include, whenever applicable, the term “business”, as defined in the CCPA.

1.1.5 “Data Processor” and “Processor” shall have the same meaning as in the EU Data Protection Laws respectively under the US Privacy Laws and also include, whenever applicable, the term “service provider”, as defined in the CCPA.

1.1.6 "EU Data Protection Laws" means in relation to any Personal Data which is Processed in the performance of the Underlying Agreement, the General Data Protection Regulation (EU) 2016/679 ("GDPR"), in each case together with all laws implementing or supplementing the same and any other applicable data protection or privacy laws in the USA, and in countries explicitly agreed between parties;

1.1.7 "EEA" means the European Economic Area;

1.1.8 "Customer Personal Data" means the data described in Annex 1 and any other Personal Data Processed by Unipie or any Subprocessor on behalf of the Customer pursuant to or in connection with the Agreement;

1.1.9 “Personal Data” shall have the meaning as defined in EU Data Protection Laws respectively the meaning set forth under the US Privacy Laws and also include, whenever applicable, the term “personal information”, as defined in the CCPA.

1.1.10 "Restricted Transfer" means a transfer of Customer Personal Data by Customer to Unipie (or any onward transfer), in each case, where such transfer would be prohibited by EU Data Protection Laws in the absence of the protection for the transferred Customer Personal Data provided by the EU Standard Contractual Clauses;

1.1.11 “Sell” or “Selling” shall have the meaning set forth in the US Privacy Laws, as applicable.

1.1.12 “Share” or “Sharing” shall have the meaning defined under the CCPA.

1.1.13 "Standard Contractual Clauses" means the standard contractual clauses set out in the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended or replaced from time to time by a competent authority under the relevant EU Data Protection Laws;

1.1.14 "Subprocessor" means any additional Data Processor (including any third party and any Unipie’s Affiliate) appointed by Unipie to Process Customer Personal Data on behalf of the Customer or any Customer Affiliate;

1.1.15 "Supervisory Authority" means (a) an independent public authority which is established by a Member State pursuant to Article 51 GDPR; and (b) any similar regulatory authority responsible for the enforcement of Applicable Laws and Regulations;

1.1.16 “US Privacy Laws” means applicable US state privacy laws, including, but not limited to, the following laws, as applicable:

1.1.16.1 California Consumer Privacy Act, as amended by the California Privacy Rights Act and relevant regulations issued by the California Privacy Protection Agency (the “CCPA”),

1.1.16.2 Virginia Consumer Data Protection Act (the “VCDPA”),

1.1.16.3 Colorado Privacy Act and relevant rules issued by the Colorado Attorney General (the “CPA”),

1.1.16.4 Connecticut Data Privacy Act (the “CTDPA”),

1.1.16.5 Utah Consumer Privacy Act (the “UCPA”),

1.1.16.6 Texas Data Privacy and Security Act (“TDPSA”),

1.1.16.7 Florida Digital Bill of Rights (“FDBR”),

1.1.16.8 Oregon Consumer Privacy Act (“OCPA”).

1.1.17 Any other terms, including, among others, "Process/Processing", "Data Subject", "Personal Data", "Personal Data Breach" and "Special Categories of Personal Data" “Business”, “Business Purpose”, “Commercial Purpose” used but not otherwise defined in the DPA or Agreement, shall have the meaning set forth under the Applicable Laws and Regulations, as applicable.

2. Data Processing Terms

2.1 In the course of providing the Services to the Customer and pursuant to the Agreement, Unipie may Process Customer Personal Data as a Data Processor on behalf of the Customer. Unipie agrees to comply with the following provisions with respect to any Customer Personal Data submitted by or for the Customer to the Services or otherwise collected and Processed by or for the Customer by Unipie.

3. Processing of the Customer Personal Data

3.1 Unipie shall only Process the types of Customer Personal Data relating to the categories of Data Subjects for the purposes of the Agreement and for the specific purposes in each case as set out in Annex 1 to this DPA and shall not Process, transfer, modify, amend or alter the Customer Personal Data or disclose or permit the disclosure of the Customer Personal Data to any third party other than in accordance with the Customer’s documented instructions (whether in the Agreement or otherwise) unless Processing is required by EU or other national law to which Unipie is subject, in which case Unipie shall to the extent permitted by such law inform the Customer of that legal requirement before Processing that Personal Data.

3.2 The Parties agree that Customer shall serve as single point of contact and be solely responsible for internal coordination, review and submission of any Processing instructions in respect of which Customer is the Data Controller.

3.3 AI training. Customer instructs Unipie not to use Customer Personal Data to train, retrain, fine-tune or otherwise improve any artificial intelligence, large language or generative AI model, and Unipie shall not permit any Subprocessor to do so. Aggregated or de-identified data that does not identify the Customer or any Data Subject and does not constitute Personal Data is not Customer Personal Data for the purposes of this instruction.

3.4 Consumption Data. Customer acknowledges that Unipie records which User or Customer-operated software agent performed which metered action in the Minoa Platform and when (“Consumption Data”) in order to measure the Customer’s use of the Services, to invoice it and to resolve disputes about it. Unipie may retain Consumption Data containing Personal Data for up to fifteen (15) months after the end of the month to which it relates, notwithstanding any earlier deletion of Customer Personal Data under this DPA, and shall delete it thereafter.

3.5 Customer-operated tools and agents. Third-party software and AI tools that the Customer connects to the Services (including through Unipie’s Model Context Protocol interface) act on the Customer’s instructions and under the Customer’s control; they are the Customer’s own processors and not Subprocessors of Unipie.

4. Unipie Personnel

4.1 Unipie shall take reasonable steps to ensure the reliability of any of its employees, agents or contractors who may have access to the Customer Personal Data, ensuring in each case that access is strictly limited to those individuals who need to access the relevant Customer Personal Data, as strictly necessary for the purposes set out in section 3.1 above in the context of that individual's duties to Unipie, ensuring that all such individuals:

4.1.1 are informed of the confidential nature of the Customer Personal Data and are aware of Unipie's obligations under this DPA and the Agreement in relation to the Customer Personal Data;

4.1.2 have undertaken appropriate training in relation to the Applicable Laws and Regulations;

4.1.3 are subject to confidentiality undertakings or professional or statutory obligations of confidentiality; and

4.1.4 are subject to user authentication and log on processes when accessing the Customer Personal Data.

5. Security

5.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Unipie shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, which may include, inter alia, when appropriate:

5.1.1 the pseudonymisation and encryption of the Customer Personal Data;

5.1.2 the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

5.1.3 the ability to restore the availability and access to Customer Personal Data in a timely manner in the event of a physical or technical incident; and

5.1.4 a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the Processing.

5.2 Without limitation to section 5.1, in particular Unipie shall implement and maintain each of the technical and organisational measures listed in Annex 2 (Technical and Organisational Measures).

5.3 In assessing the appropriate level of security, Unipie shall take account in particular of the risks that are presented by Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data transmitted, stored or otherwise Processed.

5.4 Unipie shall make changes to the technical and organisational measures set out in Annex 2, as necessary to ensure ongoing compliance with clause 5.1, and notify the Customer thereof.

6. Subprocessing

6.1 Subject to section 6.3, Unipie shall not engage any Subprocessor other than with the prior general authorisation of the Customer, which the Customer may refuse only on duly documented justified grounds.

6.2 With respect to each Subprocessor, Unipie shall:

6.2.1 carry out adequate due diligence on each Subprocessor to ensure that it is capable of providing the level of protection for the Customer Personal Data as is required by this DPA including without limitation sufficient guarantees to implement appropriate technical and organisational measures in such a manner that Processing will meet the requirements of GDPR and this DPA;

6.2.2 include terms in the contract between Unipie and each Subprocessor which are similar to those set out in this DPA. Upon request, Unipie shall provide a copy of its data protection agreements (or a respective equivalents) with Subprocessors to the Customer for its review;

6.2.3 insofar as that contract involves the transfer of Customer Personal Data outside of the EEA, incorporate the Standard Contractual Clauses or such other mechanism and each Subprocessor to ensure the adequate protection of the transferred Customer Personal Data; and

6.2.4 remain fully liable to the Customer for any failure by each Subprocessor to fulfil its obligations in relation

6.2.5 to the Processing of any Customer Personal Data in relation with the Agreement.

6.3 Unipie shall only submit for Customer's authorisation those Subprocessors which already comply with all requirements abovementioned.

6.4 Customer hereby authorises Unipie to engage those Authorised Subprocessors set out in Annex 4 (Authorised Subprocessors).

7. Data Subject Rights

7.1 Unipie shall promptly notify the Customer if it receives a request from a Data Subject under any Applicable Laws and Regulations in respect of Customer Personal Data.

7.2 Unipie shall co-operate as requested by the Customer to enable the Customer to comply with any exercise of rights by a Data Subject under any Applicable Laws and Regulations in respect of Customer Personal Data as Processed by Unipie (including within any timescales specified by Applicable Laws and Regulations) and comply with any assessment, enquiry, notice or investigation under any Applicable Laws and Regulations in respect of Customer Personal Data or this DPA, which shall include:

7.2.1 the provision of all data reasonably requested by the Customer within any reasonable timescale specified by the Customer in each case, including as far as legally permissible full details and copies of the complaint, communication or request and any Customer Personal Data it holds in relation to a Data Subject;

7.2.2 taking all necessary precautions to ensure that Personal Data, without limiting the performance of the Agreement, may be corrected, deleted or blocked at any time as per the Customer request to do so;

7.2.3 immediately informing the Customer in writing if the Data Processor for any other reason believes that certain Personal Data should be corrected, deleted or blocked by the Customer. The Customer will then issue the respective orders to the Data Processor in this respect; and

7.2.4 where applicable, providing the Customer with the personal data in a structured, commonly used and machine-readable way according to Art. 20 GDPR within the prescribed timescales.

8. Personal Data Breach

8.1 Unipie shall notify the Customer immediately, upon becoming aware of or reasonably suspecting a Personal Data Breach providing the Customer with sufficient information which allows the Customer to meet any obligations to report a Personal Data Breach under the Applicable Laws and Regulations. Such notification shall as a minimum:

8.1.1 describe the nature of the Personal Data Breach, the categories and numbers of Data Subjects concerned, and the categories and numbers of Personal Data records concerned;

8.1.2 communicate the name and contact details of Unipie's data protection officer or other relevant contact from whom more information may be obtained;

8.1.3 describe the likely consequences of the Personal Data Breach; and

8.1.4 describe the measures taken or proposed to be taken to address the Personal Data Breach.

8.2 Unipie shall co-operate with the Customer and any Customer Affiliate and take such commercially reasonable steps as are directed by the Customer to assist in the investigation, mitigation and remediation of each Personal Data Breach.

8.3 In the event of a Personal Data Breach, Unipie shall not inform any third party without first obtaining the Customer’s prior written consent, unless notification is required by EU or national law to which Unipie is subject, in which case Unipie shall to the extent permitted by such law inform the Customer of that legal requirement, provide a copy of the proposed notification and consider any comments made by the Customer before notifying the Personal Data Breach.

8.4 In addition to general notices terms under section 16.10, in the particular case of a Personal Data Breach any notifications shall be addressed to and further communications might be driven by:

8.4.1 Customer’s Data Protection Contact: Customer Contact in the applicable Order Form, unless specified otherwise in the Order Form.

8.4.2 Unipie’s Data Protection Contact: Richard Einhorn, richard@minoa.io

8.5 In the event that Unipie or the Customer does not have a designated contact for cases of a Personal Data Breach at the DPA Effective Date, it must inform the other party of Unipie or the Customer Data Protection Contact to be used for the purposes of section 8.4 above, once this contact is designated.

9. Data Protection Impact Assessment and Prior Consultation

9.1 Unipie shall provide reasonable assistance to the Customer and any Customer Affiliate with any record of processing activities as set out under Article 30 GDPR, any data protection impact assessments which are required under Article 35 GDPR and with any prior consultations to any Supervisory Authority of the Customer which are required under Article 36 GDPR, in each case solely in relation to Processing of Customer Personal Data by Unipie on behalf of the Customer and each Customer Affiliate and taking into account the nature of the Processing and information available to Unipie.

9.2 The obligation set out under section 9.1 above also applies where Applicable Laws and Regulations, other than GDPR, include similar obligations.

10. Deletion or return of Customer Personal Data

10.1 Subject to section 10.2, Unipie shall promptly and in any event within 30 (thirty) calendar days of Customer’s request:

10.1.1 return a copy of all Customer Personal Data to the Customer by allowing export of such data. The exported data shall be secured in such a way that it can be transferred with reasonable effort to other systems.

10.1.2 Securely wipe all Customer Personal Data Processed by Unipie or any Authorised Subprocessor,

and in each case provide written certification to the Customer that it has complied fully with this section 10.

10.2 Unipie may retain Customer Personal Data to the extent required by the law of European Union or national law to which Unipie is subject, and only to the extent and for such period as required by the law of European Union or national law to which Unipie is subject, and always provided that Unipie shall ensure the confidentiality of all such Customer Personal Data and shall ensure that such Customer Personal Data is only Processed as necessary for the purpose(s) specified in the law of European Union or national law to which Unipie is subject, requiring its storage and for no other purpose. Unipie may further retain Consumption Data in accordance with section 3.4 (Consumption Data).

10.3 Timelines. Customer may export Customer Personal Data through the export functions of the Services at any time during the term of the Agreement and for thirty (30) days after its end, or request an export from Unipie, which Unipie shall fulfil within thirty (30) days. Unipie shall securely delete all Customer Personal Data within sixty (60) days after the later of the end of the Agreement and the fulfilment of an export request made within that thirty (30) day period, and shall confirm the deletion in writing upon request. Copies in backup and disaster-recovery systems are deleted in the ordinary course of Unipie’s backup cycle (currently within six (6) months) and remain subject to this DPA until deleted.

11. Audit rights

11.1 Unipie shall make available to the Customer on request all relevant certificates it is holding regarding data privacy and security. Should Customer and/or Customer Affiliate request any information beyond the scope of the certification held by Unipie that they deem necessary to demonstrate compliance with this DPA Unipie shall allow for and support audits by the Customer or another auditor mandated by the Customer. Such audit shall only take place upon 10 days written notice to Unipie and solely within the working hours at the respective premises. Unipie shall accordingly permit the Customer or another auditor mandated by the Customer to inspect, audit and copy any relevant records, processes and systems in order that the Customer may satisfy itself that the provisions of this DPA are being complied with. Unipie shall provide commercially reasonable co-operation to the Customer in respect of any such audit and shall at the request of the Customer, provide the Customer with evidence of compliance with its obligations under this DPA. Unipie shall immediately inform the Customer if, in its opinion, an instruction pursuant to this section 11 (Audit Rights) infringes the GDPR or other EU or national data protection provisions.

11.2 In exercising its audit rights, Customer shall be permitted to only review the processing of Customer Personal Data and shall explicitly not be permitted to review Personal Data processed by Unipie on behalf of other third parties.

11.3 Violations, errors or irregularities that Customer determines in carrying out an audit are to be immediately remedied by Unipie upon Customer’s notice.

11.4 Any incidents regarding Customer Personal Data or any violations by Unipie or by persons employed by Unipie of provisions of applicable data protection law or provisions of this DPA, and any requests of data protection authorities must be notified to Customer immediately in writing.

11.5 Customer will immediately inform Unipie in case it determines violations, errors or irregularities.

12. Indemnity and Liability

12.1 Unipie shall indemnify and hold harmless the Customer as well as their directors, officers, employees, agents, stockholders, subcontractors and customers from and against all allegations, claims, actions, suits, demands, damages, liabilities, obligations, losses, settlements, judgments, fines and sanctions, costs and expenses (including without limitation reasonable attorneys’ fees and costs) to the extend they arise out of, any wilful and/or negligent breach of obligations as Data Processor as set out under this DPA and Applicable Laws and Regulations.

13. Governing Law and Jurisdiction

13.1 The terms of this DPA and any dispute or claim arising out of it shall be governed by and interpreted in accordance with German law and the Parties irrevocably agree that the courts of Berlin shall have exclusive jurisdiction to settle any dispute which may arise out of , under, or in connection with this DPA, and for those purposes irrevocably submit to the exclusive jurisdiction of the German courts.

14. General Terms

14.1 Subject to section 14.2, the parties agree that this DPA shall terminate automatically upon termination of the Agreement or expiry or termination of all service contracts entered into by Unipie with the Customer pursuant to the Agreement, whichever is later.

14.2 Any obligation imposed on Unipie under this DPA in relation to the Processing of Personal Data in relation to the services provided under the Agreement shall survive any termination or expiration of this DPA.

14.3 Any material breach of this DPA may, under the terms of the Agreement, lead to damages claims and a right of termination for cause.

14.4 With regard to the subject matter of this DPA, in the event of inconsistencies between the provisions of this DPA and any other agreements between the Parties, including but not limited to the Agreement, the provisions of this DPA shall prevail with regard to the Parties’ data protection obligations for Personal Data of a Data Subject from a Member State of the European Union. In the event of any conflict or inconsistency between this DPA and the Clauses in Annex 3 (Standard Contractual Clauses), Annex 3 shall prevail.

14.5 Compliance by Unipie with the provisions of the Applicable Laws and Regulations and with this DPA will be at no additional cost to the Customer, provided that no relevant changes to the Applicable Laws and Regulations as in place at the time of execution of this DPA occur.

14.6 Except to the extent set out in the Annex 3 (Standard Contractual Clauses), a person who is not a party to this DPA shall have no right to enforce any term of this DPA.

14.7 The rights of the parties to mutually rescind or vary this DPA are not subject to the consent of any other person.

14.8 Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the Parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.

14.9 Except as may be set forth in the Agreement or elsewhere in this DPA and subject to Section 14.5, the Parties agree that Unipie shall not receive any additional remuneration for the performance of its obligations under this DPA other than the remuneration to be fully paid for the services rendered by Unipie in connection with the Agreement.

14.10 Any notice to be served under this DPA shall be delivered personally or by receipted courier, sent by receipted email, in English.

If to the Customer: Customer Contact in the applicable Order Form, unless specified otherwise in the Order Form.

If to Unipie: Richard Einhorn, richard@minoa.io

or at such other address as the Parties may indicate to each other in writing.

ANNEX 1: DETAILS OF PROCESSING OF CUSTOMER PERSONAL DATA

This Annex 1 includes details of the Processing of Customer Personal Data as required by Article 28(3) GDPR and Standard Contractual Clauses.

PART B – Description of the transfer
Categories of data subjects whose personal data is transferredEmployees and contractors of Customer and its affiliates who use the Services (Users), and users of current and potential clients of the Customer.
Categories of personal data transferredContact information (Name, Surname, Email, Phone number), IP address, profile picture (where provided), statistical data. Per User: usage and consumption data (metered actions performed, timestamps, software agent used), business-case content and inputs entered or imported by Users (which may contain business contact data of the Customer’s clients and prospects, and call-transcript excerpts in text form).
Sensitive data transferred and applied restrictions or safeguardsn/a
Frequency of the transferContact information of clients of the Customer who will use ROI Calculator; contact, billing, and user profile information of Unipie users of the Customer; logging information.
Nature of the processingCustomer Personal Data will be processed in accordance with the Agreement and may be subject to the following processing activities:
Storage and processing of the data as necessary to provide, maintain, and update the services provided to the Customer by Company.
Provision of technical support to the Customer.
Metering of the use of the Services per User and per Customer-operated software agent for the purposes of invoicing and dispute resolution (Consumption Data).
Processing of requests submitted by Users or by Customer-operated software agents (including through the Model Context Protocol interface), including generation of output by third-party large language models engaged as Subprocessors, without training of such models on Customer Personal Data.
Disclosures in accordance with the Agreement and this DPA, as compelled by law.
Purpose(s) of the data transfer and further processingContact for sales purposes.
Provision of Unipie services under the Agreement.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that periodFor the duration of the Agreement including all applicable Order; deletion on request at any time and after the end of the Agreement in accordance with section 10; Consumption Data for up to fifteen (15) months after the month to which it relates.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processingAccording to the Annex 4 “Authorised Subprocessors”.

ANNEX 2: TECHNICAL AND ORGANISATIONAL MEASURES

The technical and organisational measures are included herein by reference: /legal/toms.

ANNEX 3: STANDARD CONTRACTUAL CLAUSES

By signing this DPA, the Parties agree to sign by reference and adhere to the Standard Contractual Clauses (Module Two “Transfer from controller to processor”), as provided in the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679.

The following information apply:

Part A – List of Parties
Data exporterName: As defined above for “Customer”.
Address: As defined above for “Customer”.
Contact Person’s name, position and contact details: Contacts defined for Customer for notices in the section 14.10 of the DPA.
Activities relevant to the data transferred under these clauses: Provision of Services by Unipie in the role of Data Importer to Customer in the role of Data Exporter as defined in the applicable Order.
Role: Controller.
Signature and date: As signed by Customer above.
Data importerName: Unipie Inc.
Address: 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808
Contact Person’s name, position and contact details: Max Elster, CEO, max@minoa.io.
Activities relevant to the data transferred under these clauses: Provision of Services by Unipie in the role of Data Importer to Customer in the role of Data Exporter as defined in the applicable Order.
Role: Processor.
Signature and date: As signed by Company above.
PART B – Description of the transfer
Defined in Annex 1 “Details of Processing of Customer Personal Data”
PART C – Competent supervisory authority
Applicable Supervisory AuthorityBerliner Beauftragte für Datenschutz und Informationsfreiheit
Address: Alt-Moabit 59-61, 10555 Berlin.
Telephone: +49 30 13889-0.
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de/.

ANNEX 4: AUTHORISED SUBPROCESSORS

The customer authorizes subprocessors listed in the Minoa Trust Center (https://security.minoa.io) at the time of signing this DPA. Access to the Trust Center and registration for automatic notifications about new or changing subprocessors are available at https://security.minoa.io.