- It applies automatically when you subscribe to Fleet Control. You do not need to sign anything separately.
- Your organisation is the controller. We are the processor and act only on your instructions.
- Our servers are in Germany. Your fleet data does not leave the European Union.
- We list every sub-processor in Annex 3 and give you notice before adding one.
Data Processing Agreement
This agreement governs our processing of personal data on behalf of business customers using TagPulse Fleet Control, as required by Article 28 GDPR.
Summary
The short version of this document
1. Parties, scope and how this applies
When this agreement takes effect
This Data Processing Agreement ("DPA") is entered into between AFOI KALOFORIDI OE, Chr. Smirnis 67, 151 21 Athens, Greece (Γ.Ε.ΜΗ. 069222103000), trading as TagPulse ("we", "us", the Processor), and the organisation subscribing to TagPulse Fleet Control ("you", the Controller).
It forms part of, and is incorporated into, our Terms of Service. It takes effect automatically when you subscribe to Fleet Control and continues for as long as we process personal data on your behalf. You do not need to sign or return a copy; if your procurement process requires a signed version, contact us at [email protected].
This DPA applies only to Fleet Control. Where an individual installs TagPulse on their own computer and is not enrolled in an organisation's fleet, we act as controller for that processing, and our Privacy Policy applies instead.
Where this DPA conflicts with the Terms of Service on the subject of personal data, this DPA prevails.
2. Roles of the parties
Who decides what happens to the data
You are the controller. You decide which devices to enrol, which of your staff hold administrator accounts, and what names and labels you apply to devices. You are responsible for having a lawful basis for monitoring those devices and for informing the people who use them.
We are the processor. We use the data to provide Fleet Control to you, following the settings and instructions you give through the fleet dashboard.
Service improvement. We may use information derived from the processing to maintain, secure and improve the TagPulse services, including our hardware-failure detection and prediction models. Such information is aggregated or anonymised so that it no longer identifies you, your devices or any individual. Because anonymised information is no longer personal data, its use falls outside the scope of this Agreement.
Employee monitoring. Fleet Control reports on devices used by your staff. In several EU member states this carries specific obligations — for example works-council consultation in Germany. Meeting those obligations is your responsibility as controller. We will provide the information you reasonably need in order to do so, including for a Data Protection Impact Assessment.
3. Our obligations
Article 28(3) commitments
- Documented instructions. We process personal data only on your documented instructions, including on transfers, unless required otherwise by EU or member-state law. Your instructions are the configuration and commands you issue through the fleet dashboard, together with this DPA and the Terms of Service. If we believe an instruction infringes data-protection law, we will tell you.
- Confidentiality. Everyone we authorise to process your data is bound by an appropriate duty of confidentiality.
- Security. We implement the technical and organisational measures set out in Annex 2, as required by Article 32.
- Sub-processors. We engage sub-processors only under Section 4.
- Assisting with data subject rights. Taking account of the nature of the processing, we assist you with appropriate measures in responding to requests under Articles 15 to 22. The fleet dashboard lets you export and delete a device's data directly; where that is not sufficient, contact us and we will assist.
- Assisting with Articles 32 to 36. We assist you in ensuring security, notifying breaches, and carrying out data protection impact assessments and prior consultations, taking into account the information available to us.
- Deletion or return. On termination we delete personal data processed on your behalf, unless EU or member-state law requires us to keep it. See Section 6.
- Information and audit. We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, as set out in Section 7.
4. Sub-processors
General authorisation, with notice of change
You give us general authorisation to engage the sub-processors listed in Annex 3.
We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you reasonably object on data-protection grounds within that period, we will work with you to find a solution; if none is available, you may terminate the affected subscription and receive a pro-rata refund of any prepaid, unused fees.
We impose on each sub-processor the same data-protection obligations set out in this DPA, and we remain fully liable to you for their performance.
5. Personal data breaches
What we do and how quickly
We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting data we process on your behalf. This gives you time to meet your own 72-hour obligation under Article 33.
Our notification will describe the nature of the breach, the categories and approximate number of records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where we cannot provide all of it at once, we will provide it in phases without undue further delay.
6. Deletion and return of data
What happens when you leave
You can export your fleet data at any time during the subscription from the dashboard.
After termination or expiry we keep your data for 30 days so you can export it or reactivate, and then delete it, unless we are required by law to keep it — for example billing records retained for tax purposes, which are held by Paddle as merchant of record. Backups are deleted on their normal rotation and no later than 90 days after termination.
You may ask us in writing to delete your data sooner, and we will do so.
7. Audit and information rights
How to verify what we say here
On written request, and no more than once a year unless a supervisory authority requires otherwise or a breach has occurred, we will provide the information reasonably necessary to demonstrate compliance with Article 28 — including our current technical and organisational measures, our sub-processor list, and the outcome of any independent security testing.
Where that information is not sufficient for you, you may audit us, or appoint an independent auditor who is not our competitor and who is bound by confidentiality. Audits take place during business hours, with at least 30 days' notice, and must not unreasonably disrupt our operations.
8. International transfers
Where the data physically sits
Fleet data is stored and processed in the European Union, on servers operated by Hetzner Online GmbH in Nuremberg, Germany.
A small number of sub-processors listed in Annex 3 are established outside the EEA and receive limited data as described there. Where such a transfer involves personal data, it is made under the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU-U.S. Data Privacy Framework, together with any supplementary measures required following a transfer impact assessment.
Annex 1 — Details of the processing
Required by Article 28(3)
Subject matter. Provision of the TagPulse Fleet Control service.
Duration. For the term of the subscription, plus the deletion periods in Section 6.
Nature and purpose. Collecting, storing, organising, analysing and displaying hardware and system health information from enrolled devices, in order to monitor those devices, raise alerts, detect faults and malicious software, and produce reports for administrators.
Categories of data subject. Your staff and other people who use enrolled devices; the individuals in your organisation who hold administrator accounts.
Categories of personal data.
- Device and identity data: device identifier, computer name, device serial number, Windows Product ID, local network address, approximate city and country
- Self-declared labels: the user name and company name entered at installation or set by an administrator, which are stored as entered and not verified
- Activity and health data: hardware readings, running program names, startup programs, disk health, installed software and changes to it, Windows event messages, which may contain file paths
- Remote-support connection identifiers, where such software is present on the device
- Administrator account data: name, email address, and subscription references
- Diagnostic data transmitted if the TagPulse service stops unexpectedly, as described in the Privacy Policy
Special categories. None. We do not knowingly process special category data under Article 9, and the service is not designed to receive it.
Annex 2 — Technical and organisational measures
Required by Article 32
- Location. All fleet data is stored on servers in Germany, within the European Union.
- Encryption in transit. All communication between devices, the dashboard and our servers uses TLS.
- Encryption at rest. The local database on each monitored device is encrypted with a machine-bound key. Server backups are encrypted.
- Access separation. Database-level row security ensures each customer's administrators can read only devices enrolled under their own organisation. Unauthenticated access to fleet data is not possible.
- Network exposure. The servers have no publicly reachable administrative interface. Administrative access is via an authenticated tunnel only.
- Independent testing. Independent penetration testing has been carried out and passed. Access keys are rotated following any security incident.
- Backups. Encrypted backups are taken daily and retained on a fixed rotation.
- Payment data. We never store payment card details. These are handled entirely by Paddle as merchant of record.
- Read-only device access. The monitoring agent reads hardware sensors and system information; it does not modify the monitored system's configuration or user data.
- Least privilege. Access to production systems is limited to personnel who require it, and is bound by confidentiality obligations.
Annex 3 — Sub-processors
Current as of the date above
- Hetzner Online GmbH — Germany (EU). Hosting of servers, database and backups. Receives all fleet data at rest.
- Cloudflare, Inc. — United States. DNS, network tunnel, and distribution of application downloads. Handles connection metadata, including IP addresses, in transit.
- Paddle.com Market Limited — United Kingdom, acting as merchant of record. Receives billing and account contact data for subscription payments. Does not receive device or fleet monitoring data.
- Team Cymru, Inc. — United States. Receives the SHA-256 hash of a file already flagged as potentially malicious, for malware reputation lookup. Receives no file content, filename, path, or other personal data.
- IP geolocation providers — receive a device's public IP address in order to return an approximate city and country. No other data is sent.
Google and Microsoft services described in our Privacy Policy relate to the public website only and do not process fleet data.
Contact
Data protection enquiries
For any question about this DPA, to request a signed copy, to raise a sub-processor objection, or to exercise audit rights:
AFOI KALOFORIDI OE
Chr. Smirnis 67
151 21 Athens
Greece
Company registration (Γ.Ε.ΜΗ.): 069222103000
VAT number (Α.Φ.Μ.): 999267630
[email protected]
Questions About This Agreement?
If your legal or procurement team needs anything further, please get in touch.
Contact Us