Loading...

Policy

Data Processing Agreement (DPA)

Last Updated: April 8, 2026

This Data Processing Agreement governs controller-processor responsibilities under Art. 28 GDPR in connection with your use of Hiver Ticket and forms part of the Terms of Service.

Current legal entity notice

Pivetra is currently operated as a sole trader business by Abhishek Jalan, Munich, Germany. Upon formal registration, the legal entity will be updated to Pivetra UG (haftungsbeschrankt). All legal documents will be updated accordingly.

Section 1

Subject Matter

This Data Processing Agreement ("DPA") is entered into between you as the data controller ("Controller") and Pivetra, operated by Abhishek Jalan ("Processor") under Art. 28 GDPR in connection with your use of Hiver Ticket.

This DPA forms part of the Terms of Service. In conflicts regarding data protection, the DPA prevails.

Section 2

Nature, Purpose & Duration of Processing

  • Nature: Collection, storage, organisation, and retrieval of personal data via Hiver Ticket.
  • Purpose: Provision of the Hiver Ticket customer support ticketing service.
  • Duration: Duration of the subscription. Data deleted or returned within 30 days of termination.
  • Types of data: Names, email addresses, and any personal data in support tickets.
  • Categories of data subjects: Controller's customers, end users, and employees in support tickets.

Section 3

Processor Obligations (Pivetra)

  • Process personal data only on documented instructions from the Controller (Art. 28(3)(a) GDPR).
  • Ensure staff authorised to process data are bound by confidentiality.
  • Implement appropriate TOMs in accordance with Art. 32 GDPR.
  • Not engage sub-processors without prior written consent; current sub-processors listed in Section 5.
  • Assist the Controller with data subject rights requests (Arts. 15-22 GDPR).
  • Notify the Controller within 72 hours of a personal data breach (Art. 33 GDPR).
  • Delete or return all personal data upon termination unless retention is legally required.
  • Provide all information necessary to demonstrate compliance with Art. 28 GDPR.

Section 4

Technical & Organisational Measures (TOMs)

  • Encryption in transit: TLS 1.2+. Encryption at rest: AES-256.
  • Role-based access controls and multi-factor authentication (MFA).
  • Regular penetration testing and vulnerability assessments.
  • Germany-based ISO 27001-certified data centre.
  • Documented incident response and breach notification procedures.
  • Annual data protection and security training for all staff.
  • Physical access controls at data centre facilities.

Section 5

Sub-Processors

Current sub-processor categories (all EEA/Germany-based, bound by DPAs):

Full sub-processor list available at [email protected]. 30 days' notice provided before any changes.

  • Cloud infrastructure / hosting: Germany-based data centre.
  • Email delivery service: EEA-based transactional email provider.
  • Payment processing: EEA-based payment processor (billing data only).

Section 6

Supervisory Authority

Competent supervisory authority: Bayerisches Landesamt fur Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany. www.lda.bayern.de

Section 7

Contact

DPA requests and data protection: [email protected]

Related legal documents

This DPA forms part of the Terms of Service and complements the Privacy Policy for GDPR-related processing.

View Terms of Service
Pivetra Data Processing Agreement