DATA PROCESSING AGREEMENT (DPA)

Last Updated: June 2026


1. Purpose

VisionVal GmbH is committed to protecting personal data and ensuring compliance with applicable data protection laws, including:

  • EU General Data Protection Regulation (GDPR)
  • UK GDPR
  • German Federal Data Protection Act (BDSG)
  • Applicable local privacy regulations

Where VisionVal processes personal data on behalf of customers, such processing is governed by a Data Processing Agreement (“DPA”) in accordance with Article 28 GDPR.


2. Roles and Responsibilities

Customer as Data Controller

The customer determines:

  • The purpose of processing
  • The categories of data processed
  • Retention requirements
  • Lawful basis for processing


VisionVal as Data Processor

VisionVal processes personal data only:

  • On documented instructions from the customer
  • For agreed contractual purposes
  • In accordance with applicable laws

VisionVal does not sell, rent, or otherwise exploit customer data for its own purposes.


3. Types of Processing Activities


Depending on the deployed solution, processing may include:


Retail Analytics

  • Visitor counting
  • Occupancy monitoring
  • Queue analysis
  • Heat mapping
  • Customer journey analytics
  • Store performance analytics


People Flow Management

  • Crowd density measurement
  • Flow pattern analysis
  • Congestion monitoring
  • Capacity management


Building Analytics

  • Space utilization monitoring
  • Workplace analytics
  • Occupancy measurement


Smart City Solutions

  • Public space monitoring
  • Traffic flow analytics
  • Infrastructure optimization



4. Categories of Data

The categories of personal data may include:

  • Video streams
  • Sensor observations
  • Device identifiers
  • Network metadata
  • Location-related information
  • Event logs
  • System audit logs


VisionVal encourages customers to minimize personal data collection wherever possible.


5. Special Categories of Data


VisionVal solutions are not designed to intentionally collect special categories of personal data under Article 9 GDPR.

Customers remain responsible for ensuring lawful processing if such data may be captured within their deployment environment.


6. Security Measures


VisionVal implements appropriate technical and organizational measures including:


Technical Controls

  • Encryption in transit
  • Encryption at rest
  • Network segmentation
  • Access controls
  • Multi-factor authentication
  • Secure APIs
  • Security monitoring


Organizational Controls

  • Confidentiality agreements
  • Security awareness training
  • Role-based access controls
  • Incident response procedures
  • Supplier risk management


7. Subprocessors


VisionVal may engage approved subprocessors for:

  • Cloud hosting
  • Data storage
  • Monitoring services
  • Technical support
  • Infrastructure management


Customers may request information regarding authorized subprocessors.


8. International Data Transfers


Where transfers occur outside the EEA or UK, VisionVal implements appropriate safeguards including:

  • Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Addendum
  • Adequacy decisions


9. Data Subject Rights


VisionVal assists customers in responding to requests relating to:

  • Access
  • Rectification
  • Erasure
  • Restriction
  • Portability
  • Objection


Requests should generally be directed to the data controller responsible for the deployment.


10. Security Incidents

VisionVal maintains procedures for:

  • Detection
  • Investigation
  • Containment
  • Notification
  • Remediation

of security incidents and personal data breaches.


11. Data Retention and Deletion

Personal data is retained only for the duration required by contractual instructions or legal obligations.

Upon termination of services, customer data will be returned or securely deleted in accordance with contractual requirements.


12. Contact

VisionVal GmbH

Finkenweg 7

85467 Neuching

Germany

Email: privacy@visionval.eu