1. The controller grants general authorisation to engage other processors (“sub-processors”) (Art. 28 (2) sentence 1 GDPR). The sub-processors engaged at the time this Agreement is concluded are listed in Annex 3 and are deemed authorised. The current list is available at zplcloud.com/en/subprocessors.
2. The processor announces the engagement of a new sub-processor or the replacement of an existing one at least 30 days before it takes effect in the list at zplcloud.com/en/subprocessors (Art. 28 (2) sentence 2 GDPR). The controller keeps that list under review and may additionally have announced changes notified to it by email to the address stored in the customer account.
3. The controller may object to the change in text form (e.g. email) within 14 days of the announcement under paragraph 2 on justified grounds under data protection law. The parties then seek an amicable solution. If this is not achieved, the controller may terminate the Main Agreement extraordinarily with effect from the date on which the change takes effect; fees already paid for the period thereafter are refunded pro rata. No further claims exist on account of the change.
4. The processor contractually imposes on each sub-processor the same data protection obligations as are set out in this Agreement, in particular sufficient guarantees for appropriate technical and organisational measures (Art. 28 (4) GDPR). Where a sub-processor fails to fulfil its obligations, the processor is liable to the controller for the performance of that sub-processor's obligations.
5. The following are not sub-processors within the meaning of this Section: a) services and recipients that the controller itself selects and configures in the platform, such as its own webhook targets, messaging services (Telegram, Signal, WhatsApp, ntfy, Gotify), message brokers and cloud services (Kafka, Azure Service Bus, MQTT, AMQP, RabbitMQ, Amazon SQS, Google Pub/Sub, Amazon S3, Azure Blob Storage), marketplace and shipping services (Shopify, ShipStation, Veeqo, Amazon) and Deutsche Post (INTERNETMARKE); the transmission to these recipients takes place on the instructions of the controller, and the contractual relationship with the recipient lies with the controller; b) ancillary services that the processor obtains from third parties and that do not involve access to the controller's data, such as pure telecommunications and transport services. The obligation to take appropriate security precautions remains unaffected.