Data Processing Agreement (DPA)
pursuant to Art. 28 GDPR
Notice:
This English version is provided solely for convenience and informational purposes.
Only the German version is legally binding.
In case of discrepancies, conflicts or interpretation issues, the German version shall prevail.
Template Notice:
This DPA is a template for customer-specific data processing agreements. Customer-specific information is supplemented in the respective individual contract, offer, order or upon conclusion of the contract. The DPA becomes part of the contract if it is agreed in the offer, order, individual contract or by other effective incorporation.
between
[Customer Name]
[Customer Address]
- hereinafter referred to as the “Controller” -
and
upbyte® e.K.
Schwastrum 60
24351 Damp
Germany
Owner: Riccardo Rabe
Email: [email protected]
- hereinafter referred to as the “Processor” -
1. Subject Matter and Duration of Processing
1.1 This Data Processing Agreement specifies the data protection obligations of the parties insofar as the Processor processes personal data on behalf of the Controller.
1.2 The Processor provides services in particular in the areas of software development, operation of web applications, hosting, databases, platforms, SaaS systems, customer portals, CRM systems, maintenance, support, migration, backup, technical administration, and related IT services.
1.3 The specific services are defined in the respective main contract, offer, order, project agreement, hosting agreement, SaaS agreement, or service description.
1.4 The duration of the processing corresponds to the term of the respective main contract. Insofar as data export, deletion, archiving, documentation or statutory retention is required after the end of the contract, this DPA shall continue to apply for that purpose.
2. Roles of the Parties
2.1 The Controller is the responsible party within the meaning of Art. 4(7) GDPR or is itself a processor acting on behalf of a third party.
2.2 The Processor processes personal data as a processor within the meaning of Art. 4(8) GDPR.
2.3 The Controller is responsible for the lawfulness of the processing, the legal basis, information obligations, data subject rights, retention periods, data content, and instructions.
2.4 The Processor does not determine the purposes of processing. Processing is carried out solely for the performance of the agreed services.
3. Nature and Purpose of Processing
3.1 Processing is carried out in particular for the following purposes:
- Provision and operation of web applications, platforms, websites and SaaS systems
- Hosting of databases, files, applications and technical systems
- Development, maintenance and upkeep of software
- Technical support and error analysis
- System administration and security measures
- Migration, import and export of data
- Backup, recovery and emergency measures
- Operation of communication, form, customer portal and administration systems
- Processing of employee, applicant, time-tracking and payroll data, insofar as commissioned by or technically provided by the Controller
3.2 The Processor processes only such data as is necessary for the performance of services or as is provided, entered, transmitted, or released by the Controller.
4. Categories of Personal Data
4.1 Depending on the services commissioned, the following data may in particular be processed:
- Master data
- Contact data
- Communication data
- Contract data
- Customer data
- Prospect data
- Usage data
- Access data
- Protocol and log data
- Login and authentication data
- Content data
- Documents and files
- Payment and billing data
- Order and transaction data
- Applicant data
- Employee data
- Supplier data
- Time-tracking data
- Personnel and payroll data
- Technical system data
- Support and error descriptions
4.2 Special categories of personal data within the meaning of Art. 9 GDPR are not routinely requested by the Processor. However, they may be processed if the Controller enters such data into customer systems, applications, files, forms, or databases or expressly commissions their processing.
4.3 Where special categories of personal data are processed, the responsibility for lawfulness, legal basis, protection requirements, and instructions lies with the Controller.
5. Categories of Data Subjects
Depending on the services commissioned, data of the following persons may in particular be processed:
- Customers of the Controller
- Prospects
- Users of websites, platforms and applications
- Visitors to websites
- Employees of the Controller
- Applicants
- Suppliers
- Business partners
- Contact persons
- External staff
- Service providers
- Newsletter subscribers
- Communication partners
- Administrators and technical users
- Other persons whose data the Controller processes in the systems
6. Instructions of the Controller
6.1 The Processor shall process personal data exclusively on the basis of documented instructions from the Controller, unless a legal obligation to process exists.
6.2 Instructions initially arise from the main contract, the service description, this DPA, and the approved project or support activities.
6.3 Individual instructions may be issued in text form, in particular by email, ticket, customer portal, or documented project communication.
6.4 Verbal instructions must be confirmed by the Controller in text form without undue delay.
6.5 Instructions that exceed the agreed scope of services may be treated as a change request and may be subject to separate remuneration.
6.6 If the Processor considers an instruction to be in violation of data protection law, it shall notify the Controller accordingly. Execution may be suspended until the instruction is clarified.
7. Obligations of the Processor
7.1 The Processor shall process personal data only within the scope of the commission.
7.2 The Processor shall obligate all persons authorised to process personal data to confidentiality or ensure that an appropriate statutory or contractual duty of confidentiality applies.
7.3 The Processor shall implement appropriate technical and organisational measures pursuant to Art. 32 GDPR.
7.4 The Processor shall assist the Controller within reasonable limits in:
- Data subject requests
- Access, rectification, erasure and restriction of processing
- Data portability
- Notification of personal data breaches
- Data protection impact assessments
- Prior consultations with supervisory authorities
- Evidence for authorities or customers of the Controller
7.5 Support services that exceed statutory obligations or the agreed scope of services and are not caused by misconduct on the part of the Processor may be remunerated based on effort.
8. Technical and Organisational Measures
8.1 The Processor employs appropriate technical and organisational measures. These are determined by the nature, scope, purpose and risk of the processing, as well as the respective commissioned services.
8.2 The measures include in particular:
Confidentiality
- Binding of employees, freelancers and subcontractors to confidentiality
- Access only as required
- Authorisation concepts based on the need-to-know and least-privilege principles
- Secure authentication
- SSH key-based access, where technically employed
- Password protection and role-based access rights
- Separation of customer and project data, insofar as technically and economically reasonable
- Encrypted transmission, in particular TLS/HTTPS/SFTP/VPN, where technically possible
Integrity
- Logging of administrative access and changes, where technically reasonable and available
- Controlled changes to production systems
- Patch and update processes as required
- Protection against unauthorised modification of data and systems
Availability and Resilience
- Hosting in professional data centres
- Use of established hosting and infrastructure providers
- Backup and recovery processes, where agreed
- Monitoring, where agreed or technically established
- Emergency measures in case of security or operational risks
Recoverability
- Recovery from backups, insofar as backups have been agreed and are available
- Technical support for recovery measures
- No guarantee of complete recoverability unless expressly agreed
Review
- Regular review of the security measures in place
- Adaptation to technical and organisational developments
- Documentation of essential security measures
8.3 The Processor may modify technical and organisational measures provided the level of protection is not materially reduced.
8.4 Where services are provided on third-party infrastructure, the technical and organisational measures of the sub-processors engaged shall additionally apply.
9. Server Location, Hosting and Administrative Access
9.1 Based on the current scope of services, the storage and regular operation of production data hosted by the Processor take place at server locations in Germany, unless otherwise agreed in the respective main contract.
9.2 Hosting, storage, backup, and infrastructure services may be provided through sub-processors.
9.3 Administrative, development-related, or support-related access is to be distinguished from the storage at server locations. Such access may be performed by the Processor, freelancers, or subcontractors insofar as this is necessary for the performance of services.
9.4 The Processor also engages freelancers. Insofar as they have access to personal data or production systems, they are contractually bound to confidentiality, data protection, and compliance with instructions.
9.5 Administrative or technical access from third countries, in particular by freelancers outside the EU/EEA, shall only occur insofar as it is necessary for development, maintenance, support, error analysis, or operations and a data protection legal basis exists.
10. Sub-Processors and Freelancers
10.1 The Controller grants the Processor a general authorisation to engage sub-processors and freelancers insofar as their involvement is necessary for the performance of services.
10.2 The Processor shall appropriately obligate sub-processors and freelancers with respect to data protection, confidentiality, and security.
10.3 Where sub-processors are engaged that themselves process personal data on behalf of the Controller, they shall be subject to obligations substantially equivalent to those of this DPA.
10.4 The Processor shall inform the Controller of material changes regarding sub-processors. The Controller may object for important data protection reasons.
10.5 Currently known core sub-processors and contributing parties:
- netcup GmbH, Germany: hosting, servers, web hosting, storage, infrastructure
- Hetzner Online GmbH, Germany: hosting, servers, storage, backup, infrastructure
- Cloudflare, Inc., USA: delivery, DNS and protection against attacks for websites and applications operated via Cloudflare (EU-U.S. Data Privacy Framework, EU Standard Contractual Clauses)
- Freelancers / developers / technical service providers, in particular Germany, Pakistan and the Philippines: software development, maintenance, technical support, administration, error analysis
10.6 Additional project-specific service providers are only engaged insofar as this is necessary for the respective commission or has been approved by the Controller.
10.7 Ancillary services that do not involve the targeted processing of personal data, such as telecommunications, transport, cleaning, general infrastructure, payment processing, or standard software operation, do not constitute sub-processing insofar as their core activity does not consist in the processing of personal data on behalf of the Controller.
11. Third-Country Transfers
11.1 Storage and regular server operations currently take place in Germany as a matter of principle, unless otherwise agreed.
11.2 Access by freelancers, technical service providers, or sub-processors from third countries may be necessary in the context of development, maintenance, support, error analysis, or administration.
11.3 Processing in or access from a third country shall only occur if the requirements of Art. 44 et seq. GDPR are met, in particular through:
- An adequacy decision of the European Commission,
- EU Standard Contractual Clauses,
- Additional safeguards,
- Express instruction or approval of the Controller,
- Or another permissible legal basis.
11.4 The Processor shall not disclose personal data to third parties for their own use without a separate legal basis.
12. Notification of Data Breaches
12.1 The Processor shall notify the Controller without undue delay upon becoming aware of a breach of the protection of personal data affecting the Controller’s data.
12.2 The notification shall contain, insofar as available:
- Nature of the data breach
- Categories of data affected
- Categories of persons affected
- Likely consequences
- Measures already taken or proposed
- Contact person for enquiries
12.3 The Processor shall appropriately assist the Controller in assessing and fulfilling notification obligations pursuant to Art. 33 and Art. 34 GDPR.
13. Data Subject Rights
13.1 If a data subject contacts the Processor directly, the Processor shall forward the request to the Controller insofar as an attribution is possible.
13.2 The Processor shall generally not respond to data subject requests itself, unless instructed to do so by the Controller or required by law.
13.3 The Controller remains responsible for the timely and lawful processing of data subject requests.
14. Evidence and Audits
14.1 The Processor shall provide the Controller upon request with reasonable information to demonstrate compliance with this DPA.
14.2 Evidence may include in particular:
- Description of technical and organisational measures
- Information provided by the Processor
- Documentation
- Certificates, attestations, or evidence from sub-processors engaged
- Evidence of hosting or data centre standards, where available
14.3 On-site inspections shall only be permissible with reasonable advance notice, during normal business hours, with due regard to security and confidentiality interests, and without disproportionate disruption to business operations.
14.4 Inspections by competitors or persons with a conflict of interest may be refused.
14.5 Costs for inspections or special evidence not caused by misconduct on the part of the Processor may be remunerated based on effort.
15. Deletion and Return
15.1 Upon termination of the main contract, the Processor shall, at the Controller’s choice, return or delete personal data, unless statutory retention obligations or legitimate documentation requirements apply.
15.2 Data export shall take place in a technically available and reasonable format.
15.3 Additional support for export, migration, data preparation, or reactivation may be remunerated based on effort.
15.4 Production data shall generally be deleted within 30 days of the end of the contract, unless a different period has been agreed, but not before the provision period under clause 9 of the General Terms and Conditions of upbyte® e.K. has expired.
15.5 Data in backups may persist until the expiry of regular backup cycles and shall be deleted or overwritten thereafter.
15.6 Confirmation of deletion shall be provided upon request insofar as this is technically and organisationally feasible.
16. Liability
16.1 The liability of the parties shall be governed by Art. 82 GDPR and the statutory provisions.
16.2 The liability provisions of the main contract and the General Terms and Conditions shall additionally apply insofar as they do not conflict with mandatory data protection law.
16.3 The Controller shall ensure that the personal data transmitted to or processed in the systems of the Processor may be lawfully processed.
17. Confidentiality
17.1 The parties shall treat all confidential information obtained in the course of this DPA as confidential.
17.2 The obligation of confidentiality shall continue to apply after termination of the contract.
17.3 Statutory disclosure obligations, requests from authorities, court orders, and mandatory regulatory obligations shall remain unaffected.
18. Final Provisions
18.1 This DPA forms an integral part of the respective main contract.
18.2 In the event of contradictions between this DPA and the main contract, the data protection provisions of this DPA shall prevail insofar as data processing is concerned.
18.3 Amendments and supplements shall require text form.
18.4 German law shall apply.
18.5 The place of jurisdiction shall be the registered seat of the Processor, insofar as legally permissible.
18.6 Should individual provisions be or become invalid, the remainder of this DPA shall remain in effect. The invalid provisions shall be replaced by the applicable statutory provisions.
Annex 1: Description of Processing
1. Subject Matter of Processing
Provision, development, maintenance, administration, and technical operation of software, websites, web applications, databases, platforms, hosting, SaaS, backup, support, communication, and IT systems for the Controller.
2. Purpose of Processing
Fulfilment of the contractually agreed IT, software, hosting, support, and maintenance services.
3. Nature of Processing
Collection, recording, storage, organisation, structuring, transmission, retrieval, consultation, use, adaptation, alteration, securing, restoration, erasure, and other technical processing within the scope of the commissioned services.
4. Categories of Personal Data
- Master data
- Contact data
- Communication data
- Contract data
- Usage data
- Access data
- Log data
- Content data
- Documents
- Payment data
- Applicant data
- Employee data
- Time-tracking data
- Personnel and payroll data
- Technical system data
- Support data
- Other data provided by the Controller
5. Categories of Data Subjects
- Customers
- Prospects
- Users
- Website visitors
- Employees
- Applicants
- Suppliers
- Business partners
- Contact persons
- External staff
- Communication partners
- Administrators
- Other persons whose data the Controller processes
6. Special Categories of Personal Data
Special categories of personal data are not routinely requested by the Processor. However, processing may occur if the Controller enters such data into the systems or commissions their processing. The responsibility for lawfulness and protection requirements lies with the Controller.
Annex 2: Technical and Organisational Measures
1. Organisation
- Data protection and security requirements are taken into account in projects
- Access to personal data only where necessary
- Obligation of involved persons to confidentiality
- Use of carefully selected hosting providers
- Use of contractually bound freelancers and service providers
2. Access Protection
- User and rights management
- Role-based authorisations
- Need-to-know principle
- Secure passwords or SSH key procedures, where technically employed
- Two-factor authentication, where technically available and configured
- Blocking or adjustment of access in case of security risks
3. Transmission Protection
- Encrypted transmission, where technically possible
- TLS/HTTPS for web applications
- Secure administrative access
- No deliberate disclosure of customer data to unauthorised third parties
4. System Protection
- Patch and update processes as required
- Technical hardening of systems, where commissioned or under the Processor’s responsibility
- Separation of customer projects, where technically possible
- Logging of security-relevant events, where reasonable and available
5. Backup and Recovery
- Backups only where agreed or technically established
- Recovery to the extent technically feasible
- Regular review of essential backup and recovery processes, where commissioned
- The Controller’s responsibility for their own additional backups remains unaffected
6. Data Centre and Infrastructure
- Use of professional hosting and infrastructure providers
- Server operations currently based in Germany as a matter of principle
- Physical security provided by the data centre operators engaged
- Availability as determined by the respective main contract or provider
7. Review and Improvement
- Review of measures in case of material changes
- Adaptation to technical developments
- Documentation of essential security measures
- Incident response in case of security incidents
Annex 3: Sub-Processors and Contributing Parties
Current status: September 2026
1. netcup GmbH
Registered seat: Germany
Services: Hosting, servers, web hosting, storage, infrastructure
Processing location: Germany, unless otherwise commissioned
2. Hetzner Online GmbH
Registered seat: Germany
Services: Hosting, servers, storage, backup, infrastructure
Processing location: Germany, unless otherwise commissioned
3. Cloudflare, Inc.
Registered seat: USA
Services: Delivery, DNS and protection against attacks for websites and applications operated via Cloudflare
Processing location: global network of data centres
Safeguards: Data Processing Addendum, EU-U.S. Data Privacy Framework, EU Standard Contractual Clauses
4. Freelancers / Technical Service Providers
Locations: Germany, Pakistan, Philippines
Services: Software development, maintenance, technical support, administration, error analysis
Access: Only insofar as necessary for the performance of services
Safeguards: Confidentiality obligation, compliance with instructions, data protection obligations; where third-country access applies, appropriate safeguards pursuant to Art. 44 et seq. GDPR
Additional sub-processors are only engaged insofar as this is necessary for the respective commission, has been approved by the Controller, or is permissible under this DPA.