Data processing agreement (DPA)
This data processing agreement under Art. 28 GDPR governs how PräferenzPilot processes personal data on behalf of the customer. It applies in addition to the Terms for every customer who has entered into a contract.
This is an English reading version. The legally binding version is the German original - only it counts in the event of a dispute.
§1 Subject matter and duration of the processing
The subject matter is the processing of personal data by the processor in the course of providing the SaaS application PräferenzPilot (origin calculation, management and collection of suppliers' declarations, draft proofs, REST API). The duration corresponds to the term of the usage contract; §7 (deletion) remains unaffected.
§2 Nature and purpose of the processing, types of data, data subjects
Nature and purpose: storage, display, evaluation (deterministic calculation) and transmission (email requests to suppliers) of the data entered by the customer; hosting and backup.
Types of data: contact details of contacts at the customer's suppliers (name, business email address), names of responsible persons on suppliers' declarations, the customer's user account data (email), business data with a personal reference in articles and bills of materials, log and metadata.
Categories of data subjects: employees and contacts of the customer and of the customer's suppliers.
§3 Bound by instructions
The processor processes the data exclusively on documented instructions from the customer (Art. 28(3)(a) GDPR). The customer's use of the application's functions counts as an instruction. If the processor considers that an instruction infringes data protection law, it informs the customer without delay (Art. 28(3), third sentence, GDPR). There is no processing for the processor's own purposes; processing to which the processor is obliged under Union or Member State law remains unaffected — in that case it informs the customer of those requirements before processing, unless the law prohibits this.
§4 Confidentiality
The processor ensures that the persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR).
§5 Technical and organisational measures (Art. 32 GDPR)
The processor takes in particular the following measures (Art. 28(3)(c) GDPR):
- Data held in a data centre in Frankfurt am Main (EU); application hosting in the EU region (Frankfurt).
- Strict tenant separation at database level (row-level security per account), plus account-based filtering in the application.
- Transport encryption (TLS) for all connections; encryption of data at rest at the database provider.
- Access protection through authentication; API access only via account-bound keys. A SHA-256 hash of the key itself is stored, plus its first characters (prefix) so it can be recognised in the interface — the full key cannot be reconstructed after creation. Each key can be revoked.
- Hardening of the web application (including a content security policy with nonces, security headers, rate limits on sensitive endpoints).
- Immutable, append-only calculation audit trail; logging of security-relevant events.
- Magic-link access (supplier forms) via long, single-use random tokens without requiring an account; no anonymous database access rights.
The measures are kept up to date with the state of the art; lowering the level of protection is excluded.
§6 Sub-processors (further processors)
The customer gives general authorisation (Art. 28(2) GDPR) for the use of the following further processors:
- Vercel Inc. — Hosting and delivery of the web application. Location/transfer: USA — transfer on the basis of the EU standard contractual clauses and a data processing agreement.
- Supabase, Inc. — Database, authentication and storage of the application data. Location/transfer: Stored in the Frankfurt am Main data centre (EU); provider based in the USA, safeguarded by standard contractual clauses and a data processing agreement.
- Stripe Payments Europe, Ltd. — Handling of subscription payments (for the payment processing itself, Stripe acts in part as an independent controller). Location/transfer: Ireland (EU).
- Resend (Plus Five Five, Inc.) — Sending transactional emails, in particular requests and reminders concerning suppliers' declarations on behalf of our customers. Location/transfer: USA — transfer on the basis of the EU standard contractual clauses (the provider's DPA) and the EU-U.S. Data Privacy Framework; email is sent via the EU region (Ireland).
- Google (Google Cloud EMEA Ltd. / Gemini API) — AI-assisted convenience features (plain-language explanations, input suggestions, reading uploaded documents, the assistant). Only the article, bill-of-materials and document details passed for that purpose are processed. The binding origin verdict is made by the verified engine, not by the AI. Under paid use of the Gemini API, the content transmitted is not used for training.. Location/transfer: USA/EU — transfer on the basis of the EU standard contractual clauses and the Google data processing agreement (Cloud Data Processing Addendum).
- INWX GmbH & Co. KG — Domain and email hosting. Location/transfer: Germany (EU).
- Cloudflare, Inc. (Turnstile) — Abuse protection for the open forms (registration, sign-in, password reset). It checks whether the request comes from a human; the IP address and technical browser characteristics are processed for that purpose. Turnstile sets no advertising cookies and builds no cross-site profiles.. Location/transfer: USA — transfer on the basis of the EU standard contractual clauses and the Cloudflare data processing agreement.
The processor gives advance notice of intended changes (addition or replacement) by updating this list and by a notice in the application or by email; the customer may object to the change for an important data protection reason. Where data is transferred to a third country, appropriate safeguards under Chapter V GDPR are in place (EU standard contractual clauses or an adequacy decision, e.g. the EU-U.S. Data Privacy Framework). Contracts corresponding to the obligations of this DPA are in place with all sub-processors (Art. 28(4) GDPR).
§7 Support for the controller, deletion and return
The processor supports the customer with appropriate technical and organisational measures in fulfilling data subject rights (Art. 12–23 GDPR) and the obligations under Art. 32–36 GDPR — in particular through export, deletion and information functions in the application and by reporting personal data breaches without delay (Art. 28(3)(e) and (f) GDPR).
After the end of the provision of the processing services, the processor deletes all personal data or returns it — at the customer's choice (account deletion in the application or a request to kontakt@praeferenzpilot.de) — unless Union or Member State law requires it to be retained (e.g. § 257 of the German Commercial Code, § 147 of the German Fiscal Code; the calculation audit trail is subject to customs retention rules) (Art. 28(3)(g) GDPR).
§8 Evidence and audits
The processor makes available to the customer all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR, and allows for and contributes to audits — including inspections — conducted by the customer or an auditor mandated by the customer (Art. 28(3)(h) GDPR). Audits take place after reasonable notice during normal business hours; meaningful evidence (certificates and reports from the infrastructure providers, documentation of the measures under §5) is provided as a first step.
§9 Liability and final provisions
Art. 82 GDPR applies to liability; otherwise the liability rules of the Terms apply. German law applies. Should individual provisions be invalid, the DPA remains valid in all other respects; the statutory rule applies in place of the invalid provision. In the event of conflicts between this DPA and the Terms, the provisions of this DPA prevail as regards the processing of personal data.
As of: 19. August 2026