The German original version is legally binding. This translation is provided for information purposes only and without warranty.
Data Processing Agreement (Data Processing pursuant to Article 28 GDPR)
- Subject Matter and Duration of the Agreement (1) The Processor provides the Controller with the SaaS platform grouprides, enabling the Controller to plan, organise, and manage events. In doing so, the Processor is granted access to personal data belonging to the Controller and processes such data exclusively on behalf of and in accordance with the instructions of the Controller. (2) The scope and purpose of the processing are determined by the service package subscribed to by the Controller. (3) The term of this Agreement corresponds to the term of the underlying main contract.
- Specification of the Processing (1) In the course of performing the main contract, the Processor will have access to the personal data and categories of data subjects specified in Annex 1. (2) Where the Controller is established in a Member State of the European Union or in a Contracting State of the European Economic Area, the provisions of this Data Processing Agreement shall apply. (3) Where the Controller is established in a third country outside the European Union or the European Economic Area, the following provisions shall apply: Where an adequacy decision by the European Commission pursuant to Art. 45 GDPR exists for the relevant third country, the transfer shall be based on that decision. Where no adequacy decision exists, the parties additionally agree to the Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module 4 (Processor to Controller), including the choices made and completion instructions set out in Annex 4 to this DPA (hereinafter "SCC"). The SCC are incorporated by reference in their current version and form part of this Agreement. No substantive modifications to the SCC are permitted. (4) To the extent and for as long as the SCC are applicable, they shall take precedence over the provisions of this DPA with regard to the relevant third-country transfer in the event of any conflict. In all other respects, the order of precedence under this Agreement shall remain unchanged.
- Obligations of the Processor a) Technical and Organisational Measures (1) The Processor shall implement data security measures in accordance with Art. 28(3)(c) and Art. 32 GDPR, in particular in conjunction with Art. 5(1) and (2) GDPR. The measures to be implemented are security measures designed to ensure a level of protection appropriate to the risk, with regard to the confidentiality, integrity, availability, and resilience of the systems. In doing so, the state of the art, the costs of implementation, and the nature, scope, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons within the meaning of Art. 32(1) GDPR, shall be taken into account. The technical and organisational measures set out in Annex 2 apply, and the Controller agrees to these measures. (2) The technical and organisational measures are subject to technological progress and further development. The Processor is therefore permitted to implement alternative adequate measures, provided that the level of security of the specified measures is not reduced. Material changes shall be documented. b) Duty to Assist (1) In assisting the Controller in fulfilling the rights of data subjects pursuant to Arts. 12–22 GDPR, the Processor shall, to the extent necessary, cooperate in the preparation of the Controller's record of processing activities and in compliance with the obligations referred to in Arts. 32–36 GDPR concerning security of personal data, breach notification obligations, data protection impact assessments, and prior consultations. The Processor shall provide appropriate support to the Controller to the extent possible and shall promptly forward all necessary information to the Controller. This includes, in particular: a) ensuring an appropriate level of protection through technical and organisational measures that take into account the circumstances and purposes of the processing, the projected likelihood and severity of a possible infringement due to security vulnerabilities, and that enable the immediate identification of relevant breach events; b) the obligation to report any personal data breaches to the Controller without undue delay; c) the obligation to assist the Controller in meeting its information obligations towards data subjects and to promptly make all relevant information available to the Controller in this context; d) supporting the Controller in conducting data protection impact assessments; e) supporting the Controller in the context of prior consultations with the supervisory authority. (2) For support services that are not included in the service description, are not attributable to a breach by the Processor, and exceed the Processor's statutory obligations, the Processor may claim reasonable remuneration. With regard to the level of remuneration, reference is made to the relevant remuneration clause. c) Processing of Personal Data in Home or Mobile Working Environments The Controller consents to the processing of data outside the business premises (e.g. teleworking, home working, remote working). The Processor undertakes: to support its employees in complying with the required technical and organisational measures in their private premises. to adequately inform its employees of the technical and organisational measures and other obligations of care to be observed when processing data in private premises. e) Other Obligations of the Processor (1) The Processor shall ensure the formal appointment of a Data Protection Officer who performs their duties in accordance with Arts. 38 and 39 GDPR, to the extent required by law. (2) The Processor shall ensure the maintenance of confidentiality in accordance with Art. 28(3)(b), Arts. 29 and 32(4) GDPR. The Processor shall only employ personnel in the performance of the work who have been bound to confidentiality and have previously been made aware of the relevant data protection provisions. The Processor and any person acting under the authority of the Processor who has access to personal data may process such data only in accordance with the instructions of the Controller, including the authorisations granted under this Agreement, unless they are legally required to process the data. This confidentiality obligation shall continue even after termination of the respective employment contract. (3) The Controller and the Processor shall, upon request, cooperate with the supervisory authority in the performance of its tasks. (4) The Processor shall inform the Controller without undue delay of any supervisory authority inspections or measures insofar as they relate to this Agreement. This shall also apply where a competent authority investigates the Processor in the context of administrative offence or criminal proceedings relating to the processing of personal data in the course of contract processing. (5) Where the Controller is itself subject to a supervisory authority investigation, administrative offence or criminal proceedings, a liability claim by a data subject or third party, or any other claim in connection with the processing carried out by the Processor, the Processor shall support the Controller to the best of its ability. For support services that are not included in the service description, are not attributable to a breach by the Processor, and exceed the Processor's statutory obligations, the Processor may claim reasonable remuneration. With regard to the level of remuneration, reference is made to the relevant remuneration clause. (6) The Processor shall regularly review its internal processes and technical and organisational measures in order to ensure that processing within its area of responsibility is carried out in compliance with applicable data protection law and that the rights of data subjects are safeguarded.
- Obligations and Rights of the Controller a) Responsibility (1) The Controller bears sole responsibility for assessing the lawfulness of the processing pursuant to Art. 6(1) GDPR and for ensuring the exercise of data subjects' rights under Arts. 12–22 GDPR. Notwithstanding the foregoing, the Processor is obliged to forward without undue delay any such requests that are evidently directed exclusively to the Controller. (2) Changes to the subject matter of processing and procedural changes shall be agreed jointly between the Controller and the Processor and shall be recorded in writing or in a documented electronic format. b) Authority to Issue Instructions (1) The Processor shall process personal data only on the basis of documented instructions from the Controller, unless it is required to do so under Union or Member State law. In such a case, the Processor shall inform the Controller of that legal requirement prior to processing, unless the law in question prohibits such notification on grounds of substantial public interest. The Controller instructs the Processor to provide and improve the contractually agreed services, and the parties agree that this instruction also encompasses the anonymisation, de-identification, or aggregation of the Controller's personal data for the purposes of evaluating, analysing, and improving the services provided. (2) Oral instructions shall be confirmed by the Controller without undue delay (at least in text form). The initial instructions of the Controller are established by this Agreement. (5) The Processor may not independently correct, delete, or restrict the processing of data processed on behalf of the Controller. Such actions may only be taken upon documented instruction of the Controller. Where a data subject contacts the Processor directly in this regard, the Processor shall forward such request to the Controller without undue delay. (6) The Processor may only disclose personal data from the contractual relationship to third parties or to the data subject upon prior documented instruction or consent of the Controller. (7) The Processor shall inform the Controller without undue delay if it considers an instruction to be in breach of data protection law. The Processor is entitled to suspend the execution of the relevant instruction until it has been confirmed or modified by the Controller. (8) Copies or duplicates of the data shall not be created without the knowledge of the Controller. Exceptions apply to backup copies, to the extent necessary to ensure proper data processing, and to data required to comply with statutory retention obligations. c) Audit Rights (1) The Controller has the right, in consultation with the Processor, to carry out or commission audits to verify compliance with data protection and data security requirements and with the contractual agreements, to the appropriate and necessary extent. The Processor is free to fulfil this audit right by providing the Controller with appropriate audit reports or similar documentation demonstrating data protection-compliant processing. Where any doubts remain as to the data protection compliance of the processing, the Controller shall have the right to conduct spot checks — which are as a rule to be announced in advance — to verify the Processor's compliance with this Agreement in its business operations. (2) The Processor shall ensure that the Controller is able to satisfy itself as to the Processor's compliance with its obligations under Art. 28 GDPR. The Processor undertakes to provide the Controller with the necessary information upon request and, in particular, to demonstrate the implementation of the technical and organisational measures. (3) The Processor is entitled to demonstrate compliance with such measures that do not exclusively concern the specific contract by means of: adherence to approved codes of conduct pursuant to Art. 40 GDPR; certification under an approved certification mechanism pursuant to Art. 42 GDPR; current attestations, reports, or report extracts from independent bodies (e.g. auditors, internal audit, data protection officer, IT security departments, data protection auditors, quality auditors); an appropriate certification by IT security or data protection audit (e.g. pursuant to BSI baseline protection). to erbringen.
- Sub-processing (1) Sub-processing relationships within the meaning of this clause refer exclusively to those services that are directly related to the provision of the main service. Ancillary services engaged by the Processor, such as telecommunications, postal or transport services, are not considered sub-processing relationships. However, the Processor is obliged to put in place adequate and legally compliant contractual agreements and supervisory measures with respect to such outsourced ancillary services in order to ensure the protection of the Controller's data. (2) Outsourcing to sub-processors or changes to existing sub-processors are permissible provided that the Processor notifies the Controller of the planned change in writing or in text form at least four weeks prior to the planned change, and the Controller does not object in writing or in text form within two weeks of receipt of the notification. The Processor shall enter into a contractual agreement with the sub-processor in accordance with Art. 28(2)–(4) GDPR. Where the Controller refuses consent through its objection for reasons other than material grounds, the Processor may terminate the Agreement with effect from the date on which the sub-processor was intended to commence work. (3) The Controller consents to the engagement of the sub-processors listed in Annex 3, subject to the conclusion of a contractual agreement in accordance with Art. 28(2)–(4) GDPR. (4) The transfer of the Controller's personal data to the sub-processor and the sub-processor's initial activities may only commence once all prerequisites for sub-processing have been fulfilled.
- Deletion and Return of Personal Data (1) Upon completion of the contractually agreed work, or earlier upon request by the Controller — and at the latest upon termination of the service agreement — the Processor shall return to the Controller all documents, processing and usage results, and datasets in its possession that are related to the contractual relationship, or shall destroy them in a data protection-compliant manner with the prior consent of the Controller. This also applies to test and waste material. A record of deletion shall be provided upon request. Any costs incurred by the Processor in connection with the return or deletion of data shall be borne by the Controller. (2) The Controller shall notify the Processor in text form, at least one month prior to the end of the contract, whether the data should be returned or deleted. If no instruction is received by the Processor before the expiry of this period, the Processor is both entitled and obliged to delete the data without undue delay upon contract expiry, but no later than within 14 days. (3) Documentation serving as evidence of proper and orderly data processing under this Agreement shall be retained by the Processor beyond the end of the contract in accordance with the applicable retention periods. The Processor may transfer such documentation to the Controller at the end of the contract for the Processor's own exculpation.
- Remuneration for Extended Audit and Support Services Any remuneration claims that may be made by the Processor pursuant to the preceding clauses must be reasonable. Invoicing based on the Processor's customary hourly rates for the actual effort incurred shall be deemed reasonable.
- Liability and Damages The Controller shall ensure, within its sphere of responsibility, that the obligations arising from the applicable legal provisions on the processing of personal data are fulfilled. The liability limitations set out in the main contract shall apply in principle. The Controller shall indemnify the Processor against all claims asserted by third parties against the Processor on the grounds of an infringement of their rights arising from processing of personal data instructed by the Controller, unless the third party's claim is based on unlawful processing of personal data by the Processor. Art. 82 GDPR shall remain unaffected in all other respects.
- Miscellaneous and General Provisions (1) Should the Controller's personal data held by the Processor be at risk as a result of enforcement measures, seizure, insolvency or composition proceedings, or any other events or actions by third parties, the Processor shall notify the Controller thereof without undue delay. The Processor shall immediately inform all persons responsible in this context that sovereignty over the Controller's personal data lies with the Controller. (2) The provisions of this Agreement shall continue to apply even after termination of the primary service relationship until all personal data belonging to the Controller has been fully destroyed or returned to the Controller. (3) The Processor reserves the right to amend this DPA at any time to the extent that the amendment is in the Processor's legitimate interest and does not unreasonably disadvantage the Controller. This is particularly the case in the event of: changes to statutory or regulatory requirements; changes to the case law of the highest courts; expansion or modification of the service offering, the purpose of processing, the types of data concerned, or the categories of data subjects, provided that no material primary contractual obligations are affected; editorial clarifications. In such cases, the Processor shall notify the Controller of the amendment no later than four weeks prior to its entry into force and shall provide the Controller with the amended DPA. If no objection is received by the Processor within four weeks of receipt of the notification, the amended DPA shall be deemed to have been approved. In the event that an objection is received, the Processor shall have the right to extraordinarily terminate the DPA and the underlying main contract with a notice period of one month. (4) Should individual provisions of this Agreement be invalid, this shall not affect the validity of the remainder of the Agreement. The parties undertake to replace any invalid provision with a legally permissible provision that comes as close as possible to the purpose of the invalid provision.
Annex 1: Categories of Personal Data First name and surname, address, email address, telephone number, profile photo, and other categories of data that the Controller instructs the Processor to process. Categories of data subjects: Users, participants, employees.
Annex 2: Technical and Organisational Measures
- Physical Access Control: The server infrastructure is operated exclusively in certified data centres (DigitalOcean) equipped with physical access security measures (access control systems, security personnel, video surveillance). The Processor's own office premises are secured by locks. Unauthorised third parties are not granted access to data processing systems.
- System Access Control: All systems and administrative access points are protected by secure passwords (minimum length, complexity requirements) and two-factor authentication (2FA). Enhanced requirements apply to administrative access. Inactive sessions are terminated automatically. Shared accounts are not permitted.
- Data Access Control: Access to personal data (name, email address, telephone number, profile photo) is granted exclusively on the basis of a role-based authorisation concept in accordance with the principle of least privilege. Access rights are reviewed regularly and revoked immediately upon an employee's departure. Administrative access to user data is logged.
- Data Transfer Control: All data transmissions are carried out exclusively in encrypted form via TLS 1.2 or higher (HTTPS). Personal data is only transmitted to third parties on the basis of documented instruction from the Controller or on a statutory basis. API access for enterprise clients is secured by individual, scope-limited API keys.
- Input Control: Changes to personal data are logged with a timestamp and user reference. Critical actions (e.g. deletion of events, export of participant data) are recorded in an audit log. Logs are protected against subsequent modification.
- Processing Control: Personal data is processed exclusively in accordance with the documented instructions of the Controller. Data processing agreements pursuant to Art. 28 GDPR are in place with all sub-processors (see Annex 3). All employees with access to personal data are bound to confidentiality and have received data protection training.
- Availability Control: Personal data is secured by regular automated backups. Backups are stored in encrypted form (AES-256) and recoverability is tested on a regular basis. Systems are monitored continuously; automatic alerts are triggered in the event of failures. An incident response process is in place.
- Data Separation Control: Data belonging to different controllers (e.g. enterprise clients) is processed and stored with logical separation. Test and production environments are strictly separated; no real personal data is used in the test environment.
- Pseudonymisation and Encryption: Passwords are stored exclusively as salted hashes (bcrypt or Argon2). Sensitive data fields (in particular email addresses) are stored in encrypted form in the database. Backups and data exports are transmitted and stored in encrypted form.
- System Resilience: The platform is designed to handle peak loads and incorporates scaling mechanisms. DDoS protection measures are implemented. Security-relevant components are regularly reviewed for vulnerabilities.
Annex 3: Sub-processors Name of sub-processor: Stripe Payments Europe, Ltd. | Location of processing: Europe | Service provided: Payment processing Name of sub-processor: DigitalOcean, LLC | Location of processing: USA | Service provided: Hosting
Annex 4: Standard Contractual Clauses (SCC) – Module 4 The Standard Contractual Clauses pursuant to EU Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module 4 (Processor → Controller), in their current version, apply with the following selections: Clause 7 does not apply. Clause 13 – Competent supervisory authority: Der Hamburgische Beauftragte für Datenschutz und Informationssicherheit, www.datenschutz-hamburg.de Clause 17: German law shall apply. Clause 18: The courts of Germany shall have jurisdiction. A. List of Parties Data Exporter: Grouprides UG (haftungsbeschränkt), Bogenallee 10, 20144 Hamburg, +491741617703, support@grouprides.cc, Managing Director: Malthe Luda, Role: Processor Data Importer: Client data as per the underlying main contract, Role: Controller B. Description of the Data Transfer Categories of data subjects: See Annex 1 Categories of personal data transferred: See Annex 1 Frequency of transfer: Continuous Nature of processing: As set out in the main contract Purpose(s) of the transfer and further processing: As set out in the main contract Retention period: Until termination of the contract