Data Processing Agreement
under Art. 28 GDPR · as of July 2026
This is a translation for convenience. The authoritative version is the German original at zverd.de/avv.
Parties
This agreement is concluded between the customer as controller within the meaning of Art. 4(7) GDPR (the “Controller”) and Richard Golz, Karl-Liebknecht-Str. 8, 16548 Glienicke/Nordbahn, Germany, kontakt.golz@outlook.de, trading as Zverd, as processor within the meaning of Art. 4(8) GDPR (the “Processor”).
It supplements the main contract concluded between the parties for the design, build, hosting and maintenance of a website, and applies to all processing of personal data carried out by the Processor on behalf of the Controller.
1. Subject matter and duration
The subject matter of the processing is the technical provision, hosting and maintenance of the Controller's website, including any contact, login and sales features. Processing begins when the service starts and ends when the main contract ends.
2. Nature and purpose of processing
The Processor processes personal data exclusively for the purpose of providing the contractually agreed services. This includes storing and serving website content, operating contact and enquiry forms, technical fault analysis, security and availability measures and, where commissioned, operating shop, order and analytics features. No use for the Processor's own purposes takes place.
3. Type of data and categories of data subjects
Depending on the scope of the website, the following are processed: master and contact data (name, address, email address, telephone number), the content of enquiries and messages, contract and order data including purchased items and order values, payment-related metadata without complete payment credentials, usage and connection data such as IP address, time of access and volume transferred, and credentials of editorial and customer accounts.
Categories of data subjects are prospects and customers of the Controller, visitors to the website, and employees and contacts of the Controller.
4. Processing on instructions
The Processor processes personal data solely on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by Union or Member State law; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. Instructions are given in text form, including by email. If the Processor considers that an instruction infringes data protection law, it shall inform the Controller without delay and may suspend execution until confirmation.
5. Confidentiality
The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation continues after the activity ends.
6. Technical and organisational measures
The Processor implements the measures required under Art. 32 GDPR, in particular:
- Encrypted transmission of all content via TLS/HTTPS
- Encrypted storage of credentials, access only via password manager
- Two-factor authentication for all administrative access
- Access to production systems by the Processor only
- Regular security updates of servers, dependencies and platforms
- Automated backups with restore capability
- Separation of different clients' data at system and account level
- Logging of administrative access
Measures are subject to technical development. The Processor may adapt them provided the level of protection is not reduced.
7. Sub-processors
The Controller grants general authorisation for engaging the sub-processors listed below. The Processor shall inform the Controller of intended changes at least 14 days in advance in text form. The Controller may object within that period; if no mutually agreeable solution can be found, either party may terminate for cause.
| Provider | Purpose | Location | Basis |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, CDN, reach measurement | USA / EU | Standard contractual clauses |
| Hetzner Online GmbH | Hosting (alternative, depending on project) | Germany | EU / no third-country transfer |
| Formspree, Inc. | Form delivery | USA | Standard contractual clauses |
| Snipcart inc. | Shop platform, inventory, order processing | Canada | Standard contractual clauses |
Which of these providers is used in an individual case depends on the commissioned scope and is recorded in the offer. The Processor binds sub-processors to a level of protection equivalent to that of this agreement.
Payment providers such as Stripe or PayPal do not act as sub-processors of the Processor. The Controller concludes its own contracts with them; they process payment data under their own responsibility.
8. Assistance to the Controller
The Processor assists the Controller by appropriate technical and organisational measures in fulfilling requests from data subjects for access, rectification, erasure, restriction, data portability and objection. If a data subject contacts the Processor directly, the Processor forwards the request without delay and does not respond to it itself.
The Processor further assists the Controller in complying with the obligations under Art. 32 to 36 GDPR, in particular security of processing, notification of personal data breaches and data protection impact assessments. It shall notify the Controller of any personal data breach without undue delay and at the latest within 24 hours of becoming aware of it.
9. Erasure and return
After the end of the provision of processing services, the Processor shall, at the Controller's choice, delete or return all personal data and delete existing copies, unless Union or Member State law requires storage. On request, the Processor shall first provide the data in a common, machine-readable format. Backups are deleted within the regular backup cycle, at the latest 90 days after the end of the contract.
10. Evidence and audits
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Audits are carried out with reasonable notice during normal business hours and must not unreasonably disrupt operations. Evidence may also be provided by current certificates, attestations or reports from independent bodies.
11. Third-country transfers
Where processing takes place outside the European Union or the European Economic Area, this occurs only if the conditions of Art. 44 et seq. GDPR are met, in particular on the basis of the European Commission's standard contractual clauses including any necessary supplementary measures.
12. Liability and final provisions
Art. 82 GDPR applies to liability. In all other respects the provisions of the main contract apply. Amendments and additions to this agreement require text form. In the event of conflict between this agreement and the main contract, this agreement prevails insofar as it concerns the processing of personal data. Should any provision be invalid, the remaining provisions remain unaffected.
Conclusion
This agreement is concluded in text form upon commissioning. On request, Zverd provides a signed version as a PDF. Questions to kontakt.golz@outlook.de.