Data Processing Agreement

under Art. 28 GDPR · as of July 2026

This is a translation for convenience. The authoritative version is the German original at zverd.de/avv.

Parties

This agreement is concluded between the customer as controller within the meaning of Art. 4(7) GDPR (the “Controller”) and Richard Golz, Karl-Liebknecht-Str. 8, 16548 Glienicke/Nordbahn, Germany, kontakt.golz@outlook.de, trading as Zverd, as processor within the meaning of Art. 4(8) GDPR (the “Processor”).

It supplements the main contract concluded between the parties for the design, build, hosting and maintenance of a website, and applies to all processing of personal data carried out by the Processor on behalf of the Controller.

1. Subject matter and duration

The subject matter of the processing is the technical provision, hosting and maintenance of the Controller's website, including any contact, login and sales features. Processing begins when the service starts and ends when the main contract ends.

2. Nature and purpose of processing

The Processor processes personal data exclusively for the purpose of providing the contractually agreed services. This includes storing and serving website content, operating contact and enquiry forms, technical fault analysis, security and availability measures and, where commissioned, operating shop, order and analytics features. No use for the Processor's own purposes takes place.

3. Type of data and categories of data subjects

Depending on the scope of the website, the following are processed: master and contact data (name, address, email address, telephone number), the content of enquiries and messages, contract and order data including purchased items and order values, payment-related metadata without complete payment credentials, usage and connection data such as IP address, time of access and volume transferred, and credentials of editorial and customer accounts.

Categories of data subjects are prospects and customers of the Controller, visitors to the website, and employees and contacts of the Controller.

4. Processing on instructions

The Processor processes personal data solely on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by Union or Member State law; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. Instructions are given in text form, including by email. If the Processor considers that an instruction infringes data protection law, it shall inform the Controller without delay and may suspend execution until confirmation.

5. Confidentiality

The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation continues after the activity ends.

6. Technical and organisational measures

The Processor implements the measures required under Art. 32 GDPR, in particular:

  • Encrypted transmission of all content via TLS/HTTPS
  • Encrypted storage of credentials, access only via password manager
  • Two-factor authentication for all administrative access
  • Access to production systems by the Processor only
  • Regular security updates of servers, dependencies and platforms
  • Automated backups with restore capability
  • Separation of different clients' data at system and account level
  • Logging of administrative access

Measures are subject to technical development. The Processor may adapt them provided the level of protection is not reduced.

7. Sub-processors

The Controller grants general authorisation for engaging the sub-processors listed below. The Processor shall inform the Controller of intended changes at least 14 days in advance in text form. The Controller may object within that period; if no mutually agreeable solution can be found, either party may terminate for cause.

ProviderPurposeLocationBasis
Cloudflare, Inc.Hosting, CDN, reach measurementUSA / EUStandard contractual clauses
Hetzner Online GmbHHosting (alternative, depending on project)GermanyEU / no third-country transfer
Formspree, Inc.Form deliveryUSAStandard contractual clauses
Snipcart inc.Shop platform, inventory, order processingCanadaStandard contractual clauses

Which of these providers is used in an individual case depends on the commissioned scope and is recorded in the offer. The Processor binds sub-processors to a level of protection equivalent to that of this agreement.

Payment providers such as Stripe or PayPal do not act as sub-processors of the Processor. The Controller concludes its own contracts with them; they process payment data under their own responsibility.

8. Assistance to the Controller

The Processor assists the Controller by appropriate technical and organisational measures in fulfilling requests from data subjects for access, rectification, erasure, restriction, data portability and objection. If a data subject contacts the Processor directly, the Processor forwards the request without delay and does not respond to it itself.

The Processor further assists the Controller in complying with the obligations under Art. 32 to 36 GDPR, in particular security of processing, notification of personal data breaches and data protection impact assessments. It shall notify the Controller of any personal data breach without undue delay and at the latest within 24 hours of becoming aware of it.

9. Erasure and return

After the end of the provision of processing services, the Processor shall, at the Controller's choice, delete or return all personal data and delete existing copies, unless Union or Member State law requires storage. On request, the Processor shall first provide the data in a common, machine-readable format. Backups are deleted within the regular backup cycle, at the latest 90 days after the end of the contract.

10. Evidence and audits

The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Audits are carried out with reasonable notice during normal business hours and must not unreasonably disrupt operations. Evidence may also be provided by current certificates, attestations or reports from independent bodies.

11. Third-country transfers

Where processing takes place outside the European Union or the European Economic Area, this occurs only if the conditions of Art. 44 et seq. GDPR are met, in particular on the basis of the European Commission's standard contractual clauses including any necessary supplementary measures.

12. Liability and final provisions

Art. 82 GDPR applies to liability. In all other respects the provisions of the main contract apply. Amendments and additions to this agreement require text form. In the event of conflict between this agreement and the main contract, this agreement prevails insofar as it concerns the processing of personal data. Should any provision be invalid, the remaining provisions remain unaffected.

Conclusion

This agreement is concluded in text form upon commissioning. On request, Zverd provides a signed version as a PDF. Questions to kontakt.golz@outlook.de.