howsafeismyapp

Legal

Data processing agreement (AVV)

Data Processing Agreement (AVV)

Data Processing Agreement under Article 28 GDPR. This template is intended for separately commissioned monitoring or remediation work where howsafeismyapp processes personal data on the customer's behalf. It is not automatically required merely because a customer orders a passive scan of public material. Annex 1 must be completed before signature.

Parties

Controller (Customer): [COMPLETE BEFORE SIGNATURE: customer legal name and address]

Processor: Tribus Solutions UG (haftungsbeschränkt), Donaustraße 44, 12043 Berlin, Germany, trading as howsafeismyapp ("Processor")

1. Subject matter and duration

The Processor provides the service described in Annex 1 and the underlying order. Processing begins on the agreed start date and ends when the service is completed or terminated. This DPA survives for as long as the Processor retains personal data on the Customer's behalf.

2. Nature, purpose, data and data subjects

The Processor may access, inspect, organise, modify, secure, export, or delete data only to the extent necessary for the commissioned technical assessment, remediation, or monitoring. The specific systems, purposes, personal-data categories, data subjects, and special-category restrictions must be completed in Annex 1 before work begins.

The default service is metadata-first. The Processor must not intentionally copy production row contents unless Annex 1 expressly requires it. Special categories under Article 9 GDPR and criminal-offence data under Article 10 are excluded unless specifically documented with additional safeguards.

3. Instructions

The Processor processes personal data only on documented instructions from the Customer, including instructions on international transfers. The order and Annex 1 are the initial instructions; later instructions may be given in text form. The Processor immediately informs the Customer if an instruction appears to infringe data-protection law and may suspend it pending clarification.

4. Confidentiality and personnel

The Processor ensures that authorised persons are bound to confidentiality, receive access only where necessary, and are informed of applicable security and data-protection duties. Access is revoked when no longer required.

5. Security

The technical and organisational measures in Annex 2 apply. The Processor may update them where the overall protection level does not materially decrease. The Customer remains responsible for assessing whether the measures are appropriate for its risks and notifying the Processor of heightened risks.

6. Subprocessors

The Customer grants general authorisation for the subprocessors in Annex 3. The Processor will impose data-protection obligations required by Article 28 GDPR, remain responsible for their performance, and provide at least 14 days' advance notice of a new subprocessor where reasonably possible. The Customer may object on documented data-protection grounds. If no reasonable solution is available, either party may terminate the affected service.

7. International transfers

The Processor will not transfer Customer personal data outside the EEA without an applicable adequacy decision, Standard Contractual Clauses, or another lawful safeguard. Current provider transfer mechanisms are identified in Annex

  1. The Customer may request available copies of relevant safeguards, subject
  2. to confidentiality restrictions.

8. Assistance

Taking into account the nature of processing, the Processor assists the Customer with data-subject requests and with obligations under Articles 32 to 36 GDPR, including security, breach notification, impact assessments, and prior consultation. Assistance within the agreed scope is included; material additional effort may be charged only if agreed or permitted by the main contract.

9. Personal-data breaches

The Processor notifies the Customer without undue delay after becoming aware of a personal-data breach affecting Customer data and provides available information reasonably required under Article 33(3) GDPR. The initial notice may be supplemented as investigation continues. Notice does not constitute an admission of fault.

10. Deletion and return

At the Customer's choice, the Processor deletes or returns Customer personal data after the service ends and deletes remaining copies, unless EU or Member State law requires retention. Credentials are not retained after they are no longer required. The Processor may retain evidence necessary to demonstrate contract performance or comply with law only in segregated, access-restricted form and not for other purposes.

11. Demonstration of compliance and audits

The Processor provides information reasonably necessary to demonstrate Article 28 compliance and contributes to audits by the Customer or an independent auditor. Audits should normally begin with documentation and remote review, occur during business hours, protect other customers and security information, and be announced at least 14 days in advance unless an incident or authority requires shorter notice.

12. Liability and priority

Article 82 GDPR and mandatory law remain unaffected. The liability provisions of the main agreement apply to the extent legally permitted. If this DPA conflicts with the main agreement on processing personal data, this DPA prevails.

Annex 1 -- Processing details

  • Customer and contact:
  • Service / order date:
  • Target systems and host names:
  • Duration and deletion date:
  • Purpose and operations:
  • Categories of personal data:
  • Categories of data subjects:
  • Special-category or Article 10 data: excluded / specify safeguards:
  • Authorised access and instructions:
  • Customer security/contact channel:

Annex 2 -- Technical and organisational measures

  • Data minimisation: public metadata and structure by default; no intentional
  • storage of customer production rows unless explicitly commissioned.

  • Access control: named individual accounts, least privilege, strong unique
  • credentials, MFA where available, prompt access revocation.

  • Device security: full-disk encryption, supported operating systems, screen
  • lock, timely security updates, and malware protection where appropriate.

  • Transfer security: TLS for data in transit; provider encryption at rest.
  • Secret handling: customer credentials in an approved password/secret store,
  • never committed to source control, removed after the assignment.

  • Change control: material customer-system changes documented and reversible
  • where reasonably possible; customer backup responsibility confirmed.

  • Availability and recovery: managed provider backups/recovery according to
  • the selected plan; incidents documented and communicated.

  • Separation: logical separation by customer/project and random report IDs.
  • Logging and review: security-relevant access/events logged where supported;
  • logs are access-restricted and retained only as necessary.

  • Deletion: credentials and temporary exports deleted promptly after use;
  • contracted retention applied to reports and records.

Annex 3 -- Approved subprocessors

  • Google Cloud EMEA Limited / Google group companies -- application hosting
  • and private report rendering in the selected europe-west4 EU region; Google Cloud Data Processing Addendum and applicable transfer safeguards.

  • Neon, LLC -- managed Postgres database, intended Frankfurt region;
  • Neon DPA, subprocessors, and applicable transfer safeguards.

  • Plus Five Five, Inc. (Resend) -- transactional email where commissioned;
  • US account/metadata processing; DPA, EU SCCs, and EU-US DPF where applicable. Stripe is used as an independent payment provider for our own contract and is not listed as a subprocessor processing Customer application data.

Signatures:

Customer: ____________________ Date: __________

Processor: ___________________ Date: __________

← Home