v1.2 · 08.08.2026
As of: 08.08.2026 Version: 1.0 Scope: Art. 28 GDPR, Art. 32 GDPR, Art. 82 GDPR, LOPDGDD Contracting parties: flowgeist (Processor) ↔ Client (Controller)
This Data Processing Agreement (DPA) governs the rights and obligations between the Controller (hereinafter “Client”) and the Processor (hereinafter “flowgeist”) regarding the processing of personal data in the context of using the SaaS platform CombiJornada (working time and shift planning / Jornada management).
The contract serves to fulfill the obligations under Art. 28 GDPR as well as the corresponding requirements of the Spanish Data Protection Law (LOPDGDD — Ley Orgánica de Protección de Datos Personales y Garantía de los Derechos Digitales) and applies in addition to the General Terms and Conditions (GTC) for CombiJornada.
(1) The subject matter of this contract is the processing of personal data by flowgeist in the context of providing the CombiJornada platform (working time and shift planning platform / Jornada management) for the Client.
(2) The DPA applies for the entire duration of the Client’s use of the CombiJornada platform and ends upon termination of the underlying SaaS agreement.
(3) Upon termination of the contract, the provisions regarding the Erasure and return of data (§ 3(7)) continue to apply.
(1) The processing of personal data by flowgeist takes place within the CombiJornada platform with the following data categories:
| Data category | Description | Examples |
|---|---|---|
| Master data | Basic identification and contact data | Name, first name, email address, company name, address |
| Working time data | Data for working time tracking | Work start, work end, break times, overtime |
| Shift and roster data | Data for shift and roster planning | Shift times, duty allocation, employee assignment |
| Vacation and absence data | Data for vacation and absence management | Vacation requests, approval status, sick days |
| Access data | Authentication data | NextAuth + JWT, password hash, session token, user roles |
| Documents | Uploaded files | Employment contracts, shift plans as PDF, absence certificates |
| Audit data | Logging of system accesses | Login times, actions, IP addresses, user identifiers |
| Invoice data | Payment and billing data | Stripe Customer ID, billing address |
(2) Categories of data subjects:
(3) Purposes of processing: Working time tracking, shift planning, vacation management, reporting, employee self-service, billing, security, and audit logging.
(4) Processing takes place exclusively within the scope of the Controller’s instructions (Art. 28(3)(a) GDPR). The Controller confirms that the instructions are in compliance with the legal requirements (in particular GDPR, LOPDGDD, Spanish labor law).
flowgeist processes the personal data of the Controller in strict confidence. flowgeist ensures that all persons who have access to personal data in the course of the engagement are subject to confidentiality in accordance with Art. 28(3)(b) GDPR and Art. 29 GDPR. The confidentiality obligation applies beyond the end of the contract.
flowgeist implements and maintains appropriate technical and organizational measures (TOMs) in accordance with Art. 32 GDPR to ensure a level of security appropriate to the risk. The TOMs are documented in the appendix of this contract and include in particular:
flowgeist engages the following Sub-processors (Art. 28(2) and (4) GDPR):
| Sub-processor | Headquarters | Service | Third country transfer |
|---|---|---|---|
| Hetzner Online GmbH | Germany (Falkenstein) | Hosting, PostgreSQL 16, Redis, backup | None (EU) |
| Stripe Payments Europe, Ltd. | Ireland (IE) / USA (US parent company) | Payment processing | EU-US Data Privacy Framework + SCC |
| AWS S3 (Amazon Web Services, Inc.) | USA / EU | File storage (documents, PDFs) | EU-US Data Privacy Framework + SCC |
flowgeist concludes corresponding DPA agreements with all Sub-processors in accordance with Art. 28(4) GDPR. Standard Contractual Clauses (SCC) and the EU-US Data Privacy Framework (DPF) are used for transfers to Third countries.
The Controller hereby grants general authorization to engage the above-mentioned Sub-processors (Art. 28(2) GDPR). flowgeist informs the Controller of material changes to the Sub-processor relationships.
flowgeist supports the Controller in fulfilling requests from data subjects regarding access, rectification, Erasure, restriction, and data portability (Art. 28(3)(e) GDPR). The support is provided within the technical capabilities of the platform.
flowgeist supports the Controller in conducting a Data Protection Impact Assessment in accordance with Art. 35 GDPR, insofar as the processing activities make this necessary (Art. 28(3)(f) GDPR). This includes the provision of relevant information about the processing and the TOMs.
flowgeist notifies the Controller without delay, but no later than 24 hours after becoming aware, of any Personal data breach that may be relevant to the Controller (Art. 28(3)(g), Art. 33 GDPR). The notification includes:
flowgeist documents all Personal data breaches including the measures taken.
Upon termination of the processing relationship, flowgeist erases the Controller’s personal data within 30 days, unless statutory retention obligations conflict with this. Return of the data in a structured, commonly used, and machine-readable format may be provided within 30 days after contract end upon the Controller’s request.
Retention periods:
| Data category | Retention period | Legal basis |
|---|---|---|
| Master data | 30 days after contract end | GDPR Art. 5(1)(e) |
| Working time data | 4 years | Art. 34 Estatuto de los Trabajadores |
| Shift and roster data | 4 years | Art. 34 Estatuto de los Trabajadores |
| Vacation and absence data | 4 years | Spanish labor law |
| Audit logs | 3 years | Art. 6(1)(f) GDPR |
| Invoice data | 10 years | § 147 AO / Art. 67 LGT (Spain) |
flowgeist processes the personal data exclusively within the scope of the documented instructions of the Controller (Art. 28(3)(a) GDPR). Instructions may be given in text form (email). flowgeist documents all instructions.
If flowgeist is of the opinion that an instruction infringes data protection provisions (GDPR, LOPDGDD, or Spanish labor law), flowgeist will inform the Controller without delay (Art. 28(3)(a) sentence 2 GDPR).
(1) The Controller is solely responsible for the lawfulness of the data processing (Art. 28(3) GDPR) and for compliance with the legal requirements, in particular:
(2) The Controller ensures that data subjects (employees) are informed about the data processing in accordance with Art. 13/14 GDPR and that the required legal bases (in particular Art. 6(1)(b), Art. 88 GDPR, Art. 22 LOPDGDD) exist.
(3) The Controller is responsible for compliance with the information and cooperation obligations towards the works council or employee representation (in accordance with Spanish labor law, in particular Art. 64 Estatuto de los Trabajadores).
(4) The Controller reviews and approves the Sub-processors referred to in § 3(3).
(5) The Controller bears responsibility for the accuracy, completeness, and currency of the data entered into the CombiJornada platform.
(1) The Controller has the right to audit flowgeist’s compliance with its obligations under Art. 28 GDPR. This includes in particular:
(2) flowgeist supports the Controller with audits and inspections to a reasonable and proportionate extent. Audits are conducted after prior scheduling (at least 4 weeks in advance) and with due regard for flowgeist’s trade secrets.
(3) flowgeist provides the Controller with the necessary evidence (certificates, audit reports) upon request, insofar as these are not confidential.
(1) The primary processing of personal data takes place in Germany (Hetzner Online GmbH, Falkenstein). Transfer to Third countries (outside the EU/EEA) occurs in the following cases:
AWS S3 (USA): File storage via AWS S3. AWS is certified under the EU-US Data Privacy Framework (DPF). In addition, Standard Contractual Clauses (SCC) of the European Commission are concluded.
Stripe (USA): Payment processing via Stripe Payments Europe, Ltd. (Ireland). Stripe Inc. (USA) as the parent company is certified under the EU-US Data Privacy Framework. In addition, Standard Contractual Clauses (SCC) are applied.
(2) flowgeist has conducted a Transfer Impact Assessment (TIA) in accordance with Art. 46 GDPR for both Third country transfers. The results of the TIA confirm that there are no reasons to doubt an adequate level of protection. The TIA is updated regularly (at least annually).
(3) flowgeist informs the Controller without delay if new or changed circumstances affect the Third country transfer and require an adjustment of the TIA or the protective measures.
(4) The Controller is responsible for informing data subjects about the Third country transfer in accordance with Art. 13/14 GDPR.
(1) Liability is governed by Art. 82 GDPR and the statutory provisions. flowgeist is liable to the Controller for damages arising from a breach of the obligations under this DPA or the GDPR, in accordance with the statutory provisions.
(2) flowgeist is liable without limitation for intent and gross negligence. For slight negligence, flowgeist is only liable for breach of an essential contractual obligation (cardinal obligation) whose breach jeopardizes the achievement of the contract purpose, and only to the amount of the typically foreseeable damage.
(3) Liability for indirect damages, consequential damages, and loss of profit is, insofar as legally permissible, limited to the typically foreseeable damage.
(4) The above liability limitations do not apply to damages arising from injury to life, body, or health, or to cases of mandatory statutory liability.
(1) This DPA is governed, insofar as legally permissible, by German law to the exclusion of the UN Convention on Contracts for the International Sale of Goods (CISG). For contracts with clients domiciled in Spain, Spanish law applies in addition, insofar as mandatory EU requirements (in particular GDPR) do not provide otherwise.
(2) The place of jurisdiction is, insofar as legally permissible, Mettmann (Germany). For disputes with Spanish clients, insofar as legally permissible, the client’s place of business in Spain is also agreed as the place of jurisdiction.
(3) Should individual provisions of this contract be invalid or unenforceable, the validity of the remaining provisions remains unaffected. The parties undertake to replace invalid provisions with those that come closest to the economic purpose.
(4) Amendments and supplements to this contract require text form. This also applies to the waiver of this form requirement.
(5) This DPA is part of the SaaS agreement for CombiJornada and applies in addition to the GTC.
Processor: flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany E-Mail: info@flowgeist.de Data Protection: datenschutz@flowgeist.de
Controller (Client):
Name/Company: ________________________ Address: ________________________ E-Mail: ________________________ Date: ________________________
The detailed Technical and Organizational Measures (TOMs) are documented in a separate document:
Reference: TOMs CombiJornada — Technical and Organizational Measures (As of: 08.08.2026, Version 1.0)
The TOMs include:
| Version | Date | Material changes |
|---|---|---|
| 1.0 | 08.08.2026 | Initial version as product-specific DPA for CombiJornada |
flowgeist (Processor) Ralf Carsjens Date: ______________
Client (Controller) Name: ______________ Date: ______________
© 2026 flowgeist – Ralf Carsjens · All rights reserved