v1.2 · 08.08.2026
Status: 08.08.2026 Version: 1.0 Scope: Art. 28 GDPR, Art. 32 GDPR, Art. 82 GDPR Contracting Parties: flowgeist (Processor) ↔ Customer/User (Controller)
This Data Processing Agreement (DPA) governs the processing of personal data by flowgeist on behalf of the User in connection with the use of the flowgeist FOOD App. The flowgeist FOOD App is a nutrition and health app (PWA and Native iOS/Android) that assists with the recording and analysis of nutrition data, including photo-based food analysis and health data management.
Special feature of flowgeist FOOD: With the flowgeist FOOD App, the User is generally both the data subject and the Controller within the meaning of the GDPR (single-user app). This DPA applies insofar as flowgeist processes personal data on behalf of and in accordance with the instructions of the User. This applies in particular to the processing of Health data (Art. 9 GDPR), nutrition data, and photo data that the User records in the app.
The DPA serves to fulfill the contractual obligations under Art. 28 GDPR and ensures that the processing of personal data is carried out in compliance with data protection requirements. Due to the processing of special categories of personal data (Art. 9 GDPR), heightened requirements apply to the technical and organizational measures as well as to confidentiality.
(1) Subject Matter The subject matter of this Agreement is the processing of personal data by flowgeist on behalf of the User in connection with the use of the flowgeist FOOD App. The App comprises:
(2) Duration This Agreement applies for the duration of the User’s use of the flowgeist FOOD App. It terminates upon deletion of the user account, but not before all obligations under this Agreement have been fulfilled, in particular the return or deletion of data in accordance with § 3(7).
(3) Termination The User may terminate use of the App at any time by deleting their account. flowgeist may terminate the use without notice if continuation of the processing relationship, taking into account all circumstances and weighing the interests of both Parties, is unreasonable, in particular in the event of serious breaches by the User of statutory obligations.
(1) Nature of Processing Processing encompasses the collection, storage, transmission, analysis, and evaluation of personal data in the context of operating the flowgeist FOOD App.
(2) Data Categories
| Data Category | Description | Examples |
|---|---|---|
| Master data | Basic user data | Name, email address |
| Health data (Art. 9 GDPR) | Specially protected data | Allergies, intolerances, dietary goals |
| Nutrition data | Recorded nutrition data | Nutrition diary, food items, nutritional values, meals |
| Photo data | Food photos | Images for AI-supported food analysis |
| Access data | Authentication data | Apple/Google Sign-In token, session token |
| Device data | Technical metadata | Device ID, app version, operating system |
| Audit data | Logging data | Access logs, change logs, consent logs |
(3) Data Subjects Data subjects are:
(4) Processing Purposes Processing is carried out exclusively for the purposes set out in § 1 and within the scope of the instructions given by the User.
(5) Scope The scope of processing arises from the User’s use of the App. flowgeist processes only the data that the User actively records or that is automatically generated in the course of operating the App.
(1) Confidentiality flowgeist ensures that all persons who have access to personal data in the context of the processing relationship are subject to confidentiality in accordance with Art. 28(3)(b), Art. 29, and Art. 32(4) GDPR. The confidentiality obligation continues to apply after termination of the processing relationship. flowgeist documents the confidentiality obligation in written or electronic form.
(2) Technical and Organizational Measures flowgeist implements and maintains the technical and organizational measures (TOMs) required by Art. 32 GDPR to protect personal data. The measures are described in detail in the Appendix “TOMs Reference” of this Agreement. Due to the processing of Health data (Art. 9 GDPR), heightened requirements apply, which are separately set out in the TOMs.
(3) Sub-processors flowgeist engages the following sub-processors (Art. 28(2), (4) GDPR):
| Sub-processor | Location | Purpose | Third countries |
|---|---|---|---|
| Hetzner Online GmbH | Falkenstein, Germany (DE) | Hosting, PostgreSQL 16, MinIO, Redis | None (EU) |
| Mistral AI SAS | France (FR) | Mistral Vision API for food analysis | None (EU-only) |
| Sentry (Functional Software, Inc.) | USA (US) | Error tracking, fault diagnosis | EU-US DPF + SCC |
flowgeist concludes corresponding DPAs with all sub-processors in accordance with Art. 28(4) GDPR. The engagement of further sub-processors is notified to the User in advance, unless the User has already given general consent in advance.
(4) Support for Data Subjects’ Rights flowgeist supports the User in fulfilling data subjects’ rights (Art. 15–22 GDPR), in particular with regard to requests for information, rectification, erasure, and restriction. flowgeist provides the technical means to fulfill the rights of data subjects within the statutory deadlines.
(5) Support for Data Protection Impact Assessment (DPIA) flowgeist supports the User in conducting a Data Protection Impact Assessment (Art. 35 GDPR). This is particularly necessary when processing Health data (Art. 9 GDPR). flowgeist provides the User, upon request, with the relevant information about the processing operations, the TOMs, and risk mitigation.
(6) Notification of Personal Data Breaches flowgeist notifies the User without delay, but no later than within 24 hours after becoming aware, of all personal data breaches (Art. 33 GDPR) that occur during processing on behalf of the User. The notification includes:
flowgeist documents all personal data breaches in accordance with Art. 33(5) GDPR.
(7) Deletion and Return Upon termination of the processing relationship, flowgeist deletes all personal data processed on behalf of the User within 30 days, unless the User has issued a different instruction. Return of the data to the User takes place upon request within 30 days after termination. After the expiry of a further period of 30 days (a total of 30 + 30 days), the returned data is irrevocably deleted at flowgeist.
Exempt from deletion are data subject to statutory retention obligations (in particular audit logs). This data is processed exclusively for the fulfillment of statutory obligations and deleted after the retention period expires.
(8) Instruction Binding flowgeist processes the personal data exclusively in accordance with the documented instructions of the User (Art. 28(3)(a) GDPR). Instructions are documented in text form (email, app settings). flowgeist informs the User without delay if, in flowgeist’s opinion, an instruction infringes statutory provisions (Art. 28(3) GDPR).
(9) Retention Periods
| Data Category | Retention Period | Note |
|---|---|---|
| Master data | 30 days after account deletion | Period for data subjects’ rights |
| Health data (Art. 9 GDPR) | 30 days after account deletion; immediately upon withdrawal | Immediate deletion upon withdrawal |
| Nutrition data | 30 days after account deletion | — |
| Photo data | 30 days after account deletion | — |
| Audit logs | 3 years | Statutory retention obligation |
| Sentry data | 30 days | PII minimized |
(1) Responsibility for Processing The User, as Controller, bears full responsibility for the lawfulness of the processing (Art. 28(3) GDPR). The User ensures that all prerequisites for the processing of personal data, in particular Health data, are met.
(2) Consents under Art. 9 GDPR The User is responsible for obtaining and managing consents for the processing of Health data in accordance with Art. 9(2)(a) GDPR. flowgeist provides the technical means to obtain and log consent. The User ensures that consent is given freely, informed, and unambiguously.
(3) Data Protection Impact Assessment (DPIA) The User is responsible for conducting a Data Protection Impact Assessment (Art. 35 GDPR), insofar as this is required due to the processing of Health data. flowgeist supports the User in this regard in accordance with § 3(5).
(4) Instructions The User issues all instructions for the processing of personal data in text form. Instructions may also be given via app settings, provided they are sufficiently documented.
(5) Information Obligations The User ensures that data subjects are properly informed in accordance with Art. 13, 14 GDPR. The privacy policy of the flowgeist FOOD App is provided by flowgeist and used by the User as part of the information obligations.
(6) Notification of Personal Data Breaches to Supervisory Authorities The User is responsible for notifying personal data breaches to the competent supervisory authority (Art. 33 GDPR) and informing the data subjects (Art. 34 GDPR), where required. flowgeist supports the User in fulfilling these obligations through prompt notification in accordance with § 3(6).
(1) User’s Audit Right The User has the right to verify flowgeist’s compliance with its obligations under this DPA. This includes in particular the review of the TOMs, the processing operations, and the sub-processors.
(2) Conduct of Audits The audit may be carried out by prior review of documents, through audits, or through on-site inspections. flowgeist supports the User in conducting audits and inspections to a reasonable extent.
(3) Information flowgeist provides the User, upon request at any time, with information about the processing of personal data, the TOMs employed, and the sub-processors.
(4) Certifications and Audit Evidence flowgeist may submit certifications, audit reports, or audit certificates to fulfill the audit obligations, insofar as these are suitable to demonstrate compliance with the requirements.
(1) General Principle The primary processing of personal data takes place in Germany (Hetzner Online GmbH, Falkenstein). Database (PostgreSQL 16), Object Storage (MinIO), and Cache (Redis) are operated exclusively in Germany.
(2) Third-Country Transfers
| Recipient | Country | Protection Mechanism | Note |
|---|---|---|---|
| Sentry (Functional Software, Inc.) | USA | EU-US Data Privacy Framework (DPF) + SCC | PII minimized, no Health data |
| Mistral AI SAS | France (FR) | EU Member State, no third-country transfer | EU-only |
| Apple Inc. | USA | EU-US DPF | Authentication |
| Google LLC | USA | EU-US DPF | Authentication |
(3) Health Data Health data within the meaning of Art. 9 GDPR is not transferred to third countries. Processing takes place exclusively in Germany and France (Mistral AI, EU Member State).
(4) Standard Contractual Clauses For the transfer to Sentry (USA), the Standard Contractual Clauses of the European Commission (Implementing Decision (EU) 2021/914) are applied in addition to the EU-US Data Privacy Framework. flowgeist conducts a risk assessment in accordance with Art. 46(2) GDPR and takes supplementary measures, where required.
(1) Liability under GDPR Liability is governed by Art. 82 GDPR. flowgeist is liable to the User for damage caused by a breach of the obligations under this DPA or the GDPR, insofar as flowgeist is responsible for the breach.
(2) Exclusion of Liability flowgeist is liable without limitation for intent and gross negligence. For slight negligence, flowgeist is liable only for the breach of essential contractual obligations (cardinal obligations) and only up to the amount of the typically foreseeable damage.
(3) Liability of the Controller The User, as Controller, is liable for the lawfulness of the data processing and for the instructions issued by them. flowgeist is not liable for damage attributable to impermissible or insufficient instructions from the User.
(4) Liability Independent of Fault Insofar as flowgeist as Processor is liable for damage caused by the processing of personal data, flowgeist may seek recourse from the Controller, insofar as the Controller is responsible for the damage (Art. 82(5) GDPR).
(1) Written Form Amendments and supplements to this Agreement require written form. This also applies to the waiver of the written form clause.
(2) Side Agreements No side agreements exist. No oral agreements have been made.
(3) Severability Clause Should individual provisions of this Agreement be or become invalid or unenforceable, this does not affect the validity of the remaining provisions. The Parties shall replace the invalid provision with a valid one that comes closest to the economic purpose thereof.
(4) Applicable Law This Agreement is governed by the law of the Federal Republic of Germany, excluding conflict of law rules.
(5) Place of Jurisdiction Place of jurisdiction is Mettmann, Germany, insofar as legally permissible.
(6) Contract Language The contract language is German.
flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany
Email: info@flowgeist.de Data Protection: datenschutz@flowgeist.de Web: https://foodapp.flowgeist.de
The detailed technical and organizational measures (TOMs) in accordance with Art. 32 GDPR are described in the separate document “Technical and Organizational Measures (TOMs) – flowgeist FOOD”. This Appendix is an integral part of this DPA and serves as a reference for compliance with the protection requirements.
The TOMs include in particular:
| Version | Date | Material Changes |
|---|---|---|
| 1.0 | 08.08.2026 | Initial version for flowgeist FOOD |
flowgeist Ralf Carsjens, Owner Date: ______________
Customer / User Date: ______________
© 2026 flowgeist – Ralf Carsjens · All rights reserved