v1.2 · 08.08.2026
Status: 08.08.2026 Version: 1.0 Scope: Art. 28 GDPR, Art. 32 GDPR, Art. 82 GDPR Contracting parties: flowgeist (Processor) ↔ Daycare provider (Controller)
This Data Processing Agreement (DPA) specifies the data protection obligations of the parties in the context of the use of the flowgeist KITA platform. It supplements the existing Terms and Conditions (T&C) and the underlying terms of use between the parties. In the event of contradictions between this DPA and other contractual provisions, this DPA shall prevail with regard to the processing of data within the meaning of Art. 28 GDPR.
Controller (Client):
Name/Designation: ___________________________ Address: ___________________________ Authorized representative: ___________________________ Email: ___________________________
Processor:
flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany Email: info@flowgeist.de
(1) The subject matter of this agreement is the provision and use of the flowgeist KITA platform as a daycare management platform. The platform includes the following functions:
The Processor processes personal data on behalf of the Controller exclusively in accordance with the Controller’s instructions and within the framework of this agreement.
(2) This agreement applies for the duration of the use of the flowgeist KITA platform. It terminates upon the end of the usage relationship by termination or for any other reason. The provisions regarding the deletion and return of data pursuant to § 3 (7) of this agreement shall remain applicable even after the termination of this agreement.
(1) Categories of personal data:
(2) Data subjects:
(3) Purposes of processing:
(4) Nature of processing:
(1) Confidentiality (Art. 28 (3) lit. b GDPR): The Processor processes personal data exclusively on the instructions of the Controller, including the transfer and erasure of data, unless processing is required by Union or Member State law. The Processor binds all persons authorized to process personal data to confidentiality pursuant to Art. 28 (3) lit. b GDPR and Art. 29 GDPR.
(2) Technical and organizational measures (Art. 32 GDPR): The Processor implements the necessary technical and organizational measures pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk. The measures include in particular:
The detailed description of the TOMs is contained in the appendix “TOMs Reference” as well as in the separate TOMs document.
(3) Sub-processors: The Processor exclusively engages the following as sub-processors:
No other sub-processors are engaged. A transfer of data to third countries does not take place. All processing operations are carried out in Germany (Falkenstein data center). Redis is operated as an in-memory cache locally on the server and does not constitute a sub-processor.
(4) Support with data subject rights (Art. 28 (3) lit. e GDPR): The Processor supports the Controller in fulfilling the rights of data subjects pursuant to Arts. 15 to 22 GDPR, in particular by providing the necessary functions for access, rectification, erasure, restriction, and data portability.
(5) Support with data protection impact assessment (Art. 28 (3) lit. f GDPR): The Processor supports the Controller in carrying out a data protection impact assessment (DPIA) pursuant to Art. 35 GDPR, insofar as this is necessary. This applies in particular due to the processing of special categories of personal data (Art. 9 GDPR).
(6) Notification of data protection breaches (Art. 33 GDPR): The Processor shall notify the Controller without undue delay, but no later than within 24 hours after becoming aware, of any personal data breach affecting the Controller. The notification shall include at least:
(7) Erasure and return: Upon completion of the processing assignments or upon request by the Controller, the Processor shall delete all personal data after expiry of a grace period of 30 days from the request, unless statutory retention obligations conflict therewith. The request period is 30 days from the termination of the contractual relationship.
Retention periods:
| Data Category | Period | Subsequently |
|---|---|---|
| Children’s master data | 30 days request + 30 days grace period | Deletion |
| Health data | 30 days request + 30 days grace period | Deletion |
| Audit logs | 3 years from creation | Deletion |
| Invoices | 10 years (§ 147 AO) | Deletion |
(8) Instructional bound (Art. 28 (3) lit. a GDPR): The Processor documents and complies with all instructions of the Controller. Instructions that violate applicable law, in particular the GDPR, shall be communicated by the Processor to the Controller without undue delay in writing or in text form. The Processor is entitled to suspend the execution of the instruction until the Controller confirms or adjusts it.
(1) Lawfulness of processing: The Controller bears sole responsibility for the lawfulness of the processing of personal data pursuant to Art. 6 and Art. 9 GDPR. This applies in particular to the processing of special categories of personal data pursuant to Art. 9 GDPR (in particular health data). The Controller ensures that, prior to the entry of health data, the corresponding consent of the legal guardians pursuant to Art. 9 (2) lit. a GDPR has been obtained and documented.
(2) Information of data subjects: The Controller informs the data subjects (children through their legal guardians, parents, staff) pursuant to Arts. 13 and 14 GDPR about the processing of their personal data by the flowgeist KITA platform.
(3) Data protection impact assessment (DPIA): Due to the processing of special categories of personal data (Art. 9 GDPR) and the processing of data of minors, a data protection impact assessment pursuant to Art. 35 GDPR shall be carried out by the Controller, insofar as a high risk to the rights and freedoms of natural persons exists. The Processor supports the Controller in this regard.
(4) Cooperation with supervisory authority: The Controller cooperates with the competent data protection supervisory authority (LDI NRW) within the framework of statutory obligations and provides the necessary information.
(1) The Controller has the right to audit the Processor’s compliance with the technical and organizational measures. This includes the right to inspect the TOMs documentation and to conduct audits, which must be announced with reasonable advance notice (at least 4 weeks).
(2) The Processor undertakes to inform the Controller without undue delay of material changes to the technical and organizational measures, insofar as these could affect the level of protection.
(3) The Processor shall, upon request, provide the Controller with the necessary evidence of compliance with the obligations pursuant to Art. 28 GDPR.
A transfer of data to third countries within the meaning of Art. 44 et seq. GDPR does not take place. All processing operations, including hosting, database, and backup, are carried out exclusively in Germany (Hetzner Online GmbH, Falkenstein data center). No sub-processors outside the European Union or the European Economic Area are engaged.
(1) The Processor shall be liable without limitation for damages based on an intentional or grossly negligent breach of duty by the Processor, its legal representatives, or vicarious agents.
(2) In the case of slight negligence, the Processor shall only be liable for the breach of cardinal obligations, i.e., those obligations whose fulfillment enables the proper performance of the contract in the first place and on whose compliance the Controller may regularly rely. In this case, liability is limited to the typical, foreseeable damage, up to a maximum amount of 12,000 EUR per claim.
(3) In the event of data loss, the Processor shall only be liable for the effort required to restore the data, if and to the extent that the Controller has properly fulfilled its data backup obligations. Liability is limited to the typical, foreseeable damage.
(4) Liability for indirect damages, in particular consequential damages such as loss of profit, business interruption, or loss of business data, is excluded in the case of slight negligence.
(5) The above limitations of liability shall not apply to damages resulting from injury to life, body, or health.
(6) Insofar as liability under Art. 82 GDPR (liability and compensation) is imposed on the Processor, the statutory provisions shall apply. Any recourse between the Controller and the Processor shall be governed by the national implementation laws.
(1) Amendments and additions to this agreement require text form. This also applies to the amendment of this written-form clause.
(2) Should individual provisions of this agreement be or become invalid or unenforceable, this shall not affect the validity of the remaining provisions. The parties undertake to replace the invalid provision with a valid one that comes closest to the commercial purpose of the invalid provision (severability clause).
(3) This agreement is subject to the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).
(4) Place of jurisdiction for all disputes arising from or in connection with this agreement is Mettmann, insofar as this is legally permissible.
(5) This agreement is concluded in text form (email, PDF, or electronic signature).
Processor: flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany Email: info@flowgeist.de Data protection: datenschutz@flowgeist.de
Controller: [Free fields – to be completed by the daycare provider]
The detailed description of the technical and organizational measures (TOMs) pursuant to Art. 32 GDPR is contained in the separate TOMs document for flowgeist KITA. The measures described therein are part of this DPA and are complied with by the Processor.
The measures include in particular:
| Version | Date | Material Changes |
|---|---|---|
| 1.0 | 08.08.2026 | Initial version |
Place, date
Controller (daycare provider)
Processor (flowgeist, Ralf Carsjens)
© 2026 flowgeist – Ralf Carsjens · All rights reserved