v1.2 · 08.08.2026
Status: 08.08.2026 Version: 1.0 Scope: Art. 28 GDPR, Art. 32 GDPR, Art. 82 GDPR Contracting Parties: flowgeist (Processor) ↔ Customer (Controller)
This Data Processing Agreement (DPA) governs the rights and obligations of the Controller (Customer) and the Processor (flowgeist) in connection with the processing of personal data in the context of the use of the flowgeist TOOL platform. It serves to fulfill the obligations under Art. 28 GDPR and ensures that the processing of personal data is carried out exclusively in accordance with the Controller’s instructions and in compliance with the statutory requirements of the GDPR.
The Controller engages the Processor to process personal data in the context of providing the flowgeist TOOL platform (tool management). This Agreement is an integral part of the underlying terms of use (AGB) between the Parties.
(1) The subject matter of this Agreement is the processing of personal data by the Processor on behalf of the Controller. The Processor provides the services within the scope of the flowgeist TOOL platform, a multi-tenant SaaS solution for the management of special tools and equipment, comprising:
(2) The Processor processes personal data exclusively in accordance with the written (including electronic, Art. 28(2) GDPR) instructions of the Controller, including transmission to third parties, provided this is included in the instructions or required by law.
(3) This Agreement applies for the term of the underlying usage agreement (AGB) and terminates upon its termination. Upon termination, the provisions on deletion and return pursuant to § 3(7) of this Agreement shall continue to apply.
(4) Either Party may terminate this Agreement for cause without notice, in particular in the event of serious violations of data protection requirements.
(1) The nature and scope of processing arise from the underlying usage agreement (AGB), this Agreement, and the product-specific service descriptions. The processing encompasses the following categories of personal data:
| Data Category | Description | Examples |
|---|---|---|
| Master data | Information regarding identity and company | Name, first name, email address, company name, address |
| Access data | Data for authentication | Password hash (Argon2id), MFA/TOTP secret |
| Tool usage data | Data on the use of platform functions | Who borrowed which tool, loan and return timestamps |
| Audit data | Logging of system accesses | Login times, actions performed, IP address |
| Billing data | Data for invoicing | Stripe Customer ID, invoice amount, invoice date |
| Support data | Data in the context of support processing | Support requests, communication history |
(2) The processing is carried out for the following purposes:
(3) The categories of data subjects affected by the processing comprise the following groups of persons:
(4) The transmission, disclosure, or other processing of personal data outside the purposes described in this Agreement requires the prior written instruction of the Controller and is only permissible if a legal obligation exists (Art. 28(3)(a) GDPR).
The Processor ensures that the persons who process personal data on its behalf are subject to an appropriate confidentiality obligation (Art. 28(3)(b), Art. 29 GDPR, § 53 BDSG). All employees of the Processor who have access to personal data are instructed on their data protection obligations before commencing their activities and undertake in writing to maintain confidentiality.
The Processor implements the necessary technical and organizational measures in accordance with Art. 32 GDPR to ensure a level of security appropriate to the risk for the security, confidentiality, integrity, availability, and resilience of the processing systems. The measures are described in detail in the Appendix “TOMs Reference” of this Agreement and form an integral part of this Agreement. The Processor documents the implementation and compliance with these measures.
The Processor may only engage sub-processors (other processors) to process personal data with the prior specific or general written authorization of the Controller (Art. 28(2), (4) GDPR). The Controller hereby grants its general authorization for the following sub-processors:
| Sub-processor | Location | Purpose | Third-country reference |
|---|---|---|---|
| Hetzner Online GmbH | Germany (Falkenstein) | Hosting, database (PostgreSQL 16), backup | No third countries |
| Stripe Payments Europe, Ltd. | Ireland / USA (parent company) | Payment processing | EU-US Data Privacy Framework + SCC |
The Processor enters into agreements with the sub-processors in accordance with Art. 28(4) GDPR, containing the same data protection obligations as this Agreement. The Processor remains fully responsible to the Controller for compliance with the obligations by the sub-processors. In the event of a change or the addition of further sub-processors, the Processor informs the Controller in a timely manner so that the Controller has the opportunity to object to the engagement.
The Processor supports the Controller, taking into account the nature of the processing, with appropriate technical and organizational measures insofar as this is necessary for the Controller to fulfill its obligations to respond to requests for information and other requests from data subjects (Art. 12–22 GDPR) (Art. 28(3)(e) GDPR). The Processor forwards requests from data subjects to the Controller without delay, provided such requests are directed directly to the Processor.
The Processor supports the Controller in conducting a Data Protection Impact Assessment (DPIA) in accordance with Art. 35 GDPR, insofar as this is necessary. The Processor provides the Controller, upon request, with the necessary information about the processing and the security measures implemented (Art. 28(3)(f) GDPR, Art. 35(2) GDPR).
The Processor notifies the Controller without delay, but no later than 24 hours after becoming aware, of any personal data breach affecting the Controller (Art. 28(3)(g), Art. 33 GDPR). The notification is made in writing or electronically and contains at least the following information:
The Processor documents every personal data breach, including the nature of the breach, the consequences, and the measures taken (Art. 33(5) GDPR). The Processor supports the Controller in notifying the supervisory authority and informing the data subjects, insofar as required by law.
Upon completion of the processing services or early termination of the instruction, but no later than 30 days after termination of the usage agreement, the Processor deletes all personal data processed on behalf of the Controller or returns them to the Controller, provided no statutory retention obligation conflicts therewith (Art. 28(3)(g), (h) GDPR). Deletion is carried out taking into account the following periods:
| Data Category | Period for Deletion/Return |
|---|---|
| Master data | 30 days after termination |
| Tool usage data | 30 days after termination |
| Audit logs | 3 years (statutory retention obligation) |
| Billing data | 10 years (§ 147 AO, § 14b UStG) |
Data subject to statutory retention obligations are blocked until the retention period expires and are no longer used for processing purposes. The Processor confirms the deletion to the Controller in writing or electronically.
The Processor processes personal data exclusively in accordance with the documented instructions of the Controller (Art. 28(3)(a) GDPR). The Processor informs the Controller without delay if, in the Processor’s opinion, an instruction infringes applicable legal provisions. The Processor is entitled to suspend the execution of the instruction until the Controller confirms or adjusts the lawfulness of the instruction.
The following retention periods apply to the data processed under this Agreement:
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Master data | 30 days after termination | Contract execution |
| Tool usage data | 30 days after termination | Contract execution |
| Audit logs | 3 years | Security, abuse detection |
| Stripe webhook logs (PII) | 30 days, thereafter pseudonymization | Payment processing |
| Invoices | 10 years | § 147 AO, § 14b UStG |
(1) The Controller is responsible for the lawfulness of the processing and compliance with data protection requirements (Art. 28(3)(a) GDPR). The Controller ensures that the processing of the personal data made available to the Processor is lawful and that the rights of data subjects are upheld.
(2) The Controller issues instructions for the processing of personal data in writing or in electronic form (Art. 28(2) GDPR). The Controller bears responsibility for the accuracy and completeness of the transmitted data.
(3) The Controller is responsible for the accuracy and completeness of the tool data and user data entered into the flowgeist TOOL platform. The Processor assumes no liability for the accuracy of the inventory data.
(4) The Controller informs the Processor without delay of any detected errors or irregularities in the processing of personal data.
(5) The Controller ensures that the users of the platform designated by it are informed about the applicable data protection regulations and that the required consents and authorizations are in place.
(6) The Controller assesses, prior to transmitting personal data to the Processor, whether a Data Protection Impact Assessment (DPIA) is required in accordance with Art. 35 GDPR, and conducts it if necessary.
(1) The Controller has the right to carry out or have carried out audits and inspections at any time to verify compliance with the obligations set out in this Agreement and in the Appendix (TOMs) (Art. 28(3)(h) GDPR). The Processor supports the Controller in conducting audits to a reasonable extent.
(2) The Processor provides the Controller, upon request, with the necessary evidence of compliance with the obligations under Art. 28 and Art. 32 GDPR (Art. 28(3)(h) GDPR). This includes in particular evidence of the implementation of the technical and organizational measures.
(3) Audits and inspections are planned and conducted with reasonable prior notice of at least 14 days, unless a strong suspicion of a personal data breach necessitates an immediate audit. Audits are conducted during normal business hours and do not disproportionately disrupt the Processor’s operations.
(4) The costs for routine audits are borne by the Processor. Audits conducted on the basis of a specific suspicion of a personal data breach or at the request of a supervisory authority are borne by the Party that initiated the audit, unless the suspicion is confirmed and a Party has caused the breach.
(1) The primary processing of personal data takes place in Germany. The Processor’s servers are located at Hetzner Online GmbH in Falkenstein (Germany). No transfer to third countries takes place in this respect.
(2) In the context of payment processing, data is transferred to Stripe Payments Europe, Ltd. (Ireland) as well as to the US parent company Stripe, Inc. (USA). The transfer to the USA (third country) is carried out on the basis of the EU-US Data Privacy Framework, under which Stripe, Inc. is registered as a certified entity. In addition, Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR are agreed.
(3) The Processor informs the Controller of planned changes regarding the addition or replacement of sub-processors in third countries, so that the Controller has the opportunity to object to the engagement.
(4) No further data transfers to third countries take place. The platform does not use external AI services and no external analytics services.
(1) The liability of the Parties is governed by the statutory provisions, in particular Art. 82 GDPR and §§ 280, 276 BGB.
(2) The Processor is liable to the Controller for damage caused by a breach of the obligations set out in this Agreement, in accordance with the statutory provisions.
(3) The Processor is liable without limitation for intent and gross negligence as well as for damage to life, body, and health.
(4) In the case of slight negligence, the Processor is only liable for the breach of an essential contractual obligation (cardinal obligation), the breach of which jeopardizes the achievement of the purpose of the Agreement, and only up to the amount of the typically foreseeable damage.
(5) Insofar as the Processor acts outside or in breach of the Controller’s instructions, it is liable for the resulting damage in accordance with Art. 82 GDPR.
(6) Liability for indirect damages, consequential damages, and loss of profit is, insofar as legally permissible, limited to the typically foreseeable damage.
(1) This Agreement is governed by the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).
(2) Exclusive place of jurisdiction for all disputes arising from or in connection with this Agreement is, insofar as legally permissible, Mettmann (Germany).
(3) Should individual provisions of this Agreement be or become invalid or unenforceable, this does not affect the validity of the remaining provisions. The Parties shall replace the invalid provision with a valid one that comes closest to the economic purpose of the invalid provision.
(4) Amendments and supplements to this Agreement require written form. This also applies to the waiver of the written form clause.
(5) This Agreement is an integral part of the underlying usage agreement (AGB) between the Parties. In the event of contradictions between this Agreement and the usage agreement, the provisions of this Agreement shall prevail with regard to the processing of personal data.
(6) The assignment of rights under this Agreement requires the prior written consent of the other Party.
Processor: flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany
Controller (Customer): [Name of Customer / Company] [Address] [Email Address] [Contact Person]
The technical and organizational measures in accordance with Art. 32 GDPR and Art. 28(3)(c) GDPR are described in detail in the separate document “Technical and Organizational Measures (TOMs) – flowgeist TOOL”. This document is an integral part of this Data Processing Agreement and is hereby referenced.
The measures include in particular:
| Version | Date | Material Changes |
|---|---|---|
| 1.0 | 08.08.2026 | Initial version of the DPA for flowgeist TOOL |
Place, Date: ___________________________
Controller (Customer):
Signature
Name (printed)
Place, Date: ___________________________
Processor (flowgeist):
Signature
Name (printed)
© 2026 flowgeist – Ralf Carsjens · All rights reserved