v1.2 · 08.08.2026
As of: 08.08.2026 Version: 1.2
This Data Processing Agreement (hereinafter “DPA”) is concluded between:
Controller (Client): [Name of company / organization] [Address] [Authorized representative]
– hereinafter “Controller” –
and
Processor: flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany E-Mail: info@flowgeist.de
– hereinafter “Processor” –
The Controller engages the Processor to process personal data in the context of using the flowgeist ZERO platform. This DPA governs the rights and obligations of the parties in accordance with Art. 28 GDPR and § 62 BDSG.
Where the Controller uses the platform to fulfill its own obligations as a Processor towards third parties, it remains solely responsible for compliance with the legal requirements in this respect.
(1) The subject matter of this contract is the processing of personal data by the Processor in the context of providing and using the flowgeist ZERO platform as Software-as-a-Service (SaaS) for the Controller.
(2) The platform comprises the following Core Platform Functions:
(3) In addition, the platform comprises the AI Act Compliance Module:
(4) This contract applies for the duration of the Controller’s use of the platform. It terminates upon termination of the usage relationship, but no later than upon the complete return or Erasure of all personal data in accordance with § 3(8) of this contract.
(5) Termination of this DPA occurs jointly with the termination of the underlying usage agreement. The provisions regarding the Erasure and return of personal data remain unaffected.
(1) Categories of personal data:
| Category | Description | Examples |
|---|---|---|
| Contact data | Data for communication and account management | Name, email address, phone number (optional), company name |
| AI System data | Data on managed AI systems | Designation, classification, risk category, documentation fields |
| Training data | Data within the training module | Name, email, training progress, exam results, certificate status |
| Audit data | Logging data in accordance with ISO 27001 A.12.4 | Timestamp, User-ID, Tenant-ID, Action, Resource, IP address, User-Agent |
| Payment data | Billing-relevant data | Stripe customer ID, SEPA direct debit mandate, IBAN (stored encrypted) |
(2) Categories of data subjects:
(3) Purposes of processing:
(4) Nature of processing:
(1) The Processor processes personal data exclusively on the instructions of the Controller, unless it is obliged to process the data by Union or Member State law (Art. 28(3)(a) GDPR).
(2) The Processor ensures that persons entrusted with the processing of personal data are subject to a corresponding confidentiality obligation, unless they are already subject to a statutory confidentiality obligation.
(3) All employees and agents of the Processor who have access to personal data are instructed and obligated regarding the duty of confidentiality before commencing their activities.
(1) The Processor implements the necessary technical and organizational measures in accordance with Art. 32 GDPR to ensure a level of security appropriate to the risk for the confidentiality, integrity, availability, and resilience of processing systems.
(2) The detailed description of the technical and organizational measures is set out in the appendix “TOMs Reference” of this contract as well as in the separate TOMs document.
(3) The measures include in particular:
(1) The Processor engages the following Sub-processors:
| Sub-processor | Headquarters / Country | Service | Third country transfer | Guarantees |
|---|---|---|---|---|
| Hetzner Online GmbH | Falkenstein, Germany (DE) | Hosting, server infrastructure, backups | No third country transfer | DPA in accordance with Art. 28 GDPR |
| Stripe Payments Europe, Ltd. | Ireland (IE) / USA (US) | Payment processing | EU-US DPF + SCC | DPA in accordance with Art. 28 GDPR; DPF certification |
| Postmark / ActiveCampaign | USA (US) | Email delivery (transactional emails) | EU-US DPF + SCC | DPA in accordance with Art. 28 GDPR; DPF certification |
| Mistral AI | France (FR) | AI text generation for compliance fields | No third country transfer | DPA in accordance with Art. 28 GDPR |
| Lexware GmbH | Germany (DE) | Accounting, invoicing | No third country transfer | DPA in accordance with Art. 28 GDPR |
(2) The Processor transfers the processing of personal data to a Sub-processor only on the basis of an express or general instruction from the Controller. The Controller has consented to the inclusion of the Sub-processors listed in para. 1 upon conclusion of this contract.
(3) The Processor concludes a Data Processing Agreement with all Sub-processors in accordance with Art. 28(2)–(4) GDPR, which contains the same data protection obligations as this contract.
(4) The Processor informs the Controller of intended changes regarding the addition or replacement of Sub-processors and gives the Controller the opportunity to object to such changes.
(1) The Processor supports the Controller in fulfilling its obligations to respond to requests from data subjects exercising their rights (Art. 28(3)(e) GDPR).
(2) The Processor forwards requests from data subjects that are addressed directly to it to the Controller without delay, unless the data subject expressly requests information from the Processor.
(3) The support is provided within the scope of the technical and organizational capabilities of the platform. Where the support goes beyond the standard services, separate costs may apply, which will be coordinated with the Controller in advance.
(1) The Processor supports the Controller in conducting a Data Protection Impact Assessment in accordance with Art. 35 GDPR, insofar as this is necessary for the processing under this contract (Art. 28(3)(f) GDPR).
(2) The support includes the provision of relevant information about the processing, the technical and organizational measures, and the risks to the rights and freedoms of natural persons.
(1) The Processor notifies the Controller without delay, but no later than 24 hours after becoming aware, of any Personal data breach that may affect the Controller (Art. 28(3)(g), Art. 33 GDPR).
(2) The notification includes at least:
(3) The Processor documents every Personal data breach, including the nature of the breach, the consequences, and the remedial measures taken, in accordance with Art. 33(5) GDPR.
(4) Insofar as the breach is attributable to the Controller’s fault, the Processor may limit the notification to the information available to it.
(1) After the end of the processing, at the latest upon termination of this contract, the Processor erases all personal data processed in the course of the processing or returns them on the Controller’s instruction, unless a statutory retention obligation exists (Art. 28(3)(g), Art. 5(2) GDPR).
(2) The Erasure takes into account the following retention periods:
| Data category | Retention period | Justification |
|---|---|---|
| Contact data | 30 days after contract end | Data minimization |
| AI System data | 30 days after contract end | Data minimization |
| Training data | 30 days after contract end | Data minimization |
| Audit logs | 3 years after creation | ISO 27001 A.12.4 |
| Stripe webhook logs (with PII) | 30 days, thereafter pseudonymization | Data minimization |
| Stripe webhook logs (without PII) | 10 years | § 147 AO |
| Invoices | 10 years | § 147 AO |
(3) Before Erasure, the Processor informs the Controller in a timely manner so that the Controller can retrieve the data or issue an instruction for Erasure or return.
(4) Insofar as a statutory retention obligation exists, the data is blocked and processed exclusively for the fulfillment of statutory obligations.
(1) The Processor processes personal data exclusively on documented instructions from the Controller (Art. 28(3)(a) GDPR).
(2) Instructions may be given within the scope of the usage agreement, via platform functions, or in text form (in particular by email).
(3) The Processor informs the Controller without delay if, in its opinion, an instruction infringes legal provisions. The Processor is entitled to suspend the execution of the instruction until the Controller confirms the legality of the instruction.
(1) The retention periods referred to in § 3(7)(2) apply correspondingly to the retention of data by the Processor.
(2) The Processor ensures that proper Erasure or pseudonymization takes place after expiry of the respective retention period.
(1) The Controller is responsible for the lawfulness of the processing and bears responsibility for compliance with the requirements of the GDPR and the BDSG.
(2) The Controller ensures that the prerequisites for processing by the Processor are met, in particular that a legal basis for the processing exists and the information obligations towards data subjects in accordance with Art. 13, 14 GDPR have been fulfilled.
(3) The Controller issues instructions for the processing of personal data in a clear and documented form.
(4) The Controller is responsible for compliance with the requirements of the EU AI Act, in particular for human oversight in accordance with Art. 14 EU AI Act when reviewing AI-generated content.
(5) The Controller ensures that data subjects have been informed of their rights and that any required Consents (e.g., for the Partner Program in accordance with Art. 6(1)(a) GDPR) have been obtained.
(6) The Controller reviews and is responsible for the selection of Sub-processors engaged by the Processor and approves their inclusion.
(1) The Controller has the right to audit the Processor’s compliance with its obligations (Art. 28(3)(h) GDPR).
(2) The Processor supports the Controller with audits and inspections to a reasonable extent. This includes in particular:
(3) Audits and inspections are carried out with reasonable advance notice and with due regard to the Processor’s business operations.
(4) Insofar as audits or inspections incur travel or audit costs, these may be charged to the Controller to a reasonable extent, unless otherwise agreed.
(1) The primary processing of personal data takes place in Germany (Hetzner Online GmbH, Falkenstein data center).
(2) Any transfer of personal data to Third countries (countries outside the European Economic Area) takes place exclusively on the basis of the safeguards referred to in Art. 44 et seq. GDPR and only insofar as this is necessary for the provision of services.
(3) Transfers to Third countries are made to:
(4) For all other Sub-processors (Hetzner, Lexware, Mistral AI), processing takes place exclusively within the European Union / European Economic Area.
(5) The Processor informs the Controller of intended changes regarding transfers to Third countries and gives the Controller the opportunity to object.
(1) Liability is governed by the statutory provisions, in particular Art. 82 GDPR and § 83 BDSG.
(2) The Processor is liable to the Controller for damages arising from a breach of the obligations under this contract or the GDPR, in accordance with the statutory provisions.
(3) Insofar as the Processor acts outside the Controller’s instructions or breaches data protection provisions, it is deemed to be a Controller within the meaning of the GDPR in that respect (Art. 28(10) GDPR).
(4) Any further liability of the Processor is governed by the provisions of the underlying usage agreement and the statutory provisions.
(1) Amendments and supplements to this contract require text form. This also applies to the amendment of this clause.
(2) Should individual provisions of this contract be or become invalid or unenforceable, this does not affect the validity of the remaining provisions. The parties shall replace the invalid provision with a valid one that comes closest to the economic purpose.
(3) This contract is governed by the law of the Federal Republic of Germany.
(4) The exclusive place of jurisdiction is, insofar as legally permissible, Mettmann, Germany.
(5) This DPA is part of the underlying usage agreement between the parties.
Processor: flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany E-Mail: info@flowgeist.de Data Protection Contact: datenschutz@flowgeist.de
The following overview provides a summary of the technical and organizational measures in accordance with Art. 32 GDPR. A detailed description is contained in the separate TOMs document.
| Category | Measures |
|---|---|
| Access control | Hetzner data center Falkenstein, 24/7 security personnel, visitor logging |
| Access control | MFA/TOTP, RBAC, Least Privilege, JWT 15min + rotation, Argon2id (m=64MiB, t=3, p=4) |
| Transfer control | TLS 1.3, HSTS, Let’s Encrypt with auto-rotation |
| Input control | Audit Trail ISO 27001 A.12.4, WORM logs |
| Order control | Processing only within DPA, no transfer without authorization |
| Availability control | Daily backups 03:00 UTC, AES-256 at rest, 7 days rolling, RTO 8h, RPO 24h |
| Separation control | Multi-tenant with tenant isolation at DB level, JWT-Claims tenant-scoped |
| Encryption | AES-256 at rest, TLS 1.3 in transit |
| Pseudonymization | Email SHA-256 hash with salt in audit logs |
| Regular review | Annual TOM review, penetration tests every 24 months, vulnerability scans quarterly |
| Version | Date | Material changes |
|---|---|---|
| 1.0 | 02.05.2026 | Initial version |
| 1.1 | 23.06.2026 | Finalization |
| 1.2 | 08.08.2026 | Product-specific adaptation for flowgeist ZERO (AI Act Compliance Module) |
Place, Date
Controller (Client) Name / Function
Place, Date
Processor Ralf Carsjens / Owner, flowgeist
© 2026 flowgeist – Ralf Carsjens · All rights reserved