Art. 28 DSGVO · Version 24.08.2026
Data Processing Agreement
Convenience translation. The German version is authoritative. This agreement becomes part of the hosting contract where processing on behalf applies.
1. Parties and subject
The controller is the customer identified in the hosting order. The processor is Dominik Weber, SimplifyVision, Jöllenbecker Str. 143, 33613 Bielefeld, Germany. The subject is provision and technical management of the agreed server and application environment. Schedule 1 defines processing details.
2. Duration
Processing begins with provisioning and ends with the hosting contract, subject to statutory retention and technically required deletion periods.
3. Instructions
SimplifyVision processes personal data only on documented customer instructions, including international transfers, unless law requires otherwise. The order, service description and written follow-up instructions constitute instructions. Where law requires processing, the customer is informed beforehand unless prohibited for important public-interest reasons. SimplifyVision informs the customer if an instruction appears unlawful and may suspend it pending clarification.
4. Processor duties
- Confidentiality of all authorized persons
- Appropriate technical and organizational measures under GDPR Art. 32 and Schedule 2
- Reasonable support for data-subject rights and the customer’s duties under GDPR Arts. 32–36
- Prompt notice of personal-data breaches to the designated customer contact with available information
- Required records and compliance evidence
5. Customer duties
The customer remains responsible for lawfulness, transparency, minimization, deletion and instructions. It grants only required access and reports changes in risk or data sensitivity.
6. Subprocessors
The customer grants general written authorization and specifically authorizes netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany, for data-center, network and server infrastructure in Nuremberg. SimplifyVision provides at least 14 days’ notice and sufficient information before adding or replacing a subprocessor. The customer may object for material data-protection reasons. The parties then seek a reasonable alternative; if none is available, the affected service may be terminated for cause. Equivalent obligations apply, SimplifyVision remains responsible, and a suitably redacted copy of relevant data-protection terms is supplied on request.
7. International transfers
Core infrastructure is operated in Germany. Third-country transfers occur only on documented instruction or under a valid transfer mechanism with customer notice.
8. Audit
SimplifyVision supplies suitable compliance information and enables required audits, including inspections. Audits normally require reasonable notice and business-hours scheduling while protecting other customers; shorter notice is allowed after a relevant incident or where a material breach is reasonably suspected. Only demonstrable extra effort for repeated or non-cause audits may be charged after prior agreement.
9. Return and deletion
At contract end, customer data and copies are returned or deleted as chosen unless law requires retention. Rolling backups are overwritten no later than seven days after production deletion. Deletion is confirmed on request.
Schedule 1 – Processing
Purpose: hosting, storage, delivery, backup, monitoring, troubleshooting and agreed application care.
Nature: storage, transmission, delivery, backup, restoration, logging, restriction and deletion.
Data: master, contact, contract, content, usage, communication, log and access data. Special-category data under GDPR Art. 9 is processed only under a separate documented agreement and defined safeguards.
Subjects: customer staff, customers, prospects, suppliers, website and application users.
Schedule 2 – Security measures
- Data-center physical protection by netcup
- Individual admin access, strong passwords, SSH keys and MFA where available
- Least privilege, roles and separated customer environments
- TLS and encrypted administration
- Monitoring, updates, encrypted daily backups and restore processes
- Administrative logging where technically appropriate
- Incident process and periodic review