Skip to content

Artificial intelligence is changing digital products. See what it can do for your business.

Art. 28 DSGVO · Version 24.08.2026

Data Processing Agreement

Convenience translation. The German version is authoritative. This agreement becomes part of the hosting contract where processing on behalf applies.

1. Parties and subject

The controller is the customer identified in the hosting order. The processor is Dominik Weber, SimplifyVision, Jöllenbecker Str. 143, 33613 Bielefeld, Germany. The subject is provision and technical management of the agreed server and application environment. Schedule 1 defines processing details.

2. Duration

Processing begins with provisioning and ends with the hosting contract, subject to statutory retention and technically required deletion periods.

3. Instructions

SimplifyVision processes personal data only on documented customer instructions, including international transfers, unless law requires otherwise. The order, service description and written follow-up instructions constitute instructions. Where law requires processing, the customer is informed beforehand unless prohibited for important public-interest reasons. SimplifyVision informs the customer if an instruction appears unlawful and may suspend it pending clarification.

4. Processor duties

  • Confidentiality of all authorized persons
  • Appropriate technical and organizational measures under GDPR Art. 32 and Schedule 2
  • Reasonable support for data-subject rights and the customer’s duties under GDPR Arts. 32–36
  • Prompt notice of personal-data breaches to the designated customer contact with available information
  • Required records and compliance evidence

5. Customer duties

The customer remains responsible for lawfulness, transparency, minimization, deletion and instructions. It grants only required access and reports changes in risk or data sensitivity.

6. Subprocessors

The customer grants general written authorization and specifically authorizes netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany, for data-center, network and server infrastructure in Nuremberg. SimplifyVision provides at least 14 days’ notice and sufficient information before adding or replacing a subprocessor. The customer may object for material data-protection reasons. The parties then seek a reasonable alternative; if none is available, the affected service may be terminated for cause. Equivalent obligations apply, SimplifyVision remains responsible, and a suitably redacted copy of relevant data-protection terms is supplied on request.

7. International transfers

Core infrastructure is operated in Germany. Third-country transfers occur only on documented instruction or under a valid transfer mechanism with customer notice.

8. Audit

SimplifyVision supplies suitable compliance information and enables required audits, including inspections. Audits normally require reasonable notice and business-hours scheduling while protecting other customers; shorter notice is allowed after a relevant incident or where a material breach is reasonably suspected. Only demonstrable extra effort for repeated or non-cause audits may be charged after prior agreement.

9. Return and deletion

At contract end, customer data and copies are returned or deleted as chosen unless law requires retention. Rolling backups are overwritten no later than seven days after production deletion. Deletion is confirmed on request.

Schedule 1 – Processing

Purpose: hosting, storage, delivery, backup, monitoring, troubleshooting and agreed application care.

Nature: storage, transmission, delivery, backup, restoration, logging, restriction and deletion.

Data: master, contact, contract, content, usage, communication, log and access data. Special-category data under GDPR Art. 9 is processed only under a separate documented agreement and defined safeguards.

Subjects: customer staff, customers, prospects, suppliers, website and application users.

Schedule 2 – Security measures

  • Data-center physical protection by netcup
  • Individual admin access, strong passwords, SSH keys and MFA where available
  • Least privilege, roles and separated customer environments
  • TLS and encrypted administration
  • Monitoring, updates, encrypted daily backups and restore processes
  • Administrative logging where technically appropriate
  • Incident process and periodic review