Digital RelaxMunich
Preparing website experience
Digital Relax logo lower section

Modern websites, clear systems and digital workflows for small businesses in Munich and the surrounding area.

AuditDesignLaunch
Web DesignAutomation / Support
Digital Relax Logo

ARTICLE 28 GDPR / DIGITAL RELAX

Data Processing Agreement

This standard DPA becomes part of a customer contract only where the specific offer or order provides for processing on behalf and expressly incorporates the DPA. Project-specific information is defined in the respective offer or annex. This English translation is provided for convenience; unless expressly agreed otherwise, the German version is authoritative.

Version 1.3 – 11.08.2026

1. Scope and Parties

This DPA supplements the contract between the relevant business customer as controller and Digital Relax as processor where and to the extent Digital Relax processes personal data on behalf of the customer within the meaning of Article 28 GDPR.

The DPA applies only to processing activities identified as processing on behalf in the customer order or project-specific specification. Where Digital Relax acts as controller for a processing activity, this DPA does not apply to that activity.

2. Subject Matter, Duration, Nature and Purpose

The subject matter, duration, nature and purpose of the specific processing are defined in the customer order and project-specific specification. Typical processing on behalf may concern the technical provision of a contact form, appointment management, lead or enquiry management, or agreed email automations.

Before processing begins, at least the relevant systems, processing purposes, categories of personal data and categories of data subjects are defined.

The processing specification also expressly states whether special categories of personal data under Article 9 GDPR are processed. It must record either ‘none’ or ‘yes, the following categories: …’; where such data is processed, the additional safeguards are also documented.

3. Instructions of the Controller

Digital Relax processes personal data only on documented instructions from the customer, including with regard to transfers of personal data to a third country or an international organisation. Where Digital Relax is required by Union or Member State law to process data differently, Digital Relax informs the customer of that legal requirement before processing unless the relevant law prohibits such information on important grounds of public interest. If Digital Relax considers an instruction to infringe data-protection law, Digital Relax informs the customer without undue delay and may suspend the relevant execution until the matter is clarified.

Duties and rights of the controller. The customer remains responsible for the lawfulness of the processing, in particular for legal bases, information duties and the permissibility of its instructions. The customer may issue documented instructions, obtain or arrange verification of compliance with this DPA in accordance with the agreed audit provisions, and choose between return and deletion of the processed data at the end of processing.

4. Confidentiality and Access

Digital Relax ensures that persons who obtain access to personal data processed on behalf are bound by confidentiality or an appropriate statutory duty of secrecy and receive access only to the extent required.

5. Technical and Organisational Measures

Taking into account the nature, scope, context and purposes of processing and the risks, Digital Relax implements appropriate technical and organisational measures in accordance with Article 32 GDPR.

The standard measures intended at the time the contract is concluded are documented in the TOM annex. Project-specific deviations or additional measures are recorded there or in the project specification. Digital Relax may further develop the measures provided the agreed level of protection is not reduced.

6. Sub-processors

The customer grants Digital Relax general authorisation to engage additional processors where they are actually used for the specific project. The providers intended at the time the contract is concluded are listed for the project.

Digital Relax informs the customer in an appropriate manner before each intended addition or replacement of another processor and gives the customer an opportunity to object to those changes.

Digital Relax imposes on each additional processor, by contract or another permissible legal instrument, the same data-protection obligations to the extent required for the relevant processing. If an additional processor fails to fulfil its data-protection obligations, Digital Relax remains responsible to the customer for the performance of that additional processor's obligations in accordance with Article 28(4) GDPR.

7. Assistance with Data-Subject Rights

Taking into account the nature of the processing and the information available, Digital Relax reasonably assists the customer in fulfilling requests from data subjects. If a request is received directly by Digital Relax and concerns data processed solely on behalf of the customer, Digital Relax forwards the request to the customer to the extent legally permissible.

8. Personal Data Breaches and Further Assistance

Digital Relax informs the customer without undue delay after becoming aware of a personal data breach insofar as it affects processing on behalf of the customer and provides the available information required by the customer for its statutory assessment and notification duties.

Digital Relax reasonably assists the customer with obligations under Articles 32 to 36 GDPR to the extent permitted by the nature of the processing and the information available to Digital Relax.

9. Evidence and Audits

Digital Relax provides the customer, to a reasonable extent, with the information necessary to demonstrate compliance with Article 28 GDPR and permits audits required by law. Audits are carried out with reasonable advance notice, while protecting trade secrets and, as far as possible, without unreasonable disruption to business operations.

Existing suitable audit reports, certifications, technical documentation or evidence from sub-processors may be used as a priority where they are sufficient for the audit purpose.

10. Return and Deletion at the End of Processing

After completion of the agreed processing on behalf, Digital Relax, at the customer's choice, deletes all personal data processed on behalf or returns it to the customer and deletes existing copies unless statutory law requires continued storage. Where technically unavoidable backup copies cannot be selectively deleted immediately, they are not processed for other purposes until deletion in the regular backup or overwrite cycle and are retained only to the extent required for that purpose.

This data-protection obligation to return or delete data is distinct from any additional technical migration, data conversion or individual handover service.

11. International Transfers

Where sub-processors or infrastructure outside the EU or EEA are used in processing on behalf, Digital Relax ensures that the relevant transfer has a lawful basis under Chapter V GDPR. The applicable basis depends on the provider, processing activity and current legal framework.

12. Order of Precedence and Amendments

In the event of conflicts between this DPA and the General Terms and Conditions or other general contractual provisions, the more specific provisions of this DPA take precedence for matters of processing on behalf. Project-specific information in the customer order specifies the DPA in greater detail.

Changes affecting obligations under Article 28 GDPR are documented in text form.

Project-specific processing specification

The following information becomes contractual only where the DPA is incorporated into the specific customer order. It is completed for the project in the offer or an annex.

Subject matter of processing
[___]
Duration
[for the duration of the relevant service / ___]
Nature and purpose
[___]
Categories of data
[___]
Special categories under Article 9 GDPR
☐ none    ☐ yes, the following: [___]
Additional safeguards
[___]
Categories of data subjects
[___]
Specific instructions
[___]

Technical and organisational measures (TOM)

Standard measures of Digital Relax · updated 10.08.2026. Project-specific deviations or higher requirements are documented in the customer order.

Access Control

Administrative areas and operational customer data are made accessible only to authorised persons. Access takes place through personal or uniquely attributable accounts or protected sessions. Permissions are limited to the extent required for the relevant task.

Authentication

Strong credentials and additional protection mechanisms supported by the relevant service, such as OTP or multi-factor authentication, are used for administrative access where they are configured for the respective account.

Encryption in Transit

Web and API connections are transmitted via HTTPS/TLS where the platform used provides this technically. Unencrypted public transmission of personal form data is not intended.

Secrets and Keys

API keys, tokens and administrative secrets are not stored as publicly visible website content. Where possible, they are managed in protected environment variables or secret stores of the platforms used.

Permissions and Tenant Separation

Public website content is separated from operational data. Administrative functions and customer data are processed through protected backend or admin access. Project-specific permissions are granted only where required.

Logging

Security-relevant technical events, offer acceptances and administrative activities are logged where available and required in the relevant system. Logs are not used as a substitute for complete copies of all personal data content.

Data Minimisation

Forms and operational workflows are intended to collect only the data required for the respective purpose. Unnecessary mandatory fields are avoided, and public website content is managed separately from operational personal data.

Deletion and Retention

Deletion and retention periods are defined for the relevant project or system and implemented according to the technical and organisational capabilities actually available. At the end of processing on behalf, data is returned or deleted in accordance with the customer's instruction and the DPA unless a statutory retention obligation applies.

Backups and Availability

Hosting, databases and email infrastructure predominantly use cloud services together with their respective availability, redundancy and backup mechanisms. A specific RTO, RPO or individual backup level is owed only where expressly agreed in the customer order.

Updates and Vulnerabilities

Where ongoing maintenance is agreed, security-relevant notices and available updates for the components actually maintained are reviewed at reasonable intervals or when an event warrants it. Whether and when an update is deployed depends on relevance, compatibility, the agreed maintenance scope and the technical influence available. Third-party updates may partly lie outside Digital Relax's direct control.

Incident Process

When a security incident is identified, affected access points or systems are secured where possible, the circumstances are documented and the effects are assessed. Where the incident concerns processing on behalf, the controller is informed without undue delay in accordance with the DPA.

Development and Testing

Testing and development work is carried out, where practicable, without unnecessary production personal data. Production credentials are not intentionally included in publicly accessible source code or documentation.

Physical Security

The physical security of data-centre infrastructure is provided by the respective infrastructure and hosting providers used for cloud services.

Intended sub-processors

The following providers are prepared as a technical baseline. For each customer, only providers actually used in the specific project are relevant. Before inclusion, the provider, role and, where required, the relevant plan or contract and DPA coverage are verified for the project.

Vercel Inc.

Purpose
Hosting, provision and technical delivery of web applications
Processing
USA / international infrastructure
Note
Only where actually used in the specific customer project. Before project-specific inclusion, the legal entity, data-protection role, the specific plan or contract used and the required DPA coverage are verified.

Convex, Inc.

Purpose
Database and backend processing for agreed operational functions
Processing
USA / international infrastructure
Note
Only where actually used in the specific customer project. Before project-specific inclusion, the legal entity, data-protection role and applicable data-protection terms are verified.

Plus Five Five, Inc. (Resend)

Purpose
Technical email delivery and delivery information
Processing
USA / international infrastructure
Note
Only where actually used in the specific customer project. Before project-specific inclusion, the legal entity, data-protection role and applicable data-protection terms are verified.