This is a non-binding English translation for convenience. The German version is the only legally binding one. German version
Data Processing Agreement (DPA)
Data Processing Agreement (Art. 28 GDPR)
1. Subject matter and basis
This Data Processing Agreement (DPA) specifies the obligations of the parties under Art. 28 GDPR. It applies to the processing of personal data that the processor (FHC+P GmbH, Würmstraße 55, 82166 Gräfelfing) carries out on behalf of the controller (customer/user of the Personativ service) in the course of using the service.
2. Subject matter, nature, purpose and duration
Subject matter/purpose: capture, preparation, scheduling and publication of content via connected channels as well as the associated account, customer and billing administration. Nature: collecting, storing, altering, retrieving, transmitting (to channels and service providers selected by the user), erasing. Duration: for the term of the usage relationship; thereafter in accordance with Section 7.
3. Type of data and categories of data subjects
Types of data: master data (company/name, address, VAT ID/tax number, contact details), the user's account/access data, content created by the user (texts, images, videos) including the personal data contained therein, connection data to connected channels (access tokens) as well as billing data. Data subjects: employees and contact persons of the controller as well as persons named or depicted in the content, and recipients.
4. Bound by instructions
The processor processes the data exclusively on the documented instructions of the controller (including the entries and publications made via the application), unless it is legally obliged to process. If it considers an instruction to be unlawful, it informs the controller. Instructions may be given in writing, in text form or through documented configurations in the application. The processor archives all instructions for the duration of the contractual relationship and makes them available to the controller on request.
5. Confidentiality
Persons involved in the processing are obliged to maintain confidentiality and are instructed accordingly (Art. 28(3)(b), Art. 29, Art. 32(4) GDPR).
6. Technical and organisational measures (Art. 32 GDPR)
- Transport encryption: TLS/HTTPS for all connections; HSTS.
- Encryption of sensitive data at rest: access tokens and AI keys are stored encrypted with AES-256-GCM; passwords exclusively as a cryptographic hash.
- Access/authorisation control: personal accounts, role and admin separation, allocation of rights according to the principle of least privilege.
- Tenant separation: account-based data separation at database level (row-level security); customer data is isolated per account.
- Physical access control: operation takes place in a data centre within the EU; physical access control is the responsibility of the hosting service provider (see section 8).
- Availability, recoverability and emergency management: regular, integrity-checked backups as well as documented recovery procedures.
- Security review: automated scanning of the application for exposed access credentials as well as for known vulnerabilities in the components used as part of the delivery process.
- Logging: security-relevant events; error/access logs.
- Data minimisation: no special categories (Art. 9 GDPR) are collected.
7. Erasure and return
Upon completion of the service, the processor erases the data or returns it (at the controller's choice), unless statutory retention obligations preclude this. The export of content and invoices is possible.
8. Sub-processors
The controller authorises the use of the following sub-processors:
Hostinger International Ltd, hosting / data centre, Germany (EU).
Stripe Payments Europe, Ltd., payment processing, EU/Ireland.
AI providers (only when the AI function is activated, depending on the selected provider, e.g. OpenAI, Anthropic, OpenRouter, Mistral), AI-supported text/image preparation, EU or third country (including the USA).
A change of a sub-processor will be notified to the controller at least 30 days before the planned change. The controller may object to the change in text form within 14 days of notification if facts justify the assumption that the new sub-processor does not meet the requirements demanded by Art. 28 GDPR.
For the transfer of personal data to sub-processors in third countries (in particular OpenRouter, Inc. in the USA), the Standard Contractual Clauses issued by the European Commission are agreed. Prior to the first transfer, the processor carries out a Transfer Impact Assessment and takes the necessary supplementary technical and organisational measures to ensure a level of protection that meets the requirements of the GDPR. The results are made available to the controller on request.
Publication on social networks and web destinations takes place on the controller's instructions to the platforms selected by them; these are separate controllers in this respect.
9. Support, data subject rights, data breaches
The processor supports the controller, to the extent possible, in fulfilling data subject rights (Art. 12 to 23) as well as in obligations under Art. 32 to 36. It reports personal data breaches without undue delay after becoming aware of them.
10. Evidence and audits
The processor makes available the information necessary for compliance and enables reasonable audits (Art. 28(3)(h)).
11. Final provisions
German law applies. Should individual provisions be invalid, the remainder of the agreement shall remain valid.
