PersonativPersonativ

Data Processing Agreement (DPA)

Version 2 · August 3, 2026

Data Processing Agreement (Art. 28 GDPR) 1. Subject matter and basis This Data Processing Agreement (DPA) specifies the obligations of the parties under Art. 28 GDPR. It applies to the processing of personal data that the processor (FHC+P GmbH, Würmstraße 55, 82166 Gräfelfing) carries out on behalf of the controller (customer/user of the Personativ service) in the course of using the service. 2. Subject matter, nature, purpose and duration Subject matter/purpose: capture, preparation, scheduling and publication of content via connected channels as well as the associated account, customer and billing administration. Nature: collecting, storing, altering, retrieving, transmitting (to channels and service providers selected by the user), erasing. Duration: for the term of the usage relationship; thereafter in accordance with Section 7. 3. Type of data and categories of data subjects Types of data: master data (company/name, address, VAT ID/tax number, contact details), the user's account/access data, content created by the user (texts, images, videos) including the personal data contained therein, connection data to connected channels (access tokens) as well as billing data. Data subjects: employees and contact persons of the controller as well as persons named or depicted in the content, and recipients. 4. Bound by instructions The processor processes the data exclusively on the documented instructions of the controller (including the entries and publications made via the application), unless it is legally obliged to process. If it considers an instruction to be unlawful, it informs the controller. Instructions may be given in writing, in text form or through documented configurations in the application. The processor archives all instructions for the duration of the contractual relationship and makes them available to the controller on request. 5. Confidentiality Persons involved in the processing are obliged to maintain confidentiality and are instructed accordingly (Art. 28(3)(b), Art. 29, Art. 32(4) GDPR). 6. Technical and organisational measures (Art. 32 GDPR) - Transport encryption: TLS/HTTPS for all connections; HSTS. - Encryption of sensitive data at rest: access tokens and AI keys are stored encrypted with AES-256-GCM; passwords exclusively as a cryptographic hash. - Access/authorisation control: personal accounts, role and admin separation, allocation of rights according to the principle of least privilege. - Tenant separation: account-based data separation at database level (row-level security); customer data is isolated per account. - Physical access control: operation takes place in a data centre within the EU; physical access control is the responsibility of the hosting service provider (see section 8). - Availability, recoverability and emergency management: regular, integrity-checked backups as well as documented recovery procedures. - Security review: automated scanning of the application for exposed access credentials as well as for known vulnerabilities in the components used as part of the delivery process. - Logging: security-relevant events; error/access logs. - Data minimisation: no special categories (Art. 9 GDPR) are collected. 7. Erasure and return Upon completion of the service, the processor erases the data or returns it (at the controller's choice), unless statutory retention obligations preclude this. The export of content and invoices is possible. 8. Sub-processors The controller authorises the use of the following sub-processors: Hostinger International Ltd, hosting / data centre, Germany (EU). Stripe Payments Europe, Ltd., payment processing, EU/Ireland. AI providers (only when the AI function is activated, depending on the selected provider, e.g. OpenAI, Anthropic, OpenRouter, Mistral), AI-supported text/image preparation, EU or third country (including the USA). A change of a sub-processor will be notified to the controller at least 30 days before the planned change. The controller may object to the change in text form within 14 days of notification if facts justify the assumption that the new sub-processor does not meet the requirements demanded by Art. 28 GDPR. For the transfer of personal data to sub-processors in third countries (in particular OpenRouter, Inc. in the USA), the Standard Contractual Clauses issued by the European Commission are agreed. Prior to the first transfer, the processor carries out a Transfer Impact Assessment and takes the necessary supplementary technical and organisational measures to ensure a level of protection that meets the requirements of the GDPR. The results are made available to the controller on request. Publication on social networks and web destinations takes place on the controller's instructions to the platforms selected by them; these are separate controllers in this respect. 9. Support, data subject rights, data breaches The processor supports the controller, to the extent possible, in fulfilling data subject rights (Art. 12 to 23) as well as in obligations under Art. 32 to 36. It reports personal data breaches without undue delay after becoming aware of them. 10. Evidence and audits The processor makes available the information necessary for compliance and enables reasonable audits (Art. 28(3)(h)). 11. Final provisions German law applies. Should individual provisions be invalid, the remainder of the agreement shall remain valid.