Data Processing

Data Processing Agreement (DPA)

Agreement on the processing of personal data pursuant to Art. 28 GDPR. It supplements the T&C as a binding annex and applies to any processing of personal data on behalf of the Customer via the Begehung.pro platform.

Version 1.1, as of August 2026


This Data Processing Agreement ("DPA") specifies the data protection obligations between the parties insofar as the Provider processes personal data on behalf of the Customer in connection with the Begehung.pro platform.

§ 1 Subject Matter and Contractual Relationship

(1) This DPA supplements the main contract concluded between the parties for the use of the platform (see Terms & Conditions) with respect to the processing of personal data. In the event of conflicts between this DPA and the main contract, this DPA prevails on data protection matters.

(2) "Controller" within the meaning of this DPA is the Customer named in the main contract. "Processor" is the Provider named in the main contract (Tobias Boehm Softwareentwicklung).

(3) This DPA enters into force upon conclusion of the main contract and the first processing of personal data via the platform, but no later than upon the Controller's express consent in text form.

§ 2 Definitions

The definitions set out in Art. 4 GDPR apply, in particular for "personal data", "processing", "controller", "processor", "data subject", "supervisory authority", and "personal data breach". In addition: "Platform" means the SaaS offering Begehung.pro described in the main contract; "Subprocessor" means any further processor within the meaning of Art. 28 paragraph 4 GDPR; "TOM" means technical and organizational measures within the meaning of Art. 32 GDPR.

§ 3 Subject, Duration, Nature and Purpose of Processing

(1) Subject: The provision of the SaaS services agreed in the main contract, including the capture, storage, and analysis of inspection data as well as the AI-supported ingestion of uploaded import documents and the AI-supported text suggestions on note and comment fields.

(2) Duration: Processing takes place for the term of the main contract plus the period for data return and deletion pursuant to § 11.

(3) Nature of processing: collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, making available, alignment or combination, restriction, erasure, and destruction.

(4) Purpose: digital execution and documentation of inspections, AI-supported ingestion of uploaded import documents, AI-supported text suggestions on note and comment fields, and provision of the related functions (mobile app, web app, export) in accordance with the main contract.

(5) Categories of personal data: master data of the Controller's staff (name, role, contact), image and audio recordings from inspection situations (with possibly identifiable persons), location data, notes with personal references, and – in individual cases – special categories of personal data within the meaning of Art. 9 GDPR (e.g., health data in accident documentation). Categories of data subjects: the Controller's staff, staff of contractors or third-party companies, visitors, tenants, and other persons present on the inspected premises.

§ 4 Controller's Right to Issue Instructions

(1) The Processor processes personal data exclusively on documented instructions of the Controller, including with regard to transfers to third countries.

(2) The initial instruction is the processing in accordance with the main contract and § 3 of this DPA.

(3) Subsequent individual instructions must be issued in text form (an email to datenschutz@begehung.pro is sufficient). Oral instructions must be confirmed in text form without undue delay.

(4) If the Processor considers an instruction to be unlawful, it shall inform the Controller without undue delay; pending clarification, it may suspend the processing in question.

(5) The Processor uses AI methods exclusively as a tool to provide the services commissioned by the Controller. Any further use of the data – in particular for training, fine-tuning, or permanent improvement of the Processor's own or third-party AI models – does not take place.

§ 5 Subcontractors (Subprocessors)

(1) The Controller generally consents to the engagement of further processors (subprocessors) in accordance with Art. 28 paragraph 2 sentence 2 GDPR.

(2) The current list of engaged subprocessors is available at this overview and forms part of this DPA as Annex 1.

(3) The Processor will notify the Controller of intended changes to the subprocessors at least four weeks before they take effect, in text form. The Controller may object to the change in text form within four weeks of receipt for a legitimate reason (in particular GDPR concerns).

(4) In the event of a justified objection, the subprocessor in question will not be engaged. If this is not reasonable for the Processor, either party is entitled to terminate the main contract for cause as of the effective date of the change.

(5) The Processor binds each subprocessor in writing or electronic form to data protection obligations equivalent to those set out in this DPA. Where such an agreement with a subprocessor listed in Annex 1 is still outstanding, this is marked as planned in Annex 2. The Processor is liable for the conduct of its subprocessors as for its own (Art. 28 paragraph 4 sentence 2 GDPR).

(6) Pure telecommunications, postal, and logistics services and other ancillary services that do not constitute the actual data processing are not considered subprocessors within the meaning of this DPA.

§ 6 Confidentiality

(1) The Processor binds all persons involved in the processing in writing to confidentiality, unless they are already subject to an appropriate statutory duty of confidentiality.

(2) The confidentiality obligation continues to apply beyond the end of the employment or working relationship.

(3) Upon request of the Controller, the Processor demonstrates the existence of these obligations in a suitable form, e.g., by submitting a sample declaration.

§ 7 Technical and Organizational Measures

(1) The Processor implements the technical and organizational measures (TOM) set out as in place in Annex 2 and keeps them up to the state of the art. The measures marked there as planned will be implemented prior to the conclusion of productive contracts.

(2) The Processor will notify the Controller in good time, in text form, of material changes to the TOM that might reduce the level of protection.

(3) The TOM pursue the protection objectives under Art. 32 GDPR: confidentiality, integrity, availability, and resilience of the systems, as well as the ability to restore quickly and a procedure for regular review. Which measures are in place today and which are planned is set out per objective in Annex 2.

§ 8 Assistance to the Controller

(1) The Processor forwards requests from data subjects (Art. 15 to 22 GDPR) to the Controller without undue delay and does not respond to them on its own authority.

(2) The Processor supports the Controller in fulfilling its obligations under Art. 12 to 22 GDPR through suitable technical and organizational measures, insofar as this is possible within the scope of the processing on behalf.

(3) The Processor further supports the Controller in carrying out data protection impact assessments (Art. 35 GDPR) and, where applicable, in prior consultations with the supervisory authority (Art. 36 GDPR), by providing the necessary information on the TOM and the engaged subprocessors.

(4) Insofar as the support effort goes beyond the provision of standard information, the Processor is entitled to charge reasonable remuneration based on time and effort; the Processor will inform the Controller in advance of activities likely to be subject to remuneration.

§ 9 Notification of Personal Data Breaches

(1) Upon becoming aware of a personal data breach within the meaning of Art. 4 No. 12 GDPR, the Processor will inform the Controller without undue delay – at the latest within 24 hours of becoming aware – in text form.

(2) The notification contains the information required by Art. 33 paragraph 3 GDPR (description of the incident, affected categories of data, likely consequences, measures taken and planned), to the extent available at the time of notification. Further findings are reported subsequently without undue delay.

(3) The obligation to notify the supervisory authority pursuant to Art. 33 paragraph 1 GDPR and to inform data subjects pursuant to Art. 34 GDPR rests with the Controller; the Processor supports by providing all information required for this purpose.

§ 10 Inspection and Audit Rights

(1) The Controller may verify the Processor's compliance with its contractual and statutory obligations.

(2) The primary means of evidence is an annually updated self-assessment by the Processor describing the TOM and, where available, certificates or audit reports from independent auditors (e.g., ISO 27001, BSI C5, SOC 2).

(3) An on-site inspection is permissible only if the evidence under paragraph 2 is insufficient. It must be announced with at least 30 days' notice, conducted with due regard for the Processor's business operations, and – to protect business secrets and the data of other customers – carried out by an independent auditor named by the Processor and bound to confidentiality.

(4) The Processor bears the costs of the initial self-assessment. The Controller bears the costs of additional audits unless a material breach by the Processor is confirmed.

§ 11 Return and Deletion of Data

(1) After the processing has ended, the Controller has the choice between return or deletion of the personal data (Art. 28 paragraph 3 lit. g GDPR).

(2) The choice must be communicated in text form within 90 days of the end of the contract. If no express choice is made, the Processor will delete the data after expiry of this period.

(3) Return takes place in a standardized, machine-readable format (PDF, DOCX, ZIP). Special formats may be provided by separate agreement at reasonable cost.

(4) Upon request, the Processor provides written confirmation of deletion.

(5) Insofar as statutory retention obligations preclude deletion, the affected data will be processed only on a restricted basis (blocked) and deleted after the retention obligations expire.

(6) Data in regular backups is overwritten in the course of the normal backup cycle; immediate deletion from backups is technically not reasonable. Such backup data is not reused.

(7) Paragraphs 1 to 6 do not cover the operational records of AI calls. They contain neither the prompt nor the content of the processed document nor the model’s response, but they carry user and tenant IDs and are retained indefinitely for cost and operations control.

§ 12 Liability

(1) The liability provisions of the T&C (§ 12) apply, including the clarification regarding GDPR fines in cases of intent or gross negligence arising from breaches of this DPA (§ 12 paragraph 6 T&C).

(2) The joint and several liability towards data subjects under Art. 82 GDPR is governed by the statutory provisions.

(3) The Processor maintains appropriate professional or commercial liability insurance. Key coverage details will be communicated upon request.

§ 13 Third-Country Transfers

(1) Personal data is processed exclusively within the European Union or the European Economic Area; the relevant list is set out in Annex 1. Most of the engaged subprocessors are themselves established outside the European Union; the one provider established in the EU belongs to a parent company outside the EU. Access from a third country is not agreed; should a transfer nevertheless become necessary in an individual case, paragraph 2 applies.

(2) Should a third-country transfer become necessary in an individual case, it will only take place on the basis of an EU Commission adequacy decision (Art. 45 GDPR), alternatively on the basis of EU Standard Contractual Clauses (Art. 46 paragraph 2 lit. c GDPR), if necessary supplemented by additional technical, organizational, or contractual measures in line with the requirements of the Schrems II case law.

(3) Third-country transfers are announced in advance in accordance with the rules of § 5; the Controller's right of objection applies accordingly.

§ 14 Final Provisions

(1) Amendments and supplements to this DPA must be in text form. This also applies to the cancellation of this text-form clause.

(2) Should individual provisions of this DPA be or become invalid or unenforceable, the validity of the remaining provisions shall not be affected. The invalid provision shall be replaced by a provision that comes closest to the economic purpose of the invalid one.

(3) The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods (CISG). The exclusive place of jurisdiction is – to the extent legally permissible – the Processor's place of business.

(4) On all data protection matters, this DPA prevails over the provisions of the main contract.

(5) The German-language version of this DPA is authoritative. Translations are provided for ease of understanding only.


Annex 1: List of Subprocessors

This annex lists all subprocessors engaged by the Processor, including their registered office, processing purpose, and processing location. It is updated on a continuous basis; changes are announced in accordance with § 5.

The current version is available at the subprocessors overview and forms part of this DPA.

Annex 2: Technical and Organizational Measures (TOM)

The following technical and organizational measures serve a level of protection appropriate to the risk within the meaning of Art. 32 GDPR and are kept up to the state of the art. Measures that have not yet been implemented are explicitly marked as "planned"; the appropriate level of protection is only fully reached once they are in place.

  • Confidentiality

    Physical access control (the Processor operates no data center of its own; the systems run exclusively at the providers listed in Annex 1); logical access control (two-factor authentication on all administrative accounts); use control (encryption-at-rest of databases; private storage buckets with permission checks at path level); separation control (logical multi-tenancy via row-level security on the tenant ID, separated test and production environments); encryption in transit (TLS 1.2 or higher) and at rest (AES-256). Planned: a graduated role and permission model within a tenant, and a documented physical access policy for the Processor’s own business premises.

  • Integrity

    Transmission and transport control via mandatory TLS connections, no unencrypted HTTP. Planned: input control through tamper-evident audit logs of security-relevant actions (creation, modification, deletion, and export of inspections and reports).

  • Availability and Resilience

    Daily backups with 30 days of retention; hosting in the EU; availability target as defined in § 4 paragraph 1 of the T&C. Planned: annual restore test and operation across redundant availability zones.

  • Recoverability

    In place is the daily backup described under Availability and Resilience. Planned: a defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO) of no more than 24 hours each, as well as documented recovery procedures.

  • Procedures for Regular Review

    Planned: annual review of the technical and organizational measures; penetration tests prior to productive roll-out and after material architectural changes; continuous vulnerability scans (at least monthly); annual employee training on data protection and information security.

  • Processor Control (Subprocessors)

    Careful selection of subprocessors based on their commitments regarding processing location, encryption, and retention; maintenance of the register in Annex 1. Planned: conclusion of written processing agreements with every subprocessor, obligation to apply equivalent protective measures, and regular review of compliance.

While the platform is in a public beta or pre-launch phase, the measures marked as planned are an intended target state. They will be implemented prior to the conclusion of productive contracts and documented in an updated version of this annex.