Data Formats and Switching Providers
Information pursuant to Art. 26 and Art. 28 of Regulation (EU) 2023/2854 (Data Act) on switching providers and porting the Customer's data.
Version 1 · Last updated: September 2026
This page supplements § 8 paragraphs 7 to 9 and § 10 of the T&C. It describes how the Customer retrieves its data, switches to another provider, or ports the data to its own IT infrastructure, in which formats the data are available, and which limitations are known. Under § 2 paragraph 4 (f) of the T&C, the switching rules do not apply to the free trial run; customers in the trial run can still use the return of data.
1. Procedure
Retrieval during the contract term: users with the role "owner" or "admin" prepare an archive in the "Data return" section of the web app profile and then download it. The archive reflects the state at the moment "Prepare" is clicked. Once it is ready, the application reports this in the notification list and by email. A finished archive can be downloaded for 30 days; a new archive can be prepared at any time.
Switching, porting, or erasure: the Customer sends its request in text form to kontakt@begehung.pro and states whether it wishes to switch to another provider, port the data to its own IT infrastructure, or have them erased; for a switch, it states the required details of the new provider. After the notice period of two months, shorter at the Customer's request, the transitional period of at most 30 calendar days begins. The Customer can extend it once; if it is technically unfeasible, the Provider says so within 14 working days and names an alternative period of at most seven months. During this time the Platform continues to run unchanged, the Customer retrieves its data as described above and ports them itself or through a third party it has engaged, and the Provider assists the Customer and the new provider, for example with information on formats and schemas.
After the end of the contract, the Provider makes the data available to the Customer for retrieval for 90 days, but not before the end of the transitional period (retrieval period under § 10 paragraph 1 of the T&C), longer upon request. After the retrieval period expires, the Provider erases the data; if the Customer only requested erasure, it erases them upon the end of the contract. Upon request, the Provider confirms the erasure in text form.
Charges: the Provider charges no fee for switching, porting, or erasure. If this ends the contract before the minimum contract term or a current renewal period expires, the Customer owes the agreed remuneration until that expiry, but no more than three monthly amounts, less the expenses saved by the Provider; the Customer remains free to prove a lower loss, and any remuneration paid in advance beyond that is refunded (§ 8 paragraph 9 of the T&C).
2. Methods and Formats
The data are provided as one ZIP archive per tenant for download over an encrypted connection (HTTPS). The archive contains:
- the file rueckgabe.xml with all data not contained in the data export of a sealed version: master data, team members, checklists, drafts, responses to actions, discussions, mailings, and the list of missing parts; described by the data return schema;
- one data.xml file per sealed version, newly generated at the time of preparation; described by the data export schema;
- the stored PDF files of sealed versions with a list of their SHA-256 hash values; the PDF reports of sealed versions are signed with a certificate of the Provider and bear a timestamp (PAdES);
- the stored files: photos, audio files, signature images, logos, profile pictures, and evidence photos;
- the data return schema as rueckgabe.xsd and, for each sealed version, the data export schema, each in the version according to which the XML files were generated.
The XML files are encoded in UTF-8 and follow the open standards XML 1.0 and XML Schema 1.0. Every entity carries its identifier (UUID); references between entities are attributes, and file paths are relative to the root folder of the archive. Points in time are given in UTC. The folders in the archive carry readable names with a short identifier.
3. Schemas for Download
The schemas are versioned. A change that a valid document of an earlier version would no longer satisfy is published as a new version with a new file name; a published version never changes.
In the archive, the data return schema is named rueckgabe.xsd. It includes the data export schema from the subfolder schema/; to validate a rueckgabe.xml, place both files in this arrangement.
4. Scope
Which data are exportable and which are exempt, and for what reason, is conclusively governed by § 10 paragraphs 2 and 3 of the T&C.
5. Known Limitations
- Retrieval runs through the download in the web app profile. There is currently no open application programming interface (API) for the export and no direct transfer to another provider.
- The archive reflects the state at the time of preparation. Data changed later are missing; a version sealed during preparation appears as a draft.
- Data captured in the mobile app and not yet synchronized are missing.
- Drafts have no PDF. For sealed versions without a stored PDF, no PDF is generated retroactively; their data are contained in the XML files.
- Unreadable files or files not yet uploaded are listed in a list of missing parts in the archive and in the profile; the return is completed nonetheless.
- Word files (reports and custom report templates) are not yet contained in the archive; the Provider provides them upon request.
- Former team members and memberships in other tenants are not included.
- A finished archive is deleted 30 days after completion and can then be prepared again.
- A preparation that is not finished after six hours is considered failed and can be started again.
- Photos are available in the version downsized by the Platform, audio files converted to M4A where applicable; the Platform does not keep the originally uploaded file.
6. Jurisdiction of the IT Infrastructure (Art. 28 paragraph 1 (a) Data Act)
The IT infrastructure on which the Customer's data are processed is located in Member States of the European Union:
- Database, file storage, sign-in, and server-side functions: Supabase, Frankfurt am Main (Germany)
- Synchronization of the mobile app: PowerSync, Dublin (Ireland)
- Web app servers, conversion of Word to PDF and of audio recordings, creation of the archives: Google Cloud Run, St. Ghislain (Belgium)
- AI functions: Google Vertex AI, Frankfurt am Main (Germany)
- Email delivery: Amazon Web Services, Frankfurt am Main (Germany)
- Error diagnostics: Sentry, Frankfurt am Main (Germany)
This infrastructure is subject to the law of the Union and of the respective Member State. Some operators are established in a third country (Singapore, USA) or belong to groups established in the USA; they may therefore additionally be subject to the law of these countries, including rules on access to data by public authorities. The subprocessor list names the operator, registered office, processing location, and third-country relation for each service.
7. Protection against Unlawful Governmental Access (Art. 28 paragraph 1 (b) Data Act)
Technical measures: the data are processed in data centers in the European Union. Connections run exclusively over TLS. Files are kept in private storage and are delivered only through short-lived signed links. Administrative access is protected by two-factor authentication. Further measures are described in Annex 2 of the DPA.
Contractual measures: for personal data, a data processing agreement is in place with every operator; transfers to a third country are based on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework, and the subprocessor list names the safeguard for each operator. Where Standard Contractual Clauses apply, they oblige the operator to review the lawfulness of a request by a public authority, to challenge it where possible, to disclose only the minimum data required, and to notify the Provider where this is permitted. The same technical and organizational measures apply to non-personal data.
Organizational measures: the Provider complies with a request by an authority or court of a third country for access to the Customer's data only in accordance with Art. 32 of Regulation (EU) 2023/2854, in particular on the basis of an international agreement. It then discloses only the minimum data required and informs the Customer before disclosure where this is permitted.