Note: In case of conflict between language versions, the German version prevails.
Data Processing Agreement (DPA)
pursuant to Art. 28 General Data Protection Regulation (GDPR)
Version 2.1 | Effective from: 2026-08-25
Controller (Client / Host)
Name / Company: completed at contract conclusion
Address: completed at contract conclusion
Email: completed at contract conclusion
Processor (Service Provider)
Better Projects Faster GmbH
Pariser Platz 5A, 70173 Stuttgart
Email: [email protected]
Represented by: Karsten Silz
Contents
- Preamble
- Subject Matter and Duration
- Instructions
- Obligations of the Processor
- Obligations of the Controller
- Sub-processors
- Third-country Transfers
- Technical and Organisational Measures
- Audit Rights
- Data Backup and Deletion
- Rights of Data Subjects
- Term and Termination
- Liability
- Final Provisions
- Annex 1 – TOMs
- Annex 2 – Sub-processors
Preamble and Formation
This DPA forms part of the platform's terms of use and becomes effective automatically upon conclusion of the main contract (registration / subscription). By using the platform, the host agrees to the content of this DPA. A separate signature is not required provided that consent is documented as part of the digital onboarding process.
The processor provides the controller with a web-based platform for managing holiday properties (hereinafter "Platform"). In the course of using the Platform, the processor processes personal data of third parties (in particular the host's guests) on behalf of and under the instructions of the controller.
Art. 1 – Subject Matter and Duration of Processing
- The processor processes personal data exclusively on behalf of the controller and in accordance with its instructions (Art. 28(3)(a) GDPR).
- Processing takes place for the duration of the existing main contract (service contract) between the parties. After termination, the further handling of data is governed by Art. 9 of this DPA.
1.1 Categories of Data Processed
- Master data of guests: name, address, email address, telephone number
- Booking data: check-in/check-out dates, booked accommodation, price
- Payment-related data: invoice amounts, payment status (no complete payment instrument information)
- Communication data: email correspondence between host and guests, insofar as processed via the Platform
- Registration form data: names, nationality, document numbers (where legally required)
- Tourist tax-relevant information
1.2 Categories of Data Subjects
- Guests of the controller
- Other contact persons entered by the controller
1.3 Purposes of Processing
- Operation of the booking platform and property management system
- Calendar and availability management
- Invoice creation and management for the controller
- Guest communication and automated email templates
- Fulfilment of statutory registration and tax requirements
- Provision of analyses and evaluations for the controller
Art. 2 – Controller's Right to Issue Instructions
- The processor processes personal data solely in accordance with the controller's documented instructions, unless required to do otherwise by EU or Member State law.
- Instructions are issued primarily through the configuration and use of the Platform. Instructions beyond this require written form (email suffices).
- The processor shall inform the controller without undue delay if it considers an instruction to violate the GDPR or other data protection provisions.
Art. 3 – Obligations of the Processor
The processor undertakes in particular:
To ensure that persons authorised to process the personal data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality.
To implement all measures required pursuant to Art. 32 GDPR (see Annex 1).
To engage further processors only with the prior written consent of the controller (see Art. 5).
To assist the controller in fulfilling data subjects' rights and the obligations under Art. 32–36 GDPR.
To appoint a Data Protection Officer where required by law.
To notify the controller without undue delay (where possible within 24 hours) of any personal data breaches.
Art. 4 – Obligations of the Controller
- The controller is solely responsible as the data controller within the meaning of Art. 4(7) GDPR for the lawfulness of processing, in particular for obtaining any required consents.
- The controller shall notify the processor without undue delay if it identifies errors or irregularities when reviewing the processing results.
- The controller shall designate a contact person for data protection enquiries.
- The controller shall ensure that only lawfully obtained personal data is entered into the Platform.
Art. 5 – Sub-processors
- The controller grants the processor general authorisation to engage further processors (sub-processors) in accordance with Annex 2 of this agreement.
- The processor shall notify the controller of any intended change (addition or replacement) of sub-processors with at least 30 days' advance notice. The controller has the right to object to such changes.
- The processor shall ensure that sub-processors enter into data protection obligations equivalent to those agreed in this DPA.
The sub-processors currently engaged are listed in Annex 2.
Art. 6 – Third-country Transfers
- Transfers of personal data to third countries (outside the EU/EEA) are made exclusively on the basis of appropriate safeguards pursuant to Art. 44 ff. GDPR (in particular standard contractual clauses pursuant to Art. 46(2)(c) GDPR or adequacy decision).
- This concerns Cloudflare, Inc. (hosting, CDN, object storage) and GitHub, Inc. (repositories of the host websites), both based in the USA. Both are certified under the EU-U.S. Data Privacy Framework; the Standard Contractual Clauses apply in addition.
- The processor documents the legal basis for each third-country transfer and makes it available upon request.
Art. 7 – Technical and Organisational Measures (TOMs)
The processor implements at least the following technical and organisational measures pursuant to Art. 32 GDPR:
7.1 Confidentiality
- Encryption of all data in transit (TLS 1.2 or higher); HTTPS is enforced via HSTS
- The application server is not directly reachable from the internet; access runs through an encrypted tunnel. The database is not reachable from outside
- Role-based authorisation following the principle of least privilege
- Passwordless host login via a time-limited sign-in link; host passwords are not stored
- Logical separation of tenant data; every query is scoped to the respective tenant
- Images, files and backups are held in object storage that encrypts them at rest
- Staff of the processor access a host's portal only after that host has explicitly granted access, time-limited, restricted to read access and logged
7.2 Integrity
- Logging of changes to core data (bookings, guest data, invoices) with timestamp and user
- We retain these change logs for 12 months from the time of the respective change; after that we delete them automatically. In the event of a specific security incident or legal dispute, we may suspend deletion; any such suspension is documented with its occasion, scope, duration and the person who ordered it. This rule applies to the data processed on the controller's behalf (guest data); it makes no statement about data for which we are ourselves the controller.
- Deletions are documented in dedicated proof-of-deletion registers
- Input validation and protection against injection attacks; database access exclusively through parameterised queries
- Changes reach production only after code review and automated tests
7.3 Availability
- Daily automatic database backup into encrypted object storage; retained for 14 days
- Every backup is checked for completeness; incomplete backups are discarded
- Platform availability of 99 % on annual average in accordance with the terms of use
7.4 Review of Effectiveness
- Procedures for regularly reviewing the effectiveness of the technical and organisational measures
- Review of the measures whenever the processing changes materially
- Regular updates of the software components in use
Art. 8 – Controller's Audit Rights
- The controller has the right to verify compliance with data protection requirements at the processor's premises through its own inspections or by engaging qualified third parties.
- Inspections must be notified with at least 14 days' advance notice. The processor is entitled to refuse participation by persons in a competitive relationship.
- The processor shall provide the controller with all information necessary to demonstrate compliance with its obligations (Art. 28(3)(h) GDPR), in particular current TOM documentation and any certifications (e.g. ISO 27001).
Art. 9 – Data Backup and Deletion after Contract End
- After termination of the main contract, the processor shall make all processed personal data available to the controller for export in a commonly used machine-readable format (e.g. CSV, JSON). The export function is available for at least 30 days after contract end.
- After expiry of the 30-day period, the processor shall delete or destroy all personal data of the controller unless statutory retention obligations apply.
- Invoices from the processor to the controller (subscription fees) are retained in accordance with statutory retention periods (DE: 8 years; AT: 7 years).
- Deletion will be confirmed in writing at the controller's request.
- For the change logs relating to guest data referred to in Art. 7.2, the 12-month period and its exception continue to apply after contract end; a suspension of deletion documented under Art. 7.2 remains in effect until the reason for the suspension no longer applies.
Art. 10 – Rights of Data Subjects
- The processor shall assist the controller in fulfilling data subjects' rights (access, rectification, erasure, restriction, portability, objection pursuant to Art. 15–21 GDPR) to the extent technically possible.
- Requests from data subjects received directly by the processor will be forwarded to the controller without undue delay. The processor shall not handle such requests independently unless expressly instructed to do so by the controller.
Art. 11 – Term and Termination
- This DPA enters into force upon conclusion of the main contract and terminates automatically upon its termination.
- The right to extraordinary termination for good cause remains unaffected. Good cause exists in particular where a party seriously breaches material data protection obligations under this DPA.
Art. 12 – Liability
- The liability of the parties is governed by Art. 82 GDPR. In the internal relationship: each party is liable for the damage it caused through a breach of this DPA.
- The processor is not liable for processing carried out by the controller without or contrary to an instruction.
Art. 13 – Final Provisions
- The law of the country in which the processor is domiciled applies (DE: German law; AT: Austrian law). GDPR rights remain unaffected.
- Amendments and additions to this DPA require written form. The processor may announce DPA amendments with at least 30 days' notice by email; continued use of the Platform constitutes consent.
- Should individual provisions of this DPA be or become invalid, the validity of the remaining DPA shall not be affected.
- This DPA supersedes all prior agreements between the parties on data processing.
Annex 1 – Technical and Organisational Measures (TOMs)
| Measure | Implementation |
|---|---|
| Physical access control | No servers of our own. Operated in data centres of IONOS SE (Germany) and Cloudflare; physical security rests with the data centre operators |
| System access control | Passwordless host login via a time-limited sign-in link; host passwords are not stored. Administrative access is granted separately |
| Data access control | Role-based access model (RBAC), principle of least privilege. Support access to a host account only after that host grants it, time-limited, read-only and logged |
| Separation | Logical separation of tenant data; no transfer of data between customer accounts |
| Transmission encryption | TLS 1.2+ for all data transmission; HTTPS enforced via HSTS |
| Storage encryption | Images, files and backups are held in object storage that encrypts them at rest |
| Input control | Logging of changes to core data with timestamp and user We retain these change logs for 12 months from the time of the respective change; after that we delete them automatically. In the event of a specific security incident or legal dispute, we may suspend deletion; any such suspension is documented with its occasion, scope, duration and the person who ordered it. This rule applies to the data processed on the controller's behalf (guest data); it makes no statement about data for which we are ourselves the controller. |
| Availability control | Daily automatic backup; retained for 14 days; every backup checked for completeness |
| Processor control | Contracts under Art. 28 GDPR with all sub-processors (Annex 2) |
| Deletion concept | Documented, staged deletion concept; deletions are recorded in proof-of-deletion registers |
| Data protection impact assessment | Regular review; DPIA whenever the processing changes materially |
Annex 2 – List of Approved Sub-processors
August 2026 – This list is updated with 30 days' advance notice when changes are made.
| Provider | Service | Domicile / Country | Legal basis |
|---|---|---|---|
| Cloudflare, Inc. | Website hosting, CDN, network security, object storage for images | USA | EU-U.S. DPF + Standard Contractual Clauses |
| IONOS SE | Servers for the host portal, database and sign-in service | Germany (EU) | DPA under Art. 28 GDPR |
| Brevo SAS (formerly Sendinblue) | Sending transactional emails as well as newsletter and marketing emails | France (EU) | DPA under Art. 28 GDPR |
| GitHub, Inc. | Repositories of the host websites we build | USA | EU-U.S. DPF + Standard Contractual Clauses |
Digital Contract Conclusion
This agreement is accepted in digital form as part of the onboarding process. A separate signature is not required.