Back to home

Data Processing Agreement (AVV) under Art. 28 GDPR

Radom UG (haftungsbeschränkt) · Version 1.0, October 2026

Convenience translation. The German version of this agreement prevails.

Preamble

The customer uses an online service of Radom UG (haftungsbeschränkt) under the terms and conditions of that service (the "main contract"). In doing so, Radom UG processes personal data on behalf of the customer. This agreement sets out the rights and obligations of the parties under Art. 28 GDPR.

Parties

  • Controller (the "customer"): the business that uses the service with a customer account.
  • Processor (the "provider"): Radom UG (haftungsbeschränkt), Telemannstr. 2, 60323 Frankfurt am Main, Germany, Amtsgericht Frankfurt am Main, HRB 130877, represented by its managing director Arber Lamce.

§ 1 Subject matter, duration and details of the processing

  1. This agreement covers the processing of personal data that the customer enters or uploads when using the service. Annex 1 of the respective service sets out:
    • the subject matter, nature and purpose of the processing;
    • the types of personal data;
    • the categories of data subjects;
    • the retention period.
  2. This agreement applies for the term of the main contract. The obligations to delete (§ 9) and to keep confidential (§ 4) continue for as long as the provider processes the customer's data.
  3. Data that the provider processes as a controller in its own right is not covered by this agreement. This includes in particular the customer's account data, billing, server log files and abuse protection. The service's privacy policy applies to that data.

§ 2 Instructions

  1. The provider processes the data only on documented instructions from the customer, including with regard to transfers to a third country. The exception is processing required by Union or Member State law; in that case the provider informs the customer of that legal requirement before processing, unless that law prohibits it (Art. 28(3)(a) GDPR).
  2. The instructions follow from the main contract, this agreement and the customer's use of the service's functions. The customer gives any further instructions in text form (e.g. by email). Instructions that go beyond the agreed scope of services are treated as a request to change the services.
  3. If the provider considers that an instruction infringes data protection law, it informs the customer without delay (Art. 28(3), second sentence, GDPR). It may suspend carrying out the instruction until the customer confirms or changes it.

§ 3 Obligations of the customer

  1. The customer is responsible for the lawfulness of the processing, in particular for the lawfulness of transmitting the data to the provider and for safeguarding the rights of the data subjects.
  2. The customer informs the provider without delay if, when checking the results, it finds errors or irregularities with regard to data protection law.

§ 4 Confidentiality

The provider ensures that the persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR). This obligation continues after their work ends.

§ 5 Security of processing

  1. The provider takes the technical and organisational measures under Art. 32 GDPR described in Annex 2.
  2. These measures are subject to technical progress. The provider may replace them with equivalent or better measures as long as the level of protection is not reduced. It documents material changes.

§ 6 Sub-processors

  1. The customer gives the provider general authorisation to engage other processors (sub-processors) (Art. 28(2) GDPR). The sub-processors engaged when the agreement is concluded are listed in Annex 3 and are deemed approved.
  2. The provider informs the customer in text form at least 30 days in advance of any intended addition or replacement of a sub-processor. It sends this information by email to the address stored in the customer account.
    • The customer may object to the change in text form within 14 days of receipt, for an important reason relating to data protection.
    • If the parties cannot agree, either party may terminate the main contract for cause, effective as of the change.
  3. The provider imposes on each sub-processor by contract the same data protection obligations as set out in this agreement (Art. 28(4) GDPR).
  4. Data is transferred to a third country only if the requirements of Art. 44 et seq. GDPR are met, for example on the basis of an adequacy decision or standard contractual clauses.

§ 7 Assistance with data subject rights

  1. The provider assists the customer with appropriate technical and organisational measures in fulfilling the rights of data subjects under Chapter III GDPR (Art. 28(3)(e) GDPR).
  2. If a data subject contacts the provider directly, the provider forwards the request to the customer without delay. It does not answer the request itself unless the customer instructs it to.

§ 8 Assistance with further obligations, notification of breaches

  1. The provider assists the customer in complying with the obligations under Art. 32 to 36 GDPR, taking into account the nature of the processing and the information available to it (Art. 28(3)(f) GDPR). This covers:
    • the security of processing;
    • the notification and communication of breaches;
    • data protection impact assessments.
  2. The provider notifies the customer of a personal data breach without undue delay after becoming aware of it (Art. 33(2) GDPR). The notification contains, as far as available, the information under Art. 33(3) GDPR. Information not yet available is provided later.

§ 9 Deletion and return

  1. The provider deletes the customer's data automatically when the retention period stated in Annex 1 ends. On the customer's instruction, it deletes the data earlier.
  2. When the main contract ends, the provider deletes all of the customer's data still stored no later than at the end of that retention period (Art. 28(3)(g) GDPR). This does not apply to data the provider is required to store under Union or Member State law.
  3. The service makes the results of the processing available to the customer for download immediately. The provider owes no further return. The original data remains with the customer.

§ 10 Evidence and audits

  1. On request, the provider makes available to the customer all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR (Art. 28(3)(h) GDPR). This may include certificates or evidence from sub-processors.
  2. The customer, or an auditor it engages who is bound to confidentiality, may carry out audits, including inspections.
    • The customer announces an inspection in text form at least 30 days in advance, unless there is a well-founded suspicion of a breach.
    • Inspections take place during normal business hours, without disrupting operations, and as a rule no more than once per calendar year.
    • Sub-processors' data centres are audited through their evidence.
  3. The customer bears the costs of an inspection unless it reveals a material breach of this agreement by the provider.

§ 11 Liability

Liability towards data subjects is governed by Art. 82 GDPR. Between the parties, the liability provisions of the main contract apply otherwise.

§ 12 Conclusion of the agreement and final provisions

  1. This agreement forms part of the terms and conditions of the respective service. It is concluded in electronic form (Art. 28(9) GDPR) as soon as the customer accepts those terms and conditions, for example when signing up. It applies to all personal data the customer processes in the service from that point on.
  2. On request, the provider also provides this agreement to the customer as a signed document (PDF).
  3. In the event of conflict, this agreement takes precedence over the main contract with regard to the protection of personal data.
  4. Amendments and additions require text form. This also applies to any waiver of this form requirement.
  5. If any provision is invalid, the validity of the remaining provisions is not affected.
  6. This agreement is governed by the law of the Federal Republic of Germany. The place of jurisdiction is Frankfurt am Main, to the extent permitted by law.

Annexes for the service ZUGFeRD-Bereit (zugferd-bereit.de)

Annex 1: Details of the processing

Annex 1: Details of the processing
Subject matter and purposeCreating, converting and checking (validating) electronic invoices and credit notes in the ZUGFeRD / Factur-X format. The data comes from the customer: entered in the form, uploaded as a single file, or sent as a CSV/Excel file in batch processing.
Nature of the processingReceiving, reading, converting, checking, storing for a limited time, providing for download, deleting.
Types of personal dataNames, company names, addresses and contact details (email, phone) of invoice issuers, invoice recipients and contact persons. Tax identifiers (VAT ID, tax number). Bank details (IBAN, BIC, account holder). Invoice and service data (line items, amounts, dates, references such as order, contract or project numbers). Any other information contained in the files submitted.
Categories of data subjectsCustomers, suppliers and other business partners of the customer, e.g. recipients of credit notes. Their contact persons and employees. The customer's employees, as far as they are named in invoices.
Retention periodUploaded files and generated results are stored under an identifier without name or email address and deleted automatically 90 days after processing. On the customer's instruction they are deleted earlier. These files are not included in backups.
Place of processingServers of Hetzner Online GmbH in the Nuremberg data centre, Germany. Exception: AI-assisted reading of single uploaded files (see Annex 3, no. 2) in the EU region Sweden Central. Batch processing, form entry, ZUGFeRD/Factur-X XML and validation run only on the servers in Germany, without AI.

Annex 2: Technical and organisational measures (Art. 32 GDPR)

1. Confidentiality

  • Physical access control: the servers are located in the data centre of Hetzner Online GmbH in Nuremberg. Hetzner controls physical access. The provider operates no server rooms of its own.
  • System access control:
    • Administrative access only via SSH with a cryptographic key; password login is disabled.
    • A firewall allows only SSH, HTTP and HTTPS publicly.
    • The internal application interface and the validation services can be reached only locally on the server and are protected by an internal key.
  • Data access control:
    • Customer accounts are protected by a password that is stored only as a bcrypt hash.
    • Failed login attempts are limited.
    • Only the management and persons it has expressly authorised, who are bound to confidentiality, have access to the servers.
  • Separation: stored files are kept separately per user or identifier.
  • Pseudonymisation: uploaded files and results are stored under an identifier without name or email address.

2. Integrity

  • Transfer control:
    • All connections to the service are encrypted with TLS (HTTPS); unencrypted requests are redirected to HTTPS.
    • Backups are transferred over an encrypted connection.
    • Generated e-invoices and PDF/A files are validated locally, without transfer to third parties.
  • Input control: server and application logs; server log files are rotated daily and deleted after 14 days.

3. Availability and resilience

  • Backup: the account database is backed up daily to a second Hetzner Online GmbH server in Nuremberg and kept for 14 days. An additional backup is made before every software release.
  • Operations: the services run in separate containers with resource limits and automatic restart. They are monitored automatically every 15 minutes.

4. Regular testing, assessment and evaluation

  • Every software change goes through a review (code review) and automated tests before release, and an automatic functional check after release.
  • Deletion concept, implemented automatically:
    • invoice files after 90 days;
    • log files after 14 days;
    • abuse-protection counters 30 days after last use;
    • backups after 14 days.
  • Privacy by default: analytics services are loaded only after consent. File names, email addresses and invoice contents are not sent to them.

Annex 3: Sub-processors

Annex 3: Sub-processors
No.Sub-processorServicePlace of processing
1Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, GermanyHosting, storage and backupsNuremberg data centre, Germany
2Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, IrelandAzure OpenAI Service: AI-assisted reading of single uploaded files (PDF, images, and CSV, Excel and XML files whose structure is not recognised automatically). Not used for batch processing, form entry or ZUGFeRD/Factur-X XML. Contents are not used for training.Azure region Sweden Central (EU)
3Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, IrelandGoogle Workspace: support email, only if the customer sends files or invoice data to support by emailEU; a transfer to Google LLC (USA) cannot be ruled out and takes place on the basis of the EU-US Data Privacy Framework or standard contractual clauses