Data Processing Agreement
This agreement gives effect to Article 28 GDPR between you as controller and RatisbonaFlow UG (haftungsbeschränkt), Kleiststraße 2, 93077 Bad Abbach, Germany, as processor. It forms part of our Terms of Service and is concluded together with the main contract.
We are established in the European Union, so the GDPR governs our processing regardless of where you or your website visitors are located.
1. Subject matter, nature and purpose
1.1 The subject matter is the operation of your website on our platform. We process personal data only so far as that operation requires.
1.2 Three operations are involved: delivering your website to its visitors, including the server logs this produces; storing the website content you supply; and forwarding enquiry-form submissions to the mailbox you nominate.
1.3 We do not store enquiry-form submissions. They are received, forwarded to you by email immediately, and not retained. We keep no database of form submissions.
1.4 Processing lasts as long as the main contract. Section 10 remains unaffected.
2. Types of data and categories of data subject
2.1 The following types of personal data are processed:
a) Usage data arising when the website is accessed: IP address, date and time, address requested, volume transferred, referrer, and browser and operating system identifiers.
b) Entries from the enquiry form, in the scope you defined yourself — typically name, email address, telephone number, company and the free text of the enquiry.
c) Personal data contained in the website content because you publish it there — for example names, roles, photographs, email addresses and telephone numbers of staff or contacts.
2.2 Data subjects are visitors to your website, senders of form enquiries, and the people referred to in 2.1(c).
2.3 Special categories of personal data under Article 9 GDPR are not covered by this agreement. You will ensure that no such data is placed in the content.
3. Instructions
3.1 We process personal data only on your documented instructions. The main contract together with this agreement is the initial instruction.
3.2 Further instructions may be given informally, in particular by email. We document them.
3.3 If we consider an instruction unlawful we will say so without delay and may suspend its execution until you confirm it.
3.4 We will not transfer data to a third country except on your instruction or where required by law; in the latter case we will inform you beforehand unless the law prohibits it.
4. Confidentiality
4.1 Everyone with authorised access to personal data is bound to confidentiality and has been briefed on the applicable data protection requirements.
4.2 That obligation continues after their activity ends.
5. Security of processing
5.1 We implement and maintain the measures set out in Annex 1, as required by Article 32 GDPR.
5.2 We may develop those measures further, provided the level of protection is not reduced.
6. Sub-processors
6.1 You give general authorisation for the sub-processors named in Annex 2.
6.2 We will inform you in text form at least four weeks before engaging an additional sub-processor or replacing an existing one. You may object for good cause. If you do, we may terminate the main contract on reasonable notice where the service cannot reasonably be provided without that sub-processor.
6.3 We impose on sub-processors a level of protection equivalent to this agreement and remain liable for their conduct as for our own.
6.4 Handling our own contractual relationship with you — in particular payment processing — is not sub-processing under this agreement. For that we are the controller and you are the data subject; details are in our privacy notice.
7. Assistance
7.1 We will assist you with appropriate measures in responding to requests from data subjects under Chapter III GDPR. If data subjects approach us directly, we will refer them to you.
7.2 We will also assist you in complying with Articles 32 to 36 GDPR, in particular security of processing, notification duties and data protection impact assessments, taking into account the information available to us.
7.3 Assistance is free of charge where the cause lies with us. Otherwise we may charge for the necessary effort on a time and materials basis, and will tell you beforehand.
8. Personal data breaches
8.1 We will notify you of any personal data breach that comes to our attention without undue delay, ordinarily within 24 hours of becoming aware of it.
8.2 The notification will state, so far as known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
8.3 Notification to the supervisory authority and to data subjects is your responsibility.
9. Evidence and audits
9.1 On request we will provide the information needed to demonstrate compliance with this agreement, including evidence relating to our sub-processors.
9.2 You may satisfy yourself of compliance after reasonable advance notice, during normal business hours, in a way that does not unreasonably disrupt operations. Audits are limited to what is necessary and to once a year, unless there is specific cause.
9.3 Evidence may also be provided through current certificates or audit reports of independent bodies, including those of our sub-processors.
10. Deletion and return
10.1 When the main contract ends we will, at your choice, return the processed data to you or delete it.
10.2 If you make no other choice, we delete 30 days after the contract ends. That period gives you the opportunity to request your content; it matches section 14 of the Terms of Service.
10.3 Data subject to a statutory retention obligation is excepted. Such data is blocked and kept solely for the purpose of retention.
11. Place of processing
11.1 Processing takes place in the European Union. The database runs in Frankfurt am Main, email is sent through the provider’s European region, and delivery uses European locations where possible.
11.2 Some sub-processors are incorporated in the United States. Where access from a third country cannot be excluded, standard contractual clauses under Article 46(2)(c) GDPR are in place; the providers concerned are additionally certified under the EU-US Data Privacy Framework. Details are in Annex 2.
12. Final provisions
12.1 In case of conflict between this agreement and the main contract, this agreement prevails on questions of data protection.
12.2 German law applies. The place of jurisdiction is Regensburg, Germany, to the extent permitted by law.
12.3 If any provision is or becomes invalid, the remaining provisions remain unaffected.
12.4 This agreement was drafted in German and translated into English for your convenience. In the event of a discrepancy, the German version at kordala.com/auftragsverarbeitung prevails.
Annex 1 — Technical and organisational measures
This annex describes the measures actually in place, not a general list of what is possible.
Data minimisation: the websites set no cookies, embed no advertising networks and run no analytics. There are no user accounts and no customer login — so there is no password database and no session management to attack. Form submissions are not stored.
Confidentiality in transit: all connections are TLS-encrypted; certificates are issued and renewed automatically. Unpublished draft and preview addresses can additionally be protected with a password.
Confidentiality at rest: the database is stored encrypted. Images are held in object storage reachable only through the intended delivery address and through the operator’s access keys.
Access control: access to hosting, database, object storage and email is exclusively through the operator’s personal accounts with two-factor authentication. API keys are restricted in their permissions wherever the provider allows it — the deployment key is scoped to a single project, the image key to cache purging alone, and the administration tool’s key is read-only apart from creating payment and portal links.
Integrity and traceability: every change to content is versioned; the previous version is retained and can be restored. All program code and content modules are held in version control. Changes are deployed by the operator alone.
Availability: the database supports point-in-time recovery. Content additionally exists in version control and can therefore be reconstructed independently of the database provider.
Separation: each customer is a separate record with its own key; the assignment follows from the hostname requested and is determined afresh on every request. A request cannot be redirected to another customer through the path.
Deletion: a dedicated procedure removes a customer completely — content, versions, drafts, images and caches — so that nothing is left behind.
The limits of these measures: the service is run by a small company with one responsible person. There is no organisational separation of duties, no certified information security management system and no regular external penetration testing. A substantial part of the protection rests on the measures of the sub-processors in Annex 2, which are certified accordingly.
Annex 2 — Sub-processors
Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA — operation and delivery of the website, server logs. Processing in European locations where possible. Standard contractual clauses; certified under the EU-US Data Privacy Framework.
Neon Inc., 209 Kearny St, San Francisco, CA 94108, USA — database holding the website content. Server location Frankfurt am Main, European Union. Standard contractual clauses.
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA — storage and delivery of images. Standard contractual clauses; certified under the EU-US Data Privacy Framework.
Mailgun Technologies, Inc., 112 E Pecan St #1135, San Antonio, TX 78205, USA — delivery of form submissions to your mailbox. Operated in the provider’s European region. Standard contractual clauses.
Our payment provider is deliberately not listed. It processes your own data, not that of your website visitors; for that we are the controller and not a processor.
As of August 2026. Draft based on the service as actually operated — to be reviewed by a lawyer before going live.