The German version of this document is the sole legally binding version. This English translation is provided for informational purposes only.

Data Processing Agreement (DPA)

as of: July 22, 2025


Appendix 1: Description of the Processing

  • Nature and purpose of the processing:
    • Provision of the SaaS service “Brink” for the creation, management, storage, and sharing of brand guides.
    • Use of AI services to provide content support for text creation within the brand guides at the Controller's instruction.
    • Storage, hosting, technical provision, and backup of the data entered by the Controller.
  • Categories of data subjects:
    • Employees, customers, business partners, and other natural persons whose data is uploaded to or created in the Service by the Controller.
  • Categories of personal data:
    • Contact data (e.g., name, email, phone number)
    • Content data (e.g., texts, images, logos, fonts that may contain personal data)
    • The Controller undertakes not to process any special categories of personal data within the meaning of Art. 9 GDPR via the Service.

Appendix 2: Technical and Organizational Measures (TOMs)

The Processor implements the following measures in accordance with Art. 32 GDPR to ensure a level of security appropriate to the risk:

  1. Confidentiality:
    • Access control: It is ensured that only authorized persons can access the data to which they are entitled. This is achieved through a role and authorization concept, secure authentication methods (e.g., strong passwords, multi-factor authentication), and the application of the principle of least privilege.
    • Encryption: Personal data is encrypted during transmission over public networks (in-transit) and during storage on servers (at-rest) using strong, state-of-the-art cryptographic methods.
  2. Integrity:
    • Input control and logging: Essential systemic events are logged to support the traceability of processing operations and to monitor the integrity of the systems.
  3. Availability and Resilience:
    • Availability control: The systems are protected against failure through the use of redundant infrastructure at established hosting providers and by monitoring systems.
    • Recoverability: The ability to restore the availability of personal data in the event of a technical incident is supported by regular data backups.
  4. Procedures for regular review:
    • The Processor regularly reviews the effectiveness of the measures taken and adapts them as necessary to new technical developments and risk assessments.

Appendix 3: Approved Sub-processors

By concluding the Main Agreement, the Controller approves the engagement of the following sub-processors. The transfer of personal data to third countries is always based on appropriate safeguards in accordance with Art. 44 et seq. GDPR.

Category Company Location Purpose of Processing Legal Basis for Third-Country Transfer (if applicable)
Customer Support & Ticketing Zammad GmbH Germany Provision of the support and ticket management platform N/A (Processing within EEA)
Customer Support & Ticketing Asayer SAS France Provision of the software platform for in-app support N/A (Processing within EEA)
Infrastructure & Hosting Amazon Web Services, Inc. USA Provision of server infrastructure and storage of application and customer data EU-U.S. Data Privacy Framework (DPF) (Art. 45 GDPR)
Infrastructure & Hosting Platform.sh SAS France Provision of PaaS infrastructure for hosting and deployment N/A (Processing within EEA)
Infrastructure & Hosting Jonas Pasche (Uberspace) Germany Provision of webspace and server infrastructure N/A (Processing within EEA)
AI Services Anthropic, PBC USA Processing of user inputs (prompts, content) to create AI-generated texts EU Standard Contractual Clauses (SCCs) (Art. 46 GDPR)
AI Services Google Ireland Limited / Google LLC Ireland / USA Processing of user inputs (prompts, content) to create AI-generated texts EU-U.S. Data Privacy Framework (DPF) (Art. 45 GDPR) and EU Standard Contractual Clauses (SCCs) (Art. 46 GDPR)
AI Services OpenAI, L.L.C. USA Processing of user inputs (prompts, content) to create AI-generated texts EU Standard Contractual Clauses (SCCs) (Art. 46 GDPR)
Email Communication MailerLite Limited Ireland Sending of transactional emails and newsletters to the Controller N/A (Processing within EEA)
Email Communication Gandi SAS France Hosting of the Processor's internal email communication N/A (Processing within EEA)
Marketing Website Webflow, Inc. USA Hosting of the public corporate website EU-U.S. Data Privacy Framework (DPF) (Art. 45 GDPR)

The German version of this document is the sole legally binding version. This English translation is provided for informational purposes only.