Data Processing Agreement (DPA)

Version 1 · Last updated: August 8, 2026

This Data Processing Agreement (“DPA”) governs the processing of personal data by

Franz Josef Drexler
Silberbach 38
4230 Pregarten, Austria
contact@drefrajo.dev

– the “Processor” –

on behalf of the applicable business customer that incorporates this DPA through a contract, order, proposal, service agreement, or Terms of Service

– the “Controller” –

together, the “Parties”.

This DPA is intended to satisfy the requirements of Article 28(3) and (4) of the General Data Protection Regulation (“GDPR”).

It applies only to the extent that the Processor processes personal data on behalf of the Controller. Processing for which the Processor independently determines the purposes and essential means – including its own contract, account, billing, security, or communication data – is outside the scope of this DPA.


1. Incorporation and Relationship with the Main Agreement

  1. This DPA supplements the agreement between the Parties governing the relevant services (“Main Agreement”).

  2. The Main Agreement may include Terms of Service, proposals, order confirmations, service descriptions, hosting or maintenance agreements, or other contracts incorporating this DPA.

  3. This DPA may be concluded electronically and incorporated into the Main Agreement by reference. A separate handwritten signature is not required.

  4. Where the Main Agreement and this DPA conflict with respect to the processing of personal data on behalf of the Controller, this DPA prevails for that processing.

  5. This DPA applies only to services for which the Processor actually acts as a processor. Pure consultancy, website development, or setting up a third-party account held directly by the Controller does not by itself create a processor relationship where the Processor does not process personal data on the Controller’s behalf.

  6. The German and English versions of this DPA are intended to have the same substantive meaning. In the event of an unintended discrepancy, the German version shall prevail.


2. Roles and Responsibilities

  1. The Controller determines the purposes and, to the extent contemplated by the GDPR, the essential means of the processing.

  2. The Processor processes personal data solely on behalf of and on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless the Processor is required to carry out other processing by Union or Member State law. In that case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

  3. The Controller is in particular responsible for:

    • the lawfulness of the processing;
    • establishing an appropriate legal basis;
    • fulfilling transparency obligations towards data subjects;
    • the lawful collection and transmission of personal data to the Processor;
    • defining appropriate retention and deletion periods where these are not already defined by the applicable service;
    • the lawfulness of its instructions;
    • handling data subject rights falling within its responsibility.
  4. The Processor may determine the technical and organisational details of providing the services insofar as they do not conflict with the purposes or documented instructions determined by the Controller.

  5. If the Processor determines the purposes and means of processing contrary to this DPA, the applicable statutory rules governing controllers shall apply to that processing.


3. Documented Instructions

  1. Documented instructions from the Controller include in particular:

    • this DPA and the Main Agreement;
    • the applicable service description;
    • settings and configurations selected by the Controller within a service;
    • functionality and processing operations initiated by the Controller;
    • written or electronically documented instructions submitted through support, email, or a comparable communication channel.
  2. The Processor shall process personal data only within those instructions.

  3. If the Processor considers an instruction to infringe the GDPR or other applicable Union or Member State data protection law, it shall inform the Controller without undue delay. Performance of the relevant instruction may be suspended pending clarification.

  4. Additional instructions that materially change the agreed scope of the services may require a separate agreement and reasonable additional fees.


4. Subject Matter, Duration, Nature, and Purpose of Processing

The specific processing activities are determined by the Main Agreement and the service categories described in Annex 1.

Processing may in particular include:

  • collection and recording;
  • storage and organisation;
  • retrieval and display;
  • transmission;
  • provision and hosting;
  • modification and updating;
  • automated processing and content generation;
  • backup and restoration where applicable;
  • deletion and destruction.

Processing continues for the duration of the relevant service and for the period reasonably required to return or delete personal data in accordance with this DPA.


5. Confidentiality and Access

  1. The Processor shall ensure that persons granted access to personal data processed on behalf of the Controller access such data only to the extent necessary.

  2. Persons authorised to access such data shall be subject to appropriate confidentiality obligations or an appropriate statutory duty of confidentiality.

  3. This requirement also applies to future employees, contractors, and other persons acting under the Processor’s authority.

  4. Manual access to customer or interview content shall occur only where necessary for operation, troubleshooting, support, security, abuse prevention, or compliance with a documented instruction.

  5. Personal data shall not be used for private purposes, unrelated commercial purposes, or other purposes incompatible with the Controller’s instructions.


6. Technical and Organisational Measures

  1. Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, the Processor shall implement appropriate technical and organisational measures pursuant to Article 32 GDPR.

  2. The measures currently contemplated are described in Annex 2.

  3. The measures may be further developed in response to technological developments and changing risks, provided that the overall agreed level of protection is not materially and inappropriately reduced.

  4. Measures are applied on a risk-based basis. Not every listed measure is necessarily technically required for every service or system.


7. Assistance with Data Subject Rights

  1. Taking into account the nature of the processing and insofar as technically and organisationally possible, the Processor shall assist the Controller in responding to requests by data subjects under Chapter III GDPR.

  2. Where the Processor receives a request from a data subject that clearly concerns processing controlled by the Controller, the Processor shall generally forward the request to the Controller or direct the data subject to the Controller.

  3. The Processor shall not respond to such requests on behalf of the Controller unless instructed to do so or required by law.

  4. Functionality made directly available to the Controller for viewing, exporting, rectifying, or deleting data constitutes part of such assistance.


8. Assistance with Data Protection Obligations

Taking into account the nature of the processing and the information available to it, the Processor shall reasonably assist the Controller in complying with Articles 32 to 36 GDPR, in particular regarding:

  • security of processing;
  • assessment and management of personal data breaches;
  • data protection impact assessments;
  • prior consultation with supervisory authorities where required.

Responsibility for the legal assessment and decision remains with the Controller.


9. Personal Data Breaches

  1. Where the Processor becomes aware of a personal data breach affecting personal data processed on behalf of the Controller, it shall notify the Controller without undue delay.

  2. To the extent available at the relevant time, the notification shall contain:

    • a description of the nature of the breach;
    • affected categories of data and data subjects;
    • where possible, an approximate assessment of the scope;
    • known or likely consequences;
    • measures already taken or proposed;
    • a contact point for further information.
  3. Where all information is not yet available, information may be provided in phases.

  4. The Processor shall take reasonable measures to contain and remediate the incident.

  5. The Controller remains generally responsible for determining whether notification to a supervisory authority or communication to affected data subjects is required.


10. Subprocessors

  1. The Controller grants the Processor general authorisation to engage additional processors (“Subprocessors”).

  2. The current list of Subprocessors is available at:

/en/subprocessors

  1. The list should in particular identify:

    • the name of the Subprocessor;
    • its function or processing purpose;
    • the principal processing location or relevant region;
    • where applicable, the transfer mechanism relied upon for international transfers.
  2. Where the Processor intends to add or replace a Subprocessor, affected Controllers shall generally be notified at least 14 days before the change.

  3. A shorter notification period may be used where necessary for urgent security reasons, to comply with law, because an existing provider unexpectedly discontinues a service, or due to comparable circumstances outside the Processor’s reasonable control. In such cases, the Processor shall notify the Controller as early as reasonably possible.

  4. The Controller may object within the notice period on reasonable data protection grounds.

  5. The Parties shall first attempt to find a reasonable solution. Where no reasonable alternative can be made available, the Processor may discontinue the service dependent on the relevant Subprocessor or terminate the affected portion of the Main Agreement.

  6. The Processor shall impose on its Subprocessors, by contract or another legal act, the same data protection obligations as set out in this DPA between the Controller and the Processor. In particular, sufficient guarantees must be provided that appropriate technical and organisational measures are implemented so that the processing meets the requirements of the GDPR.

  7. The Processor remains fully liable to the Controller for the performance of its Subprocessors’ data protection obligations.

Providers Contracted Directly by the Controller

  1. Services, accounts, or infrastructure contracted directly by and operated under the Controller’s own account shall not become Subprocessors of the Processor solely because the Processor configures or administers them on the Controller’s behalf.

  2. This may include, for example, a cloud, hosting, analytics, form, or CMS account contractually held by the Controller.

  3. To the extent that the Processor accesses personal data within such systems on the Controller’s behalf, that access remains subject to this DPA.


11. International Data Transfers

  1. The Controller instructs and authorises the Processor to process personal data at the processing locations disclosed in the current Subprocessor List.

  2. Where personal data is transferred from the European Economic Area to a third country and Chapter V GDPR requires a specific transfer mechanism, the Processor shall, within the scope of its responsibility, ensure that an appropriate transfer mechanism is available.

  3. Such mechanism may in particular include:

    • an adequacy decision pursuant to Article 45 GDPR;
    • the EU-US Data Privacy Framework where applicable to the relevant recipient and processing;
    • European Commission Standard Contractual Clauses pursuant to Article 46 GDPR;
    • other safeguards permitted by applicable law.
  4. Supplementary technical and organisational measures shall be considered where required.

  5. This DPA does not by itself constitute Standard Contractual Clauses for international transfers under Chapter V GDPR.

  6. Where additional Standard Contractual Clauses or other documentation become necessary for a specific transfer, the Parties shall reasonably cooperate in putting them in place.


12. Return and Deletion

  1. Following termination of the relevant processing services, the Processor shall, at the Controller’s choice, delete or return personal data processed on its behalf unless retention is required by applicable law.

  2. The Controller may exercise this choice before or no later than termination of the relevant service.

  3. Unless the Controller provides a different instruction, deletion constitutes the Controller’s documented default instruction.

  4. Following termination, active copies controlled by the Processor shall be deleted without undue delay and generally no later than 30 days after the end of processing, unless the relevant service description requires earlier deletion.

  5. The 30-day period is not a guaranteed recovery or retention period. Following deletion initiated by the Controller or carried out pursuant to an agreed retention period, there is no entitlement to recovery of the deleted data.

  6. Where a service provides export functionality, the Controller may use that functionality to obtain a return of its data.

  7. Upon request, and where technically possible and within the agreed scope of services, the Processor may reasonably assist with an electronic return of data.

  8. Personal data may temporarily remain in Subprocessor backup copies until removed in accordance with the relevant regular backup or overwrite cycle. Such copies shall not be used for unrelated purposes and shall remain protected until deletion.

  9. Statutory retention requirements remain unaffected.


13. Information and Audits

  1. The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA.

  2. Where appropriate, existing documentation, descriptions of technical and organisational measures, provider documentation, contractual evidence, and written responses should be used first.

  3. The Controller may conduct audits itself or through an independent auditor bound by appropriate confidentiality obligations.

  4. Audits should:

    • take place at reasonable intervals;
    • generally be subject to reasonable prior notice;
    • avoid unnecessary disruption to the Processor’s business;
    • be limited to systems and information relevant to the processing performed on behalf of the Controller;
    • appropriately protect the confidentiality, security, and trade secrets of the Processor and other customers.
  5. In the absence of a specific reason, comprehensive customer-initiated audits should generally not be required more than once in any twelve-month period.

  6. This limitation does not apply where:

    • there are specific indications of a material data protection breach or non-compliance;
    • a relevant security incident has occurred;
    • a competent supervisory authority requests an audit or relevant information;
    • mandatory data protection law requires otherwise.
  7. The Controller shall bear the costs of any external auditor it appoints and its own internal audit costs.

  8. Where an audit or additional evidence request causes substantial work beyond providing existing compliance materials and reasonable responses, the Processor may charge reasonable and previously disclosed costs for that additional assistance.

  9. Such charges shall not apply where the additional audit effort became necessary directly because of a material breach of this DPA or applicable data protection law attributable to the Processor.

  10. Nothing in this Section limits the investigative or audit powers of a competent data protection supervisory authority.


14. Documentation and Cooperation with Supervisory Authorities

  1. The Processor shall maintain the records of categories of processing activities carried out on behalf of Controllers as required by applicable law.

  2. The Processor shall cooperate with competent data protection supervisory authorities to the extent required by law.

  3. The Controller shall provide the information reasonably required by the Processor to comply with its own statutory documentation obligations.


15. Special Categories and Highly Sensitive Data

  1. Unless expressly agreed otherwise in an applicable service annex, the services are not designed for the systematic processing of:

    • special categories of personal data under Article 9 GDPR;
    • personal data relating to criminal convictions and offences under Article 10 GDPR;
    • end-user passwords or authentication secrets in plaintext;
    • private cryptographic keys;
    • other comparably highly sensitive secrets.
  2. The Controller shall not knowingly submit or cause such data to be processed through the relevant services unless the Parties have first agreed in writing on the purpose, scope, and any additional safeguards required.

  3. This restriction does not prevent the Processor from handling administrative credentials, API keys, access tokens, or comparable secrets that are technically necessary to manage infrastructure or systems on the Controller’s behalf. Such credentials shall be appropriately protected and used solely for the agreed purpose.


16. Costs of Assistance

Ordinary compliance by the Processor with its statutory obligations under this DPA forms part of the agreed service.

Where the Controller requests exceptional and individually burdensome assistance beyond the agreed scope – such as extensive bespoke data exports, special audits, unusual documentation, or additional technical measures – such assistance may be charged separately following prior notice, provided that mandatory rights of the Controller are not unreasonably restricted.


17. Liability

  1. Statutory liability of the Parties under the GDPR, including liability towards data subjects and supervisory authorities, remains unaffected.

  2. To the extent permitted by law, any liability provisions contained in the Main Agreement also apply to claims arising under this DPA as between the Parties.

  3. Where the Main Agreement contains no applicable liability provision, statutory law applies.


18. Term and Termination

  1. This DPA takes effect when validly incorporated into the Main Agreement.

  2. It remains in effect for as long as the Processor processes personal data on behalf of the Controller.

  3. Obligations intended by their nature to survive termination – in particular confidentiality, deletion, return, and compliance evidence obligations – remain effective to the extent required.


19. Governing Law and Jurisdiction

  1. This DPA is governed by Austrian law, excluding its conflict-of-laws rules, unless mandatory law requires otherwise.

  2. To the extent legally permissible between businesses, the courts having subject-matter jurisdiction at the Processor’s place of establishment shall have jurisdiction over disputes arising from this DPA.

  3. Mandatory jurisdiction, rights of data subjects, and powers of competent data protection supervisory authorities remain unaffected.


Annex 1 – Description of Processing

A. Interview Service

Subject Matter and Purpose

Provision of a web-based, AI-assisted Interview Service through which the Controller can conduct interviews with persons invited by the Controller (“Clients”) and generate project documentation and visual concepts from those interviews.

Categories of Data Subjects

  • Clients invited by the Controller;
  • where applicable, third parties mentioned by Clients or the Controller in free-text content.

Creator account, contractual, billing, and the Processor’s own security data processed for the Processor’s own purposes are outside the scope of this Annex.

Categories of Personal Data

In particular:

  • technical access data;
  • interview inputs and chat messages;
  • timestamps and processing status;
  • project information and instructions supplied by the Controller;
  • requested changes;
  • inspiration links and visual-direction information;
  • generated interview plans;
  • AI responses;
  • project documents;
  • image prompts;
  • visual concepts;
  • Project Submissions;
  • other personal information that may be contained in free-text content.

Nature of Processing

  • collection and storage of inputs;
  • provision and retrieval of interview history;
  • transmission of required content to AI Subprocessors;
  • automated generation and revision of text and images;
  • making results available to the Controller;
  • storage, export, and deletion.

Retention

Unless deleted earlier by the Controller:

  • completed interviews: deletion no later than 24 months after submission;
  • incomplete interviews: deletion no later than 24 months after the last activity.

The Controller may export or download available interview results during the retention period.

The service may send an advance notification before scheduled automatic deletion. Such notification does not extend the applicable retention period.

Sensitive Data

The Interview Service is not intended for processing the data described in Section 15(1) of this DPA.


B. Website, Hosting, CMS, and Infrastructure Services

This Section applies only to the extent that the Processor actually processes personal data on behalf of the Controller in connection with a customer website or its related infrastructure.

Potential Services

Depending on the Main Agreement, services may include:

  • website development and technical deployment;
  • operation or administration of hosting infrastructure;
  • setup and management of cloud and CDN services;
  • administration of technical backends;
  • CMS operation or administration;
  • administration of databases or file storage;
  • deployment and technical maintenance;
  • security and troubleshooting;
  • management of domains, DNS, and similar web infrastructure;
  • integration and technical configuration of form, analytics, storage, or other web services.

Not every service listed above is provided for every project.

Third-Party Accounts Held by the Controller

Where a third-party account is created directly for the Controller and the Controller itself is the contractual customer and account holder of the relevant provider, that provider does not become a Subprocessor of the Processor solely because the Processor configures or administers the account.

Following handover of such an account, responsibility for the continuing contract and configuration generally rests with the Controller unless ongoing management by the Processor has been agreed.

Categories of Data Subjects

Depending on the website and customer project, these may include:

  • website visitors and users;
  • prospective customers and form submitters;
  • customers of the Controller;
  • business partners and suppliers;
  • employees and contractors of the Controller;
  • CMS or administration users;
  • other persons whose data the Controller processes through the website or associated systems.

Categories of Personal Data

Depending on the project, these may include:

  • IP addresses and online identifiers;
  • browser, device, and technical log data;
  • contact and identification data;
  • communications and form content;
  • CMS account and user information;
  • content supplied by the Controller;
  • uploaded files and media;
  • customer, prospect, and business-partner data;
  • usage and operational information;
  • other ordinary personal data required for the relevant website.

Nature and Purpose of Processing

In particular:

  • hosting and delivery of the website;
  • storage and retrieval of data;
  • technical administration;
  • deployment;
  • maintenance and troubleshooting;
  • security measures;
  • administration of CMS systems, databases, and file storage;
  • technical transmission to recipients or services designated by the Controller.

Duration and Retention

Processing generally continues for the duration of the commissioned hosting, management, or maintenance service.

Where the Controller can directly configure deletion or retention within a system under its control, the Controller is responsible for that configuration.

Upon termination of processing, Section 12 of this DPA applies.

Sensitive Data

The standard services are not designed for systematic processing of the highly sensitive data described in Section 15(1).

Such processing requires prior written agreement regarding its purpose, scope, and any additional safeguards required.


Annex 2 – Technical and Organisational Measures (TOMs)

The following measures describe the Processor’s baseline security measures. They are applied according to the relevant risk and technical infrastructure used for the specific service.

1. Access Control

  • Access to customer data only where necessary for operation, development, support, maintenance, security, or compliance with a documented instruction.
  • Individual and unique administrative credentials.
  • Use of a password manager for administrative credentials.
  • Restriction of access according to need-to-know and, where appropriate, least-privilege principles.
  • Removal of access rights that are no longer required.
  • Future employees or contractors with access to data are subject to confidentiality obligations.

2. Protection of Administrative Endpoints

  • Use of encrypted local storage or full-device encryption on administrative work devices.
  • Devices protected by user authentication and operating-system security functionality.
  • Regular installation of relevant security updates.

3. Encryption in Transit

  • TLS/HTTPS used for publicly accessible web services and API connections where technically applicable.
  • Encrypted administrative connections and secure interfaces used where applicable.

4. Protection of Stored Data

  • Use of encryption at rest provided as part of managed cloud and database services where available in the relevant service.
  • No general representation that independent end-to-end encryption or additional disk-level encryption is implemented for every hosting platform that may be used.
  • Infrastructure is selected and configured taking into account the sensitivity and risk of the relevant processing.

5. Secret Management

  • Access tokens, API keys, and other technical secrets are not intentionally stored in publicly accessible source code.
  • Appropriate platform secret/environment mechanisms or a suitable password manager are used.
  • Access is restricted to persons and systems that actually require the relevant secret.

6. Application and Network Security

Depending on risk and technical suitability, measures may include:

  • access controls;
  • non-guessable access tokens or links for protected resources;
  • rate limiting;
  • input and size limits;
  • security functionality provided by hosting and infrastructure platforms;
  • firewalls or comparable network filtering where relevant to the particular infrastructure.

7. Maintenance and Vulnerability Management

  • Regular updating of relevant software dependencies and systems.
  • Timely assessment of security-relevant updates and known vulnerabilities.
  • Adjustment of technical measures where there is a material change in risk or infrastructure.

8. Availability and Restoration

  • Use of redundancy, replication, backup, or recovery functionality provided by managed infrastructure where included in the relevant service.
  • Additional project-specific backups may be implemented depending on risk and technical feasibility.
  • Unless expressly agreed otherwise in the Main Agreement, no specific backup, recovery-point, recovery-time, or availability SLA is provided.
  • Despite appropriate security and recovery measures, complete protection against data loss cannot be guaranteed.

9. Data Minimisation and Deletion

  • Processing limited to data required for the relevant service.
  • Logging and notification content limited to what is reasonably necessary.
  • Deletion functionality provided in accordance with the relevant service.
  • Removal of active data no longer required in accordance with agreed retention and deletion rules.

10. Security Incidents

  • Assessment of identified security incidents.
  • Containment and remediation measures.
  • Notification of affected Controllers without undue delay where personal data is affected.
  • Appropriate documentation of relevant personal data breaches.

Annex 3 – Subprocessors

The current list of Subprocessors engaged by the Processor is maintained at:

/en/subprocessors

and is updated in accordance with Section 10 of this DPA.

Providers contracted directly by the Controller and whose accounts are held by the Controller are not included solely because the Processor technically configures or administers those services.