Data Processing Agreement
Last updated: 2026-08-31
This Data Processing Agreement (“DPA”) supplements the Terms of Service between the controller (the “Customer”) and the processor (Haulbi GmbH, the “Processor”) and forms an integral part of the contract under Art. 28 GDPR. Defined terms have the meaning given in the GDPR.
[TODO: legal review — this DPA is a template. Counsel should confirm that the clauses below satisfy Art. 28 (3) GDPR and any additional requirements under German data-protection law, especially § 26 BDSG and § 32 BDSG.]
1. Subject matter & duration
Subject matter. The Processor processes personal data on behalf of the Controller to provide the Haulbi service, including related support, security, billing and product-improvement activities.
Duration. The DPA runs for the term of the underlying subscription. On termination it ends automatically, subject to Section 9 below (return / deletion of data).
2. Nature & purpose of processing
- Hosting and operating the Haulbi multi-tenant platform.
- Storing, indexing and retrieving Customer Data on Customer’s instruction via the application UI and APIs.
- Backup, encryption, monitoring, logging and security incident response.
- Customer support, billing and account administration.
3. Categories of personal data & data subjects
The Processor processes:
- Categories of data: identification data (names, email addresses, phone numbers), authentication data (hashed passwords, SSO identifiers), professional data (role, company, region), content of CRM/ERP records uploaded by the Customer, and technical log data (IP addresses, request metadata).
- Categories of data subjects: the Customer’s employees, contractors, business contacts, leads and other individuals whose data the Customer chooses to store in Haulbi.
The Processor does not determine the purposes or means of the processing and acts only on documented instructions of the Controller.
4. Obligations of the Processor
The Processor undertakes to:
- Process personal data only on documented instructions of the Controller, including with regard to transfers, unless required to do so by EU or German law (Art. 28 (3) (a) GDPR);
- Ensure that persons authorised to process personal data are committed to confidentiality (Art. 28 (3) (b) GDPR);
- Implement the technical and organisational measures set out in Section 6 below (Art. 32 GDPR);
- Engage sub-processors only in accordance with Section 5 (Art. 28 (2) and (4) GDPR);
- Assist the Controller in responding to data-subject rights requests under Section 7;
- Notify the Controller of personal-data breaches without undue delay and support breach notifications under Section 8;
- Return or delete personal data at the end of the service under Section 9;
- Make available all information necessary to demonstrate compliance and allow audits under Section 10;
- Inform the Controller immediately if, in the Processor’s opinion, an instruction infringes the GDPR or other EU / German data-protection provisions.
5. Sub-processors
The Controller hereby authorises the engagement of the following sub-processors at the time of conclusion of this DPA:
- Hosting & infrastructure — [TODO: confirm hosting provider — placeholder: Vercel Inc., EU region]
- Email delivery — [TODO: confirm transactional email provider — placeholder: Postmark / SMTP]
- Payment processing — [TODO: confirm payment processor — placeholder: Stripe]
- Customer support tooling — internal ticketing platform.
The Processor will notify the Controller at least 30 days in advance of adding or replacing a sub-processor, giving the Controller the right to object on reasonable grounds related to data protection. If the objection cannot be resolved, the Controller may terminate the affected service for cause without liability.
6. Technical & organisational measures (TOMs)
The Processor implements measures pursuant to Art. 32 GDPR, including but not limited to:
- Encryption. TLS 1.2+ in transit; AES-256 at rest for primary storage and backups. [TODO: legal review — list exact cipher suites and KMS strategy.]
- Access control. Role-based access, least privilege, SSO + MFA for internal systems; quarterly access reviews.
- Logging & monitoring. Centralised application and infrastructure logs, retention ≥ 180 days, alerting on anomalous activity.
- Backups. Encrypted, geographically redundant backups with regular restore testing.
- Personnel. Background checks, mandatory security & data-protection onboarding and annual training.
- Software development. Secure SDLC, peer review, dependency scanning, separate staging environment.
- Incident response. Documented runbook, 24/7 on-call rotation, post-mortem with the Controller.
- Business continuity. Multi-AZ deployment, documented RTO/RPO targets, annual DR exercise.
- Vendor risk management. Due-diligence reviews of sub-processors, including data-handling and security posture.
7. Data-subject rights assistance
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures (to the extent possible) in fulfilling its obligation to respond to requests for exercising data subjects’ rights (Arts. 15 – 22 GDPR).
8. Notification of incidents
The Processor will notify the Controller of a personal-data breach affecting Controller data without undue delay, and in any event within 48 hours of becoming aware of the breach. The notification will describe the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address the breach and mitigate its possible adverse effects (Art. 33 (3) GDPR).
9. Return / deletion at end of service
Upon termination of the underlying subscription, the Processor will, at the Controller’s choice:
- Return the Customer Data in a commonly used, machine-readable format within 30 days; or
- Delete the Customer Data, including all copies, unless EU or German law requires continued storage.
Backups are rotated within the standard retention cycle, after which residual Customer Data is irreversibly overwritten or destroyed.
10. Audits
The Processor will make available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR and this DPA, and allow audits, including inspections, at the Controller’s reasonable request, no more than once per twelve-month period, on at least 30 days’ notice and during normal business hours, without unreasonably interfering with the Processor’s operations. The Controller may rely on independent third-party auditors subject to a confidentiality undertaking.
Independent attestations (e.g. SOC 2, ISO 27001) are accepted in lieu of an on-site audit where they cover the relevant controls.
11. Liability
Liability under this DPA is governed by the liability provisions of the underlying Terms of Service, subject to mandatory provisions of the GDPR.
12. Governing law
This DPA is governed by the laws of the Federal Republic of Germany, excluding its conflict-of-laws rules and the UN Convention on Contracts for the International Sale of Goods.
13. Contact for DPA inquiries
For all DPA-related inquiries, including sub-processor notifications, audits and incident communication, contact:
Data Protection Officer
dpo@haulbi.com
[TODO: legal review — confirm DPO name and postal address.]
Have questions? Contact us
← Back to all legal pages