Data Processing Agreement
This agreement ("DPA") is part of the Terms of Service between the Customer ("Controller") and Foth Group GmbH, Seehofstraße 137, 14167 Berlin ("Processor"). It applies whenever the Processor processes personal data on behalf of the Controller in the course of providing the sparevoice service.
1. Subject matter, duration, nature and purpose
- Subject matter: receiving, storing, displaying and answering messages and comments from the Controller's connected messaging channels, including the generation of reply drafts by AI models.
- Duration: the term of the Service contract, plus the deletion period in Section 8.
- Nature: collection via platform APIs, storage, organisation, analysis (classification, summarisation, language detection), generation of text, transmission to platforms on instruction, erasure.
- Purpose: enabling the Controller to manage and answer conversations with its end users.
2. Types of data and categories of data subjects
Data subjects: end users who communicate with the Controller through connected channels; the Controller's own staff using the Service.
Data types: platform user IDs and public usernames or display names; message and comment content including attachments provided by the platform; timestamps and conversation metadata; reply drafts and sent replies; derived tags, summaries and detected language; settings and instructions entered by the Controller's staff.
The Service is not designed for special categories of data (Art. 9 GDPR). Where end users volunteer such data in a message, it is processed only as part of the conversation and under the same protections.
3. Instructions
The Processor processes personal data only on the Controller's documented instructions. The Service contract, this DPA and the settings the Controller configures in the Service (channels, modes, active hours, selectivity, per-contact rules, approvals) constitute those instructions. The Processor informs the Controller without delay if it believes an instruction infringes data protection law.
4. Obligations of the Processor
- Ensure that persons authorised to process the data are bound by confidentiality.
- Implement and maintain the technical and organisational measures in the Annex.
- Engage sub-processors only under Section 5.
- Assist the Controller, by appropriate technical and organisational measures, in responding to data subject requests (Art. 12–23 GDPR).
- Assist the Controller in complying with Art. 32–36 GDPR, taking into account the nature of the processing and the information available.
- Notify the Controller without undue delay, and no later than 48 hours after becoming aware, of a personal data breach affecting the Controller's data, with the information required by Art. 33 (3) GDPR as it becomes available.
- Delete or return all personal data at the end of the Service as set out in Section 8.
- Make available all information necessary to demonstrate compliance with Art. 28 GDPR and allow for and contribute to audits under Section 7.
5. Sub-processors
The Controller grants general authorisation to engage the sub-processors listed below. The Processor imposes on each sub-processor data protection obligations equivalent to this DPA and remains fully liable for their performance.
| Sub-processor | Service | Location / transfer mechanism |
|---|---|---|
| Hetzner Online GmbH | Hosting, storage, backups | Germany |
| Anthropic PBC | AI generation of drafts, summaries, classifications | USA — EU SCCs, transfer impact assessment |
| OpenAI, L.L.C. | AI generation of drafts (secondary model) | USA — EU SCCs, transfer impact assessment |
| Stripe Payments Europe, Ltd. | Payment processing (Controller's account data only) | Ireland / USA — EU SCCs |
Meta Platforms Ireland Ltd. and other connected platforms act as independent controllers for processing on their own services and are not sub-processors.
The Processor will inform the Controller at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if no solution is found, the Controller may terminate the affected part of the Service without penalty.
6. International transfers
Personal data is stored in Germany. Transfers to sub-processors in third countries take place only under Chapter V GDPR, currently on the basis of the EU Standard Contractual Clauses (2021/914) supplemented by a transfer impact assessment and additional safeguards (encryption in transit, minimisation of transferred content, contractual prohibition of training use).
7. Audits
The Controller may verify compliance once per year, or additionally after a data breach, by requesting documentation (including current certifications or audit reports of sub-processors) and, where documentation is insufficient, by an on-site or remote audit during business hours with 30 days' notice, conducted in a manner that does not unreasonably disrupt operations or expose other customers' data.
8. Deletion and return
On termination of the Service, or on disconnection of a channel, the Processor deletes the associated personal data within 30 days unless Union or Member State law requires longer storage. Before that, the Controller may export its conversation history through the Service. Deletion requests received via Meta's data deletion callback are executed within 30 days and confirmed to the platform. Backups containing deleted data are overwritten within the regular backup rotation of at most 35 days.
9. Liability and precedence
Liability is governed by the Service contract. In case of conflict, this DPA prevails over the Terms of Service for matters of data protection. Mandatory provisions of the GDPR remain unaffected.
Annex: Technical and organisational measures
Confidentiality
- Production access restricted to named administrators; two-factor authentication mandatory; access reviewed quarterly and revoked on role change.
- Role-based access within the Service; tenant separation enforced at the data layer so that no customer can read another customer's data.
- Platform access tokens stored encrypted; secrets held outside the code base and never logged.
- Encryption in transit (TLS 1.2+, HSTS) and at rest (disk-level encryption on all storage).
Integrity
- Webhook payloads verified by platform signature (HMAC) before processing.
- Every send is attributed to an approval or a rule and logged with time, actor and content.
- Change management: code review, staged deployment, versioned configuration.
Availability and resilience
- Daily encrypted backups stored in Germany, retention 35 days, restore tested quarterly.
- Monitoring of service health and channel delivery with alerting to on-call staff.
- Rate limiting and firewalling at the network edge; automatic security updates for the operating system.
Procedures
- Data protection by design: minimisation of data sent to AI providers (conversation excerpt and instructions only), no training use, no advertising use.
- Documented incident response with 48-hour notification to Controllers.
- Deletion concept with defined retention periods (see Privacy Policy) and automated purge jobs.
- Staff instructed on confidentiality and data protection on joining and annually.