Data Processing Agreement

Pursuant to Art. 28 GDPR · Version 1.0 · 9 September 2026

This agreement ("DPA") is part of the Terms of Service between the Customer ("Controller") and Foth Group GmbH, Seehofstraße 137, 14167 Berlin ("Processor"). It applies whenever the Processor processes personal data on behalf of the Controller in the course of providing the sparevoice service.

1. Subject matter, duration, nature and purpose

2. Types of data and categories of data subjects

Data subjects: end users who communicate with the Controller through connected channels; the Controller's own staff using the Service.

Data types: platform user IDs and public usernames or display names; message and comment content including attachments provided by the platform; timestamps and conversation metadata; reply drafts and sent replies; derived tags, summaries and detected language; settings and instructions entered by the Controller's staff.

The Service is not designed for special categories of data (Art. 9 GDPR). Where end users volunteer such data in a message, it is processed only as part of the conversation and under the same protections.

3. Instructions

The Processor processes personal data only on the Controller's documented instructions. The Service contract, this DPA and the settings the Controller configures in the Service (channels, modes, active hours, selectivity, per-contact rules, approvals) constitute those instructions. The Processor informs the Controller without delay if it believes an instruction infringes data protection law.

4. Obligations of the Processor

  1. Ensure that persons authorised to process the data are bound by confidentiality.
  2. Implement and maintain the technical and organisational measures in the Annex.
  3. Engage sub-processors only under Section 5.
  4. Assist the Controller, by appropriate technical and organisational measures, in responding to data subject requests (Art. 12–23 GDPR).
  5. Assist the Controller in complying with Art. 32–36 GDPR, taking into account the nature of the processing and the information available.
  6. Notify the Controller without undue delay, and no later than 48 hours after becoming aware, of a personal data breach affecting the Controller's data, with the information required by Art. 33 (3) GDPR as it becomes available.
  7. Delete or return all personal data at the end of the Service as set out in Section 8.
  8. Make available all information necessary to demonstrate compliance with Art. 28 GDPR and allow for and contribute to audits under Section 7.

5. Sub-processors

The Controller grants general authorisation to engage the sub-processors listed below. The Processor imposes on each sub-processor data protection obligations equivalent to this DPA and remains fully liable for their performance.

Sub-processorServiceLocation / transfer mechanism
Hetzner Online GmbHHosting, storage, backupsGermany
Anthropic PBCAI generation of drafts, summaries, classificationsUSA — EU SCCs, transfer impact assessment
OpenAI, L.L.C.AI generation of drafts (secondary model)USA — EU SCCs, transfer impact assessment
Stripe Payments Europe, Ltd.Payment processing (Controller's account data only)Ireland / USA — EU SCCs

Meta Platforms Ireland Ltd. and other connected platforms act as independent controllers for processing on their own services and are not sub-processors.

The Processor will inform the Controller at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if no solution is found, the Controller may terminate the affected part of the Service without penalty.

6. International transfers

Personal data is stored in Germany. Transfers to sub-processors in third countries take place only under Chapter V GDPR, currently on the basis of the EU Standard Contractual Clauses (2021/914) supplemented by a transfer impact assessment and additional safeguards (encryption in transit, minimisation of transferred content, contractual prohibition of training use).

7. Audits

The Controller may verify compliance once per year, or additionally after a data breach, by requesting documentation (including current certifications or audit reports of sub-processors) and, where documentation is insufficient, by an on-site or remote audit during business hours with 30 days' notice, conducted in a manner that does not unreasonably disrupt operations or expose other customers' data.

8. Deletion and return

On termination of the Service, or on disconnection of a channel, the Processor deletes the associated personal data within 30 days unless Union or Member State law requires longer storage. Before that, the Controller may export its conversation history through the Service. Deletion requests received via Meta's data deletion callback are executed within 30 days and confirmed to the platform. Backups containing deleted data are overwritten within the regular backup rotation of at most 35 days.

9. Liability and precedence

Liability is governed by the Service contract. In case of conflict, this DPA prevails over the Terms of Service for matters of data protection. Mandatory provisions of the GDPR remain unaffected.

Annex: Technical and organisational measures

Confidentiality

Integrity

Availability and resilience

Procedures