Legal
Data Processing Agreement
Version 1 · As of 1 September 2026
1. Parties, subject matter, order of precedence
(1) This agreement supplements the general terms and conditions for the use of Biber DPP (the “Main Contract”) and governs the processing of personal data on behalf of the customer.
(2) The controller within the meaning of Article 4(7) GDPR is the customer. The processor within the meaning of Article 4(8) GDPR is BCCM Inkubator GmbH, Bahnhofstraße 32, 09648 Mittweida, Germany, Amtsgericht Chemnitz, HRB 36502.
(3) If this agreement and the Main Contract conflict, the provisions of this agreement prevail insofar as they concern the processing of personal data. The Main Contract applies in all other respects.
(4) Contact for data protection matters at the processor: datenschutz@biberware.com. A data protection officer does not currently have to be designated under Section 38 of the German Federal Data Protection Act (BDSG).
2. Subject matter, duration, nature and purpose of the processing
(1) The subject matter of the processing is the provision of the Biber DPP platform for creating, managing and publishing digital product passports.
(2) Nature of the processing: collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by publication initiated by the controller, restriction, erasure and destruction.
(3) Purpose of the processing: exclusively the provision of the services agreed in the Main Contract. No processing for the processor's own purposes takes place.
(4) Duration: this agreement runs for the term of the Main Contract. It ends when the Main Contract ends; the provisions on deletion and return survive.
(5) Categories of data subjects:
- employees and other users of the controller,
- contact persons at the controller's suppliers and business partners (supplier users),
- further natural persons whose data the controller enters into product data or documents.
(6) Categories of personal data:
- master and contact data (name, business email address, organisational affiliation, role),
- login and authentication data,
- usage and log data (timestamps, IP address, features accessed, change history),
- personal data that the controller itself enters into product data, free text fields or uploaded documents.
(7) Special categories of personal data under Article 9 GDPR are not subject to the processing. The controller ensures that it does not enter such data into the Platform.
(8) The controller further ensures that it does not enter personal data into content that is carried over into the publicly accessible part of a product passport or into a verifiable credential issued by the Platform, unless there is a legal basis for doing so. The controller is advised that credentials once published or issued to third parties cannot be retrieved from those third parties by the processor.
3. Instructions
(1) The processor processes personal data exclusively on documented instructions from the controller. This also applies to transfers of personal data to a third country or an international organisation.
(2) The services set out in the Main Contract, and the use of the Platform's features by the controller and its users, constitute instructions. Further instructions are issued by the controller in text form to the address named in clause 1(4).
(3) The controller designates the persons authorised to issue instructions and keeps that information up to date. Absent notice to the contrary, the holders of the controller's administrative user accounts are deemed authorised to issue instructions.
(4) If the processor is required by Union or Member State law to carry out processing that is not based on an instruction, it informs the controller before the processing, unless that law prohibits such information on important grounds of public interest.
(5) If the processor considers that an instruction infringes data protection law, it informs the controller without undue delay. It is entitled to suspend execution of the instruction concerned until that instruction is confirmed or amended.
(6) Additional effort on the part of the processor arising from instructions that go beyond the services agreed in the Main Contract is remunerated on a time and materials basis at the processor's rates applicable at the time.
4. Confidentiality
(1) The processor obliges the persons involved in the processing to confidentiality, insofar as they are not already subject to an appropriate statutory duty of confidentiality, and ensures that they process the data only on instructions.
(2) The obligation continues to apply after the activity has ended.
(3) The persons involved in the processing are familiarised with the relevant data protection requirements.
5. Technical and organisational measures
(1) The processor implements the technical and organisational measures under Article 32 GDPR described in Annex 1.
(2) The measures are subject to technical progress. The processor may adapt them provided the agreed level of protection is not reduced. Material changes are documented; the version of Annex 1 in force at any given time is made available.
(3) The processor reviews the effectiveness of the measures regularly.
6. Sub-processors
(1) The controller grants the processor general authorisation to engage further processors under Article 28(2) sentence 1 GDPR. The sub-processors engaged at the time the contract is concluded are listed in Annex 2; the controller consents to their use.
(2) The processor informs the controller in text form at least 30 days before intending to engage a new sub-processor or to replace an existing one.
(3) The controller may object to the change in text form within 14 days of receiving the information, on important data protection grounds. If the objection cannot be resolved by a solution reasonable for both sides, the controller is entitled to terminate the Main Contract for cause with effect from the date the change takes effect. No further claims exist.
(4) The processor concludes a contract with each sub-processor imposing on it essentially the same data protection obligations as those set out in this agreement, in particular sufficient guarantees of appropriate technical and organisational measures. If the sub-processor fails to fulfil its data protection obligations, the processor remains liable to the controller for the performance of those obligations.
(5) Ancillary services that the processor obtains from third parties and that are not directed at processing the controller's personal data, such as telecommunications, cleaning or maintenance services, do not constitute sub-processing. The processor also takes appropriate measures to protect the data in these cases.
7. Assistance with data subject rights
(1) The processor assists the controller by appropriate technical and organisational measures in fulfilling requests from data subjects under Articles 15 to 22 GDPR. For this purpose the Platform provides features for access, rectification, export in a structured, commonly used and machine-readable format, and erasure.
(2) If a data subject contacts the processor directly, the processor does not answer the request itself but forwards it to the controller without undue delay.
(3) Assistance beyond the features of the Platform is remunerated on a time and materials basis.
8. Assistance with Articles 32 to 36 GDPR
Taking into account the nature of the processing and the information available to it, the processor assists the controller in complying with the obligations under Articles 32 to 36 GDPR, in particular with security of processing, data protection impact assessments and prior consultation of the supervisory authority. Clause 7(3) applies accordingly.
9. Notification of personal data breaches
(1) The processor notifies the controller of any personal data breach without undue delay after becoming aware of it, as a rule within 24 hours.
(2) The notification contains, where available, a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Missing information is supplied subsequently.
(3) The processor takes the necessary measures to secure the data and mitigate adverse effects without undue delay, and documents the incident.
(4) Notifications to the supervisory authority or to data subjects are made by the controller alone.
10. Deletion and return after termination
(1) After the Main Contract ends, the processor deletes the personal data processed on behalf of the controller or returns it, at the controller's choice.
(2) The controller may retrieve the data within 30 days after the contract ends via the Platform's export function. If it does not communicate a different choice before that period expires, the processor deletes the data after the period expires. Backup copies are deleted at the latest on their regular expiry, and no later than 90 days after the contract ends.
(3) Excluded from deletion is data subject to a statutory retention obligation or required for the establishment, exercise or defence of legal claims (Article 17(3) GDPR), in particular evidence of the conclusion of the contract and of acceptance of this agreement, as well as billing records. Processing of such data is restricted accordingly.
(4) The processor confirms deletion in text form on request.
11. Evidence and audits
(1) On request, the processor demonstrates compliance with the obligations under this agreement in an appropriate manner, in particular by submitting documentation of the technical and organisational measures, by self-assessments, or by certificates, attestations and audit reports of independent bodies, including those of its sub-processors.
(2) If that evidence is insufficient in an individual case, the controller or an auditor appointed by it may carry out an audit during normal business hours after giving at least four weeks' prior notice. Audits take place at most once per calendar year, unless there is specific cause.
(3) Audits are carried out in a way that does not unreasonably impair operations. The appointed auditor must not be a competitor of the processor and must be bound to confidentiality.
(4) The controller bears the processor's effort for audits under paragraph 2, unless the audit reveals a material breach of this agreement by the processor.
12. Processing in third countries
(1) Processing takes place in principle in the European Union or the European Economic Area.
(2) Where a sub-processor processes data in a third country or can access data from there, this takes place only on the basis of an adequacy decision under Article 45 GDPR or appropriate safeguards under Article 46 GDPR, in particular the European Commission's standard contractual clauses, in each case supplemented by any necessary additional measures.
(3) The applicable basis is stated in Annex 2.
13. The processor acting as its own controller
The processor is its own controller for processing it does not carry out on behalf of the customer, in particular for contract initiation and administration, billing and accounting, fulfilment of its own statutory obligations, and the evaluation of security-relevant log data to defend against attacks and to assert its own legal claims. The processor's privacy policy applies to that processing.
14. Liability
(1) The liability provisions of the Main Contract govern liability between the parties, unless otherwise provided below.
(2) Article 82 GDPR and liability towards data subjects and supervisory authorities remain unaffected.
15. Final provisions
(1) Amendments and supplements to this agreement require text form. This also applies to any change to this clause.
(2) Should individual provisions be or become invalid, the validity of the remaining provisions remains unaffected.
(3) The law of the Federal Republic of Germany applies. The place of jurisdiction is the processor's registered seat, insofar as the controller is a merchant, a legal entity under public law or a special fund under public law.
Annex 1: Technical and organisational measures under Article 32 GDPR
As of 1 September 2026
Confidentiality
Physical access control
Operations take place in the data centres of the infrastructure providers used. Physical access protection is ensured by those providers (access control systems, video surveillance, security personnel, logging). The processor does not operate its own data centres.
System access control
- Authentication exclusively via a dedicated identity provider (OIDC)
- Multi-factor authentication for administrative access
- Password policies, lockout after failed login attempts
- Administrative access to servers and databases exclusively over network paths that are not publicly reachable, using key-based authentication; no password login
- Encrypted storage of operational secrets (SOPS/age)
- Workstations with full-disk encryption and automatic screen lock
Data access control
- Role-based authorisation model down to field level
- Authorisations granted on the principle of least privilege
- Separation of administrative and application roles
- Access to production data by the processor's staff only where required to remedy a specific fault
- Logging of security-relevant events and administrative access
Separation control
- Tenant separation at application and database level
- Separate environments for development, test and production
- No use of production data in test and development environments
Pseudonymisation and data minimisation
- Collection limited to what is required for operations
- Reduction and filtering of personal content in error and diagnostic data
- Limited retention period for log data
Integrity
Transfer control
- Transport encryption (TLS) for all external connections
- Encrypted database connections (
sslmode=verify-full) - Encryption of data at rest at the infrastructure provider level
- No transfer of personal data on mobile storage media
Input control
- Logging of creation, modification and deletion of business records with timestamp and user reference
- Traceable versioning of published product passports
Availability and resilience
- Regular, automated backup of the databases by the managed service provider
- Regular verification of restorability
- Redundant infrastructure and system monitoring with alerting
- Protective measures against overload and abuse (rate limiting)
- Prompt installation of security updates, automated dependency scanning
Procedures for regular review, assessment and evaluation
- Data protection management with a record of processing activities and a deletion concept
- Staff bound to confidentiality and given data protection training
- Supplier control: selection of sub-processors against data protection criteria, contractual commitment, regular review
- Process for handling security incidents and notification under clause 9
- Data protection considered when developing new features (privacy by design and by default), code review before promotion to production
Annex 2: Sub-processors
As of 1 September 2026
The Platform's error diagnostics run on the processor's own infrastructure and are therefore not a sub-processor.
| Company | Seat | Service | Place of processing | Basis for third-country transfer |
|---|---|---|---|---|
| Hetzner Online GmbH | Germany | Server infrastructure, object storage for documents, DNS | Falkenstein, Germany | no third-country transfer |
| Aiven Oy | Finland | Managed PostgreSQL and managed Valkey (cache), operated on infrastructure of UpCloud Ltd. (Finland) | Frankfurt am Main, Germany | no third-country transfer |
| CAOS Ltd. (Zitadel Cloud) | Switzerland | Identity and access management | EU | Adequacy decision for Switzerland under Art. 45 GDPR |
| Brevo (Sendinblue SAS) | France | Transactional email (invitations, system notifications) | France | no third-country transfer |