Legal
Data Processing Agreement
Agreement under Art. 28 GDPR with technical and organisational measures and sub-processors.
Data Processing Agreement (DPA)
As of: 14 September 2026
This English version is provided for convenience. Only the German version is legally binding.
Agreement on the processing of personal data on behalf of a controller pursuant to Art. 28 of the General Data Protection Regulation (GDPR) between the Customer as controller (hereinafter "Controller") and gh0stservice GmbH, Else-Lang-Str. 10, 50858 Köln, Germany, as processor (hereinafter "Processor").
1. Subject matter and application
- This agreement governs the rights and obligations of the parties to the extent that the Processor processes personal data on behalf of the Controller in the course of the services gh0stcloud Self-Service, Managed Packages or Consulting (hereinafter "Main Contract").
- This agreement is concluded electronically upon conclusion of the Main Contract (Art. 28(9) GDPR) and applies for the term of the Main Contract and beyond, for as long as the Processor processes personal data of the Controller.
- The subject matter, nature and purpose of the processing, the type of data and the categories of data subjects are described in Annex 1. In the event of conflicts, this agreement takes precedence over the Main Contract and the GTC in matters of data protection.
2. Instructions
- The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless it is required to do so by Union or Member State law. In such a case, it informs the Controller of that legal requirement before processing, unless that law prohibits such information.
- Documented instructions are the Main Contract, this agreement, the configuration that the Controller makes via the portal, gh0stcli, application programming interfaces or its Git repository, and individual instructions in text form.
- If the Processor considers that an instruction infringes data protection provisions, it informs the Controller without undue delay. It may suspend execution of the instruction until the Controller confirms or changes it.
3. Confidentiality
The Processor ensures that all persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access is granted only to persons who need it to provide the services.
4. Security of processing
- The Processor implements the technical and organisational measures pursuant to Art. 32 GDPR described in Annex 2.
- The measures are subject to technical progress. The Processor may develop them further, provided that the level of protection is not reduced. It documents material changes.
- The Controller is responsible for the security of the applications, configurations and access that it operates and controls itself on the platform.
5. Sub-processors
- The Controller grants general authorisation to engage sub-processors. The sub-processors engaged at the time the agreement is concluded are listed in Annex 3; their engagement is deemed approved.
- The Processor informs the Controller at least 30 days before engaging a new sub-processor or replacing a sub-processor, in text form to the email address stored in the account, and updates Annex 3. The Controller may object in text form within this period for good cause relating to data protection. The parties will then endeavour to find a mutually agreeable solution. If this is not possible, the Controller may terminate the Main Contract with effect from the date of the planned engagement.
- External operations specialists whom the Processor may call in to provide cover or in the event of incidents receive access to personal data of the Controller only with the Controller's prior consent in the individual case.
- The Processor contractually imposes on each sub-processor the same data protection obligations as set out in this agreement, in particular sufficient guarantees for appropriate technical and organisational measures. It is liable to the Controller for the sub-processor's compliance with these obligations.
- Ancillary services that involve no access to personal data of the Controller, such as telecommunications services or the issuance of TLS certificates on the basis of hostnames, do not constitute sub-processing.
6. Place of processing and third-country transfers
Processing takes place exclusively in data centres in Germany. Processing outside the European Union or the European Economic Area takes place only with the prior consent of the Controller in text form and in compliance with Art. 44 et seq. GDPR.
7. Assistance to the Controller
- The Processor assists the Controller by appropriate technical and organisational measures in responding to requests from data subjects (Art. 12 to 23 GDPR). If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay.
- Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in ensuring compliance with the obligations under Art. 32 to 36 GDPR (security, notification of breaches, data protection impact assessment, prior consultation).
- The Processor may charge at the agreed hourly rate for assistance that goes beyond providing the functions of the platform and the information referred to in this agreement and that does not result from a breach by the Processor.
8. Personal data breaches
- The Processor notifies the Controller of a personal data breach without undue delay, and at the latest within 48 hours after becoming aware of it.
- The notification contains, where known, the information pursuant to Art. 33(3) GDPR: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken and proposed, and a contact point. Information that is not immediately available is provided in phases.
- The Processor takes the necessary measures without undue delay to contain the breach and to mitigate its adverse effects.
9. Deletion and return
- After the end of the provision of services, the provisions on switching providers and data transfer in the GTC (clause 12) apply first. The Controller can then retrieve its data for at least 30 calendar days.
- After this period expires, the Processor deletes all personal data of the Controller, unless Union or Member State law requires storage. Backup copies are overwritten in the regular rotation cycle no later than 30 days after deletion.
- On request, the Processor confirms the deletion in text form.
10. Evidence and audits
- The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR, in particular this agreement with its annexes, a current description of the technical and organisational measures and existing evidence from its sub-processors.
- The Controller, or an auditor mandated by the Controller who is bound to confidentiality and is not a competitor of the Processor, may conduct audits, including inspections. On-site audits must be announced at least 30 days in advance, take place during business hours and must not jeopardise operations or the confidentiality of other customers' data. Except where there are specific indications of a violation or following a personal data breach, they are limited to once per calendar year.
- The Controller bears the costs of an audit, unless the audit reveals a material violation by the Processor.
- The rights of the supervisory authorities remain unaffected.
11. Liability
Liability is governed by Art. 82 GDPR. Otherwise, the liability provisions of the Main Contract apply to the extent that Art. 82 GDPR does not preclude this.
12. Final provisions
- Amendments and additions to this agreement require text form. For amendments proposed by the Processor, clause 17 of the GTC applies accordingly.
- German law applies. Should individual provisions be invalid, the remainder of the agreement remains valid.
Annex 1: Description of the processing
Subject matter and purpose: Provision and operation of the gh0stcloud platform for running the Controller's applications, including compute, storage, databases, networking, certificates, secrets management, monitoring, logging, data backup and support. For Managed Packages, additionally the setup, updating, monitoring, backup and restoration of the managed applications in accordance with the service description. For Consulting, access to the Controller's systems to the extent required for the engagement.
Nature of the processing: storage, organisation, backup, restoration, transfer, retrieval in the course of support and error analysis, erasure.
Duration: term of the Main Contract plus the periods under clause 9.
Categories of data subjects: determined by the Controller; typically employees, users of its applications, customers, prospective customers, suppliers and other contact persons of the Controller.
Type of personal data: determined by the Controller; typically contact and master data, usage and log data of its applications, content and files, communication data, contract and billing data of its own customers. Special categories of personal data (Art. 9 GDPR) are processed only if the Controller introduces them into its applications; in that case, the Controller assesses whether the measures described are appropriate for them.
Places of processing: data centres of Hetzner Online GmbH in Germany.
Annex 2: Technical and organisational measures (Art. 32 GDPR)
1. Confidentiality
Physical access control
- The systems run exclusively in data centres of Hetzner Online GmbH in Germany, which are certified to ISO/IEC 27001 and have access control systems, video surveillance and security personnel.
- The Processor does not operate its own server rooms in which data of the Controller is processed.
System access control
- Central sign-in via Keycloak with personal accounts; no shared administration accounts.
- Multi-factor authentication is mandatory for all administrative access, in particular for Keycloak, Hetzner administration, GitLab and secrets management.
- Administrative access to the clusters takes place via an encrypted private network (WireGuard-based).
- Automatic termination of inactive sessions.
Data access control
- Role and authorisation concept based on the principle of least privilege.
- Credentials, keys and tokens are stored in a central secrets management system (OpenBao) with access rights restricted to individual projects.
- Customers do not receive administrator rights at cluster level.
Separation control
- Applications of different customers run in separate namespaces with network rules that block traffic between tenants by default.
- Admission policies for workloads enforce secure defaults, including running without root privileges and resource limits.
- Development and production environments run in separate clusters.
Pseudonymisation
- Internal processing, such as billing and metrics, uses technical identifiers instead of plain names where possible.
2. Integrity
Transfer control
- Public endpoints are accessible exclusively via TLS; certificates are renewed automatically.
- Administrative connections run over encrypted channels.
Input control
- Changes to the platform and applications are made via Git with a complete version history (GitOps); deviations from the defined state are automatically reverted.
- Audit logs of the Kubernetes application programming interfaces are retained for 12 months; sign-in events are logged.
3. Availability and resilience
- Backup of databases and persistent data to object storage in Germany, for Managed Packages in accordance with the service description.
- Operation on multiple servers with automatic restart and relocation of failed components.
- Automated monitoring around the clock with alerting.
- Protection against volumetric attacks by the infrastructure of the data centre operator.
4. Recoverability
- Documented restoration procedures.
- Restoration tests for Managed Packages at the intervals agreed there.
5. Procedures for regular review
- Automated monitoring of dependencies for new versions and security vulnerabilities, with a reviewed update process.
- Procedures for handling security incidents and for notifying personal data breaches.
- Procedures for receiving and handling reported security vulnerabilities.
- Review of these measures at least annually and in the event of material changes.
- Commitment of all employees to confidentiality and data protection.
Annex 3: Sub-processors
| Sub-processor | Service | Place of processing | Data concerned |
|---|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | data centre operation, servers, storage, object storage for backups | Germany | all data that the Controller processes on the platform |
No transfer to third countries takes place. The Processor operates all other systems itself on this infrastructure.
In individual cases, subject to consent: external operations specialists (natural persons established in the European Union) for cover and incident resolution, see clause 5.3.