Skip to content

Data Processing Agreement

Under Art. 28 GDPR – annex to the General Terms and Conditions

This is a courtesy translation. The German version of this document is the legally binding one.

When we operate or maintain a website for you, we process personal data on your behalf. This agreement sets out what we may and may not do with that data. You as the client are the controller within the meaning of the GDPR; we are the processor.

Version: September 2026

§ 1 Subject matter, duration and order of precedence

The processor is Elvis Ayong, Kitmon360 – Webdesign (sole proprietorship), Düppelstraße 15, 45897 Gelsenkirchen, Germany. The controller is the client under the underlying main contract.

The subject matter of the processing is the operation, hosting and maintenance of the website created for the controller, including the data arising in that context.

The term of this agreement corresponds to the term of the main contract. It ends automatically when the main contract ends.

In the event of conflict between this agreement and the main contract, this agreement prevails insofar as the processing of personal data is concerned.

§ 2 Nature and purpose of processing, types of data, data subjects

The purpose of the processing is to provide and technically operate the controller’s website and to forward enquiries to the controller.

The following types of personal data are processed in particular:

  • contact and master data from forms: name, email address, telephone number, message text
  • usage data from server logs: IP address, time of access, address requested, volume of data transferred
  • where agreed: appointment and booking data

The categories of data subjects are visitors to the website, prospective and existing clients of the controller and, where the website includes an application form, job applicants.

Special categories of personal data under Art. 9 GDPR are not processed unless the parties expressly agree otherwise separately in text form.

§ 3 Right to issue instructions

The processor processes personal data solely on documented instructions from the controller, unless required to process by Union or Member State law. In that case the processor informs the controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.

Instructions are given in text form. The underlying main contract and this agreement constitute the initial instruction.

The processor informs the controller without undue delay if, in its opinion, an instruction infringes data protection law. The processor is entitled to suspend performance of the instruction concerned until it is confirmed or amended.

§ 4 Confidentiality

The processor carries out the processing itself. Where it engages employees or other persons, it binds them to confidentiality before they begin work, unless they are already subject to a statutory duty of confidentiality.

The confidentiality obligation continues to apply after this agreement ends.

§ 5 Technical and organisational measures

The processor implements the measures required under Art. 32 GDPR to ensure a level of protection appropriate to the risk. These include in particular:

  • encrypted transmission of all connections via TLS (HTTPS); requests over unencrypted connections are redirected
  • encrypted storage of data at the hosting service provider used
  • access to production systems only via personal accounts with two-factor authentication
  • separation of different clients’ projects from one another
  • regular automated backups and testing of restorability
  • prompt installation of security-relevant updates to the software used
  • logging of administrative access and changes
  • data minimisation by default: no analytics cookies and no tracking services are used unless expressly agreed with the controller
  • a defined procedure for deleting data after the contract ends
  • review and evaluation of the effectiveness of these measures at least once a year

The processor may adapt the measures during the term of the agreement provided the level of protection is not reduced.

§ 6 Sub-processors

The controller consents to the engagement of the following sub-processors:

  • Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA – hosting and delivery of the website

The processor provides the controller, on request and in text form, with the current and complete list of sub-processors engaged, including the providers of the email mailbox and domain management.

If the processor intends to engage a further sub-processor or replace an existing one, it notifies the controller in text form at least four weeks in advance. The controller may object within two weeks on important data protection grounds. If it objects and no mutually acceptable solution is found, either party may terminate the main contract on one month’s notice.

The processor imposes on every sub-processor data protection obligations equivalent to those in this agreement.

§ 7 Processing in third countries

Personal data is processed outside the European Union or the European Economic Area only where the requirements of Art. 44 to 49 GDPR are met.

Where a sub-processor processes data in a third country, the transfer is based on an adequacy decision of the European Commission or on standard contractual clauses together with any supplementary measures required.

The website is delivered from locations within the European Union where possible.

§ 8 Assistance with data subject rights

The processor assists the controller by appropriate technical and organisational measures in responding to requests from data subjects under Art. 12 to 23 GDPR.

If a data subject contacts the processor directly, the processor forwards the request to the controller without undue delay and does not respond to it itself.

The processor provides information to third parties or data subjects only on prior instruction from the controller.

§ 9 Assistance with security, notification duties and impact assessment

The processor assists the controller in complying with the obligations under Art. 32 to 36 GDPR, in particular regarding security of processing, notification of personal data breaches and data protection impact assessments.

If the processor becomes aware of a personal data breach, it notifies the controller without undue delay, as a rule within 24 hours of becoming aware, and shares the circumstances known to it.

§ 10 Evidence and audits

On request, the processor makes available to the controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR.

The controller may satisfy itself of compliance during normal business hours after giving reasonable prior notice. Any audit must not unreasonably disrupt operations.

Evidence may also be provided by submitting appropriate certifications, attestations or reports from independent bodies, including those of the sub-processors engaged.

§ 11 Deletion and return after the agreement ends

After this agreement ends, the processor either returns the processed data to the controller or deletes it, at the controller’s choice.

The controller communicates its choice in text form within 30 days of the end of the agreement. If it makes no choice, the processor deletes the data once that period expires.

Where statutory retention obligations exist, the data concerned remains stored until the relevant period expires; processing is restricted accordingly.

Backup copies are deleted as part of the usual backup cycles.

§ 12 Liability and final provisions

Art. 82 GDPR governs liability. As between the parties, the liability provisions of the main contract apply in addition.

Amendments and additions to this agreement must be made in text form.

The law of the Federal Republic of Germany applies. The place of jurisdiction is the processor’s registered office, provided the controller is a merchant, a legal entity under public law or a special fund under public law.

Should any provision of this agreement be or become invalid, the validity of the remaining provisions remains unaffected. The statutory provision takes the place of the invalid provision.