Data Processing Agreement (Art. 28 GDPR)

37 sectionsapprox. 26 min read
Contents

As of June 2026

Note on the authoritative language: This English text is a non-binding convenience translation. The legally binding and authoritative version is the German original (available at regfish.de/legal/dpa). In the event of any discrepancy between this translation and the German version, or in the event of a dispute, the German version shall prevail. This data processing agreement (hereinafter the β€žDPA" or the β€žAgreement") sets out in concrete terms the data protection obligations of the contracting parties in connection with the processing of personal data carried out in the context of the main contract concluded between the parties for the services designated below.

between

regfish GmbH, Bleichstraße 8a, 35390 Gießen, Germany (hereinafter β€žregfish", β€žthe processor" or β€žwe")

and

the customer in accordance with the master data of the respective customer account (hereinafter the β€žcustomer", β€žthe controller" or β€žyou") (hereinafter jointly the β€žparties" and individually a β€žparty") Note on linguistic form: For ease of reading, the masculine linguistic form is predominantly used in the following. This is always intended to refer equally to all customers irrespective of gender.

Β§ 1 Subject matter, scope and order of precedence

(1) The subject matter of this Agreement is the processing of personal data by regfish on behalf of and in accordance with the instructions of the customer within the meaning of Art. 28 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter the β€žGDPR"). In this respect, regfish acts as the processor and the customer as the controller. (2) This Agreement applies to all services in which regfish processes personal data for the customer on the customer's instructions without any purpose of its own, namely: – web hosting and WordPress hosting (storage and processing of the content uploaded by the customer, including the personal data of third parties contained therein), – e-mail services (mailboxes and e-mail forwarding), – DNS services (DNS hosting, DNSSEC, DynDNS, hidden primary, DNS automation), – web forwarding (HTTP forwarder), – the public application programming interface (API) for DNS and TLS automation, insofar as personal data of the customer is processed through it. The processing description contained in Annex 1 sets out in concrete terms the subject matter, nature, purpose, types of data, categories of data subjects and duration of the processing. (3) The following are not covered by this Agreement and are expressly excluded: – the registration, transfer and renewal of domains: The transmission of the domain holder and contact data (in particular the holder and the administrative and technical contact) to the respective registry (e.g. DENIC eG, EURid, nic.at, Nominet) is based on a separate legal and contractual obligation of regfish and the registry. In this respect, regfish and the registry act as separate or joint controllers and not as processors. – the issuance of TLS/SSL and other certificates (DV, OV, EV, wildcard, SAN, S/MIME, code signing): The processing of the application data is carried out by the issuing certification authority (CA, e.g. DigiCert, Sectigo, GeoTrust, Thawte, RapidSSL) in accordance with the requirements of the CA/Browser Forum as its own controller. regfish merely brokers these services. The processing of the aforementioned data is presented in the privacy policy (available at regfish.de/legal/privacy) as separate or joint controllership. (4) In relation to the other contractual documents, the following order of precedence applies in matters of data protection; in the event of conflicts, the document with the higher precedence shall prevail: – an individual arrangement agreed between the parties, – this data processing agreement, – the additional terms and service descriptions (available at regfish.de/legal/additional-terms), – the service level agreement (SLA, available at regfish.de/legal/sla), – the general terms and conditions (available at regfish.de/legal/terms), – the acceptable use policy (AUP, available at regfish.de/legal/acceptable-use). In all matters of data protection, this DPA shall take precedence over the general terms and conditions and the acceptable use policy. (5) This Agreement applies exclusively to business customers within the meaning of section 14 of the German Civil Code (BGB) as well as to legal persons under public law and special funds under public law. It is not directed at consumers within the meaning of section 13 BGB.

Β§ 2 Nature, purpose, scope and duration of the processing

(1) The nature, purpose and scope of the processing, the type of personal data and the categories of data subjects are set out conclusively in Annex 1 to this Agreement. (2) The processing takes place within the territory of the European Union or the European Economic Area. Processing in a third country shall only take place under the conditions set out in Β§ 11 of this Agreement and within the framework of the engagement of further processors in accordance with Β§ 7 and Annex 3. (3) The duration of the processing corresponds to the term of the main contract for the respective service. This DPA ends upon termination of the last main contract concerned, without prejudice to obligations that continue to have effect pursuant to Β§ 9 and Β§ 4 paragraph 3.

Β§ 3 Processor bound by instructions

(1) regfish processes personal data solely on documented instructions from the customer, including with regard to the transfer of personal data to a third country or an international organisation. This does not apply where regfish is required to process the data by Union law or the law of a Member State to which regfish is subject; in such a case, regfish shall inform the customer of that legal requirement before processing, unless the law in question prohibits such information on important grounds of public interest. (2) The determinations underlying this Agreement, its annexes and the main contract are deemed to be the customer's initial instructions. The customer's use of the technical functions, configuration interfaces and the API made available by regfish is deemed to be an individual instruction within the framework of the contractually agreed services. (3) Instructions that go beyond the contractually agreed service shall be issued in text form (e.g. by e-mail to support@regfish.de) and are binding on regfish, unless regfish objects to them on the grounds set out in paragraph 4. The customer shall confirm oral instructions in text form without undue delay. (4) If regfish is of the opinion that an instruction infringes the GDPR or other data protection provisions of the Union or the Member States, regfish shall inform the customer without undue delay. regfish is entitled to suspend the execution of the instruction in question until it has been confirmed or amended by an authorised contact person of the customer. This obligation to provide notice cannot be waived by the parties. (5) Each party shall designate the persons authorised to issue and receive instructions. Changes shall be notified to the other party in text form.

Β§ 4 Confidentiality

(1) regfish places the persons authorised to process the personal data under an obligation of confidentiality, insofar as they are not already subject to an appropriate statutory duty of confidentiality. (2) regfish ensures that the persons involved in the processing are familiar with the relevant data protection provisions and are instructed in accordance with their duties. (3) The obligation of confidentiality continues to apply after the termination of this Agreement and after the departure of the persons concerned.

Β§ 5 Technical and organisational measures (Art. 32 GDPR)

(1) regfish takes the technical and organisational measures (hereinafter β€žTOM") necessary for the security of the processing in accordance with the state of the art, taking into account the costs of implementation as well as the nature, scope, circumstances and purposes of the processing and the varying likelihood and severity of the risk to the rights and freedoms of natural persons. (2) The measures taken at the time of conclusion of the Agreement are described in Annex 2. The customer acknowledges these measures as appropriate. (3) The TOM are subject to technical progress and further development. regfish is entitled to adapt and further develop the TOM, provided that the agreed level of protection is not thereby reduced. Material changes shall be documented; the respective current version of Annex 2 shall be made available to the customer upon request.

Β§ 6 Support for the controller

(1) regfish supports the customer, to the extent reasonable and taking into account the nature of the processing and the information available to regfish, by appropriate technical and organisational measures in the fulfilment of the customer's obligation to respond to requests from data subjects to exercise their rights under Chapter III of the GDPR (Art. 12 to 23 GDPR). (2) If a data subject contacts regfish directly to exercise their rights, regfish shall forward this request to the customer without undue delay and shall not respond to it itself, unless the customer has issued a differing instruction to this effect. (3) regfish further supports the customer in complying with the obligations set out in Art. 32 to 36 GDPR, in particular in ensuring the security of the processing, in notifying personal data breaches (Β§ 8 of this Agreement), in carrying out data protection impact assessments (Art. 35 GDPR) and in any prior consultation of the supervisory authority (Art. 36 GDPR). (4) regfish provides the cooperation mandatorily owed under Art. 28(3)(e), (f) and (h) GDPR free of charge. For support services that go beyond the cooperation legally owed or beyond the services agreed in the main contract, regfish may demand reasonable remuneration at the hourly rate applicable from time to time in accordance with the price list (available at regfish.de/legal/additional-terms), unless the service is based on a circumstance attributable to regfish. regfish shall give notice of any expense arising before performance.

Β§ 7 Engagement of further processors (sub-processors)

(1) The customer hereby grants regfish general authorisation for the engagement of further processors (hereinafter β€žsub-processors") within the meaning of Art. 28(2) sentence 1 GDPR. Annex 3 reflects the status of the sub-processors engaged at the time of conclusion of the Agreement. The respective current version, which is available at regfish.de/legal/subprocessors, is authoritative; changes are governed by paragraphs 2 to 4. (2) regfish shall inform the customer of any intended change concerning the addition or replacement of sub-processors in text form, with a reasonable advance notice period of at least fourteen (14) days before the intended engagement. The information shall be provided by notice to the e-mail address stored in the customer account or by announcement on the website referred to in paragraph 1 together with separate notification. (3) The customer may object to the change within the advance notice period in text form, on important grounds related to data protection. If the customer does not object within the period, the change shall be deemed approved. (4) In the event of a justified objection, the parties shall endeavour to reach an amicable solution. If such a solution cannot be reached and the engagement of the sub-processor in question is necessary for the provision of the service, regfish is entitled, and the customer is entitled, to extraordinarily terminate the service affected by the change upon reasonable notice. No further claims shall exist. (5) regfish imposes on each sub-processor by contract the same data protection obligations as are set out in this DPA, in particular the obligation to provide sufficient guarantees of appropriate technical and organisational measures. Where the sub-processor fails to fulfil its data protection obligations, regfish shall remain fully liable to the customer for the performance of that sub-processor's obligations. (6) Services that regfish uses as an ancillary service to support its business activities and in which there is no more than incidental access to the customer's personal data (e.g. telecommunications, cleaning or pure maintenance services) shall not be regarded as sub-processors within the meaning of this paragraph. regfish ensures an appropriate level of protection even for such services.

Β§ 8 Notification of personal data breaches

(1) regfish notifies the customer of any personal data breach of which it becomes aware that has occurred in the context of the processing on behalf of the controller, without undue delay, without culpable hesitation and, as a rule, within forty-eight (48) hours of becoming aware of it. (2) The notification shall contain, insofar as available, the information specified in Art. 33(3) GDPR, in particular a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the name and contact details of the contact person, a description of the likely consequences and of the measures taken or proposed to remedy the breach and to mitigate possible adverse effects. (3) Insofar as not all information can be provided at the same time, regfish shall provide it in phases and without further undue delay. The obligation to notify the supervisory authority (Art. 33 GDPR) and, where applicable, the data subjects (Art. 34 GDPR) lies with the customer as the controller; regfish supports the customer in this respect pursuant to Β§ 6 paragraph 3.

Β§ 9 Erasure and return after the end of the processing

(1) After the provision of the processing services has been completed, regfish shall, at the customer's choice, either erase all personal data or return it to the customer and erase existing copies, unless there is an obligation to store the personal data under Union or Member State law. (2) The customer shall notify regfish of its choice (erasure or return) in text form at the latest upon termination of the main contract concerned. If the customer makes no choice, regfish is entitled to erase the data after the expiry of a reasonable period and after prior request to the customer to secure the data. (3) The return shall be made in a common, machine-readable format or by providing the data for export via the agreed interfaces. Any effort that goes beyond the standard export functions shall be remunerated in accordance with Β§ 6 paragraph 4. (4) Insofar as statutory retention obligations preclude erasure, in particular under section 257 of the German Commercial Code (HGB) or section 147 of the German Fiscal Code (AO), regfish shall store the data concerned until the expiry of the respective period and shall restrict its processing accordingly; upon expiry of the period the data shall be erased. (5) regfish shall provide the customer, upon request, with appropriate evidence of the erasure or return.

Β§ 10 Rights of verification, control and audit

(1) regfish makes available to the customer all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and in this Agreement and allows for and contributes to audits, including inspections, conducted by the customer or an auditor mandated by the customer. (2) regfish provides the evidence primarily by submitting suitable documents, in particular by the description of the TOM in accordance with Annex 2, by current attestations, certifications or reports of independent bodies (e.g. in accordance with ISO/IEC 27001, insofar as available) and by self-disclosures. (3) If the evidence submitted under paragraph 2 is not sufficient to fulfil the customer's control obligation, the customer is entitled to carry out an on-site inspection or to have it carried out by an auditor who is bound to confidentiality and not in a competitive relationship with regfish. The following applies in this respect: – The inspection shall be announced with reasonable advance notice of at least two (2) weeks. – It shall take place during normal business hours and without disproportionate disruption to regfish's operations. – It shall, as a rule, take place no more than once per calendar year; on a specific occasion, in particular following a personal data breach or upon the justified request of a supervisory authority, also more frequently. – The confidentiality of the data of other customers and third parties as well as regfish's trade and business secrets shall be preserved; the auditor may be required to sign a separate confidentiality declaration. (4) regfish may invoice the customer for the reasonable expense incurred by regfish through an inspection under paragraph 3 that goes beyond the customary cooperation, at the hourly rate applicable from time to time in accordance with the price list (available at regfish.de/legal/additional-terms). This does not exclude the customer's right of control and audit; the cooperation mandatorily owed under Art. 28(3)(h) GDPR remains free of charge. (5) regfish shall inform the customer without undue delay if a supervisory authority takes control measures against regfish, insofar as these concern the processing on behalf of the customer.

Β§ 11 Transfer to third countries

(1) A transfer of personal data to a country outside the European Union or the European Economic Area (third country) or to an international organisation shall only take place if the conditions of Art. 44 to 49 GDPR are met and within the framework of the customer's instructions and of the sub-processing permitted under Β§ 7 and Annex 3. (2) A transfer shall primarily be based on an adequacy decision of the European Commission pursuant to Art. 45 GDPR. In the case of a transfer to recipients in the United States of America, this presupposes that the respective recipient is actively certified under the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795). (3) If there is no adequacy decision for the respective transfer or such a decision ceases to apply, or if the recipient is not or is no longer certified under the EU-US Data Privacy Framework, regfish bases the transfer on the standard contractual clauses of the European Commission pursuant to Implementing Decision (EU) 2021/914 of 4 June 2021 in the respective applicable module version, supplemented by a transfer impact assessment and by the necessary additional protective measures (in particular encryption and pseudonymisation). In this case, the standard contractual clauses apply automatically. (4) regfish informs the customer, insofar as legally permissible, of legally binding requests by an authority of a third country, addressed to regfish or a sub-processor, for the disclosure of the personal data processed on behalf of the customer. (5) The transfer basis applicable to the respective sub-processor is set out in Annex 3.

Β§ 12 Responsibility of the customer

(1) The customer is solely responsible, as the controller, for the lawfulness of the processing and for safeguarding the rights of the data subjects. In particular, the customer ensures that a legal basis exists for the processing of the personal data uploaded or transmitted by it. (2) If the customer uses the procured services to provide services to third parties for its part (reseller constellation), the customer remains the direct contractual partner vis-Γ -vis regfish. In this case, the customer is the controller or processor vis-Γ -vis its end customers, and regfish acts vis-Γ -vis the customer as its processor or sub-processor. The customer ensures that the data protection chain of responsibility vis-Γ -vis its end customers is mapped seamlessly; it is entitled and obliged to pass on the obligations of this Agreement in its relationship with its end customers, insofar as this is necessary. (3) The customer shall designate to regfish a contact person for data protection matters, insofar as it has appointed a data protection officer.

Β§ 13 Liability

(1) Art. 82 GDPR applies to the liability of the parties. In the relationship between the parties (internal relationship), the liability provisions of the liability section of the general terms and conditions (Β§ 14 of the general terms and conditions, available at regfish.de/legal/terms) apply in addition, insofar as these do not conflict with mandatory data protection requirements. Any quantitative limitation of liability under the general terms and conditions takes effect exclusively in the internal relationship between the parties; the joint and several liability towards data subjects in the external relationship pursuant to Art. 82 GDPR remains unaffected thereby (paragraph 2). (2) A limitation of liability towards data subjects or supervisory authorities pursuant to Art. 82 and Art. 83 GDPR is neither associated with nor intended by this Agreement. (3) If one party establishes that the other party or a sub-processor is in breach of data protection obligations, the parties shall inform each other without undue delay.

Β§ 14 regfish's data protection officer

(1) regfish has appointed a data protection officer: Rudolf Fiedler, c/o DPP Data Protection GmbH, Zum Gottschalkhof 2, 60594 Frankfurt am Main, telephone +49 69 175366960, e-mail datenschutz@regfish.de. (2) The supervisory authority responsible for regfish is: Der Hessische Beauftragte fΓΌr Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, e-mail poststelle@datenschutz.hessen.de.

Β§ 15 Term, termination and final provisions

(1) This Agreement enters into force upon the effectiveness of the first main contract for a service referred to in § 1 paragraph 2 and ends upon termination of the last main contract concerned. The obligations under § 4 (confidentiality) and § 9 (erasure and return) continue to have effect beyond the end of the Agreement. (2) This Agreement is concluded in text form or in an equivalent electronic format (Art. 28(9) GDPR). Conclusion by electronic confirmation in the customer account or in the ordering process is sufficient and is recognised by both parties. (3) Amendments and supplements to this Agreement and its annexes must be made in text form. This also applies to the waiver of the text form requirement. The updating of Annexes 2 and 3 in accordance with § 5 paragraph 3 and § 7 paragraph 2 remains unaffected thereby. (4) Should individual provisions of this Agreement be or become wholly or partly invalid or unenforceable, the validity of the remaining provisions shall not be affected thereby. The parties shall replace an invalid or unenforceable provision with a valid one that comes as close as possible to the economic and data protection purpose of the invalid provision. (5) The law of the Federal Republic of Germany applies to the exclusion of the UN Convention on Contracts for the International Sale of Goods. Insofar as the customer is a merchant, a legal person under public law or a special fund under public law, the exclusive place of jurisdiction for all disputes arising from or in connection with this Agreement is the registered office of regfish in Gießen, unless another exclusive statutory place of jurisdiction exists. ==============================================================================

Annex 1 to the data processing agreement

Subject matter, nature and purpose of the processing, types of data and categories of data subjects

1. Subject matter of the processing

The subject matter is the provision of the services commissioned by the customer in which regfish processes personal data on the customer's instructions: – web hosting and WordPress hosting, – e-mail services (mailboxes and forwarding), – DNS services (DNS hosting, DNSSEC, DynDNS, hidden primary, DNS automation), – web forwarding (HTTP forwarder), – public API for DNS and TLS automation, insofar as personal data is processed.

2. Nature of the processing

Collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, querying, use, transmission (transmission and resolution of data traffic within the framework of the services), dissemination of provision initiated by the customer, alignment, combination, restriction, erasure and destruction of personal data by automated and non-automated procedures.

3. Purpose of the processing

Provision, operation, maintenance and securing of the commissioned hosting, e-mail, DNS, forwarding and API services as well as the technical administration, troubleshooting and ensuring of operational security necessary for this, in each case within the framework of the customer's instructions.

4. Type of personal data

Depending on the commissioned service and on the content uploaded or transmitted by the customer, the following may be processed: – master and contact data (names, addresses, e-mail addresses, telephone numbers), – content data of the websites, applications and databases operated by the customer, including the personal data of third parties contained therein, – e-mail communication data (sender, recipient, subject, content, metadata), – DNS and configuration data (e.g. host names, zone data, IP addresses), – usage, connection and log data (e.g. access and server logs, IP addresses, timestamps), – authentication and access data (e.g. user identifiers, hashed passwords, API keys), – special categories of personal data pursuant to Art. 9 GDPR only if and insofar as the customer uploads such data into the content operated by it; the processing of such data lies solely within the customer's area of responsibility.

5. Categories of data subjects

– customers of the customer and their prospective customers, – employees, staff and other contact persons of the customer, – end users and visitors of the websites and applications operated by the customer, – communication partners of the customer (in particular in e-mail traffic), – other third parties whose personal data the customer processes within the framework of the services.

6. Duration of the processing

The processing is carried out for the term of the respective main contract plus the periods necessary for erasure or return pursuant to Β§ 9 of the Agreement and for the fulfilment of statutory retention obligations.

7. Place of processing

The hosting and mail infrastructure is operated by regfish itself within the European Union. Processing outside the European Union or the European Economic Area takes place only within the framework of the sub-processing set out in Annex 3 and under the conditions of Β§ 11 of the Agreement. ==============================================================================

Annex 2 to the data processing agreement

Technical and organisational measures pursuant to Art. 32 GDPR regfish maintains the technical and organisational measures described below. They apply in accordance with the respective service and the protection requirements of the data processed; not every measure is equally relevant for every service. The version current at the time of the processing is authoritative in each case; the agreed level of protection is not thereby reduced (Β§ 5 paragraph 3 of the Agreement).

1. Confidentiality

1.1 Physical access control (protection against unauthorised physical access to data processing facilities) – operation of the servers in data centres with controlled access, an access authorisation concept and logging, – electronic access security and video surveillance of the data centres by the respective operators, – visitor regulations and accompaniment of external persons, – securing of regfish's business premises against unauthorised physical access. 1.2 System access control (protection against unauthorised use of systems) – individual user identifiers, no shared accounts for administrative access, – authentication with password policies and two-factor authentication for administrative and customer-side access, – storage of passwords exclusively in hashed form, – automatic locking of sessions after inactivity, – secured and encrypted administration access (e.g. SSH with key authentication, VPN), – blocking of access of departed employees. 1.3 Data access control (protection against unauthorised access to knowledge, alteration and erasure) – a role-based and need-based authorisation concept following the principle of least privilege, – separation of administration and application authorisations, – logging of access and administrative activities, – regular review and adjustment of the authorisations granted. 1.4 Separation control (separate processing of data for different purposes) – multi-tenant separation of the data of different customers at the logical level, – separation of production, test and development systems, – purpose-bound processing separated by mandate. 1.5 Pseudonymisation and encryption – transport encryption of data transmission (TLS) for web, mail and API access, – DNSSEC to secure the integrity and authenticity of DNS responses, insofar as commissioned, – encryption of stored data in accordance with its protection requirements as well as exclusively hashed storage of access data, – pseudonymisation of personal data, insofar as this is possible and appropriate in accordance with the purpose of the processing.

2. Integrity

2.1 Transfer control (protection during transmission and transport) – encrypted transmission of personal data over public networks, – secured interfaces (API) with authentication, – documented procedures for the handover of data to sub-processors. 2.2 Input control (traceability of input, alteration and erasure) – logging of inputs, alterations and erasures in administrative systems, – traceability of by whom data was entered into, altered in or removed from processing systems, – retention of the logs in accordance with an established concept.

3. Availability and resilience

3.1 Availability control – regular, automated data backups with separate storage, – redundant configuration of critical components, – uninterruptible power supply and air conditioning in the data centres, – protective measures against malware and against overload and abuse attacks (including the mitigation of distributed denial-of-service attacks), – monitoring of the systems and status information via status.regfish.de. 3.2 Recoverability – documented procedures for the rapid restoration of the availability of personal data following a physical or technical incident, – review of recoverability from data backups. 3.3 Resilience – configuration of the systems for load peaks and for permanent operation, – capacity and resource monitoring.

4. Procedure for regular review, assessment and evaluation

4.1 Data protection management – designated data protection officer (see Β§ 14 of the Agreement), – internal policies and instruction of staff on data protection, – obligation of staff to confidentiality, – record of processing activities, insofar as required, – processes for handling data subject requests and for the notification of personal data breaches. 4.2 Order control – selection of the sub-processors according to suitability criteria, – contractual obligation of the sub-processors pursuant to Art. 28 GDPR, – review of the sub-processors' compliance with their obligations. 4.3 Review of effectiveness – regular review, assessment and evaluation of the effectiveness of the technical and organisational measures, – adaptation of the measures to the state of the art and to changed risks, – use of certifications or attestations as evidence, insofar as available. ==============================================================================

Annex 3 to the data processing agreement

Register of sub-processors The following sub-processors are generally approved as of June 2026 (Β§ 7 of the Agreement). The respective current version is available at regfish.de/legal/subprocessors. regfish operates the hosting and mail infrastructure itself; in this respect, no external sub-processor is engaged.

1. Stripe Payments Europe, Ltd.

– Purpose: processing of payments (SEPA direct debit and credit card). – Registered office: Ireland (European Union). – Transfer basis: processing within the European Union; a third-country transfer does not, as a rule, take place. Insofar as a transfer to the Stripe group of companies in the United States takes place, the basis under Β§ 11 of the Agreement applies (EU-US Data Privacy Framework, alternatively standard contractual clauses (EU) 2021/914).

2. Intercom R&D Unlimited Company (contracting entity for customers in the European Economic Area)

– Purpose: support and chat function on the website (integration by means of the click-to-load procedure). – Registered office: Ireland (European Union); group-affiliated processing also in the United States of America. – Transfer basis: for processing in the United States, the EU-US Data Privacy Framework (adequacy decision (EU) 2023/1795), alternatively standard contractual clauses (EU) 2021/914 with additional protective measures.

3. Cloudflare, Inc. (contracting entity for customers in the European Economic Area: Cloudflare Ireland Ltd., Ireland)

– Purpose: protection against automated attacks and abusive use by means of the bot protection service Cloudflare Turnstile. – Registered office: Cloudflare, Inc., United States of America; Cloudflare Ireland Ltd., Ireland (European Union). – Transfer basis: insofar as processing takes place in the United States of America, the EU-US Data Privacy Framework (adequacy decision (EU) 2023/1795), alternatively standard contractual clauses (EU) 2021/914 with additional protective measures.

4. Datargo GmbH

– Purpose: customer relationship management (CRM) as well as support and chat function on the website (integration by means of the click-to-load procedure); will in future replace the previous support and chat solution (Intercom, no. 2); until then, both remain in use. – Registered office: Frankfurt am Main, Germany (European Union). – Transfer basis: processing within the European Union; no transfer to a third country takes place.

As of June 2026