Data Processing Agreement (DPA)

Agreement on the processing of personal data on behalf of a controller pursuant to Art. 28 GDPR

between the customer registered with Bold Bloom, whose company, legal form, address and, where applicable, authority to represent follow from the company details stored during registration — as the controller, hereinafter "AG" (Auftraggeber) —

and Julia Kalder, c/o Autorenglück #80461, Albert-Einstein-Str. 47, 02977 Hoyerswerda — as the processor, hereinafter "AN" (Auftragnehmer) —

— together referred to as the "Parties" —

This English version is a courtesy translation. In the event of discrepancies, the German version prevails.

Preamble

(1) The AG has engaged the AN to provide and operate the Bold Bloom software service supporting coaching, team and organisational development processes. Processing takes place on the basis of the user, team, client and other content data entered, uploaded, selected or supplied via interfaces by the AG, in particular coaching and session notes, files, appointment, mood and feedback data.

(2) Part of performing the contract is the processing of personal data. Art. 28 GDPR in particular imposes certain requirements on such processing on behalf of a controller. To meet those requirements the Parties conclude the following agreement, performance of which is not remunerated separately unless expressly agreed.

§ 1 Definitions

The definitions of controller (Art. 4(7) GDPR), processor (Art. 4(8) GDPR), personal data (Art. 4(1) GDPR), special categories of personal data (Art. 9, Art. 10, Art. 4(13)–(15) GDPR), processing (Art. 4(2) GDPR) and supervisory authority (Art. 4(21) GDPR) apply as set out in the GDPR.

§ 2 Competent data protection supervisory authority

(1) The competent supervisory authority for the AG is the authority of the federal state in which the AG has its place of business, see the BfDI list of addresses.

(2) The competent supervisory authority for the AN is the authority of the federal state of North Rhine-Westphalia (LDI NRW), see the BfDI list of addresses.

(3) The Parties and, where applicable, their representatives cooperate with the supervisory authority on request in the performance of its tasks.

§ 3 Subject matter and term

(1) In performing the services the AN gains access to personal data and processes it exclusively on behalf of and on the instructions of the AG. The scope and purpose of the processing follow from the agreed services. Assessing the lawfulness of the processing is the AG's responsibility.

(2) The Parties conclude this agreement in order to specify their mutual data protection rights and obligations.

(3) The provisions of this agreement apply to all activities connected with the provision of the services in which the AN, its employees or persons commissioned by the AN come into contact with personal data originating from the AG or collected for the AG.

(4) The term of this agreement follows the agreed contract term, unless the provisions below give rise to further obligations or termination rights.

§ 4 Right to issue instructions

(1) The AN processes data only within the scope of the contract and in accordance with the AG's instructions; this applies in particular to transfers of personal data to a third country or an international organisation. Where the AN is required to carry out further processing by Union or Member State law to which it is subject, it informs the AG of those legal requirements before processing.

(2) The AG's instructions are initially laid down by this agreement and may subsequently be amended, supplemented or replaced by the AG in text form by individual instructions. The AG may issue such instructions at any time. This includes instructions regarding the rectification, erasure and blocking of data.

(3) All instructions issued are to be documented by both the AG and the AN. Instructions going beyond the services agreed in the main contract are treated as a request for a change of services.

(4) Where the AN considers that an instruction of the AG infringes data protection provisions, it informs the AG without undue delay. The AN may suspend performance of the instruction in question until it is confirmed or amended by the AG. The AN may refuse to carry out a manifestly unlawful instruction.

§ 5 Type of data processed, categories of data subjects

(1) In performing the contract the AN gains access to the personal data specified in Annex a).

(2) The categories of data subjects affected by the processing are likewise set out in Annex a).

§ 6 Protective measures of the AN

(1) The AN is obliged to observe the statutory data protection provisions and not to disclose information obtained from the AG's sphere to third parties or expose it to their access. Documents and data are to be secured against access by unauthorised persons, taking into account the state of the art.

(2) Within its area of responsibility the AN organises its internal operations so as to meet the specific requirements of data protection. It takes all necessary technical and organisational measures for the adequate protection of the AG's data pursuant to Art. 32 GDPR, in particular at least the measures listed in Annex b) covering (a) physical access control, (b) system access control, (c) data access control, (d) transfer control, (e) input control, (f) commissioning control, (g) availability control and (h) separation control. The AN reserves the right to change the security measures taken at any time, ensuring that the contractually agreed level of protection is not undercut.

(3) Persons employed by the AN in the processing of data are prohibited from processing personal data without authorisation. The AN obliges all persons entrusted by it with the handling and performance of this agreement accordingly (confidentiality undertaking, Art. 28(3)(b) GDPR) and ensures compliance with due care. These undertakings must be framed so that they survive the termination of this agreement or of the employment relationship. On request, the undertakings are to be evidenced to the AG in a suitable manner.

(4) The processing of special categories of personal data has been subjected to a Data Protection Impact Assessment (DPIA) under Art. 35 GDPR. The DPIA is reviewed on a regular cadence and made available to the AG on request.

§ 7 Information obligations of the AN

(1) In the event of disruptions, suspected personal data breaches, breaches of the AN's contractual obligations, suspected security-relevant incidents or other irregularities in the processing of personal data by the AN, by persons employed by it in the context of the engagement or by third parties, the AN informs the AG without undue delay in text form, and at the latest within 24 hours of becoming aware, insofar as the incident concerns the subject matter of the engagement. The same applies to inspections of the AN by the data protection supervisory authority. A notification of a personal data breach contains at least (a) a description of the nature of the breach, where possible stating the categories and number of data subjects and of personal data records concerned, and (b) a description of the measures taken or proposed by the AN to address the breach and, where appropriate, to mitigate its possible adverse effects.

(2) The AN takes the necessary measures without undue delay to secure the data and to mitigate possible adverse consequences for data subjects, informs the AG thereof and requests further instructions.

(3) The AN is further obliged to provide the AG with information at any time insofar as the AG's data is affected by a breach under paragraph 1.

(4) Should the AG's data held by the AN be endangered by seizure or attachment, by insolvency or composition proceedings or by other events or measures of third parties, the AN informs the AG without undue delay, unless prohibited from doing so by judicial or official order.

(5) Insofar as legally permissible and necessary, the AN points out to authorities, courts or other third parties that the data is processed on behalf of the AG and that the AG is the controller within the meaning of the GDPR.

(6) The AN informs the AG without undue delay of material changes to the security measures under § 6(2) of this agreement.

(7) The AN and, where applicable, its representative maintain a record of all categories of processing activities carried out on behalf of the AG containing all the information required under Art. 30(2) GDPR. The record is made available to the AG on request.

(8) The AN cooperates to a reasonable extent in the AG's preparation of its own record and communicates the necessary information to the AG in a suitable manner.

(9) The decision on a notification to the competent supervisory authority under Art. 33 GDPR and on the communication to data subjects under Art. 34 GDPR rests with the AG as controller. The AN makes such notifications or communications only on documented instructions from the AG, unless the AN is itself under a statutory duty to notify or inform.

§ 8 Audit rights of the AG

(1) On reasonable request the AN demonstrates to the AG compliance with this agreement and with its obligations under Art. 28 GDPR by means of suitable documents and evidence. Evidence may in particular take the form of current descriptions of technical and organisational measures, data protection or security concepts, questionnaires, audit reports, certificates, self-assessments or comparable documentation.

(2) Insofar as the documents and evidence submitted under paragraph 1 are insufficient in an individual case, or where there is justified cause, the AG is entitled, after prior coordination, to carry out an inspection or to have one carried out by an auditor bound to confidentiality.

(3) On-site inspections are generally to be announced at least ten working days in advance in text form, to be conducted during ordinary business hours and to be arranged so that business operations, trade secrets and confidentiality towards other customers are not unreasonably impaired. In the event of significant security incidents, official orders or specific suspicion of a material breach, a shorter reasonable notice period may apply.

(4) The costs of an inspection going beyond ordinary evidence-gathering are borne by the AG, unless the inspection reveals a material breach of contract for which the AN is responsible.

(5) Findings and results of inspections are to be treated confidentially.

§ 9 Use of subprocessors

(1) The following partial services are performed with the involvement of the following subprocessors:

  • Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus — provision and technical operation of the Bold Bloom platform, hosting, database operation, storage of application data and backups;
  • Wildbit LLC / Postmark, 2400 Market Street, No. 200, Suite 235B, Philadelphia, PA 19103, USA, or Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, USA, depending on the technical configuration — delivery of system and contract-related emails (EU Standard Contractual Clauses);
  • Functional Software, Inc. dba Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA — detection, analysis and remediation of technical errors and error tracking, with PII scrubbing enabled (EU Standard Contractual Clauses);
  • Better Stack, Inc., 651 N Broad Street, Suite 206, Middletown, DE 19709, USA — aggregation and evaluation of technical log data, with PII scrubbing at the handler boundary (EU Standard Contractual Clauses);
  • Mistral AI SAS, 15 Rue des Halles, 75001 Paris, France — provision of the optional AI features, in particular "AI Session Proposal", the AI-assisted team analysis and the Coaching Toolkit evaluations (processing within the EU, no third-country transfer);
  • Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA — provision of the optional Google sign-in and the optional Google Calendar integration, in each case only where the AG or its authorised users activate them (EU Standard Contractual Clauses);
  • Slack Technologies, LLC, 500 Howard Street, San Francisco, CA 94105, USA, and Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA — delivery of optional webhook notifications to Slack or Microsoft Teams, in each case only where the AG sets up such an integration (EU Standard Contractual Clauses);
  • Kloudend Ltd. (ip-api.com), United Kingdom — approximate GeoIP classification of sign-in events, exclusively after the explicit consent of the person concerned and only where the feature is enabled (UK adequacy decision).

(2) Beyond this, the AN is entitled within the scope of its contractual obligations to establish further subprocessing relationships, provided it informs the AG in advance. The AG may object within 14 days of being informed on substantive data protection or security grounds. In the event of a justified objection the Parties will examine a reasonable alternative. If no reasonable solution can be found, either Party may terminate the service affected by the change on reasonable notice; the remaining services are unaffected.

(3) The AN selects subprocessors carefully, taking into account their suitability, reliability and the technical and organisational measures required for the respective processing. The AN binds each subprocessor by contract under Art. 28(4) GDPR to data protection obligations substantially equivalent to those provided for in this agreement. The AN remains responsible towards the AG for the subprocessor's compliance with its data protection obligations. The AN enables the AG to exercise its audit rights in respect of the subprocessing by means of suitable evidence and information provided through the AN. This does not establish any direct audit, instruction or control right of the AG vis-à-vis the respective subprocessor.

(4) Insofar as a subprocessor processes personal data outside the European Economic Area or accesses personal data from a third country, the AN ensures that the requirements of Chapter V GDPR are met. To that end, where necessary, an adequacy decision, the conclusion of EU Standard Contractual Clauses or another appropriate safeguard under Art. 46 GDPR is relied upon, a transfer impact assessment is carried out and appropriate supplementary protective measures are implemented.

(5) A subprocessing relationship within the meaning of these provisions does not exist where the AN commissions third parties with services that are to be regarded as purely ancillary. These include, for example, postal, transport and shipping services, cleaning services, telecommunications services without a specific connection to the services the AN provides for the AG, and security services. Maintenance and inspection services constitute subprocessing relationships requiring consent insofar as they are provided for IT systems that are also used in connection with the provision of services for the AG.

(6) Payment service providers are not subprocessors within the meaning of this agreement. In processing payments and issuing invoices the AN is itself the controller under data protection law and not a processor acting for the AG; the service providers used for that purpose are disclosed in the AN's privacy policy.

(7) The AN maintains an internal Sub-Processor DPA Register under Art. 28(3) GDPR documenting, for each subprocessor, the provider's standard DPA URL, the date of DPA acceptance, the DPA version, the responsible internal contract owner and the next review date. The register is reviewed at least annually and made available to the AG for inspection on reasoned request.

§ 10 Specific rules for AI

(1) Insofar as the AN uses AI services in the processing carried out for the engagement, only the subprocessors named in § 9 of this agreement may be used for that purpose.

(2) The AN does not use private accounts or consumer versions of AI services for processing carried out for the engagement. Where technically and contractually available, settings are chosen under which the AG's personal data is not used for training, fine-tuning or the general improvement of the respective provider's AI models.

(3) AI inputs, prompts, uploaded content, AI outputs and technical log and error data are subject, insofar as they contain personal data, to the provisions of this agreement and to the agreed retention and erasure periods.

(4) In designing and providing the AI features the AN observes the principle of data minimisation. Personal data is processed only insofar as necessary for the specific agreed function. Where technically possible and appropriate for the respective processing purpose, anonymised, pseudonymised or synthetic data is to be used.

(5) Content generated by AI features serves exclusively as suggestions and working aids, in particular for preparing and structuring coaching sessions. The AN does not take automated legal, economic or other significant decisions about data subjects on the basis of AI outputs. The professional, coaching-related, legal and substantive review, approval and use of AI-generated results rest with the AG or its authorised users, unless expressly agreed otherwise.

(6) Automated decisions producing legal effects or similarly significantly affecting data subjects within the meaning of Art. 22 GDPR are not the subject of this agreement unless expressly agreed, legally reviewed and approved in documented form.

§ 11 Data subject requests and rights

(1) Taking into account the nature of the processing and the information available to it, the AN supports the AG to a reasonable extent by appropriate technical and organisational measures in fulfilling the AG's obligations under Art. 12 to 22 and Art. 32 to 36 GDPR, in particular in relation to data subject requests, personal data breaches, data protection impact assessments and prior consultations. Insofar as such support causes effort going beyond the contractually owed services or the AN's statutory obligations, it is to be remunerated appropriately by the AG.

(2) If a data subject asserts rights — for instance to information, rectification or erasure of their data — directly against the AN, the AN does not act on its own initiative but refers the data subject to the AG without undue delay and awaits the AG's instructions.

§ 12 Termination

(1) On termination of the main contract the AG has the right to have the personal data processed on its behalf returned or to demand its erasure. The AG communicates its instruction to that effect to the AN in text form at the latest upon termination of the main contract.

(2) In the case of return, the AN provides the AG with the active data sets in a common, machine-readable format. Where no instruction to return is given, the AN erases the active data sets at the latest 30 days after termination of the main contract. In the case of return, erasure takes place at the latest 30 days after the data has been provided.

(3) Backup copies are deleted within the regular backup rotation, at the latest after 7 days. Statutory retention obligations remain unaffected; in that case data may be processed only to fulfil the respective statutory obligation.

(4) The AN confirms erasure in text form on reasoned request by the AG.

§ 13 Liability

(1) For compensation of damage suffered by a data subject as a result of processing or use that is impermissible or incorrect under data protection law in the context of the processing on behalf of the controller, the AG is, in the internal relationship with the AN, solely responsible towards the data subject.

(2) The AG indemnifies the AN economically, on first demand, against monetary claims of third parties in connection with the processing of data on behalf of the controller. This does not apply if and insofar as the AN has failed to comply with the obligations specifically imposed on processors by the GDPR, or has acted in disregard of or contrary to the AG's lawfully issued instructions, and the monetary claim arises from this. Art. 82(2) to (4) GDPR remain unaffected.

(3) The Parties release each other from liability where a Party demonstrates that it is in no respect responsible for the circumstance through which the damage to a data subject arose.

§ 14 Final provisions

(1) No verbal side agreements have been made. Amendments, supplements and additions to this agreement are valid only if agreed between the Parties in text form. This does not apply to individual contractual agreements within the meaning of § 305b BGB with an authorised representative of the provider. Otherwise, the form requirement cannot be set aside by verbal agreement, conclusive conduct or tacitly.

(2) Should individual provisions of this agreement be or become wholly or partly void or ineffective, the validity of the remaining provisions is not affected. Statutory law takes the place of provisions not incorporated or ineffective. Where such statutory law is not available in the respective case (gap in the rules) or would lead to an untenable result, the Parties will enter into negotiations to agree an effective provision in place of the provision not incorporated or ineffective which comes as close as possible to it in economic terms.

(3) This agreement is governed by German law.

(4) Where the AG is a merchant, a legal person under public law or a special fund under public law, the exclusive venue for all disputes arising from this agreement is Düsseldorf.

Annex a) — Categories of personal data, data subjects and purposes of processing

1. Categories of personal data: account, identification and authentication data; organisation, company and contact data; team, client and coaching data; mood, feedback and wellbeing data; calendar, appointment and integration data; AI inputs, AI outputs and technical context data; usage, security and technical log data; support, error and communication data.

1.9 Special categories of personal data: In the course of contractual use of Bold Bloom, the processing of special categories of personal data under Art. 9 GDPR may be envisaged. This concerns in particular information on physical or mental condition, mood, emotions, personal thoughts, strains or health conditions, insofar as contained in coaching notes, session notes, mood checks, wellbeing or feedback surveys and other content introduced by the AG. The processing of data on criminal convictions and offences under Art. 10 GDPR is neither envisaged nor necessary. The AG ensures that such data is not processed unless expressly agreed and legally safeguarded in an individual case.

2. Categories of data subjects: employees, users and other authorised persons of the AG holding a Bold Bloom account; administrators, coaches, team leads, HR staff and other contacts of the AG; clients, coachees, team members and other persons whose data the AG processes in coaching, team or organisational development processes; participants in mood, feedback, wellbeing or retrospective surveys; persons named in coaching notes, session notes, files, attachments, comments or other content supplied by the AG; persons whose calendar or appointment data is processed under a calendar integration activated by the AG; persons submitting support requests or named in bug reports; other natural persons whose personal data the AG enters, uploads, provides or transmits via activated integrations.

3. Purposes of processing: provision and operation of the Bold Bloom software service; conduct and organisation of coaching, team and organisational development processes; provision of the optional AI features; provision of the optional integrations; technical operation and IT security. The German version of this annex sets out each purpose in detail.

Annex b) — Technical and organisational measures

The AN takes the following measures pursuant to Art. 32 GDPR. The complete and current description is provided to the AG on request.

  • Physical access control: processing takes place in the hosting provider's certified data centres with access security, video surveillance and documented visitor management. The AN does not operate server rooms of its own.
  • System access control: personal user accounts, state-of-the-art password hashing, checks against breached passwords, multi-factor authentication for administrative access, automatic session termination after inactivity and an absolute session lifetime.
  • Data access control: role- and permission-based authorisation concept, tenant separation at database level, restriction of administrative rights to what is necessary, logging of security-relevant access.
  • Transfer control: transport encryption (TLS) for all connections, encryption of stored data and encrypted backups, use of EU Standard Contractual Clauses for third-country transfers, PII scrubbing before transmission to error and log services.
  • Input control: audit logs of the creation, modification and deletion of security-relevant records with timestamp and acting person.
  • Commissioning control: written data processing agreements with all subprocessors, a maintained subprocessor register with annual review, documented instruction status.
  • Availability control: daily encrypted backups, documented restore procedure, monitoring of basic functions, protective measures against overload and abusive access.
  • Separation control: logical separation of different controllers' data, separate environments for development, testing and production, no use of production data in test environments.

Questions about this agreement can be directed to info@bold-bloom.com.

Version: 2026-09-12