Contracting parties
Represented by: Majid Goschka, Grigor Muradyan
Irma-Keilhack-Ring 25, 22145 Hamburg, Germany
Data protection contact: compliance@batteriepasswerk.com
General support: support@batteriepasswerk.com
Controller (Customer). The following details are automatically taken from the account data provided at registration and identify the controller; no separate entry is required:
- Company name (registration field "Company")
- Address (registration fields "Street and number", "Postal code", "City", "Country" - via address autocomplete)
- Authorised representative(s) (registration field "Account owner": first and last name)
- Data protection contact (registration field "Business email")
Preamble
This Data Processing Agreement ("DPA") specifies the data protection obligations of the parties arising from the processing of personal data commissioned under the SaaS usage contract between them ("Main Contract"). It applies to all activities in which employees of the processor or third parties commissioned by it process personal data of the controller (Article 28 GDPR).
In the event of conflicts between this DPA and the Main Contract, this DPA prevails on data protection matters. The binding version is the German language version.
Subject matter and term
(1) The subject of processing is the provision of the "Batteriepasswerk" SaaS for creating, managing and publishing digital battery passports under Regulation (EU) 2023/1542, including related functions (account and team management, supplier portal, certificate management, support ticketing, payment processing).
(2) The term of this DPA corresponds to the term of the Main Contract. Termination follows the Main Contract; separate termination of this DPA is not possible while the Main Contract exists.
Nature and purpose of processing
(1) The processing serves the purpose of enabling the controller to use the SaaS as contractually agreed. It includes in particular: collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission, dissemination, alignment, combination, restriction, erasure and destruction. The processor processes the personal data exclusively to perform the Main Contract and this DPA and in accordance with the documented instructions of the controller, and not for its own purposes.
(2) The place of processing is the European Union and, with respect to individual sub-processors, third countries within the meaning of Article 44 GDPR; see Annex 1 and § 9.
Types of personal data
The following categories of personal data are processed:
- Master data of the controller's team members (first/last name, email address, possibly phone number, role);
- Authentication data (encrypted password hashes, session tokens, magic-link tokens);
- Company data of the controller (company name, address, VAT ID, contact persons);
- Contact data of the controller's external suppliers, where the controller invites them via the supplier portal (name, email);
- Contents of support tickets, including requests and attachments submitted by the controller;
- Usage logs (login times, audit-log entries for security-relevant events);
- Payment metadata (payment provider customer ID, subscription status, invoice IDs). Card data itself is not processed by the processor but exclusively by the payment provider, which acts as an independent controller in that respect; for payment metadata it acts as a sub-processor (Annex 1).
The processor does not process special categories of personal data within the meaning of Article 9 GDPR.
Categories of data subjects
- Employees and other staff of the controller who use the SaaS;
- Contact persons at the controller (owner, accounting, support);
- External suppliers of the controller who submit data or certificates via the supplier portal.
Rights and obligations of the controller
(1) The controller alone is responsible for assessing the lawfulness of the processing and for safeguarding the rights of data subjects (Articles 12–23 GDPR).
(2) The controller issues all instructions to the processor in writing or in verifiable text form (email to compliance@batteriepasswerk.com). Verbal instructions are confirmed by the processor in writing without undue delay. The persons authorised to issue instructions are named in Annex 3; changes must be notified to the other party in text form.
(3) If the processor considers that an instruction violates data protection law, it must inform the controller without undue delay. The processor is entitled to suspend the execution of the instruction in question until it is confirmed or amended by the controller.
Notification duties of the processor
(1) The processor notifies the controller without undue delay, and at the latest within 48 hours of becoming aware of:
- any personal data breach within the meaning of Article 4(12) GDPR;
- any seizure, confiscation or significant disruption affecting the security or availability of the processed data;
- any request from a supervisory authority concerning the controller (where legally permitted).
(2) Notification is made to the contact details stored by the controller (in-app: Settings → Company; alternatively by email to the data protection contact given by the controller). It contains at least the information required by Article 33(3) GDPR, insofar as known to the processor.
(3) The processor reasonably supports the controller in fulfilling its notification obligations under Articles 33, 34 GDPR.
Support with data subject rights and data protection impact assessments
The processor supports the controller with appropriate technical and organisational measures in fulfilling data subject requests under Articles 15–22 GDPR. In particular, it provides within the SaaS:
- a complete data export of all company data, triggerable by the owner, as a structured file (Articles 15, 20 GDPR); access secrets are filtered out;
- rectification and deletion functions within the application (Articles 16, 17 GDPR);
- deletion of a single user's personal data by the controller via team management (owner or administrator; no self-service); access and profile are permanently deleted and the frozen plaintext name in the tamper-proof audit log is replaced by a neutral placeholder (anonymisation), so the audit trail remains complete but without personal reference.
Requests from data subjects addressed directly to the processor are forwarded without undue delay to the controller and not answered independently, unless the controller expressly instructs otherwise.
Beyond data subject rights, the processor reasonably supports the controller upon request in ensuring the security of processing (Article 32 GDPR), with data protection impact assessments (Article 35 GDPR) and prior consultations with the supervisory authority (Article 36 GDPR), taking into account the nature of the processing and the information available to it (Article 28(3)(f) GDPR).
Technical and organisational measures (TOM)
(1) The processor implements the technical and organisational measures described in Annex 2 to ensure a level of protection appropriate to the risk under Article 32 GDPR.
(2) The measures are subject to technical progress. The processor is entitled to adapt them continuously to the state of the art, provided the level of protection is not reduced. Material changes are documented.
Sub-processors
(1) The controller hereby grants its general written authorisation to engage the sub-processors listed in Annex 1 for the purposes specified there.
(2) The processor informs the controller of intended changes to the list (addition or replacement of sub-processors) at least 14 calendar days before they take effect. The controller may object to the change within this period on important data protection grounds. In case of objection, the parties endeavour to find an amicable solution; if this is not possible, the controller has a special right to terminate the Main Contract.
(3) The processor contractually binds the sub-processors to the data protection obligations of this DPA or to substantially equivalent provisions. For transfers to third countries it concludes Standard Contractual Clauses (SCC) under Article 46(2)(c) GDPR and takes supplementary measures where necessary.
Audit rights of the controller
(1) The controller has the right to verify compliance with this DPA before the start of processing and regularly during the term of the contract.
(2) The processor primarily demonstrates compliance through suitable evidence (including sub-processor certificates, documented TOMs, third-party audit reports, this DPA). Further on-site inspections are to be carried out with reasonable advance notice (at least 14 days), during normal business hours, without disrupting operations, and at most once per calendar year. The processor's reasonable effort is to be reimbursed, unless the inspection is prompted by a specific data protection incident.
Confidentiality
The processor obliges all persons involved in the processing, before they begin their work, to maintain confidentiality in writing pursuant to Article 28(3)(b), Article 29 GDPR, insofar as they are not already subject to a statutory duty of confidentiality. The obligation continues after the end of the employment relationship.
Deletion and return of data
(1) After the end of the provision of processing services, the processor must, at the controller's choice, return or delete all personal data (Article 28(3) sentence 2(g) GDPR), unless there is an obligation to continue storage under Union or German law (e.g. commercial/tax retention periods; retention requirements for battery passports under Regulation (EU) 2023/1542).
(2) The SaaS distinguishes three separate processes for this. Termination of the Main Contract does not by itself trigger deletion; personal data is deleted exclusively according to the following rules:
- a) Data export: The controller has at any time a complete export of all company data as a structured file (Articles 15, 20 GDPR); access secrets (secrets, token hashes, passwords) are filtered out.
- b) Cancellation: Cancellation is a purely billing process and deletes no data. After the paid period ends, the account reverts to the free plan; company and passport data remain readable and exportable.
- c) Retention: For battery passports subject to retention under Regulation (EU) 2023/1542, an archive access (ongoing subscription) and a lifetime archive (one-time payment) are available. In both states, passport and product data are technically locked against changes but remain publicly resolvable via QR (Article 77).
- d) Deletion of individual data subjects: Deletion of a single user's personal data is carried out by the controller via team management (removing the employee account). Access and profile are deleted and the plaintext name in the tamper-proof audit log is anonymised; the company's product data remains unaffected.
- e) Final deletion of the entire company: This takes place exclusively on the express, logged instruction of the controller (owner) and only from the free plan. The owner deliberately confirms the instruction (entering the company name and confirming retention responsibility as an economic operator); the process is recorded as evidence of the transfer of liability in a tenant-independent deletion register (deletion_log). After a grace period of 30 calendar days (soft-delete, during which restoration by support is possible), an automated background process irreversibly deletes the data: first the files in object storage, then the members' auth accounts and the company including all data tables (including models, passports and lifecycle events); the time of deletion is then recorded in the deletion register.
Liability
The liability of the parties is governed by the provisions of the Main Contract. Liability under Article 82 GDPR remains unaffected.
Final provisions
(1) Should individual provisions of this DPA be or become invalid or unenforceable, the validity of the remaining provisions remains unaffected. The parties will replace an invalid provision with a valid one that comes as close as possible to the economic purpose of the invalid provision.
(2) Amendments and additions to this DPA require text form (email is sufficient).
(3) The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods. The exclusive place of jurisdiction for all disputes arising from or in connection with this DPA is Hamburg, provided the controller is a merchant, a legal entity under public law or a special fund under public law.
Annex 1 - Sub-processors
The processor uses the following sub-processors to provide the services. Changes to the list are announced with 14 calendar days' notice (§ 9).
| Service | Provider | Purpose | Place of processing | Legal basis |
|---|---|---|---|---|
| Supabase | Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992 | Database (Postgres), authentication, object storage (certificate uploads). Uses Amazon Web Services (AWS, EU region) as a further sub-processor, covered by the Supabase DPA. | EU (Frankfurt) / USA | DPA + SCCs |
| Vercel | Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA | Hosting of the web application and serverless functions (region fra1 = Frankfurt) | EU (Frankfurt) / USA | DPA + SCCs |
| Stripe | Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland | Payment processing, invoicing, customer portal. Independent controller for card data, sub-processor for payment metadata. | EU (Ireland) / USA | DPA + SCCs |
| Resend | Resend Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA | Transactional emails (invitations, reminders, support replies) | USA | DPA + SCCs |
| Sentry | Functional Software, Inc. dba Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA | Error monitoring in operation (only active when SENTRY_DSN is configured) | USA | DPA + SCCs |
Annex 2 - Technical and organisational measures
Overview of measures under Article 32 GDPR. The measures are continuously adapted to the state of the art.
| Area | Measure |
|---|---|
| Confidentiality - encryption | TLS 1.2+ (in transit) for all connections between client, Vercel and Supabase; AES-256 at rest for database and object storage (Supabase-managed). |
| Confidentiality - access control | Row-Level Security (RLS) in Postgres isolates tenants per row via tenant_id; role-based permissions (Owner / Admin / Editor / Viewer) at database, API and UI level; JWT auth via Supabase. |
| Confidentiality - operational access | Two-factor authentication (MFA) for all admin consoles (Supabase, Vercel, Stripe, Resend, Sentry); service-role keys exclusively in server-side Vercel functions, never in the client bundle; no production credentials on developer devices. |
| Integrity | All writing API calls run through authenticated endpoints with input validation; audit log for security-relevant events (role change, cancellation, deletion); full database transaction semantics prevent inconsistent intermediate states. |
| Availability - backup | Point-in-time recovery (PITR) for the database via Supabase Pro (7-day lookback, minute-precise restore); daily database snapshots; regular restore drills. |
| Availability - redundancy | Serverless execution on Vercel with automatic scaling and health monitoring; no single-point-of-failure servers operated in-house; DDoS protection at network level by Vercel. |
| Resilience | Rate limiting on public and unauthenticated endpoints (fixed-window, fail-open); error monitoring via Sentry (when configured); no permanent block if the rate-limit store fails. |
| Deletion concept | Cancellation deletes no data (revert to free plan, still readable and exportable). Deletion of individual users' personal data via team management with anonymisation of the audit log (plaintext name → neutral placeholder). Battery passports subject to retention are technically frozen via archive/lifetime access but remain publicly resolvable (Article 77). Final company deletion only on deliberate owner instruction with assumption of liability: soft-delete → 30-day grace period → automated purge process (object storage, auth accounts, company cascade). Tenant-independent deletion register (deletion_log) documents the instruction and transfer of liability. |
| Data minimisation | Only the fields necessary for the purpose are collected; no processing of special categories of personal data (Article 9 GDPR); no sharing with advertising networks or analytics services using a personal identifier. The reach measurement used (Vercel Web Analytics) works without cookies and without a personal identifier. |
| Commissioning control | Documented list of all sub-processors (Annex 1); DPAs with all sub-processors; regular review of sub-processor certifications; 14-day objection period against new sub-processors. |
| Separation | Separate environments for production, staging and local development; separate database projects per environment; no customer production data in staging or on developer devices. |
Annex 3 - Persons authorised to issue instructions
Instructions within the meaning of § 5 of this DPA are issued (controller) or received (processor) exclusively by the persons named below. Changes must be notified to the other party in text form.
Controller. The controller's authorised person is automatically taken from the registration data (account owner: name and business email); the controller may name additional persons in text form.
Processor.
Majid Goschka, partner - compliance@batteriepasswerk.com
Grigor Muradyan, partner - compliance@batteriepasswerk.com
Conclusion. This DPA is concluded in electronic form (Article 28(9) GDPR) upon acceptance of the Terms at registration. The processor acts through both partners jointly; the controller's consent is given by the account owner.