Data Processing Agreement (DPA)

pursuant to Art. 28 GDPR including the EU Standard Contractual Clauses

Version 2026-09 · Last updated: September 2026

This translation is provided for information only. Only the German version is legally binding. German version

This agreement is concluded between the customer of the FibreAct platform as controller ("Client") and PARPALİ YAZILIM VE BİLİŞİM HİZMETLERİ TİCARET LİMİTED ŞİRKETİ, Beştepe Mah., Yenimahalle / Ankara, Türkiye, as processor ("Contractor"). It is agreed electronically upon conclusion of the usage contract for the platform on the basis of the General Terms and Conditions; the express confirmation in the customer account, for example before publishing a company website, reaffirms it. It applies to all processing of personal data that the Contractor carries out on behalf of the Client.

§ 1 Subject matter and duration

(1) The subject matter of the assignment is the provision of the FibreAct platform as software-as-a-service under the usage contract, in particular storage, provision and transmission of the data entered by the Client and its users, operation of the mobile apps and the company website with contact form, and technical support and maintenance.

(2) The nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

(3) The term of this agreement follows the term of the usage contract. The obligations under this agreement continue as long as the Contractor processes personal data of the Client.

§ 2 Instructions

(1) The Contractor processes personal data only on documented instructions from the Client – including with regard to transfers of personal data to a third country or an international organisation –, unless it is required to carry out other processing by Union or Member State law to which it is subject; in such a case, it informs the Client of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

(2) The Client’s instructions result from the usage contract, this agreement and the settings that the Client makes in the platform. The Client issues further instructions in text form to datenschutz@fibreact.com. The Contractor may make instructions that go beyond the agreed scope of services subject to a remuneration agreement or reject them; in the event of rejection, the Client may terminate the usage contract for cause.

(3) The Contractor informs the Client without undue delay if, in its opinion, an instruction infringes data protection provisions. It may suspend the execution of the instruction until it is confirmed or changed by the Client.

§ 3 Obligations of the Contractor

(1) The Contractor ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

(2) The Contractor takes the technical and organisational measures under Art. 32 GDPR described in Annex 2. It may adapt them to technical progress, provided that the level of protection is not reduced.

(3) Taking into account the nature of the processing, the Contractor assists the Client by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR.

(4) Taking into account the nature of processing and the information available to it, the Contractor assists the Client in ensuring compliance with the obligations under Art. 32 to 36 GDPR.

(5) The Contractor notifies the Client of a personal data breach without undue delay, at the latest within 48 hours after becoming aware of it. The notification contains, where available, the information under Art. 33 (3) GDPR; information not yet available is provided without undue delay.

(6) The Contractor maintains a record of all categories of processing activities carried out on behalf of the Client under Art. 30 (2) GDPR.

(7) The Contractor’s data protection contact can be reached at datenschutz@fibreact.com.

§ 4 Place of processing and transfers to third countries

(1) Subject to the sub-processors listed in Annex 3, the data are stored on servers in the Federal Republic of Germany.

(2) The Contractor has its registered office in Türkiye. There is no adequacy decision of the European Commission for Türkiye. Insofar as employees of the Contractor access the data from Türkiye for administration, maintenance and support, this constitutes a transfer to a third country.

(3) For these transfers, the parties hereby agree on the standard contractual clauses for the transfer of personal data to third countries pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module 2 (transfer controller to processor), available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj ("Standard Contractual Clauses"). They become part of this agreement unchanged by reference. The following applies:

  • Annex I.A: the data exporter is the Client with the details stored in the customer account (name, address, contact person, contact details); role: controller. The data importer is the Contractor; contact person: management, datenschutz@fibreact.com; role: processor. Activity relevant to the transfer: provision of the FibreAct platform. Electronic acceptance of this agreement replaces signature and date; the time of conclusion of the contract is decisive.
  • Annex I.B is completed by Annex 1, Annex II by Annex 2 and Annex III by Annex 3 of this agreement.
  • Clause 7 (docking clause) does not apply.
  • Clause 9: Option 2 (general written authorisation) applies; the period for prior information about changes is four weeks. § 5 of this agreement applies in addition.
  • Clause 11: the optional provision does not apply.
  • Clause 13 and Annex I.C: where the data exporter is established in an EU Member State, the supervisory authority responsible for it is competent. Where the data exporter is not established in the European Union but falls within the scope of the GDPR under Art. 3 (2) GDPR and has appointed a representative under Art. 27 (1) GDPR, the supervisory authority of the Member State in which the representative is established is competent; where it has not appointed a representative, the supervisory authority of the Member State in which the data subjects whose data are transferred are located is competent.
  • Clause 17: Option 1 applies; the law of the Federal Republic of Germany applies.
  • Clause 18: the courts of the Federal Republic of Germany have jurisdiction.

(4) In the event of a conflict between this agreement and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

(5) In accordance with Clause 14, the parties warrant that they have no reason to believe that the laws and practices in the third country prevent the data importer from fulfilling its obligations under the Standard Contractual Clauses. The Contractor has documented its assessment and makes this documentation and all information required for the Client’s own assessment available on request. In addition: subject to Annex 3, the data are stored exclusively in Germany and are not permanently copied to Türkiye; access from Türkiye only takes place as required for operation, maintenance or support, via encrypted connections and by authorised employees, and logins to the servers are logged. The Contractor examines disclosure requests from public authorities for their lawfulness, challenges them in accordance with Clause 15.2 where, after careful assessment, there are sufficient grounds to do so, discloses only the minimum data required and informs the Client in accordance with Clause 15.1 where permitted.

§ 5 Sub-processors

(1) The Client grants general authorisation to engage further processors ("Sub-processors"). The Sub-processors engaged at the time of conclusion of the contract are listed in Annex 3 and are deemed approved.

(2) The Contractor informs the Client in text form, for example by e-mail or by a notice in the customer account, at least four weeks before engaging or replacing a Sub-processor. The Client may object to the change for an objective data protection reason in text form within this period. If the parties cannot agree, either party may terminate the affected service or, if it cannot be separated, the usage contract as of the date the change takes effect.

(3) The Contractor imposes on each Sub-processor by way of a contract the same data protection obligations as set out in this agreement and in the Standard Contractual Clauses, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Where a Sub-processor fails to fulfil its data protection obligations, the Contractor remains liable to the Client for their performance (Art. 28 (4) sentence 2 GDPR, Clause 9 (d) of the Standard Contractual Clauses). An onward transfer to a third country only takes place under the conditions of Clause 8.7 of the Standard Contractual Clauses.

(4) Services that the Contractor uses as ancillary services, such as telecommunications and transport services, and services that the Client itself agrees with third parties do not constitute sub-processing. Paddle.com Market Limited acts as an independent controller for payment processing.

§ 6 Evidence and audits

(1) The Contractor makes available to the Client all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and this agreement.

(2) The Client may carry out audits, including inspections, itself or through an auditor mandated by it who is bound to confidentiality and is not a competitor of the Contractor. When deciding on an audit, the Client may take into account suitable evidence provided by the Contractor, such as audit reports of independent bodies. Audits must be announced with reasonable notice, generally 30 days; where there are specific indications of a violation, the notice period may be reasonably shortened. Audits take place during normal business hours and must not impair the protection of other customers’ data.

(3) Each party bears its own costs arising from audits.

§ 7 Data subject rights

If a data subject contacts the Contractor directly, the Contractor refers them to the Client, where the request can be attributed to the Client, and forwards the request to the Client without undue delay. The Contractor does not respond to the request itself unless instructed to do so by the Client. The platform provides functions for access to, rectification and erasure of data.

§ 8 Deletion and return

(1) During the term of the contract, the Client can retrieve and delete its data via the platform’s export functions.

(2) After termination of the usage contract, the Contractor deletes the Client’s personal data within 90 days unless Union or Member State law requires storage. If the Client requests the return of data that cannot be retrieved via the export functions before the end of the contract, the Contractor provides them in a common machine-readable format. Until deletion, access to the data is limited to the purpose of return. Backups are overwritten no later than 14 days after deletion in the production system.

(3) The Contractor confirms deletion in text form.

§ 9 Liability and final provisions

(1) Liability towards data subjects is governed by Art. 82 GDPR. Between the parties, the liability provisions of the usage contract apply; they do not apply to liability under Clause 12 of the Standard Contractual Clauses or towards data subjects.

(2) Changes to this agreement are governed by the provisions of the General Terms and Conditions on changes; Annex 3 is changed in accordance with § 5. The Standard Contractual Clauses cannot be changed in this way; changes must not contradict them.

(3) The law of the Federal Republic of Germany applies. If individual provisions are invalid, the validity of the remaining provisions remains unaffected.

Annex 1 – Description of the processing (Annex I.B of the Standard Contractual Clauses)

Categories of data subjects:

  • employees, subcontractors and other users of the Client, in particular installers, site managers and dispatchers,
  • contact persons of clients and business partners of the Client,
  • connection owners, property owners and residents at work sites, insofar as their data are recorded,
  • persons recognisable in photos or documents,
  • visitors to the company website who use the contact form.

Types of personal data:

  • user master data: name, e-mail address, telephone number, role, company affiliation,
  • access and log data: login times, device information, app version, push token,
  • job and installation data: work site addresses, appointments, status, measured values, form content, signatures, notes,
  • photos and documents,
  • location data of mobile devices when using the app; in the background only if the Client has activated this and the data subject has granted permission on the device,
  • communication content, such as messages within the platform,
  • contact form enquiries: name, e-mail address, where applicable telephone number and company, message, a non-reversible hash value of the IP address.

Special categories of personal data (Art. 9 GDPR) are not subject of the processing. The Client ensures that such data are not entered.

Nature and purpose of the processing: storage, organisation, evaluation, provision and transmission within the functions of the platform, in particular job management, mobile documentation, reporting, geocoding of work site addresses, sending notifications, translation of website content, delivery of the company website and forwarding of contact enquiries, as well as support, maintenance and security.

Purpose of the transfer to Türkiye: remote access as required for administration, maintenance and support.

Frequency of the transfer: as required during the term of the contract; processing on the servers is continuous.

Retention: term of the contract and thereafter in accordance with § 8; contact form enquiries are deleted automatically after the period set by the Client (30 to 730 days, default 180 days).

Transfers to Sub-processors: see Annex 3 (subject matter, nature and duration correspond to the services listed there and the term of the contract).

Annex 2 – Technical and organisational measures (Art. 32 GDPR, Annex II of the Standard Contractual Clauses)

Confidentiality (physical access, system access, data access and separation control):

  • operation of the servers in a data centre in Germany with physical access control by the data centre operator,
  • administrative access to the servers exclusively via encrypted connections; firewall; automatic blocking of senders after repeated failed login attempts; logging of logins,
  • personal user accounts; passwords are stored only as bcrypt hash values; session tokens are limited to 24 hours; login attempts are limited,
  • role- and permission-based authorisation concept within the platform,
  • logical separation of the data of different customers; tenant separation is checked by automated code analysis,
  • access to production data only by authorised employees, insofar as required for operation, maintenance or support.

Pseudonymisation and data minimisation:

  • IP addresses of contact form users are stored only as a non-reversible hash value generated with a secret key,
  • only address information without names is transmitted to the geocoding service,
  • company websites use no cookies and no tracking services,
  • privacy-friendly default settings, such as deactivated background location recording.

Integrity (transmission and input control):

  • encryption of all connections between devices and platform in accordance with the state of the art (TLS),
  • logging of security-relevant and administrative operations,
  • program changes are tested before release.

Availability and resilience:

  • daily backup of the database with a retention of 14 days,
  • automatic restart of application processes in the event of errors,
  • protection against overload by limiting requests per sender.

Procedures for regular review:

  • review and adaptation of the measures in the event of significant changes to the platform,
  • selection of Sub-processors according to data protection criteria and contractual commitment,
  • commitment of persons authorised to process data to confidentiality.

Annex 3 – Sub-processors (Annex III of the Standard Contractual Clauses)

  • Contabo GmbH, Aschauer Straße 32a, 81549 Munich, Germany – provision of servers (application, database, file storage, e-mail sending); place of processing: Germany.
  • Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, or Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, depending on the contracting party of the respective service – Firebase Cloud Messaging for push notifications (push token, notification content) and Google Maps Platform for geocoding work site addresses (address information without names); processing also in the USA; transfer on the basis of the European Commission’s standard contractual clauses contained in Google’s data processing terms.
  • Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA – machine translation of company website texts, only insofar as the Client uses the translation function (website texts such as slogan, description, services, references and image descriptions); transfer on the basis of the European Commission’s standard contractual clauses (Module 3, processor to processor); the data are not used to train AI models.