Legal
Last updated: 18 June 2026
This data processing agreement (the “DPA”) specifies the data protection obligations of the parties for the processing of personal data that Bites GbR (the “processor”) carries out for the customer (the “controller”) in connection with the use of the Reguly platform. It is an annex to and part of the main contract (terms and conditions) concluded between the parties and is deemed agreed upon its conclusion.
This DPA implements the requirements of Art. 28 GDPR. On data protection matters, its provisions prevail over any conflicting provisions of the main contract.
The subject matter of the processing is the provision of the Reguly platform under the main contract. The processor processes personal data exclusively for the purpose of providing these services in accordance with the contract. The duration of processing corresponds to the term of the main contract, unless otherwise provided in this DPA (in particular regarding deletion and return).
Depending on the controller’s use, the following may be processed: master data (e.g. names, contact details), communication and content data, and product- and compliance-related data that the controller enters into the platform. Categories of data subjects are in particular the controller’s employees, contacts and business partners, as well as other persons whose data the controller processes in the platform. The specific determination is the controller’s responsibility; the processing of special categories of personal data (Art. 9 GDPR) is not part of the engagement unless expressly agreed.
The processor processes the data exclusively on the documented instructions of the controller, unless required to process by law; in such a case, the processor informs the controller of the legal requirement before processing, unless the law prohibits this. Use of the platform within the agreed functions constitutes an instruction; supplementary instructions are issued in text form. If the processor considers an instruction unlawful, it informs the controller and may suspend its implementation until confirmed.
The processor ensures that persons authorised to process the data are committed to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b), Art. 29, Art. 32(4) GDPR). It implements the technical and organisational measures required under Art. 32 GDPR (Annex A), assists the controller as far as possible in responding to data subject requests (Art. 12–23 GDPR) and in complying with the obligations under Art. 32–36 GDPR, provides the information necessary to demonstrate compliance, and maintains, where applicable, a record of all processing activities (Art. 30(2) GDPR).
The processor implements the technical and organisational measures described in Annex A and develops them further in line with the state of the art. Measures that do not fall below the agreed level of protection are permitted.
The controller grants the processor general authorisation to engage further processors (sub-processors). The sub-processors engaged at the time the contract is concluded are listed in Annex B. The processor informs the controller in advance of intended changes (addition or replacement) and grants it the right to object on important data protection grounds within 14 days. Each sub-processor is bound to data protection obligations equivalent to those of this DPA.
The processor notifies the controller of personal data breaches without undue delay after becoming aware of them and assists the controller in fulfilling its obligations under Art. 33 and 34 GDPR.
After the end of the provision of the processing services, the processor, at the controller’s choice, deletes or returns all personal data and deletes existing copies, unless a statutory retention obligation applies. The controller can export the data it has entered via the functions provided during the term and for 30 days after the contract ends.
The processor makes available to the controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for and contributes to audits — including inspections — conducted by the controller or an auditor mandated by it. Audits take place with reasonable advance notice, during normal business hours and without disrupting operations; evidence may also be provided through suitable certificates, attestations or current audit reports.
Processing of personal data in a third country only takes place in compliance with the requirements of Art. 44 et seq. GDPR. Where engaged sub-processors transfer data to the USA or other third countries, this is done on the basis of an adequacy decision or appropriate safeguards, in particular the EU Standard Contractual Clauses (Art. 46 GDPR), together with any necessary supplementary measures.
The controller is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects. It determines the nature, scope and purpose of the data it enters into the platform and ensures that an appropriate legal basis exists for processing it.
Liability is governed by the provisions of the main contract and Art. 82 GDPR. The law of the Federal Republic of Germany applies. Should individual provisions of this DPA be invalid, the validity of the remaining provisions remains unaffected.
The processor implements in particular the following measures:
At the time the contract is concluded, the following sub-processors are engaged: