Reguly

Legal

Data Processing Agreement (DPA)

Last updated: 18 June 2026

This page is a translation. Only the German version is legally binding; in case of doubt it prevails.

Data Processing Agreement (DPA)

This data processing agreement (the “DPA”) specifies the data protection obligations of the parties for the processing of personal data that Bites GbR (the “processor”) carries out for the customer (the “controller”) in connection with the use of the Reguly platform. It is an annex to and part of the main contract (terms and conditions) concluded between the parties and is deemed agreed upon its conclusion.

This DPA implements the requirements of Art. 28 GDPR. On data protection matters, its provisions prevail over any conflicting provisions of the main contract.

1. Subject matter, duration and purpose of processing

The subject matter of the processing is the provision of the Reguly platform under the main contract. The processor processes personal data exclusively for the purpose of providing these services in accordance with the contract. The duration of processing corresponds to the term of the main contract, unless otherwise provided in this DPA (in particular regarding deletion and return).

2. Type of data and categories of data subjects

Depending on the controller’s use, the following may be processed: master data (e.g. names, contact details), communication and content data, and product- and compliance-related data that the controller enters into the platform. Categories of data subjects are in particular the controller’s employees, contacts and business partners, as well as other persons whose data the controller processes in the platform. The specific determination is the controller’s responsibility; the processing of special categories of personal data (Art. 9 GDPR) is not part of the engagement unless expressly agreed.

3. Right to issue instructions

The processor processes the data exclusively on the documented instructions of the controller, unless required to process by law; in such a case, the processor informs the controller of the legal requirement before processing, unless the law prohibits this. Use of the platform within the agreed functions constitutes an instruction; supplementary instructions are issued in text form. If the processor considers an instruction unlawful, it informs the controller and may suspend its implementation until confirmed.

4. Obligations of the processor

The processor ensures that persons authorised to process the data are committed to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b), Art. 29, Art. 32(4) GDPR). It implements the technical and organisational measures required under Art. 32 GDPR (Annex A), assists the controller as far as possible in responding to data subject requests (Art. 12–23 GDPR) and in complying with the obligations under Art. 32–36 GDPR, provides the information necessary to demonstrate compliance, and maintains, where applicable, a record of all processing activities (Art. 30(2) GDPR).

5. Technical and organisational measures

The processor implements the technical and organisational measures described in Annex A and develops them further in line with the state of the art. Measures that do not fall below the agreed level of protection are permitted.

6. Sub-processors

The controller grants the processor general authorisation to engage further processors (sub-processors). The sub-processors engaged at the time the contract is concluded are listed in Annex B. The processor informs the controller in advance of intended changes (addition or replacement) and grants it the right to object on important data protection grounds within 14 days. Each sub-processor is bound to data protection obligations equivalent to those of this DPA.

7. Notification of personal data breaches

The processor notifies the controller of personal data breaches without undue delay after becoming aware of them and assists the controller in fulfilling its obligations under Art. 33 and 34 GDPR.

8. Deletion and return

After the end of the provision of the processing services, the processor, at the controller’s choice, deletes or returns all personal data and deletes existing copies, unless a statutory retention obligation applies. The controller can export the data it has entered via the functions provided during the term and for 30 days after the contract ends.

9. Evidence and audits

The processor makes available to the controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for and contributes to audits — including inspections — conducted by the controller or an auditor mandated by it. Audits take place with reasonable advance notice, during normal business hours and without disrupting operations; evidence may also be provided through suitable certificates, attestations or current audit reports.

10. Transfers to third countries

Processing of personal data in a third country only takes place in compliance with the requirements of Art. 44 et seq. GDPR. Where engaged sub-processors transfer data to the USA or other third countries, this is done on the basis of an adequacy decision or appropriate safeguards, in particular the EU Standard Contractual Clauses (Art. 46 GDPR), together with any necessary supplementary measures.

11. Obligations of the controller

The controller is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects. It determines the nature, scope and purpose of the data it enters into the platform and ensures that an appropriate legal basis exists for processing it.

12. Liability and final provisions

Liability is governed by the provisions of the main contract and Art. 82 GDPR. The law of the Federal Republic of Germany applies. Should individual provisions of this DPA be invalid, the validity of the remaining provisions remains unaffected.

Annex A — Technical and organisational measures (Art. 32 GDPR)

The processor implements in particular the following measures:

  • End-to-end encryption of data transmission via TLS and encryption of stored data in line with the state of the art;
  • Access and authorisation control via role-based permissions, individual user accounts and authentication;
  • Tenant separation — logical separation of different customers’ data;
  • Data minimisation and pseudonymisation where possible (e.g. salted hashes instead of raw IP addresses);
  • Regular backups and tested restore procedures (availability and resilience);
  • Logging of security-relevant events;
  • Selection of hosting providers contractually bound to data protection with appropriate safeguards;
  • Procedures for regularly testing, assessing and evaluating the effectiveness of the measures.

Annex B — Approved sub-processors

At the time the contract is concluded, the following sub-processors are engaged:

  • Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA — hosting of the web application (EU Standard Contractual Clauses).
  • Render Services, Inc., San Francisco, USA — hosting of the application backend and database (EU Standard Contractual Clauses).