Data Processing Agreement
Data processing agreement pursuant to Art. 28 GDPR between the Customer, hereinafter the „Controller“, and onEco GmbH, Friedrichstrasse 171, 10117 Berlin, Germany, operating under the brand name Prelumen, hereinafter the „Processor“, hereinafter jointly the „Parties“. The German version prevails; this translation is provided for information purposes only.
Section 1 Subject matter, duration, order of precedence
(1) This agreement specifies the data protection rights and obligations of the Parties in connection with the processing of personal data carried out by the Processor on behalf of the Controller in the course of providing the services under the General Terms and Conditions for Prelumen (the „Main Agreement“).
(2) The subject matter, nature and purpose of the processing, the categories of data subjects and the types of personal data are set out in Annex 1.
(3) The term of this agreement corresponds to the term of the Main Agreement. It ends automatically when the Main Agreement ends; the obligations under Section 9 survive.
(4) In the event of conflicts between this agreement and the Main Agreement, this agreement prevails insofar as the processing of personal data is concerned.
Section 2 Responsibility
(1) As between the Parties, the Controller is solely responsible within the meaning of Art. 4 (7) GDPR. It assesses the lawfulness of the processing and safeguards the rights of data subjects.
(2) The Controller shall in particular ensure that a valid legal basis exists for the processing, that data subjects are informed in accordance with Art. 13 and 14 GDPR, and that effective consent has been obtained where required. Where the Controller embeds a measurement script in a website, it is also responsible for the obligations under Section 25 TDDDG.
(3) The Processor processes personal data exclusively within the scope of this agreement and on documented instructions from the Controller.
Section 3 Right to issue instructions
(1) The Controller issues instructions in text form as a rule. Oral instructions are confirmed in text form without undue delay.
(2) Configuration of the services by the Controller via the provided user interfaces and application programming interfaces constitutes an instruction within the meaning of this agreement.
(3) If the Processor considers an instruction to infringe data protection law, it shall inform the Controller without undue delay. The Processor is entitled to suspend execution of the instruction until it is confirmed or amended.
(4) The Parties designate the persons authorised to issue and receive instructions in Annex 1 and shall notify each other of any changes without undue delay.
Section 4 Obligations of the Processor
(1) Confidentiality. To ensure that persons involved in the processing are committed to confidentiality unless they are already subject to an appropriate statutory duty of confidentiality (Art. 28 (3) (b), Art. 29, Art. 32 (4) GDPR), and to train them on data protection at regular intervals.
(2) Security of processing. To implement the technical and organisational measures pursuant to Art. 32 GDPR set out in Annex 3 and to maintain them for the term of the agreement. The Processor may develop the measures further provided the agreed level of protection is not reduced.
(3) Assistance with data subject rights. To assist the Controller, by appropriate technical and organisational measures, in responding to requests from data subjects under Chapter III GDPR (Art. 28 (3) (e) GDPR). If a data subject contacts the Processor directly, the Processor shall forward the request to the Controller without undue delay and shall not respond to it itself.
(4) Assistance with obligations under Art. 32 to 36 GDPR. To assist the Controller in ensuring the security of processing, in notifying personal data breaches, in carrying out data protection impact assessments and in prior consultations, taking into account the nature of the processing and the information available to the Processor.
(5) Notification of data breaches. To inform the Controller without undue delay and at the latest within 24 hours of becoming aware of any personal data breach affecting data covered by this agreement, and to provide the Controller with the information required to fulfil its obligations under Art. 33 and 34 GDPR.
(6) Record of processing activities. To maintain a record of all categories of processing activities pursuant to Art. 30 (2) GDPR.
(7) Point of contact. To designate a point of contact for data protection enquiries: [email protected].
(8) Place of processing. To carry out processing exclusively in Member States of the European Union or the European Economic Area, unless the conditions of Section 6 are met.
Section 5 Sub-processors
(1) The Controller grants the Processor general authorisation to engage further processors within the meaning of Art. 28 (2) sentence 2 GDPR. The sub-processors engaged at the time this agreement is concluded are listed in Annex 2.
(2) The Processor shall inform the Controller at least 30 days before engaging a new sub-processor or replacing an existing one, in text form or by way of a notification within the service. The Controller may object to the change in text form within 14 days of receiving the information, on important grounds relating to data protection.
(3) If the Controller objects, the Parties shall seek an amicable solution. If no such solution can be found and it is unreasonable for the Processor to provide the service without the sub-processor concerned, either Party may terminate the Main Agreement upon one month notice.
(4) The Processor shall impose on each sub-processor, by contract, data protection obligations equivalent to those under this agreement. The Processor is liable for the fault of its sub-processors as for its own.
(5) Ancillary services without a direct connection to the commissioned processing, such as telecommunications services, cleaning or the disposal of data carriers, do not constitute sub-processing within the meaning of this provision.
Section 6 Transfers to third countries
(1) Processing outside the European Union or the European Economic Area takes place only where the specific requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision pursuant to Art. 45 GDPR or standard contractual clauses pursuant to Art. 46 (2) (c) GDPR together with any required supplementary measures.
(2) Third-country connections existing at the time this agreement is concluded are marked in Annex 2.
Section 7 Audit rights of the Controller
(1) The Controller has the right to verify compliance with this agreement (Art. 28 (3) (h) GDPR).
(2) The Processor provides evidence primarily through current certifications, attestations or audit reports from recognised bodies, and through a documented description of the technical and organisational measures.
(3) Where this is not sufficient in an individual case, the Controller may, upon reasonable notice of at least 14 days, during normal business hours and without disrupting operations, carry out an on-site inspection or have one carried out by an auditor bound to confidentiality who must not be a competitor of the Processor. The Processor may charge reasonable remuneration for the effort involved in an on-site inspection unless the inspection is justified by a specific cause.
Section 8 Rectification, restriction and erasure
(1) The Processor rectifies, erases or restricts the processing of data only on the instructions of the Controller.
(2) Where a data subject contacts the Processor directly, Section 4 (3) applies.
Section 9 Termination
(1) After the end of the processing, the Processor shall delete all personal data or return it at the choice of the Controller, unless a statutory retention obligation applies.
(2) The Controller may retrieve its data in a common, machine-readable format during the 30-day period following the end of the contract specified in the General Terms and Conditions. Deletion takes place after that period.
(3) The Processor may retain documentation serving as evidence of proper data processing beyond the end of the contract in accordance with the applicable retention periods.
(4) The Processor confirms deletion in text form upon request.
Section 10 Final provisions
(1) Amendments and additions to this agreement and its annexes require text form.
(2) Should any provision be or become invalid, the validity of the remaining provisions remains unaffected.
(3) The law of the Federal Republic of Germany applies. The place of jurisdiction is Berlin, to the extent permitted by law.
Annex 1 — Subject matter and details of the processing
Subject matter. Provision of the software-as-a-service offerings Prelumen Analytics, Prelumen Reports and Prelumen Profiles, including their administration in the Prelumen Hub.
Nature and purpose of the processing. Collection, storage, analysis and provision of usage and measurement data from the websites of the Controller for the purpose of reach and performance analysis and the creation of compliance and transparency reports. Processing is automated.
Categories of data subjects.
- visitors to websites operated or managed by the Controller
- users of the Controller to whom it grants access to the Prelumen Hub
Types of personal data.
- usage data: pages accessed, time and duration of access, referrer, interaction events, session identifier
- technical data: browser type and version, operating system, screen resolution, language setting. The IP address is received for processing but is neither logged nor stored.
- approximate location at country or region level, derived from the IP address without storing the IP address itself
- master data of the users of the Controller: name, business email address, role
Special categories of personal data under Art. 9 GDPR. Not processed. The Controller shall ensure that it does not transmit such data via the services, in particular not via custom events or user-defined parameters.
Duration of the processing. For the term of the Main Agreement. Retention period for measurement data: for the term of the contractual relationship
Persons authorised to issue instructions on behalf of the Controller. The persons registered as administrators in the Prelumen Hub and any persons designated by the Controller in text form.
Recipient of instructions at the Processor. [email protected]
Annex 2 — Sub-processors
- Salesforce, Inc. (Heroku), registered in the USA — application hosting and database. Place of processing: EU region (Ireland). Third-country safeguard for possible parent-company access: standard contractual clauses.
- Cloudflare, Inc., USA — content delivery, DNS and attack protection. Place of processing: EU edge, group access from the USA possible. Third-country safeguard: standard contractual clauses.
- JAWS DB, LLC, registered in the USA — operation of the database as a Heroku add-on on Amazon Web Services infrastructure. Third-country safeguard: standard contractual clauses.
- Stripe Payments Europe, Limited, Ireland — payment processing.
- Brevo GmbH, Berlin, Germany — delivery of transactional emails. According to the provider, transfers to third countries, in particular the USA and India, cannot be ruled out. Third-country safeguard: standard contractual clauses.
The Processor makes a current version of this list available on this page. Changes are announced in accordance with Section 5 (2).
Annex 3 — Technical and organisational measures pursuant to Art. 32 GDPR
1. Confidentiality
Physical access control. Processing takes place exclusively in the data centres of the service providers engaged. These have access control systems, video surveillance and documented visitor management and are certified to ISO/IEC 27001. The Processor does not operate its own server rooms.
System access control. Access to production systems is limited to the managing directors and to individually authorised persons and takes place via personal accounts.
Data access control. Permissions are granted following the principle of least privilege. Development, test and production environments are separated from one another.
Separation control. Customer data is kept separated by tenant.
Data minimisation and pseudonymisation. IP addresses of website visitors are neither logged nor stored as part of the measurement. Prelumen Analytics operates without cookies in its standard mode.
2. Integrity
Transfer control. Transmission takes place exclusively encrypted via TLS. The Processor does not itself apply additional encryption of data at rest; encryption at storage level depends on the scope of service of the database provider engaged.
Input control. Changes to the application code are versioned and traceable.
3. Availability and resilience
Availability control. The database is backed up daily; backups are retained on a rolling 30-day basis. Restorability is tested annually. Protection against denial-of-service attacks is provided via Cloudflare. The hosting and database providers engaged operate redundant infrastructure.
Restorability. The maximum tolerated data loss is 24 hours, corresponding to the daily backup interval. No fixed recovery time is guaranteed.
4. Procedures for regular review
Data protection management. A record of the categories of processing activities pursuant to Art. 30 (2) GDPR is maintained. Persons involved in the processing are bound to confidentiality. A reporting process for personal data breaches is in place, with notification to the Controller within 24 hours.
Supplier control. Sub-processors are selected according to documented criteria, agreements pursuant to Art. 28 GDPR are concluded and compliance is reviewed regularly.
Incident response. A documented process for detecting, assessing and handling security incidents is in place.
Data protection by design and by default. Prelumen Analytics is designed to operate cookie-free in its standard mode and honours do-not-track signals. Usage data is not passed on to advertising networks.
Version: 20 August 2026