Data Processing Agreement
This agreement specifies the obligations under Art. 28 GDPR for the use of the services dfine.io Review and dfine.io Streaming Classic. It is an annex to the service agreement, the main contract consisting of your booked service (selected plan or individual quote) and our Terms and Conditions. The sub-processors engaged and their data processing agreements are maintained on an ongoing basis in our Trust & Compliance overview.
Recitals
By concluding the service agreement, the parties have entered into a commissioned data processing relationship. In order to specify the resulting rights and obligations in accordance with the requirements of the European General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and the German Federal Data Protection Act (BDSG), the parties conclude the following agreement.
§ 1 Scope
(1)This agreement applies to the processing (Art. 4 No. 2 GDPR) of all personal data (hereinafter: data) that is the subject of the service agreement or that arises in the course of its performance and is processed on the instructions of the controller. Data of the processor's employees is excluded from the scope insofar as it exclusively concerns the employment relationship with the processor.
(2)This agreement takes precedence over other agreements and arrangements between the parties, unless the parties expressly agree otherwise.
§ 2 Specification of the subject matter
(1)The subject matter of the processing is the provision and operation of the SaaS services "dfine.io Review" (media review platform: upload and versioning of media files, frame-accurate commenting and annotation, live review sessions with conferencing, approvals and protected sharing) and "dfine.io Streaming Classic" (private live streaming, on request on TISAX-assessed infrastructure, Google Cloud europe-west3 Frankfurt am Main, or on-premises at the controller's site). The specific scope of services, duration, nature and purpose of the processing are otherwise determined by the service agreement (the main contract), which consists of the service booked by the controller (in self-service, the plans selected during checkout; for individually agreed services, the respective quote or framework agreement) and the processor's Terms and Conditions, available at https://dfine.io/terms. The duration of the processing corresponds to the term of the service agreement: it begins when the service agreement takes effect and ends upon its termination; the return and deletion of data after termination are governed by § 7.
(2)The following types of personal data are subject to the processing. For both services: account and contact data of users (name, email address); authentication data (access tokens, password hashes, session identifiers); usage and connection metadata (timestamps, duration, connection status, IP addresses in the course of connection setup); billing-related data (via the payment service provider). Additionally for dfine.io Review: media content uploaded by the controller (video, image, audio, documents) including versions, which may contain personal data; comments and annotations including optional AI-assisted translations; sharing and access data (link policies, password hashes, expiry dates, guest interactions); audio/video streams of the live sessions (real-time processing); audit and usage logs. Specific to dfine.io Streaming Classic: video and stream content is not stored server-side; the signal is passed through in real time only (recording and cloud storage upload are disabled server-side).
(3)Categories of data subjects: employees of the controller; external service providers, reviewers and viewers invited by the controller (including those without their own account); where applicable, customers of the controller as well as persons depicted or named in uploaded media content.
(4)No special categories of data (Art. 9 GDPR) are processed by design; insofar as uploaded media content contains such data in individual cases, the controller remains responsible for lawfulness.
(5)The personal data processed has a high protection requirement.
§ 3 Obligations and right to issue instructions
(1)The parties are obliged to comply with the obligations imposed on them by data protection regulations (in particular the GDPR). The controller may at any time request the release, correction, adjustment, deletion and restriction of the processing of the data.
(2)To ensure the protection of the rights of data subjects, the processor supports the controller appropriately, in particular by ensuring suitable technical and organisational measures.
(3)If a data subject contacts the processor directly to assert a data subject right, the processor will forward this request to the controller without undue delay.
(4)The processor may only process data within the scope of the controller's instructions, unless it is required to carry out other processing by the law of the Union or of the member state to which the processor is subject (Art. 28(3) sentence 2 lit. a GDPR). In such a case, the processor shall inform the controller of these legal requirements prior to processing, unless the law in question prohibits such information on important grounds of public interest. Instructions must be documented. Instructions are initially defined by the service agreement and may thereafter be changed, supplemented or replaced by the controller in documented form.
(5)The processor shall inform the controller without undue delay if it believes that an instruction violates data protection regulations, and is entitled to suspend the execution of the relevant instruction until it is confirmed or amended by the controller. The persons authorised to issue and receive instructions and the information channels are set out in the annex "Right to issue instructions".
(6)Changes to the subject matter of processing involving procedural changes shall be agreed jointly and documented.
(7)The processor shall provide information to third parties or the data subject only with the controller's prior express written (or documented electronic) consent, unless it is required to disclose under Union or member state law.
(8)The processor shall not use the data for any other purposes and is in particular not entitled to pass it on to third parties, unless required to disclose under Union or member state law. Copies and duplicates are not created without the controller's knowledge.
(9)The controller maintains the record of processing activities pursuant to Art. 30(1) GDPR. The processor provides the controller with information for inclusion in the record on request. The processor maintains a record of all categories of processing activities carried out on behalf of the controller pursuant to Art. 30(2) GDPR.
(10)Places of processing: for dfine.io Streaming Classic, processing takes place exclusively within the Federal Republic of Germany (Hetzner, Nuremberg; TISAX option: Google Cloud, Frankfurt am Main). For dfine.io Review, the core data (database, object storage, media processing, logs) is stored and processed exclusively within the European Union (including Frankfurt am Main; object storage with EU jurisdiction configuration); delivery and individual services (authentication, edge network) are provided via globally distributed infrastructure of the service providers named in the annex "Sub-processors". Transfers to third countries take place exclusively in accordance with Chapter V of the GDPR (EU-U.S. Data Privacy Framework or standard contractual clauses).
(11)The processor ensures that natural persons under its authority who have access to data process it only on the controller's instructions.
§ 4 Compliance with mandatory legal obligations
(1)The processor ensures that the persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and demonstrates this to the controller on request.
(2)The parties support each other in demonstrating and documenting their accountability obligations (Art. 5(2), Art. 24(1) GDPR).
(3)The processor is currently not subject to the statutory obligation to appoint a data protection officer. The contact for data protection is: Stefan King, dfine.io GmbH, Hufelandstr. 44, 10407 Berlin, mail@dfine.io.
(4)The processor informs the controller without undue delay of any controls and measures by supervisory authorities.
§ 5 Technical and organisational measures and their control
(1)The parties agree on the specific security measures set out in the annex "Technical and organisational measures (TOM)". The annex forms part of this agreement.
(2)If a review by the controller reveals a need to adapt the measures pursuant to Art. 32 GDPR, the adaptations shall be implemented by the processor.
(3)Technical and organisational measures are subject to technical progress. The processor is permitted to implement alternative adequate measures; the level of security defined in the annex must not be undercut. Material changes shall be documented.
(4)The processor enables and supports inspections by the controller or an auditor commissioned by it and provides the necessary evidence of compliance.
(5)The review may also be carried out on the basis of current attestations or reports by independent bodies (e.g. auditors, independent data protection auditors), compliance with approved codes of conduct (Art. 40 GDPR) or a suitable certification.
(6)The review may also be carried out by an on-site inspection during normal business hours.
(7)The processor provides the controller with the information required for a data protection impact assessment (Art. 35 GDPR).
(8)The processor takes all necessary measures to secure the data in agreement with the controller, taking into account the state of the art.
§ 6 Notification of breaches by the processor
The processor informs the controller promptly of serious disruptions to its operations, of suspected breaches of this agreement or statutory data protection provisions, or of other irregularities in the processing of the controller's data. This applies in particular with regard to the notification obligation under Art. 33(2) GDPR. The processor undertakes to support the controller appropriately in its obligations under Art. 33 and 34 GDPR. Notifications under Art. 33 or 34 GDPR on behalf of the controller may only be carried out by the processor following prior instruction pursuant to § 3.
§ 7 Deletion and return of data
(1)Data carriers and data records provided remain the property of the controller.
(2)Upon completion of the contractually agreed services or earlier upon request by the controller, at the latest upon termination of the service agreement, the processor shall return all processed data or, subject to prior consent, delete it in a data protection-compliant manner, including copies. A deletion protocol shall be provided on request.
(3)Documentation serving as evidence of proper data processing may be retained by the processor beyond the end of the contract in accordance with the respective retention periods.
(4)Deletion mechanics for dfine.io Streaming Classic: video/stream content does not exist structurally (no persistence, § 2(2)). Session metadata is deleted automatically after 12 months (monthly cleanup run). User, project and access data is deleted by the controller via self-service (hard deletion); deletion of the organisation on request. Operational backups (Hetzner, Germany, daily 02:40 UTC) with a maximum of 7 rotating states; data deleted in the application is therefore removed from all backup states no later than 7 days after deletion. No archiving beyond this takes place.
(5)Deletion mechanics for dfine.io Review: media, versions, comments, projects, shares and accounts are deleted by the controller via self-service (hard deletion including object storage). The database recovery window (point-in-time restore) is 48 hours; after that, deleted data is also removed from the recovery history. Audit logs are retained for 365 days and then deleted. No archiving beyond this takes place.
§ 8 Sub-processors
(1)The processor receives the controller's general authorisation to engage the sub-processors listed in the annex "Sub-processors". The processor informs the controller at least four weeks in advance in documented form of any intended changes to this list by adding or replacing sub-processors, giving the controller sufficient time to object before engagement. An individual controller cannot prevent a change to the sub-processors engaged. If the controller objects within this period on substantial, data-protection-related grounds, it shall have an extraordinary right to terminate the affected service(s) with effect from the time of the change; the engagement of the sub-processor remains unaffected. Ancillary services obtained by the processor from third parties (e.g. telecommunications) do not count as sub-processing; the processor also concludes appropriate agreements for these.
(2)Where sub-processors are engaged, the processor ensures that its contractual arrangements with the sub-processor correspond at least to the level of data protection of this agreement, in particular with regard to suitable technical and organisational measures.
(3)The controller shall be granted control and review rights in the agreement with the sub-processor; on request, the controller receives information about the data protection-relevant obligations of the sub-processor.
(4)If the sub-processor fails to meet its data protection obligations, the processor remains liable to the controller for compliance.
§ 9 Data protection control
The processor undertakes to grant the controller's data protection officer access during normal business hours in connection with this order, including rights of entry, inspection and enquiry, and instructs its staff to cooperate. Statutory obligations of confidentiality remain unaffected.
§ 10 Liability and damages
Reference is made to Article 82 GDPR with regard to liability and the right to compensation.
§ 11 Final provisions
(1)Amendments and additions to this agreement require written form and an express reference to that effect; this also applies to any waiver of this formal requirement.
(2)Should individual provisions of this agreement be or become invalid or unenforceable, the validity of the remaining provisions shall not be affected. The invalid provision shall be replaced by the valid provision that most closely reflects the intended purpose.
(3)This agreement is executed in German and English. The German version is the binding contract language; in the event of any discrepancy between the two versions, the German version prevails.
Annex "Right to issue instructions" to § 3
Persons authorised to issue instructions on the controller's side: named in writing by the controller upon conclusion of the contract.
Person authorised to receive instructions on the processor's side: Stefan King (Managing Director), email: mail@dfine.io.
Designated information channel for instructions considered problematic under data protection law: documented electronic information (email). Instructions (including verbal ones) are to be documented by the parties.
Annex "Technical and organisational measures (TOM)"
Specification of the individual measures pursuant to Art. 32 GDPR for both services. As of 15 July 2026, verified against code, configuration and live infrastructure of the processor.
| No. | Measure | Implementation |
|---|---|---|
| 1 | Pseudonymisation and encryption | Transport encrypted end to end: web/app/API TLS 1.2 and 1.3, legacy protocols (TLS 1.0/1.1) disabled at all endpoints; RTMPS ingest (Streaming) TLS 1.2 with ECDHE forward secrecy (AES-256-GCM); real-time media via WebRTC with DTLS-SRTP. Passwords and share-link passphrases as bcrypt hashes. Storage at Review encrypted at rest by the provider. Optional (Streaming, dedicated engines): confidential computing (RAM encryption, AMD SEV/SEV-SNP or Intel TDX). |
| 2 | Confidentiality, integrity, availability, resilience | Tenant separation: organisation-scoped records with server-side tenant scope; Streaming: unique access tokens per customer, server-side validation on every connection setup (round-trip authentication). Server hardening: SSH key-only, only ports 22/80/443 exposed, database bound to localhost, fail2ban, application-level rate limiting. Optional geo-blocking per organisation. |
| 3 | Rapid recoverability | Streaming Classic: daily automatic server backups (Hetzner, Germany, 02:40 UTC), 7 rotating states; RPO ≤ 24 hours; documented restore procedure, target time 15 to 25 minutes. Review: database with point-in-time restore (any point within the last 48 hours); object storage with high provider-side redundancy. |
| 4 | Regular review and evaluation | CVE-driven patching (maintenance windows at night); automated certificate renewal; continuous operational monitoring with heartbeat; periodic audits of the security statements against code and live systems. |
| 5 | Identification and authorisation of users | App users: session authentication; two-factor authentication (TOTP) is available as an option and is activated by the account holder. Streaming Classic: a single account per customer with no multi-user or role management, so activation of 2FA rests with the customer, who may make it binding under their own security policy. Review: role and permission model per organisation. External parties/guests: protected sharing links (password, expiry, download control, revocable; Review) or access code or confidential login with IP binding (Streaming viewers). |
| 6 | Protection during transmission | See No. 1. No unencrypted endpoints exist. |
| 7 | Protection during storage | Review: media files in object storage with EU jurisdiction, database in Frankfurt (eu-central-1), each encrypted at rest by the provider; access only via organisation-scoped access controls. Streaming: no storage of video content; metadata database containerised, bound to localhost, not publicly reachable. |
| 8 | Physical security of processing locations | Data centres of the infrastructure providers with relevant certifications: Hetzner (Germany, ISO 27001), Google Cloud Frankfurt (TISAX-labelled, ISO 27001/27017/27018, SOC 2 Type II), AWS eu-central-1 (ISO 27001, SOC 2), Cloudflare (EU jurisdiction). No own server room of the processor. |
| 9 | Logging of events | Error/audit logs aggregated within the EU (Review: 365 days); stream sessions logged per organisation (times, duration); operational telemetry without content access; audit export for the controller (JSON/PDF). |
| 10 | System configuration | Infrastructure and application configuration versioned in the repository (configuration as code); deployments via CI pipeline; documented hardening baseline per server. |
| 11 | Internal governance / IT security | Responsibility and administrative access lie exclusively with the Managing Director (personal SSH keys / person-bound admin accounts, password logins disabled on servers); no further group of persons with production access. |
| 12 | Certification / quality assurance | Infrastructure level: certifications of the data centre and platform operators (No. 8); TISAX-labelled infrastructure for the TISAX Streaming option (ENX assessment of the provider). The processor itself does not hold its own TISAX label. |
| 13 | Data minimisation | Streaming: no persistence of video content; telemetry limited to operational metrics. Review: storage only of the content introduced by the controller; AI translation only on request (opt-in) and plan-bound. |
| 14 | Data quality | Master data editable by users themselves (self-service); organisation-scoped, consistent data storage; versioning of media data (Review). |
| 15 | Limited storage period | Streaming: session metadata 12 months; backups a maximum of 7 daily states. Review: content until deletion by the controller; database recovery history 48 hours; audit logs 365 days. |
| 16 | Accountability | TOM documentation with verification status; publicly maintained sub-processor list with DPA links (dfine.io/trust); audit logs; record pursuant to Art. 30(2) GDPR on request. |
| 17 | Data portability and deletion | Hard deletion routines in both applications; deletion of the organisation on request; audit export; deletion cascades: Streaming backups within 7 days, Review recovery history within 48 hours (§ 7(4) and (5)). |
| 18 | Support for the controller | Forwarding of data subject requests (§ 3(3)); support with notifications under Art. 33/34 GDPR; direct, personal contact channel (mail@dfine.io). |
Evidence: no own certification under Art. 42 GDPR; infrastructure evidence of the data centre and platform operators (ISO 27001, SOC 2, TISAX label, EU-U.S. Data Privacy Framework) available.
Annex "Sub-processors" to § 8
The sub-processors engaged to perform the contract. The continuously maintained version with DPA links is published in the Trust & Compliance overview. As of 15 July 2026.
| Sub-processor (name, seat) | Region / transfer basis | Service |
|---|---|---|
| Hetzner Online GmbH, Gunzenhausen (DE) | Germany (DC Nuremberg) | VPS hosting for API, app, database and container registry; server backups |
| Google Cloud EMEA Limited, Dublin (IE) | Germany (DC Frankfurt, europe-west3) | Dedicated streaming instance of the TISAX option (pass-through, no persistence) |
| Stripe Payments Europe, Limited, Dublin (IE) | EU; EU-U.S. Data Privacy Framework | Billing and payment processing |
| Axiom, Inc. (Delaware, USA) | EU data region; EU-U.S. DPF | Error logging and audit trail |
| Apilayer Data Products GmbH, Vienna (AT), service: ipstack | EU (Austria) | IP geolocation for optional geo-blocking |
| Sub-processor (name, seat) | Region / transfer basis | Service |
|---|---|---|
| Vercel Inc. (USA) | App hosting Frankfurt (fra1); EU-U.S. DPF | Hosting of the application |
| Neon, LLC, a Databricks, Inc. company (USA) | EU (AWS eu-central-1, Frankfurt) | Postgres database; primary storage of user, project and media data (metadata) |
| Clerk, Inc. (USA) | Globally distributed edge infrastructure; EU-U.S. DPF (incl. UK/Swiss) | Authentication and identity management |
| Stripe Payments Europe, Limited, Dublin (IE) | EU; EU-U.S. DPF | Billing and payment processing |
| Cloudflare, Inc. (USA) | R2 object storage with EU jurisdiction; EU-U.S. DPF | Object storage for uploaded media files; Workers |
| Amazon Web Services EMEA SARL (LU) | EU (eu-central-1, Frankfurt) | Batch encoding of video/image data |
| LiveKit Incorporated (USA) | EU region; EU-U.S. DPF | Real-time conferencing and live streaming |
| Upstash, Inc. (Delaware, USA) | EU (eu-central-1, Frankfurt) | Redis for rate limiting and cache |
| Axiom, Inc. (Delaware, USA) | EU data region; EU-U.S. DPF | Observability and audit logs (365 days) |
| Plus Five Five, Inc., service: Resend (USA) | EU (eu-west-1) | Transactional email delivery |
Conclusion
For standard customers, this agreement is incorporated as an annex to the service agreement via the Terms and Conditions; a separate signature is not required. On request we provide the version signed by us as a PDF for you to counter-sign. Enterprise and TISAX customers are usually served under an individually negotiated contract; requests to mail@dfine.io.