Data protection · Art. 28 GDPR

Data Processing Agreement

This agreement specifies the obligations under Art. 28 GDPR for the use of the services dfine.io Review and dfine.io Streaming Classic. It is an annex to the service agreement, the main contract consisting of your booked service (selected plan or individual quote) and our Terms and Conditions. The sub-processors engaged and their data processing agreements are maintained on an ongoing basis in our Trust & Compliance overview.

This English text is a translation for the convenience of international customers. The binding contract language is German; in the event of any discrepancy, the German version prevails.
Request signed PDF

Version: 15 July 2026

Processor
dfine.io GmbH, Hufelandstr. 44, 10407 Berlin, Germany, represented by its Managing Director Stefan King (Local Court Berlin Charlottenburg, HRB 193425-B)

Recitals

By concluding the service agreement, the parties have entered into a commissioned data processing relationship. In order to specify the resulting rights and obligations in accordance with the requirements of the European General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and the German Federal Data Protection Act (BDSG), the parties conclude the following agreement.

§ 1 Scope

(1)This agreement applies to the processing (Art. 4 No. 2 GDPR) of all personal data (hereinafter: data) that is the subject of the service agreement or that arises in the course of its performance and is processed on the instructions of the controller. Data of the processor's employees is excluded from the scope insofar as it exclusively concerns the employment relationship with the processor.

(2)This agreement takes precedence over other agreements and arrangements between the parties, unless the parties expressly agree otherwise.

§ 2 Specification of the subject matter

(1)The subject matter of the processing is the provision and operation of the SaaS services "dfine.io Review" (media review platform: upload and versioning of media files, frame-accurate commenting and annotation, live review sessions with conferencing, approvals and protected sharing) and "dfine.io Streaming Classic" (private live streaming, on request on TISAX-assessed infrastructure, Google Cloud europe-west3 Frankfurt am Main, or on-premises at the controller's site). The specific scope of services, duration, nature and purpose of the processing are otherwise determined by the service agreement (the main contract), which consists of the service booked by the controller (in self-service, the plans selected during checkout; for individually agreed services, the respective quote or framework agreement) and the processor's Terms and Conditions, available at https://dfine.io/terms. The duration of the processing corresponds to the term of the service agreement: it begins when the service agreement takes effect and ends upon its termination; the return and deletion of data after termination are governed by § 7.

(2)The following types of personal data are subject to the processing. For both services: account and contact data of users (name, email address); authentication data (access tokens, password hashes, session identifiers); usage and connection metadata (timestamps, duration, connection status, IP addresses in the course of connection setup); billing-related data (via the payment service provider). Additionally for dfine.io Review: media content uploaded by the controller (video, image, audio, documents) including versions, which may contain personal data; comments and annotations including optional AI-assisted translations; sharing and access data (link policies, password hashes, expiry dates, guest interactions); audio/video streams of the live sessions (real-time processing); audit and usage logs. Specific to dfine.io Streaming Classic: video and stream content is not stored server-side; the signal is passed through in real time only (recording and cloud storage upload are disabled server-side).

(3)Categories of data subjects: employees of the controller; external service providers, reviewers and viewers invited by the controller (including those without their own account); where applicable, customers of the controller as well as persons depicted or named in uploaded media content.

(4)No special categories of data (Art. 9 GDPR) are processed by design; insofar as uploaded media content contains such data in individual cases, the controller remains responsible for lawfulness.

(5)The personal data processed has a high protection requirement.

§ 3 Obligations and right to issue instructions

(1)The parties are obliged to comply with the obligations imposed on them by data protection regulations (in particular the GDPR). The controller may at any time request the release, correction, adjustment, deletion and restriction of the processing of the data.

(2)To ensure the protection of the rights of data subjects, the processor supports the controller appropriately, in particular by ensuring suitable technical and organisational measures.

(3)If a data subject contacts the processor directly to assert a data subject right, the processor will forward this request to the controller without undue delay.

(4)The processor may only process data within the scope of the controller's instructions, unless it is required to carry out other processing by the law of the Union or of the member state to which the processor is subject (Art. 28(3) sentence 2 lit. a GDPR). In such a case, the processor shall inform the controller of these legal requirements prior to processing, unless the law in question prohibits such information on important grounds of public interest. Instructions must be documented. Instructions are initially defined by the service agreement and may thereafter be changed, supplemented or replaced by the controller in documented form.

(5)The processor shall inform the controller without undue delay if it believes that an instruction violates data protection regulations, and is entitled to suspend the execution of the relevant instruction until it is confirmed or amended by the controller. The persons authorised to issue and receive instructions and the information channels are set out in the annex "Right to issue instructions".

(6)Changes to the subject matter of processing involving procedural changes shall be agreed jointly and documented.

(7)The processor shall provide information to third parties or the data subject only with the controller's prior express written (or documented electronic) consent, unless it is required to disclose under Union or member state law.

(8)The processor shall not use the data for any other purposes and is in particular not entitled to pass it on to third parties, unless required to disclose under Union or member state law. Copies and duplicates are not created without the controller's knowledge.

(9)The controller maintains the record of processing activities pursuant to Art. 30(1) GDPR. The processor provides the controller with information for inclusion in the record on request. The processor maintains a record of all categories of processing activities carried out on behalf of the controller pursuant to Art. 30(2) GDPR.

(10)Places of processing: for dfine.io Streaming Classic, processing takes place exclusively within the Federal Republic of Germany (Hetzner, Nuremberg; TISAX option: Google Cloud, Frankfurt am Main). For dfine.io Review, the core data (database, object storage, media processing, logs) is stored and processed exclusively within the European Union (including Frankfurt am Main; object storage with EU jurisdiction configuration); delivery and individual services (authentication, edge network) are provided via globally distributed infrastructure of the service providers named in the annex "Sub-processors". Transfers to third countries take place exclusively in accordance with Chapter V of the GDPR (EU-U.S. Data Privacy Framework or standard contractual clauses).

(11)The processor ensures that natural persons under its authority who have access to data process it only on the controller's instructions.

§ 4 Compliance with mandatory legal obligations

(1)The processor ensures that the persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and demonstrates this to the controller on request.

(2)The parties support each other in demonstrating and documenting their accountability obligations (Art. 5(2), Art. 24(1) GDPR).

(3)The processor is currently not subject to the statutory obligation to appoint a data protection officer. The contact for data protection is: Stefan King, dfine.io GmbH, Hufelandstr. 44, 10407 Berlin, mail@dfine.io.

(4)The processor informs the controller without undue delay of any controls and measures by supervisory authorities.

§ 5 Technical and organisational measures and their control

(1)The parties agree on the specific security measures set out in the annex "Technical and organisational measures (TOM)". The annex forms part of this agreement.

(2)If a review by the controller reveals a need to adapt the measures pursuant to Art. 32 GDPR, the adaptations shall be implemented by the processor.

(3)Technical and organisational measures are subject to technical progress. The processor is permitted to implement alternative adequate measures; the level of security defined in the annex must not be undercut. Material changes shall be documented.

(4)The processor enables and supports inspections by the controller or an auditor commissioned by it and provides the necessary evidence of compliance.

(5)The review may also be carried out on the basis of current attestations or reports by independent bodies (e.g. auditors, independent data protection auditors), compliance with approved codes of conduct (Art. 40 GDPR) or a suitable certification.

(6)The review may also be carried out by an on-site inspection during normal business hours.

(7)The processor provides the controller with the information required for a data protection impact assessment (Art. 35 GDPR).

(8)The processor takes all necessary measures to secure the data in agreement with the controller, taking into account the state of the art.

§ 6 Notification of breaches by the processor

The processor informs the controller promptly of serious disruptions to its operations, of suspected breaches of this agreement or statutory data protection provisions, or of other irregularities in the processing of the controller's data. This applies in particular with regard to the notification obligation under Art. 33(2) GDPR. The processor undertakes to support the controller appropriately in its obligations under Art. 33 and 34 GDPR. Notifications under Art. 33 or 34 GDPR on behalf of the controller may only be carried out by the processor following prior instruction pursuant to § 3.

§ 7 Deletion and return of data

(1)Data carriers and data records provided remain the property of the controller.

(2)Upon completion of the contractually agreed services or earlier upon request by the controller, at the latest upon termination of the service agreement, the processor shall return all processed data or, subject to prior consent, delete it in a data protection-compliant manner, including copies. A deletion protocol shall be provided on request.

(3)Documentation serving as evidence of proper data processing may be retained by the processor beyond the end of the contract in accordance with the respective retention periods.

(4)Deletion mechanics for dfine.io Streaming Classic: video/stream content does not exist structurally (no persistence, § 2(2)). Session metadata is deleted automatically after 12 months (monthly cleanup run). User, project and access data is deleted by the controller via self-service (hard deletion); deletion of the organisation on request. Operational backups (Hetzner, Germany, daily 02:40 UTC) with a maximum of 7 rotating states; data deleted in the application is therefore removed from all backup states no later than 7 days after deletion. No archiving beyond this takes place.

(5)Deletion mechanics for dfine.io Review: media, versions, comments, projects, shares and accounts are deleted by the controller via self-service (hard deletion including object storage). The database recovery window (point-in-time restore) is 48 hours; after that, deleted data is also removed from the recovery history. Audit logs are retained for 365 days and then deleted. No archiving beyond this takes place.

§ 8 Sub-processors

(1)The processor receives the controller's general authorisation to engage the sub-processors listed in the annex "Sub-processors". The processor informs the controller at least four weeks in advance in documented form of any intended changes to this list by adding or replacing sub-processors, giving the controller sufficient time to object before engagement. An individual controller cannot prevent a change to the sub-processors engaged. If the controller objects within this period on substantial, data-protection-related grounds, it shall have an extraordinary right to terminate the affected service(s) with effect from the time of the change; the engagement of the sub-processor remains unaffected. Ancillary services obtained by the processor from third parties (e.g. telecommunications) do not count as sub-processing; the processor also concludes appropriate agreements for these.

(2)Where sub-processors are engaged, the processor ensures that its contractual arrangements with the sub-processor correspond at least to the level of data protection of this agreement, in particular with regard to suitable technical and organisational measures.

(3)The controller shall be granted control and review rights in the agreement with the sub-processor; on request, the controller receives information about the data protection-relevant obligations of the sub-processor.

(4)If the sub-processor fails to meet its data protection obligations, the processor remains liable to the controller for compliance.

§ 9 Data protection control

The processor undertakes to grant the controller's data protection officer access during normal business hours in connection with this order, including rights of entry, inspection and enquiry, and instructs its staff to cooperate. Statutory obligations of confidentiality remain unaffected.

§ 10 Liability and damages

Reference is made to Article 82 GDPR with regard to liability and the right to compensation.

§ 11 Final provisions

(1)Amendments and additions to this agreement require written form and an express reference to that effect; this also applies to any waiver of this formal requirement.

(2)Should individual provisions of this agreement be or become invalid or unenforceable, the validity of the remaining provisions shall not be affected. The invalid provision shall be replaced by the valid provision that most closely reflects the intended purpose.

(3)This agreement is executed in German and English. The German version is the binding contract language; in the event of any discrepancy between the two versions, the German version prevails.

Annex "Right to issue instructions" to § 3

Persons authorised to issue instructions on the controller's side: named in writing by the controller upon conclusion of the contract.

Person authorised to receive instructions on the processor's side: Stefan King (Managing Director), email: mail@dfine.io.

Designated information channel for instructions considered problematic under data protection law: documented electronic information (email). Instructions (including verbal ones) are to be documented by the parties.

Annex "Technical and organisational measures (TOM)"

Specification of the individual measures pursuant to Art. 32 GDPR for both services. As of 15 July 2026, verified against code, configuration and live infrastructure of the processor.

No.MeasureImplementation
1Pseudonymisation and encryptionTransport encrypted end to end: web/app/API TLS 1.2 and 1.3, legacy protocols (TLS 1.0/1.1) disabled at all endpoints; RTMPS ingest (Streaming) TLS 1.2 with ECDHE forward secrecy (AES-256-GCM); real-time media via WebRTC with DTLS-SRTP. Passwords and share-link passphrases as bcrypt hashes. Storage at Review encrypted at rest by the provider. Optional (Streaming, dedicated engines): confidential computing (RAM encryption, AMD SEV/SEV-SNP or Intel TDX).
2Confidentiality, integrity, availability, resilienceTenant separation: organisation-scoped records with server-side tenant scope; Streaming: unique access tokens per customer, server-side validation on every connection setup (round-trip authentication). Server hardening: SSH key-only, only ports 22/80/443 exposed, database bound to localhost, fail2ban, application-level rate limiting. Optional geo-blocking per organisation.
3Rapid recoverabilityStreaming Classic: daily automatic server backups (Hetzner, Germany, 02:40 UTC), 7 rotating states; RPO ≤ 24 hours; documented restore procedure, target time 15 to 25 minutes. Review: database with point-in-time restore (any point within the last 48 hours); object storage with high provider-side redundancy.
4Regular review and evaluationCVE-driven patching (maintenance windows at night); automated certificate renewal; continuous operational monitoring with heartbeat; periodic audits of the security statements against code and live systems.
5Identification and authorisation of usersApp users: session authentication; two-factor authentication (TOTP) is available as an option and is activated by the account holder. Streaming Classic: a single account per customer with no multi-user or role management, so activation of 2FA rests with the customer, who may make it binding under their own security policy. Review: role and permission model per organisation. External parties/guests: protected sharing links (password, expiry, download control, revocable; Review) or access code or confidential login with IP binding (Streaming viewers).
6Protection during transmissionSee No. 1. No unencrypted endpoints exist.
7Protection during storageReview: media files in object storage with EU jurisdiction, database in Frankfurt (eu-central-1), each encrypted at rest by the provider; access only via organisation-scoped access controls. Streaming: no storage of video content; metadata database containerised, bound to localhost, not publicly reachable.
8Physical security of processing locationsData centres of the infrastructure providers with relevant certifications: Hetzner (Germany, ISO 27001), Google Cloud Frankfurt (TISAX-labelled, ISO 27001/27017/27018, SOC 2 Type II), AWS eu-central-1 (ISO 27001, SOC 2), Cloudflare (EU jurisdiction). No own server room of the processor.
9Logging of eventsError/audit logs aggregated within the EU (Review: 365 days); stream sessions logged per organisation (times, duration); operational telemetry without content access; audit export for the controller (JSON/PDF).
10System configurationInfrastructure and application configuration versioned in the repository (configuration as code); deployments via CI pipeline; documented hardening baseline per server.
11Internal governance / IT securityResponsibility and administrative access lie exclusively with the Managing Director (personal SSH keys / person-bound admin accounts, password logins disabled on servers); no further group of persons with production access.
12Certification / quality assuranceInfrastructure level: certifications of the data centre and platform operators (No. 8); TISAX-labelled infrastructure for the TISAX Streaming option (ENX assessment of the provider). The processor itself does not hold its own TISAX label.
13Data minimisationStreaming: no persistence of video content; telemetry limited to operational metrics. Review: storage only of the content introduced by the controller; AI translation only on request (opt-in) and plan-bound.
14Data qualityMaster data editable by users themselves (self-service); organisation-scoped, consistent data storage; versioning of media data (Review).
15Limited storage periodStreaming: session metadata 12 months; backups a maximum of 7 daily states. Review: content until deletion by the controller; database recovery history 48 hours; audit logs 365 days.
16AccountabilityTOM documentation with verification status; publicly maintained sub-processor list with DPA links (dfine.io/trust); audit logs; record pursuant to Art. 30(2) GDPR on request.
17Data portability and deletionHard deletion routines in both applications; deletion of the organisation on request; audit export; deletion cascades: Streaming backups within 7 days, Review recovery history within 48 hours (§ 7(4) and (5)).
18Support for the controllerForwarding of data subject requests (§ 3(3)); support with notifications under Art. 33/34 GDPR; direct, personal contact channel (mail@dfine.io).

Evidence: no own certification under Art. 42 GDPR; infrastructure evidence of the data centre and platform operators (ISO 27001, SOC 2, TISAX label, EU-U.S. Data Privacy Framework) available.

Annex "Sub-processors" to § 8

The sub-processors engaged to perform the contract. The continuously maintained version with DPA links is published in the Trust & Compliance overview. As of 15 July 2026.

Part A · dfine.io Streaming Classic
Sub-processor (name, seat)Region / transfer basisService
Hetzner Online GmbH, Gunzenhausen (DE)Germany (DC Nuremberg)VPS hosting for API, app, database and container registry; server backups
Google Cloud EMEA Limited, Dublin (IE)Germany (DC Frankfurt, europe-west3)Dedicated streaming instance of the TISAX option (pass-through, no persistence)
Stripe Payments Europe, Limited, Dublin (IE)EU; EU-U.S. Data Privacy FrameworkBilling and payment processing
Axiom, Inc. (Delaware, USA)EU data region; EU-U.S. DPFError logging and audit trail
Apilayer Data Products GmbH, Vienna (AT), service: ipstackEU (Austria)IP geolocation for optional geo-blocking
Part B · dfine.io Review
Sub-processor (name, seat)Region / transfer basisService
Vercel Inc. (USA)App hosting Frankfurt (fra1); EU-U.S. DPFHosting of the application
Neon, LLC, a Databricks, Inc. company (USA)EU (AWS eu-central-1, Frankfurt)Postgres database; primary storage of user, project and media data (metadata)
Clerk, Inc. (USA)Globally distributed edge infrastructure; EU-U.S. DPF (incl. UK/Swiss)Authentication and identity management
Stripe Payments Europe, Limited, Dublin (IE)EU; EU-U.S. DPFBilling and payment processing
Cloudflare, Inc. (USA)R2 object storage with EU jurisdiction; EU-U.S. DPFObject storage for uploaded media files; Workers
Amazon Web Services EMEA SARL (LU)EU (eu-central-1, Frankfurt)Batch encoding of video/image data
LiveKit Incorporated (USA)EU region; EU-U.S. DPFReal-time conferencing and live streaming
Upstash, Inc. (Delaware, USA)EU (eu-central-1, Frankfurt)Redis for rate limiting and cache
Axiom, Inc. (Delaware, USA)EU data region; EU-U.S. DPFObservability and audit logs (365 days)
Plus Five Five, Inc., service: Resend (USA)EU (eu-west-1)Transactional email delivery

Conclusion

For standard customers, this agreement is incorporated as an annex to the service agreement via the Terms and Conditions; a separate signature is not required. On request we provide the version signed by us as a PDF for you to counter-sign. Enterprise and TISAX customers are usually served under an individually negotiated contract; requests to mail@dfine.io.