pursuant to Art. 28 GDPR
Courtesy translation — the German version (Auftragsverarbeitungsvertrag) is legally binding.
Between the customer’s company (hereinafter the “Controller” or “Client”) and Krone Baustein e.K., trading as BauFin, Eschenstieg 1, 20259 Hamburg, represented by Krzysztof Jerzy Buczyński, owner (tax no. 22/282/38532, VAT ID DE344558054, Amtsgericht Hamburg HRA 127948; hereinafter the “Processor” or “BauFin”) — together the “Parties”.
The Controller uses the BauFin SaaS platform. In doing so, the Processor processes personal data (Art. 4(1) GDPR) on the Controller’s behalf and instructions. This agreement specifies the Parties’ duties and rights under Art. 28 GDPR. If the Concierge module is booked, BauFin additionally handles data subject requests (Art. 15–22 GDPR) operationally on the basis of a separate power of attorney.
(1) Subject is the processing of personal data on the Controller’s behalf within the BauFin SaaS platform. (2) Processing comprises: hosting and storage in the multi-tenant architecture; provision of the application logic (accounting, invoicing, GoBD archive, employee/subcontractor management, customer portal, GPS tracking, AI-supported analyses); automated notifications (e-mail, push); backups and disaster recovery; optionally the handling of data subject requests (Concierge). (3) Terms follow Art. 4 GDPR (Controller, Processor, sub-processor, TOMs = technical and organisational measures under Art. 32 GDPR).
(1) Nature: collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure by transmission, alignment, combination, restriction, erasure and destruction. (2) Purpose: performance of the software usage contract, in particular supporting the trade-business processes (accounting, invoicing, payroll, project management), compliance functions (GoBD, XRechnung, construction withholding tax § 48 EStG, ArbZG checks, instant notification DSRV) and statutory retention (§ 147 AO, § 257 HGB). (3) Categories of data subjects (detail: Annex 3): employees, subcontractors and suppliers, the Controller’s customers, business partners and authorities. (4) Data categories (detail: Annex 3): master data, employment data, financial data, compliance data, communication data, and location data of company vehicles (with active mileage-log/BauFin Box module; particularly sensitive, but not special categories under Art. 9 GDPR merely due to the location reference). (5) Location: application, database and backup processing in the EU/EEA by default; third-country elements only in the cases of § 8 and Annex 2, safeguarded under Art. 44 et seq. GDPR.
(1) This agreement enters into force with the software usage contract and ends with its termination. (2) Post-contractual duties (in particular deletion/return under § 12, statutory retention) remain unaffected.
BauFin processes data solely on documented instructions. In detail: (1) instructions are usually given by using the software functions, by e-mail to [email protected] or via the ticket system; oral instructions must be confirmed in writing; (2) duty to flag unlawful instructions, with the right to suspend execution; (3) confidentiality: all authorised persons committed in writing, training at least annually; (4) security under Art. 32 GDPR — measures in Annex 1 (TOMs), reviewed annually; (5) sub-processors only with general authorisation — § 7 and Annex 2; (6) support for data subject rights (Art. 15–22): in the standard model provision of data (JSON/CSV) with the Controller replying; in the Concierge module operational handling based on the power of attorney; (7) support for duties under Art. 32–36 GDPR (incl. DPIA); extra effort billable unless covered by Concierge; (8) breach notification without undue delay, at the latest within 24 hours (§ 10); (9) deletion/return after contract end (§ 12); (10) evidence and audits (§ 5(4)); (11) own record under Art. 30(2) GDPR with extracts on request; (12) data protection officer: contact per Annex 1, if appointed.
(1) The Controller is solely responsible for the lawfulness of processing (Art. 6 GDPR), including consents, information duties (Art. 13/14) and employee data protection (§ 26 BDSG). (2) The Controller documents its instructions; standard instructions follow from this agreement and the use of the software. (3) It informs about changes of its requirements without delay. (4) Control rights: review of compliance documentation, written information, on-site audits with at least 14 days’ notice, at most once per year (unless there is justified cause). Costs are borne by the Controller unless the audit reveals a material breach. (5) A valid certified audit procedure (e.g. ISO 27001, BSI C5) replaces the on-site audit.
(1) BauFin implements measures under Art. 32 GDPR considering the state of the art, costs, nature and risks. (2) Details in Annex 1, at minimum: encryption (TLS 1.3 in transit, AES-256 at rest), confidentiality/integrity/availability/resilience, recoverability (RTO 24h, RPO 1h), annual effectiveness review. (3) Material TOM changes are communicated.
(1) The Controller grants general authorisation (Art. 28(2) sentence 2 GDPR). (2) The current list is in Annex 2 (service categories: hosting in German data centres, transactional e-mail within the EU, DNS/TLS/CDN/WAF, encrypted storage of data exports, AI functions with transmission only upon explicit user action based on DPA + SCC). Processing on the provider’s own infrastructure (incl. GPS/location data, push, geocoding, maps, routing) is not sub-processing; payments are handled by independent controllers. (3) Changes are announced at least 30 days in advance; the Controller may object. (4) In case of a justified, unresolved objection: right to terminate with 30 days’ notice to the end of the billing period. (5) Written contracts with equivalent duties exist with every sub-processor; presented on request (redacted where necessary). (6) For third-country transfers § 8 additionally applies.
(1) By default, processing takes place exclusively in the EU/EEA. (2) Third-country transfers occur for: a) AI functions (“Financial Guide”, AI assistant) — transmission of the required data to Anthropic, PBC (US) based on a DPA, SCC and supplementary measures, data-minimised; b) payments — handled by independent controllers within the EU/EEA, no third-country transfer by BauFin; c) network and security services — access/network data may pass through global infrastructure, safeguarded by DPA, SCC and technical measures. (3) BauFin applies supplementary “Schrems II” measures (transport/content encryption, access restrictions). (4) Other transfers only after contract amendment and prior information.
(1) Requests are to be addressed to the Controller; requests received directly are forwarded without delay. (2) Standard model — software functions: access (JSON/CSV export), rectification (admin UI), erasure (soft delete respecting statutory retention), restriction (marking), portability (machine-readable export), objection (marking and blocking). (3) Concierge module: operational handling based on the power of attorney — receipt ([email protected] or forwarding), identity verification, substantive review, retention check, export/changes, reply letter under Art. 12(3) GDPR, dispatch, audit-log documentation. (4) Deadlines: reply within one month (Art. 12(3) GDPR), extendable by at most two months in complex cases; data subject and Controller are informed. (5) The Controller remains ultimately responsible externally (Art. 24 GDPR). (6) Remuneration: standard model included in the software fee; Concierge in the module fee; extraordinary effort (over 20 requests/month, identity disputes, court proceedings) billed by effort.
(1) Notification to the Controller without undue delay, at the latest within 24 hours of becoming aware, including the nature of the breach, affected categories and numbers, likely consequences and measures. (2) For critical severity additionally a first notification by phone to the stored emergency number. (3) Support with duties under Art. 33/34 GDPR (72-hour notification, informing data subjects); in Concierge also preparation of notification texts. (4) Forensics and evidence preservation for later reviews. (5) Mutual cooperation in investigation and remediation.
(1) BauFin keeps a record under Art. 30(2) GDPR. (2) Content at minimum: contact details of the Processor and sub-processors, categories of processing, third-country transfers with safeguards, TOM description. (3) Extracts on request. (4) Support for the Controller’s own record under Art. 30(1); in the Concierge module template texts for BauFin-related entries.
(1) The Controller chooses: complete return (JSON/CSV/SQL dump) or complete deletion. (2) Choice at the latest 30 days before contract end to [email protected]; absent a choice, automatic deletion 90 days after contract end. (3) Implementation: deletion/deactivation of active tenant data after 90 days; rotation of technical backups within up to 35 further days; deletion of non-retained logs within 90 days. (4) Exception — statutory retention (§ 147 AO, § 257 HGB): access-restricted archive, access only for tax authorities/courts, automatic deletion after expiry. (5) Written deletion confirmation with date and method. (6) Costs: simple data output included; complex conversions or repeated exports billed by effort.
(1) Externally, joint and several liability under Art. 82(4) GDPR remains unaffected. (2) Internally, BauFin is liable for breaches of its Art. 28 duties, of this agreement, and for acts outside documented instructions. (3) The Controller is internally liable in particular for erroneous instructions, missing legal bases, breached information duties and violations of § 26 BDSG. (4) BauFin’s internal liability cap: annual net remuneration under the main contract in the year of damage; the cap does not apply to intent/gross negligence, breach of cardinal duties, personal injury, product liability and external liability under Art. 82 GDPR. (5) IT liability insurance per Annex 1.
No contractual penalty is agreed. Statutory and contractual damages claims remain unaffected.
(1) This agreement applies for the term of the main contract. (2) Isolated termination is not possible; the end of the main contract also ends this agreement. (3) Termination for cause without notice (repeated breach after warning, insolvency, lasting destruction of trust). (4) Surviving duties: confidentiality, deletion/return, statutory retention, liability for damage incurred.
(1) Amendments require text form (§ 126b BGB). (2) Severability clause. (3) German law excluding the CISG. (4) Place of jurisdiction — where permissible — the Processor’s seat. (5) In data protection matters this agreement prevails over the main contract. (6) Annexes as integral parts: Annex 1 (TOMs), Annex 2 (sub-processors), Annex 3 (data categories).
Confidentiality: production servers in ISO-27001-certified data centres of the hosting provider IONOS SE in Germany; administrative access only for authorised administrators with personal accounts. System access control: password + 2FA (TOTP, mandatory for admins), password requirements per BSI TR-02102, account lockout, session timeout, role-based access (RBAC). Data access control: strict tenant separation (schema per tenant), AES-256 at rest, TLS 1.3 in transit, complete audit log, four-eyes principle for critical operations. Separation control: logical separation, separate backups per tenant, separated test/production environments (synthetic test data). Pseudonymisation: logs and AI requests largely pseudonymised/aggregated. Integrity: encrypted transfer, signed tokens, e-mail with DKIM/SPF/DMARC, push via self-operated service; full change log with user/timestamp/values. Availability: hourly database backups (RPO 1h), daily full backups, 35-day retention, documented DR plan (RTO 24h), monthly test restore. Review: annual TOM review, incident response with 24/7 alerting, annual external penetration test (critical/high findings fixed within 30 days), IT liability insurance with at least EUR 1 million cover. Data protection officer: currently no appointment duty (§ 38 BDSG); contact: [email protected].
IONOS SE (Montabaur, DE; data centres in Germany) — hosting of application and database servers; DPA, ISO-27001 data centres. · Cloudflare, Inc. (US; EU edge) — CDN, DDoS protection, DNS proxy for technical connection data; DPA + SCC. · Zoho Corporation B.V. (Utrecht, NL; EU data centres) — transactional e-mail; DPA, processing in the EU. · Backblaze, Inc. (US; data centre Amsterdam, NL) — encrypted storage of data exports (module “Datenexport Pro” only); DPA + SCC. · Anthropic, PBC (US) — AI functions, only upon active use; DPA + SCC, data minimisation; an exclusive EU endpoint is not warranted. Own infrastructure (no sub-processing): GPS/location data, push notifications, geocoding, maps and routing run exclusively on the provider’s own infrastructure in German data centres; vehicle location and movement data do not leave the provider’s infrastructure. Payment providers (independent controllers): Revolut Bank UAB and PayPal (Europe) S.à r.l. et Cie, S.C.A. process payment data as independent controllers; the Controller’s customer data is not transmitted to them.
Data subjects: owners/managing directors, employees, subcontractors, suppliers, the Controller’s customers, commissioned auditors (tax advisors, auditors), authority contacts. Data categories: master data (name, address, date of birth, tax ID, VAT ID, social security number, bank details, health insurer); employment data (wage, working-time account, vacation, sick days without diagnosis, qualifications, instant notification, payslips); financial data (invoices, dunning, payments, receivables, bookings, receipts); compliance data (§ 48b EStG exemption certificates, construction withholding tax, instant notifications, A1, audit reports, GoBD audit trails); communication data (e-mails, chat, notes, attachments); location data with the active mileage-log/BauFin Box module (GPS coordinates, routes, speed, ignition, OBD data, driver assignment if enabled) — particularly sensitive, but not Art. 9 categories merely due to location. Special categories (Art. 9): health data only to a limited extent (sick days without diagnosis) in the employment context (Art. 9(2)(b) GDPR, § 26 BDSG); beyond that only if the Controller exceptionally processes such data — for which it remains solely responsible. BetrVG note: with a works council, the fleet module requires a works agreement (§ 87(1) no. 6 BetrVG); this is the Controller’s sole responsibility.
