Data Processing Agreement (DPA)
pursuant to Art. 28 GDPR · Version 1 · June 2026 · Berlin
This English text is a convenience translation to aid understanding. Only the German version of this document is legally binding; in the event of any discrepancy, the German version prevails.
The DPA pursuant to Art. 28 GDPR is validly concluded upon registration. Here you can read it and download it as a PDF with your details — as an additional document for your records!
For a personalised, filled-in PDF, please log in. You can read the contract text here at any time.
Processor
Mandria Labs GbR, Lachenmeyrstr. 16, 81827 München, Deutschland, represented by die Gesellschafter Martin Dietrich und Daniel Seitz. Contact: datenschutz@flowpresent.org.
Preamble
With flow present (flowpresent.org), the Processor provides cloud-based software for planning and running workshops and seminars (briefing, session planning, slide editor, live mode, follow-up). In the course of this use, the Processor processes personal data on behalf of and on the documented instructions of the Controller — in particular data of workshop participants that the Controller collects via the service.
This agreement specifies the data-protection obligations of the parties for the processing described in Annex 1. It applies to all plans (including the free plan) as soon as personal data of third parties is processed via the service on behalf of the Controller.
Allocation of responsibility: For the account master data of the customer’s user account (e.g. sign-in email, profile, billing data), flow present is an independent controller within the meaning of Art. 4 no. 7 GDPR; in this respect the privacy policy at flowpresent.org/datenschutz applies and not this DPA. This DPA governs exclusively the processing carried out on behalf of the Controller (Art. 28 GDPR).
Section 1 — Subject matter, nature and purpose of the processing
- The subject matter of the assignment is the processing of personal data by the Processor for the Controller in connection with the provision and operation of flow present.
- The nature, scope and purpose of the processing, the type of personal data as well as the categories of data subjects are set out conclusively in Annex 1.
- The processing takes place exclusively within the European Union or the European Economic Area, unless expressly provided otherwise in Annex 3.
Section 2 — Duration of the assignment
The agreement begins with the Controller’s registration or first use of the service and runs for an indefinite period. It ends automatically upon termination of the usage relationship (deletion of the account or organisation). The provisions on deletion and return (Section 9) remain effective beyond the end of the agreement.
Section 3 — Right of instruction of the Controller
- The Processor processes personal data solely on the documented instructions of the Controller, including with regard to transfers to third countries, unless it is required to process such data by Union or Member State law.
- Use of the service in accordance with the documentation and the configuration settings that have been made is deemed to be a documented instruction. Individual instructions are given in text form to datenschutz@flowpresent.org.
- The Processor shall inform the Controller without undue delay if, in its opinion, an instruction infringes data-protection provisions. It is entitled to suspend the execution of the instruction concerned until it is confirmed or amended.
Section 4 — Obligations of the Processor
The Processor undertakes in particular:
- to carry out the processing solely within the scope of this agreement and the instructions of the Controller;
- to ensure that persons authorised to process the data have committed themselves to confidentiality, unless they are already under an appropriate statutory obligation of confidentiality (Art. 28(3)(b), Art. 29, Art. 32(4) GDPR);
- to implement and maintain the technical and organisational measures pursuant to Art. 32 GDPR in accordance with Annex 2;
- to assist the Controller, to the extent possible, in fulfilling its obligations under Art. 32–36 GDPR (Section 6);
- to provide a data-protection contact for data-protection enquiries (datenschutz@flowpresent.org); there is currently no statutory obligation to designate a data protection officer;
- to maintain a record of all categories of processing activities carried out on behalf of the Controller pursuant to Art. 30(2) GDPR;
- to inform the Controller without undue delay if a supervisory authority takes action against the Processor, insofar as this concerns the processing carried out on behalf of the Controller.
Section 5 — Technical and organisational measures (Art. 32 GDPR)
- The Processor implements the technical and organisational measures described in Annex 2 to protect the personal data and maintains them for the duration of the agreement.
- The measures are subject to technical progress. The Processor is entitled to develop them further, provided that the agreed level of protection is not undercut. Material changes are documented.
Section 6 — Assistance obligations
- The Processor assists the Controller, by appropriate technical and organisational measures, in responding to requests by data subjects to exercise their rights (Art. 12–23 GDPR). If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay.
- The Processor assists the Controller in complying with the obligations under Art. 32–36 GDPR (data security, notification of breaches, data protection impact assessment, prior consultation), taking into account the nature of the processing and the information available to it.
Section 7 — Notification of personal data breaches
The Processor shall notify the Controller of any personal data breach that comes to its attention affecting data processed on behalf of the Controller without undue delay — as a rule within 48 hours of becoming aware of it. The notification shall contain at least the information required under Art. 33(3) GDPR, insofar as available. The notification to the supervisory authority pursuant to Art. 33 GDPR as well as, where applicable, the communication to the data subjects pursuant to Art. 34 GDPR is the responsibility of the Controller.
Section 8 — Sub-processing
- The Controller consents to the use of the sub-processors listed in Annex 3 (general written authorisation pursuant to Art. 28(2) GDPR).
- The Processor shall inform the Controller in advance in text form (e.g. by email or via a published list at flowpresent.org) of any intended changes concerning the addition or replacement of sub-processors. The Controller may object to a change within 14 days on important data-protection grounds; in the event of an objection, the parties are obliged to reach an amicable solution, failing which the Controller has a right of termination.
- The Processor shall contractually bind each sub-processor to data-protection obligations equivalent to those of this agreement (Art. 28(4) GDPR). Where a sub-processor breaches its data-protection obligations, the Processor remains liable to the Controller as for its own conduct.
- Ancillary services (telecommunications, maintenance or comparable services) as well as optional third-party services that are only triggered by a separate action of the Controller or the participants (see Annex 3, Section B) do not constitute sub-processing within the meaning of this agreement.
Section 9 — Deletion and return after the end of the agreement
- Upon completion of the processing, the Processor shall delete all personal data processed on behalf of the Controller or return it, at the Controller’s choice, unless a statutory retention obligation exists.
- The Controller may export its data itself at any time during the term of the agreement. Upon deletion of the account or organisation via the settings, the associated content and uploaded files are removed immediately.
- Statutory retention obligations (in particular for billing data) remain unaffected; such data is blocked for the duration of the statutory periods and subsequently deleted.
Section 10 — Rights of monitoring and verification
- The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
- Proof may also be provided by means of appropriate certifications, current audit reports or reports of independent bodies (e.g. ISO 27001 of the infrastructure providers used) as well as by a documented self-assessment.
- On-site inspections shall be carried out with reasonable advance notice, during normal business hours and without disrupting operations.
Section 11 — Final provisions
- Amendments and supplements to this agreement require text form. This also applies to any amendment of this clause.
- In the event of contradictions between this agreement and other agreements of the parties, the provisions of this agreement prevail on data-protection matters.
- Should individual provisions be invalid, the validity of the remaining provisions shall remain unaffected. The parties shall replace the invalid provision with a valid one that comes as close as possible to its economic purpose.
- The law of the Federal Republic of Germany applies.
Annex 1 · Subject matter and details of the processing
Categories of data subjects
- Workshop participants (with and without login);
- Members of the Controller’s organisation (trainers, moderators, staff);
- Third parties entered into content by the Controller (e.g. persons mentioned by name in briefings, slides or free text).
Type of personal data
| Data category | Examples |
|---|---|
| Identification / contact data | Display names, participant names (e.g. for group draws), optional profile pictures |
| Workshop content | Briefings, session plans, slide content (texts, images, videos, notes) — insofar as personal information is contained |
| Contribution / interaction data | Responses to polls, scale questions, free text, word clouds (pseudonymous via a device-bound random key), team chat messages |
| Uploaded files | Files uploaded by team members or participants during live operation |
| Technical usage data | Infrastructure access logs (IP address, user agent, timestamp; time-limited) |
Annex 2 · Technical and organisational measures (Art. 32 GDPR)
1. Confidentiality
- Physical access control: operation in ISO 27001-certified data centres of the infrastructure providers used (AWS region eu-central-1, Frankfurt); no own physical server operation.
- System access control: passwordless authentication via magic link (no password storage); session cookies httpOnly and Secure.
- Data access control: role- and organisation-based access restriction; data accessible exclusively to the respective team; separation at database level.
- Separation control: multi-tenant data storage, logical separation of data per organisation.
- Pseudonymisation: participant responses are stored via a random, device-bound key without any link to a user account.
2. Integrity
- Transmission control: transport encryption (TLS) for all data transfers; encryption of data at rest at infrastructure level.
- Input control: traceable editing of collaborative documents; logging of relevant system and access events.
3. Availability and resilience
- Regular data backup by the infrastructure service providers used.
- Monitoring of stability and security; error and outage detection.
- Redundant, scalable cloud infrastructure.
4. Procedures for regular review, assessment and evaluation
- Data protection by design and by default (Art. 25 GDPR): data minimisation, no advertising trackers, no usage profiles for advertising purposes.
- Assignment control: contractual binding of all sub-processors; review of the protective measures taken.
- Incident management process for handling security incidents.
flow present is open source and can be self-hosted. When self-hosting, the operating organisation is responsible for the technical and organisational measures on its own; this DPA relates to the cloud version operated by the Processor.
Annex 3 · Approved sub-processors
| Provider | Service | Location | Legal basis |
|---|---|---|---|
| Supabase Inc., San Francisco (USA) | Database, authentication, file storage, real-time features | EU – Frankfurt (AWS eu-central-1), ISO 27001 | DPA concluded pursuant to Art. 28; SCC / Data Privacy Framework for any US access |
| Vercel Inc., San Francisco (USA) | Application hosting; access logs (IP, user agent, timestamp, max. 30 days) | EU region routing | DPA; SCC / Data Privacy Framework |
| Functional Software Inc. (Sentry), USA | Error and stability monitoring (technical diagnostic data) | EU region (Frankfurt / Germany) | DPA; SCC / Data Privacy Framework; IP transmission disabled |
Optional third-party services (user-triggered)
| Service | Function | Note |
|---|---|---|
| Stripe (Ireland / USA) | Payment processing for paid plans | Concerns the account holder (flow present as controller), not participant data |
| Unsplash (USA) | Optional image search | Upon use, the request / IP is transmitted |
| LibreTranslate (own EU server) | Optional live translation of slide content | Runs on our own server in Germany (EU); no transmission to an external translation service. When self-hosting, fully within your own infrastructure |
| Open-Meteo (Switzerland) | Optional weather variable in slides | No personal data |