Data Processing Agreement (AVV)
Last updated 14/07/2026
This is a courtesy translation. The German version is authoritative.
This Art. 28 GDPR Data Processing Agreement is incorporated by reference into our Terms and applies automatically at signup.
- Subject matter, duration, nature and purpose — processing of roster and scheduling personal data for the duration of the customer's subscription, for the purpose of operating the sub.bud service.
- Categories of data subjects — the customer's staff (coordinators, admins) and instructors.
- Categories of data — name, email, phone (optional), availability, class assignments, notification delivery status.
- Documented instructions — the processor processes data only per the customer's instructions as given through the service's normal use, or as otherwise agreed in writing.
- Confidentiality — personnel with access are bound to confidentiality.
- Technical and organisational measures (Art. 32) — per-tenant row-level security enforced at the database layer and verified by an automated isolation test suite on every change; encryption in transit; role-scoped access; tenant-scoped audit logging; nightly encrypted backups; EU (Frankfurt) hosting.
- Subprocessors — the list in our Privacy Policy is incorporated here by reference; the customer authorizes their use. Before engaging a new subprocessor, we will give at least 14 days' notice, during which the customer may object on reasonable data-protection grounds.
- Assistance — the processor assists with data subject requests and Art. 32–36 obligations as reasonably required.
- Deletion / return on termination — data is exported to the customer and then deleted per our lifecycle process.
- Audit rights — the customer may request evidence of compliance with this agreement; on request, the processor provides documentation of the technical and organisational measures above and reasonable evidence of compliance, handled through written information rather than on-site inspections by default, given the scale of the operation.