Parties
Data processing agreement under Art. 28 GDPR (English translation of the German draft)
between the user of the Sunworker platform who accepts this agreement on the platform (“controller”) and Sunworkers Ltd. (trading as “Sunworker”), Sinasi Bei 69, Kings Resort, Block C, Flat/Office A2, 8015 Paphos, Cyprus, registered with the Registrar of Companies of the Republic of Cyprus under HE 464110, represented by its director Andy Staudinger, email kontakt@sunworker.eu (“processor”).
§ 1 Subject matter and duration
(1) This agreement governs the processing of personal data that the processor carries out on behalf of the controller. It applies only to the services in § 2.
(2) For all other functions of the platform (profiles, search, requests, chat, reviews, payment processing, escrow, commission invoices, timesheets, support) the processor is itself the controller. Its privacy policy applies to them, not this agreement.
(3) The agreement applies as long as the controller uses a service under § 2. It ends when the user agreement for the platform ends (terms of use).
§ 2 Nature and purpose of the processing
The processor provides the following services on the controller’s behalf:
(1) Invoice in the name of the professional. On the basis of the invoicing mandate, the processor creates, numbers, stores and sends the professional’s invoice to their client (invoice issued by a third party, Section 14(2) sentence 6 of the German VAT Act). The number sequence is kept per professional. If the professional uploads an invoice of their own, the processor stores it for the professional. The controller is the professional.
(2) Accounting add-ons. If the controller connects an accounting program, the processor transfers documents to it: individually, automatically or retroactively, depending on the settings. The DATEV export creates a file for download. The controller is the professional or the venue that connects the add-on.
(3) User management of a venue. The processor manages invitations, roles, permissions and departments of a venue’s members and logs their actions in the venue’s audit log. The controller is the venue.
The processor processes the data only to provide these services. Where it uses the same data for its own purposes (for example escrow, its own commission invoice, its own statutory retention, checking an uploaded invoice before payout), it acts as a controller in its own right to that extent.
§ 3 Types of data
- Master data of the invoice issuer and recipient: name, company, address, tax number, VAT identification number, VAT status.
- Invoice and document data: invoice number, date, service period, line items, amounts, tax rates, payment status, invoice PDF.
- Access data for accounting programs: API key (stored encrypted).
- Data of a venue’s members: name, email address, role, permissions, department, time and type of their actions.
§ 4 Categories of data subjects
- Professionals as invoice issuers.
- Clients (venues and private individuals) and their contact persons as invoice recipients.
- Members of a venue (people the venue invites to its account).
§ 5 Instructions
(1) The processor processes the data only on documented instructions from the controller, unless a legal obligation requires otherwise (Art. 28(3)(a) GDPR). In that case it informs the controller beforehand, as far as the law permits.
(2) The controller gives instructions through the platform settings (for example the invoicing mandate, connecting an add-on, the “transfer automatically” switch, granting permissions) or in text form to kontakt@sunworker.eu. A setting counts as a documented instruction; the processor logs it with a timestamp.
(3) If the processor considers an instruction unlawful, it says so without undue delay. It may suspend carrying it out until the controller confirms or changes it.
§ 6 Confidentiality
The processor only uses persons who have committed themselves to confidentiality or are under a statutory obligation of confidentiality (Art. 28(3)(b) GDPR). These persons process the data only on the controller’s instructions.
§ 7 Technical and organisational measures
(1) The processor takes the measures under Art. 32 GDPR described in Annex 2.
(2) It may adapt them to the state of the art. The level of protection must not drop in the process. It documents material changes.
§ 8 Sub-processors
(1) The controller gives general authorisation for the sub-processors in Annex 1.
(2) The processor informs the controller of every intended change at least 30 days in advance in text form (email or notice on the platform). The controller may object in text form within this period. If it objects, it may end the affected service under § 2; the processor can then no longer offer it to the controller.
(3) The processor contractually binds every sub-processor to the same data protection obligations (Art. 28(4) GDPR). If processing takes place outside the EU or the EEA, it ensures a safeguard under Art. 44 et seq. GDPR.
(4) Services that the controller chooses itself and with which it has its own contract, in particular accounting programs (§ 9), are not sub-processors.
§ 9 Transfer to the controller’s own services
(1) If the controller connects an accounting program (currently Lexware Office of Haufe Service Center GmbH or sevDesk of sevdesk GmbH), the processor transfers the data to that service on the controller’s instruction.
(2) Processing there is governed solely by the contract between the controller and the service, including a separate data processing agreement.
(3) The processor stores the API key encrypted and shows only its last four characters. If the controller disconnects, the processor deletes the key. Data already transferred remains with the service.
§ 10 Assistance to the controller
(1) The processor assists the controller with appropriate measures in responding to requests from data subjects (Art. 12 to 22 GDPR). If a data subject contacts the processor directly, it forwards the request without undue delay.
(2) It assists the controller with the obligations under Art. 32 to 36 GDPR (security, notification, impact assessment, prior consultation), as far as it has the necessary information.
(3) Assistance under this section is free of charge for the controller. It is provided by email to kontakt@sunworker.eu.
§ 11 Notification of breaches
(1) The processor notifies the controller of every personal data breach without undue delay, at the latest 48 hours after becoming aware of it.
(2) The notification contains, as far as known: the nature of the breach, the data and persons concerned, likely consequences, measures taken and a contact point. It provides missing information later.
§ 12 Audit rights
(1) The processor makes available to the controller the information necessary to demonstrate compliance with its obligations (Art. 28(3)(h) GDPR). Primarily this is done through documents, reports and written information.
(2) If these are not sufficient, the controller may request an on-site audit: with 30 days’ notice, during business hours, at most once a year, except after a breach. The auditor must be bound to confidentiality. The controller bears the costs.
§ 13 Deletion and return
(1) When the service ends, the processor deletes the data it has processed on the controller’s behalf or returns it on request (Art. 28(3)(g) GDPR). The controller can download its invoices and documents on the platform beforehand.
(2) Data that the processor must retain under Union or Member State law, or that it processes as a controller in its own right (last paragraph of § 2), is not deleted. It retains invoices and accounting documents for 8 years and books for 10 years. After that it deletes them.
(3) Backups are overwritten in the normal cycle: daily backups after 7 days, weekly after 4 weeks, monthly after 3 months. Deleted data is therefore also removed from the backups after about 3 months at the latest.
§ 14 Liability
The parties are liable for damage suffered by data subjects in accordance with Art. 82 GDPR. Between the parties, the liability provisions of the terms of use apply, unless Art. 82 GDPR provides otherwise.
§ 15 Applicable law and jurisdiction
(1) This agreement is governed by the law of the Federal Republic of Germany, like the user agreement (§ 16(1) of the terms of use). Art. 28(3) GDPR requires the law of the Union or of a Member State; this is fulfilled.
(2) The courts at the processor’s registered office in Paphos (Cyprus) have exclusive jurisdiction over disputes arising from this agreement (Art. 25 of Regulation (EU) No 1215/2012), as in § 16(2) of the terms of use. The processor may also sue the controller at the controller’s general place of jurisdiction.
(3) Private individuals do not enter into this agreement.
§ 16 Conclusion and changes
(1) The agreement is concluded electronically (Art. 28(9) GDPR): the controller accepts it on the platform, for example when granting the invoicing mandate, when connecting an add-on or when inviting the first member. The processor stores the time, account and version of the acceptance.
(2) The processor announces changes in text form at least 30 days before they take effect, by email and as a notice on the platform. The controller agrees to the changes on the platform. If it has not agreed by the time they take effect, the services under § 2 end; it can continue to use the other functions of the platform. § 13 (deletion and return) applies accordingly to the services that have ended.
(3) In the event of conflicts, this agreement takes precedence over the terms of use where the protection of personal data is concerned.
(4) If a provision is invalid, the remaining provisions remain valid.
Annex 1: Sub-processors
Sub-processors for the services in § 2
Supabase Pte. Ltd.Database, authentication service, file storage (invoices, documents)
- Address
- 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513
- Service
- Database, authentication service, file storage (invoices, documents)
- Place of processing
- Amazon Web Services, eu-central-1, Frankfurt am Main
- Third-country safeguard
- Standard contractual clauses (2021/914) for access in individual cases from Singapore and via US sub-processors
Henrik Kramer e.K. (Prepaid-Hoster.de)API server, background jobs (document transfer), sending invoices by email via our own mail server
- Address
- Kurpromenade 48, 23743 Grömitz, Germany
- Service
- API server, background jobs (document transfer), sending invoices by email via our own mail server
- Place of processing
- maincubes FRA01 data centre, Offenbach am Main
- Third-country safeguard
- not required
Vercel Inc.Delivery of the website; the pages with documents and permissions are generated there on the server
- Address
- 440 N Barranca Avenue #4133, Covina, CA 91723, USA
- Service
- Delivery of the website; the pages with documents and permissions are generated there on the server
- Place of processing
- Server functions in Frankfurt am Main (region fra1, checked in the Vercel dashboard on 30 September 2026); static content delivered via Vercel’s global network
- Third-country safeguard
- EU-US Data Privacy Framework (2023/1795), supplemented by standard contractual clauses
Google Cloud EMEA LimitedText comparison of uploaded invoices
- Address
- 70 Sir John Rogerson’s Quay, Dublin 2, Ireland
- Service
- Text comparison of uploaded invoices
- Place of processing
- EU (project in the “EU Data Boundary” folder)
- Third-country safeguard
- EU-US Data Privacy Framework, supplemented by standard contractual clauses, for possible access by Google LLC
Annex 2: Technical and organisational measures
1. Confidentiality (Art. 32(1)(b) GDPR)
- Physical access: data is stored in secured data centres in Germany; physical security is provided by the data centre operators.
- System access: access to servers only for authorised persons with strong authentication; protection against unauthorised sign-in attempts; firewall.
- Data access: role and permission concept; each person sees only the data they are authorised for; access restrictions also in the database; files in non-public storage, available only via time-limited links; limits on repeated sign-in and request attempts; logging of access to sensitive documents.
- Administrative access: additional protection by a second factor.
- Credentials and keys: stored separately from the program code; users’ credentials for add-ons are encrypted.
- Separation: test and demo accounts are marked as such; production data is processed in a separate database.
2. Integrity (Art. 32(1)(b) GDPR)
- Transfer: encrypted transmission (TLS) on all connections.
- Input: logging of administrative and business actions.
3. Availability and resilience (Art. 32(1)(b) GDPR)
- Regular encrypted backups on separate storage hardware in a secured data centre in Germany.
- Controlled updates with the option to roll back.
4. Recoverability (Art. 32(1)(c) GDPR)
- Regular tests of restoring from backups.
5. Review (Art. 32(1)(d) GDPR)
- Automated tests before every update.
- Defined retention and deletion periods.
- Defined procedure for personal data breaches, with notification to the controller within 48 hours (§ 11).
- Data protection contact: kontakt@sunworker.eu.