This Data Processing Agreement (DPA) governs how FlowMate GmbH, as processor, handles personal data on behalf of customers under Article 28 GDPR, forming an integral part of the main agreement between FlowMate and the customer.
Version May 2023
This Agreement on the processing of personal data according to Art. 28 GDPR is entered into between FlowMate GmbH, Harry-Blum-Platz 2, 50678 Cologne, Germany ("processor"), and the client of the services offered by FlowMate ("controller").
The controller shall have personal data processed by the processor on its behalf on the basis of the General Terms and Conditions of FlowMate GmbH (the "main agreement").
The object of the processing of personal data is the provision of the services stipulated in the main agreement by the processor for the controller. The purpose of the processing, as well as the categories of data subjects and categories of personal data, can be derived from the main agreement and are presented in Annex 1.
The processing shall initially take place exclusively in a member state of the European Union or in another contracting state of the Treaty on the European Economic Area (EEA). Should data processing take place in a third country, the processor shall ensure that this occurs exclusively in compliance with the requirements of the General Data Protection Regulation (GDPR), Article 44 et seqq.
4.1.
The controller is the controller of the data processing of the personal data as stated in Art. 4 (7) GDPR. It is responsible for compliance with the legal obligations on data protection, in particular for the lawfulness of the data processing and transfer of the data to the processor.
4.2.
The controller shall at all times be entitled to issue supplementary instructions on the nature, scope and procedures of the data processing. Instructions may be issued orally or in writing. Oral instructions must be confirmed and documented immediately in writing vis-à-vis the processor.
4.3.
The processor shall inform the controller immediately in writing if, in the processor's view, an instruction issued by the controller breaches legal obligations. The processor is entitled to suspend implementation of the instruction involved until it has been confirmed or amended by the controller. If a direct liability of the processor towards third parties or under the GDPR could result from the instruction, the processor is entitled to reject the instruction.
4.4.
The controller must inform the processor immediately, stating the reasons, if it identifies errors or irregularities regarding the requirements of this agreement or the GDPR in the order results or regarding the activity of the processor.
5.1.
The controller is entitled to all rights of inspection required pursuant to the guidelines of the GDPR to observe its obligations under data protection law. The right of inspection exists subject to observance of an appropriate announcement period and during the normal business hours of the processor. The processor must facilitate and contribute to the exercise of this right.
5.2.
The controller must take care that inspections are only carried out to the extent necessary in order not to excessively disrupt the processor's operations. Should the controller commission an auditor who is a competitor of the processor, the latter is entitled to object to the activity of this auditor.
5.3.
The processor may, to the extent necessary, make the inspection by the controller dependent on the signing of a non-disclosure agreement with regard to the personal data and business secrets of other controllers and the technical and organisational measures in place.
5.4.
If agreed with the controller, the processor may demand remuneration for its activity in connection with an inspection. The performance of the inspection is independent of any agreement between the parties on the remuneration to which the processor is entitled.
6.1.
All processing of the personal data shall occur exclusively on the basis of the main agreement and the instructions given by the controller. When transmitting personal data to a third country or an international organisation, the processor shall comply with the provisions of Art. 44 et seqq. GDPR. This does not apply if the processor is obliged to different processing by the law of the European Union or the member states to which the processor is subject and the requirements of Art. 28 (3) no. 1 GDPR are complied with.
6.2.
The processor shall set up its internal organisation to ensure compliance with the legal data protection obligations. In accordance with Article 32 GDPR, it will take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk of varying likelihood and severity for the rights and freedoms of natural persons.
6.3.
A description of the technical and organisational measures can be found in Annex 2 to this agreement.
6.4.
The processor is entitled to alter the measures mentioned if it is ensured that the agreed protection level and the requirements under Art. 32 and Art. 28 (1) GDPR are not undercut.
6.5.
The processor names the following contact for all concerns of data protection and the execution of this agreement: Guido Wirtz, Anton-Brune-Weg 63A, 59519 Möhnesee, Germany, e-mail guido.wirtz@gwconsult.de.
6.6.
Persons authorized to process personal data on behalf of the processor have been obligated in writing to observe confidentiality and the valid legal obligations of data protection. This obligation continues beyond the end of the employment relationship for an unlimited period. Compliance with confidentiality and data protection by employees must be proven to the controller upon request.
6.7.
The processor shall support the controller, taking into account the type of processing and the information available to it, in observing the obligations mentioned in Art. 33 to 36 GDPR.
6.8.
Upon legitimate request of the controller, the processor shall provide it with all information required to prove compliance with the obligations incumbent on the processor under Article 28 GDPR.
7.1.
The processor will, as far as possible, assist the controller in fulfilling its obligation to respond to requests to exercise the rights of data subjects referred to in Chapter III of the GDPR.
7.2.
If a data subject contacts the processor with a request to this effect and the order processing is affected, the processor shall refer the data subject to the controller, provided that an assignment to the controller is possible based on the information provided by the data subject.
8.1.
In the case of a personal data breach regarding the controller's personal data, the processor shall, without undue delay after becoming aware of it, notify the controller of the breach. The notification shall contain at least: (a) a description of the type of breach, if possible stating the type and quantity of data affected and categories of data subjects; (b) the name and contact details of the data protection officer or another contact point for further information; (c) a description of the probable consequences of the breach; and (d) a description of the measures taken or proposed by the controller to eliminate the breach and, if necessary, to mitigate its possible adverse effects.
8.2.
The controller alone is responsible for any notification that may be necessary to a regulatory authority or to data subjects. The processor shall cooperate to the extent required.
9.1.
The processor shall use the sub-processors stated in Annex 3 for the processing of the controller's personal data. The processor is obliged to inform the controller of the commissioning of other sub-processors or changes in subcontracting, by sending an e-mail to the administrator of the controller's company account. The controller may object to the change within four weeks after publication (receipt of the objection). The processor shall not implement the change before expiry of the objection period.
9.2.
The processor shall observe the conditions mentioned in paragraphs 2 and 4 of Art. 28 GDPR for any sub-processor. It must also ensure that the contractual agreements otherwise made with the customer, as well as any supplementary instructions of the customer, are also observed by the sub-processors.
9.3.
If a sub-processor does not process the transmitted data within the territory of the EU or EEA, the processor shall ensure that this is done exclusively in accordance with the provisions of Art. 44 et seqq. GDPR.
The processor shall not be entitled to any separate remuneration for the services rendered under this Agreement unless expressly agreed otherwise.
The liability of the parties is based on the agreements of the respective contract under which the order processing is carried out. The direct liability of the parties to a data subject arising from statutory data protection provisions remains unaffected.
The term of this Agreement corresponds to the term of the main agreement.
13.1.
After the provision of the processing services has concluded, the processor shall, at the controller's option, delete all personal data unless an obligation to store the personal data exists under EU law or the law of the member states to which the processor is subject.
13.2.
The controller is entitled to supervise the complete and contractually compliant deletion of the data on the processor's premises.
13.3.
Any right of retention of the processor regarding the processed data and the associated data carriers is excluded.
The final provisions of the main agreement shall apply.
© 2026 FlowMate GmbH, Cologne. All rights reserved.