Data Processing Agreement (DPA, Art. 28 GDPR)
If you process personal data on your server on behalf of others, you need a data processing agreement pursuant to Art. 28 GDPR with us. As a customer, you can conclude the following standardised agreement electronically directly in your customer area (Account → Privacy) — no signature is required (Art. 28 (9) GDPR). After conclusion, you receive the full contract text by email and can access and print it at any time in your customer area.
Version: 2026-08-06. This agreement is drawn up bilingually; in case of doubt, the German version prevails (Section 12).
This data processing agreement (hereinafter "DPA") is concluded between the customer as controller within the meaning of Art. 4 (7) GDPR (hereinafter "Controller") and ComputeBox – Moritz Möller Workstations, Böhnhusener Weg 11, 24220 Flintbek, Germany, email: [email protected], as processor within the meaning of Art. 4 (8) GDPR (hereinafter "Processor").
This DPA specifies the data protection obligations of the parties under the existing contract between them for the provision of virtual servers and GPU servers (hereinafter the "Principal Agreement", based on the Processor's General Terms and Conditions). It implements the requirements of Art. 28 (3) GDPR.
The DPA is concluded electronically via the Controller's customer account in the Processor's customer panel (Art. 28 (9) GDPR: an electronic format is sufficient; no signature is required). As evidence, the Processor records the user account, the time of conclusion, the version of the contract text, and the IP address and browser identifier of the conclusion, and confirms the conclusion by email reproducing the full contract text.
Section 1 Subject matter and duration of the processing
The subject matter of the processing is the provision of virtual servers and GPU servers, including storage and network connectivity (Infrastructure as a Service, IaaS), in accordance with the Principal Agreement. The Controller may store and process personal data on the provided infrastructure under its own responsibility. The Processor's service consists of providing, operating and maintaining the infrastructure; the Processor does not process the data stored on the servers as to its content.
The Processor accesses the Controller's content data only to the extent necessary for operating the infrastructure, maintaining its security and availability, troubleshooting, or handling abuse cases (including the notice-and-action procedure under the Digital Services Act), or where the Controller requests such access in an individual case (e.g. support).
The term of this DPA corresponds to the term of the Principal Agreement. It ends, without requiring separate termination, upon termination of the Principal Agreement, but at the earliest when the Processor no longer processes any personal data of the Controller. Termination of the Principal Agreement is governed by the provisions agreed therein.
Section 2 Nature and purpose of the processing, types of personal data, categories of data subjects
The nature and purpose of the processing, the types of personal data processed and the categories of data subjects are determined solely by the Controller. They are set out in Annex 1; to the extent the Controller does not document its own specifications, the standard examples listed in Annex 1 apply.
The Controller must not process special categories of personal data (Art. 9 GDPR) or data subject to specific statutory secrecy obligations (e.g. Section 203 German Criminal Code) on the infrastructure without first ensuring that the additional safeguards required for such data are in place; where necessary, supplementary agreements must be concluded with the Processor.
Section 3 Responsibility and right to issue instructions
The Controller is solely responsible for the lawfulness of the processing and for safeguarding the rights of data subjects. The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28 (3) sentence 2 (a) GDPR).
The Principal Agreement, this DPA and the configuration of the services by the Controller via the customer panel or the provided interfaces (e.g. creating, modifying, backing up and deleting servers) constitute documented instructions. Any individual instructions beyond that require text form (e.g. email to the address stated in the preamble). Verbal instructions must be confirmed in text form without undue delay.
If the Processor is of the opinion that an instruction infringes the GDPR or other Union or Member State data protection provisions, it shall immediately inform the Controller (Art. 28 (3) sentence 3 GDPR). The Processor is entitled to suspend execution of the instruction concerned until the Controller confirms or amends it.
Instructions may be issued by the Controller, acting through the users authorised for its customer account. The recipient of instructions at the Processor is the contact address stated in the preamble.
Section 4 Confidentiality
The Processor ensures that the persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28 (3) sentence 2 (b) GDPR). The duty of confidentiality continues to apply after the end of the engagement.
The Processor grants access to the Controller's personal data only to persons who need it to perform the contractual tasks (need-to-know principle) and makes the relevant data protection obligations known to them.
Section 5 Technical and organisational measures
The Processor shall take all technical and organisational measures required pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk (Art. 28 (3) sentence 2 (c) GDPR). The measures in place at the time of conclusion of this DPA are described in Annex 2; they form the basis of this engagement.
The measures are subject to technical progress. The Processor may further develop them and replace them with equivalent or better measures, provided the agreed level of protection is not reduced. Material changes are documented; the current version of Annex 2 is made available to the Controller on the Processor's website or on request.
Section 6 Sub-processors
The Controller grants the Processor general authorisation to engage further processors (sub-processors) (Art. 28 (2) sentence 1 GDPR). The sub-processors engaged at the time of conclusion of this DPA are listed in Annex 3 and are approved upon conclusion of this DPA.
The Processor shall inform the Controller in advance in text form (e.g. by email or via the customer panel) of any intended addition or replacement of a sub-processor. The Controller may object to the change in text form within 30 days of receipt of the information on important data protection grounds (Art. 28 (2) sentence 2 GDPR). If the Controller objects and the Processor cannot reasonably provide the service without the new sub-processor, either party is entitled to terminate the Principal Agreement with reasonable notice. If no objection is raised within the period, the change is deemed approved.
The Processor shall impose on each sub-processor, by way of a contract or other legal instrument, the same data protection obligations as set out in this DPA, in particular sufficient guarantees of appropriate technical and organisational measures (Art. 28 (4) GDPR). Where a sub-processor fails to fulfil its data protection obligations, the Processor remains liable to the Controller for the performance of that sub-processor's obligations.
Services which the Processor obtains or provides as an independent controller (e.g. payment processing for its own invoicing, dispatch of its own transactional and contract notifications, telecommunications services, maintenance without data access) as well as ancillary services without a specific connection to the Controller's data do not constitute sub-processing within the meaning of this clause.
Section 7 Data subject rights
The Processor shall assist the Controller, insofar as this is possible, by appropriate technical and organisational measures, in fulfilling the Controller's obligation to respond to requests for exercising data subject rights (Chapter III GDPR) (Art. 28 (3) sentence 2 (e) GDPR). Given the nature of the service (IaaS without content-level data access), this assistance primarily consists of the Controller being able to control the stored data itself at any time via root access, export, backup and deletion functions.
If a data subject contacts the Processor directly and the request can be attributed to the Controller, the Processor shall forward the request to the Controller without undue delay and shall not respond to it itself, unless legally obliged to do so.
Section 8 Assistance obligations and notification of personal data breaches
Taking into account the nature of the processing and the information available to it, the Processor shall assist the Controller in ensuring compliance with the obligations pursuant to Art. 32 to 36 GDPR (security of processing, notification of breaches to the supervisory authority, communication to data subjects, data protection impact assessment, prior consultation) (Art. 28 (3) sentence 2 (f) GDPR).
The Processor shall notify the Controller of any personal data breach affecting the Controller's data without undue delay after becoming aware of it, and in any event in such time that the Controller can meet its notification deadline under Art. 33 (1) GDPR (72 hours) (Art. 33 (2) GDPR). The notification shall contain, where available, the information listed in Art. 33 (3) GDPR; information not immediately available shall be provided without undue further delay. Notification is sent to the email address stored in the Controller's customer account.
The assessment of, and notification to, supervisory authorities and data subjects remains the responsibility of the Controller. The Processor shall without undue delay take appropriate measures to secure the data and to mitigate possible adverse effects, and shall coordinate with the Controller in doing so.
Section 9 Deletion and return upon termination of the engagement
During the contract term, the Controller can export, back up or delete its data itself at any time (root access, backup and export functions; for data export in vzdump format see clause 12 of the Terms and Conditions). The Controller is expected to secure any data it needs before the end of the contract.
Upon termination of the Principal Agreement, the following applies in line with its provisions (clauses 7.5 and 12 of the Terms and Conditions): the virtual server is stopped at the end of the contract. Deletion of the server, including the stored data, takes place at the earliest 7 days after the end of the contract. Upon the Controller's request expressed in text form before deletion, the Processor keeps a data archive available for retrieval for 30 days. Retrieval is free of charge and is not conditional on the settlement of outstanding claims; there is no right of retention over the Controller's data (clause 12.4 of the Terms and Conditions). After expiry of the respective period, the Processor deletes all personal data of the Controller, including existing backup copies, in accordance with the state of the art, unless Union or Member State law requires further storage (Art. 28 (3) sentence 2 (g) GDPR).
Data remaining in backup copies that cannot be deleted immediately for technical reasons are protected against access until their scheduled overwriting or deletion and are no longer actively processed. Upon request, the Processor confirms the deletion in text form.
Section 10 Evidence and audit rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller (Art. 28 (3) sentence 2 (h) GDPR).
Evidence is provided primarily through appropriate documentation: the current version of Annex 2 (TOM), self-declarations, audit reports or certifications, where available. Only where such documentation does not provide sufficient clarification in the individual case may the Controller request an on-site inspection.
On-site inspections take place upon prior notice with a reasonable lead time (generally at least 14 days), during normal business hours, without disproportionately disrupting operations, and at most once per contract year unless a specific cause (e.g. a personal data breach) requires a further inspection. Auditors must not be competitors of the Processor and must be bound to confidentiality. Access to data centre premises is subject to the security rules of the respective site operators. Each party bears its own costs of the inspection; for support exceeding the provision of existing documentation, the Processor may charge reasonable remuneration.
Section 11 Place of processing and international data transfers
Processing takes place, as a rule, in data centres in Germany. The Processor does not transfer the Controller's personal data to third countries outside the EU or EEA, unless this occurs on documented instructions from the Controller or through the sub-processors approved in Annex 3.
To the extent that a transfer to third countries cannot be excluded when using Cloudflare (Annex 3), such transfer is based on the safeguards under Chapter V GDPR: on the EU-US Data Privacy Framework (Commission adequacy decision of 10 July 2023, Art. 45 GDPR), for as long as and to the extent that the recipient is certified under it, and, additionally and as a fallback, on the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) as agreed in the Cloudflare Customer Data Processing Addendum. The same applies to other sub-processors marked in Annex 3 as involving third countries.
Section 12 Liability and final provisions
The liability of the parties is governed by Art. 82 GDPR and, supplementarily, by the liability provisions of the Principal Agreement. The indemnification provision of the Principal Agreement for breaches of data protection obligations by the Controller remains unaffected.
In the event of conflicts between this DPA and the Principal Agreement, the provisions of this DPA prevail with regard to the processing of personal data on behalf of the Controller. Amendments and additions to this DPA require text form; where the Processor amends the contract text, the new version is made available for conclusion in the customer panel and replaces the previous version only upon renewed conclusion by the Controller.
This DPA is governed by the law of the Federal Republic of Germany. Should individual provisions of this DPA be or become invalid, the validity of the remaining provisions remains unaffected. This DPA is drawn up bilingually; in case of doubt, the German version prevails.
Annex 1: Subject matter of the processing (details provided by the Controller)
The Controller determines and documents the details of the processing, in particular in its record of processing activities pursuant to Art. 30 (1) GDPR; the Controller's own specifications take precedence over the following standard examples. Unless the Controller documents otherwise, the following applies:
- Nature and purpose of the processing: storage, hosting and processing of data on virtual servers within the applications and services operated by the Controller (e.g. web applications, databases, AI/GPU workloads, development and test environments).
- Types of personal data: the data stored by the Controller on the server, e.g. master and contact data, contract and billing data, content data, usage data, log and metadata.
- Categories of data subjects: the persons affected by the Controller's applications, e.g. customers and prospects, employees, suppliers, users of the services operated by the Controller.
- Special categories of personal data (Art. 9 GDPR): none, unless separately agreed (cf. Section 2 (2)).
Annex 2: Technical and organisational measures (Art. 32 GDPR)
Status of the measures as of the date of this version of the DPA.
- Physical access control: operation of own hardware in two geographically separate data centre sites in Germany with two different colocation operators: site 1 with LWLcom GmbH, Ladestraße 35a, 28197 Bremen; site 2 with CSN-Solutions GmbH, Kastanienallee 11, 23899 Gudow. Physical access is restricted by the access control systems of the respective site operators (individual access, authorisation management, logging).
- System access control: personal accounts, role-based permissions, two-factor authentication for the customer panel and additional 2FA step-up approvals for particularly sensitive administrative functions; administrative access to the infrastructure exclusively via SSH with key-based authentication, password login is disabled, access only from the internal management network or via the encrypted site-to-site link.
- Authorisation control: least-privilege principle, including separate database roles with deliberately restricted (in part column-level) permissions for web and background processes; access to customer content data only for operational, security and abuse-handling purposes (cf. Section 1 (2)).
- Separation control: tenant separation through virtualisation (dedicated virtual servers per customer), separated network segments, and Kubernetes namespaces with restrictive pod security requirements and default-deny network policies for the management platform.
- Encryption and pseudonymisation: TLS encryption for all external connections to the customer panel and management interfaces (Cloudflare as upstream proxy, encrypted origin connection); encrypted site-to-site link between the data centres using WireGuard; encrypted backups of the management platform to self-hosted S3-compatible storage; passwords are stored exclusively as hashes. VM disks are currently not encrypted at rest; in this respect, the protection of stored customer data relies on the physical access controls of the sites and on logical tenant separation. The Controller can encrypt its disks within the VM under its own responsibility (root access, e.g. LUKS).
- Input and traceability control: logging of security-relevant events, including authentication events (login audit), assignment history of IP addresses to servers and customer accounts, an administration audit log, and an append-only consent and contract evidence log.
- Availability control: redundant operation of the management platform across two sites (multiple application replicas, cross-site replicated database, resilient queueing infrastructure); redundant power and network connectivity of the sites, which according to the site operators correspond to Tier 3 level (redundant, concurrently maintainable supply paths); DDoS shielding of the panel domains via Cloudflare; monitoring and alerting.
- Recoverability: regular backups of the management platform with defined restore procedures; restore tests at least annually. Backups of customer servers are only created where the Controller has booked or activated the backup feature; they reside on storage operated by the Processor itself; encryption of VM backups is currently being rolled out step by step and is not yet complete for all backup storage; retention in accordance with the booked backup plan (service description).
- Processor control: careful selection of sub-processors, conclusion of data processing agreements with them (cf. Section 6 and Annex 3), clear internal responsibilities, confidentiality obligations of the personnel deployed.
- Deletion concept: deletion routine at the end of the contract pursuant to Section 9 (server stopped at contract end, deletion at the earliest 7 days later, 30-day retrieval archive on request); secrets management without plain-text storage; documented handling of storage media upon hardware decommissioning: secure erasure of decommissioned media in accordance with NIST SP 800-88; physical destruction of defective or non-erasable media by a certified service provider in accordance with DIN 66399 with certificate of destruction.
- Procedures for regular testing, assessment and evaluation (Art. 32 (1) (d) GDPR): continuous development of the measures in line with the state of the art, documented operational and incident runbooks, review of access rights and measures at least annually and on an ad-hoc basis.
Annex 3: Approved sub-processors
The following sub-processors are approved upon conclusion of this DPA (Section 6).
- Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Content delivery network, reverse proxy and DDoS protection for the Processor's domains. The Controller's data is affected only insofar as its traffic is routed via these domains (in particular use of the customer panel and the remote console provided through it); direct network traffic to the Controller's server IP addresses does not pass through Cloudflare. Third-country relevance: USA. Safeguards under Chapter V GDPR: EU-US Data Privacy Framework, for as long as and to the extent that Cloudflare is certified under it, and, additionally and as a fallback, EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) pursuant to the Cloudflare Customer Data Processing Addendum (version v6.4 of 3 April 2026 or the current version from time to time). The remote console traffic passes through the Cloudflare domains and is therefore covered by the scope described.
- LWLcom GmbH, Ladestraße 35a, 28197 Bremen (data centre / colocation operator site 1). Provision of data centre space, power, cooling and physical security for the Processor's own hardware. No regular access to data; physical access to the systems cannot be excluded. No third-country relevance (Germany).
- CSN-Solutions GmbH, Kastanienallee 11, 23899 Gudow (data centre / colocation operator site 2). As for site 1. No third-country relevance (Germany).
Note: the payment service provider Stripe and the email dispatch service Amazon SES (Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg) are not listed as sub-processors. Stripe processes payment data for the Processor's own invoicing; Amazon SES dispatches only the Processor's own transactional and contract notifications to the Controller. In both cases, the Processor is itself the controller; no personal data from the Controller's servers is processed through these services. Details are set out in the Processor's privacy policy.
Version: 2026-08-06