Data Processing Agreement

Effective: 2026-09-24 (permalink)

Between

the Customer (the “Controller”)

and

Professional Wiki GmbH, Tieckstraße 24, 10115 Berlin, Germany (the “Processor”)

1. General

(1) The Processor processes personal data on behalf of the Controller within the meaning of Articles 4(8) and 28 of the GDPR. This Agreement sets out the parties’ rights and obligations relating to such processing.

(2) Where this Agreement uses “data processing” or “processing,” the term has the meaning of Article 4(2) GDPR.

2. Subject Matter of the Engagement

The subject matter, type, and purpose of the processing, as well as the categories of personal data and the categories of data subjects, are defined in Annex 1.

3. Rights and Duties of the Controller

(1) The Controller is the “controller” under Article 4(7) GDPR for processing performed by the Processor. Under clause 4(5), the Processor may point out if, in its view, an instruction or the processing ordered is unlawful.

(2) The Controller is responsible for data subject rights. The Processor will promptly inform the Controller if data subjects exercise their rights directly with the Processor.

(3) The Controller may issue additional instructions at any time on the nature, scope, or method of processing. Instructions must be in text form (e.g., email).

(4) Any remuneration for additional effort resulting from such instructions remains unaffected.

(5) The Controller issues instructions via the channels defined in Annex 1 (Instruction Channels & Contacts).

(6) The Controller will promptly inform the Processor of any errors or irregularities it detects in processing by the Processor.

(7) Where an information duty to third parties exists (e.g., Articles 33, 34 GDPR or other legal reporting duties), the Controller is responsible for compliance.

4. General Duties of the Processor

(1) The Processor will process personal data solely under this Agreement and the Controller’s instructions. Statutory obligations to process otherwise remain unaffected; the Processor will inform the Controller of such legal requirements before processing unless prohibited in the public interest. Any processing beyond this Agreement or the Controller’s instructions requires the Controller’s prior written consent.

(2) Storage and routine processing occur in the EU/EEA. Optional edge delivery/CDN services may process personal data globally under appropriate safeguards, as set out in Clause 18 and Annex 2.

(3) The Processor ensures contractual performance of all agreed measures in connection with the commissioned processing.

(4) The Processor will organize its operations so that data processed for the Controller is adequately secured and protected from unauthorized access. Material changes to processing that affect data security will be coordinated in advance with the Controller.

(5) If the Processor believes an instruction violates the law, it will promptly notify the Controller and may suspend execution until the Controller confirms or changes the instruction. If the Processor shows that following the instruction could trigger Processor liability under Article 82 GDPR, it may suspend the relevant processing until liability is clarified.

(6) Processing outside the Processor’s or its sub-processors’ premises requires the Controller’s consent in writing or text form. Processing may occur from secured remote workplaces under the TOMs in Annex 3. The Processor ensures equivalent security controls for such work; no additional consent is required.

(7) Data processed for the Controller will be kept logically separate from other data; physical separation is not mandatory.

(8) Instruction channels and contacts are set out in Annex 1 (Instruction Channels & Contacts).

5. Data Protection Officer (DPO)

The Processor has not appointed a DPO because no obligation arises under Article 37 GDPR. The Processor designates privacy@professional.wiki as the contact address for all data protection-related inquiries.

6. Notification Duties of the Processor

(1) The Processor will promptly notify the Controller of any breach of data protection law, this Agreement, or the Controller’s instructions occurring during processing by the Processor or persons engaged in the processing. This also applies to any personal data breach affecting data processed for the Controller.

(2) The Processor will also promptly inform the Controller if a supervisory authority acts against the Processor under Article 58 GDPR in a way that may involve processing performed for the Controller.

(3) The Processor is aware that the Controller may have to notify under Articles 33 and 34 GDPR within 72 hours. The Processor will support the Controller in fulfilling such duties and, in particular, report any unauthorized access to personal data processed for the Controller without delay and no later than 48 hours after becoming aware. The notice must include:

  • a description of the personal data breach, including, where possible, the categories and approximate number of data subjects and data records concerned; and
  • a description of the measures taken or proposed to address the breach and, where appropriate, to mitigate its possible adverse effects.

7. Cooperation Duties of the Processor

(1) The Processor will assist the Controller in responding to data subject requests under Articles 12–23 GDPR (see also clause 11).

(2) The Processor will assist with the Controller’s records of processing activities by providing necessary information.

(3) Considering the nature of processing and available information, the Processor will assist the Controller in meeting its obligations under Articles 32–36 GDPR.

8. Audit Rights

(1) The Controller may assess, as necessary, compliance with data protection law, this Agreement, and the Controller’s instructions.

(2) The Processor must provide information required to conduct such assessments.

(3) The Controller may request access to data processed for the Controller and to the systems and programs used.

(4) Following reasonable advance notice, the Controller may conduct on-site audits during regular business hours. The Controller will avoid disproportionate disruption.

(5) In case of supervisory authority measures against the Controller under Article 58 GDPR, especially regarding information and audit duties, the Processor will provide the required information and allow on-site inspections by the competent authority. The Processor will inform the Controller about planned measures.

9. Sub-Processing

(1) The Processor may engage sub-processors only with the Controller’s consent in text form. Existing sub-processors at signature are listed in Annex 2.

(2) The Processor will carefully select sub-processors and verify, before engagement and regularly during the term, that they can meet the agreed requirements, notably appropriate technical and organizational measures under Article 32 GDPR. The Processor will document results and provide them to the Controller on request.

(3) The Processor will obtain confirmation that the sub-processor has appointed a DPO under Article 37 GDPR. If not, the Processor will inform the Controller and provide information showing that no legal obligation exists.

(4) The Processor will ensure this Agreement’s rules and the Controller’s instructions bind the sub-processor.

(5) The Processor will conclude a data processing agreement with the sub-processor that satisfies Article 28 GDPR and imposes the same data protection obligations as in this Agreement. A copy will be provided to the Controller on request.

(6) The Processor shall ensure by contract that the Controller’s and supervisory authorities’ audit rights under clause 8 extend to the sub-processor to the extent contractually permissible. Such audits shall be satisfied through the review of documentation, certifications (such as ISO 27001 or SOC 2 reports), or equivalent third-party audit attestations, and, where permitted, through assessments conducted in accordance with the sub-processor’s established audit program. On-site audits shall only take place where expressly provided for in the sub-processor’s contractual terms.

(7) Not deemed sub-processing are ancillary services the Processor uses from third parties to carry out its business (e.g., cleaning, pure telecom services without specific relation to services for the Controller, postal and courier services, transport, guarding). Even for such ancillary services, the Processor will ensure adequate safeguards. Maintenance of IT systems or applications is a sub-processing and requires consent if those systems are used to provide services for the Controller. Maintenance may involve access to the personal data processed by the Controller.

10. Confidentiality Commitment

(1) The Processor will keep confidential all data obtained or becoming known in connection with the engagement and will observe the same secrecy rules that bind the Controller. The Controller will disclose any special secrecy rules that apply.

(2) The Processor confirms knowledge of applicable data protection provisions and that its staff are familiar with them and bound to confidentiality and to follow the Controller’s instructions.

(3) Proof of such staff commitments will be provided on request.

11. Data Subject Rights

(1) The Controller alone is responsible for honoring data subject rights. The Processor will support the Controller by promptly providing the information required so the Controller can comply, in particular with Article 12(3) GDPR deadlines.

(2) Where the Processor’s involvement is required (e.g., access, rectification, restriction, erasure), the Processor will implement the necessary measures as instructed and support the Controller with appropriate technical and organizational means.

(3) Any remuneration for additional effort in this context remains unaffected.

12. Mutual Confidentiality

(1) Both parties will keep all information received in connection with this Agreement confidential for an unlimited period and use it only to perform this Agreement. Neither party may use such information for other purposes or disclose it to third parties.

(2) This does not apply to information demonstrably received from third parties without a duty of confidentiality or that is publicly known.

13. Remuneration

The Processor’s remuneration is agreed separately.

14. Technical and Organizational Measures (TOMs)

(1) The Processor undertakes to maintain technical and organizational measures necessary to comply with applicable data protection law, in particular Article 32 GDPR.

(2) The TOMs in place at signature are attached as Annex 3. The parties acknowledge that changes may be necessary to adapt to legal and technical developments. Material changes that could adversely affect confidentiality, integrity, or availability will be coordinated in advance. Minor adjustments that do not negatively affect those aspects may be implemented without prior coordination. The Controller may request the current TOMs at any time.

(3) The Processor will regularly, and when indicated, review the effectiveness of the TOMs and inform the Controller if optimizations/changes are needed.

15. Term

(1) This Agreement starts upon signature and is concluded for an indefinite term.

(2) It may be terminated on 30 days’ notice, effective at month-end.

(3) The Controller may terminate without notice if there is a serious breach of applicable data protection law or of this Agreement, if the Processor cannot or will not follow an instruction, or if the Processor unlawfully refuses access for the Controller or the competent supervisory authority.

16. End of Processing

(1) Upon termination, the Processor will, at the Controller’s choice, return or delete all documents, data, and processing or usage results related to the engagement. Deletion will be documented. Statutory retention duties remain unaffected. If deletion of physical media is chosen, media will be destroyed with at least DIN 66399 security level 3; destruction will be evidenced, indicating the DIN level.

(2) The Controller may verify complete and compliant return/deletion, including by on-site inspection at the Processor’s premises with reasonable advance notice.

(3) The Processor may retain personal data beyond termination only where a legal retention duty applies; such data may only be processed for that purpose and must be deleted immediately after the retention period ends.

17. No Right of Retention

The parties agree that the Processor has no right of retention under § 273 BGB in respect of the processed data or related media.

18. International Data Transfers

(1) Where the Processor or a Subprocessor transfers personal data to, or processes such data from, a third country outside the European Economic Area that does not provide an adequate level of data protection within the meaning of Article 45 GDPR, the transfer shall take place solely based on appropriate safeguards pursuant to Article 46 GDPR.

(2) The Standard Contractual Clauses (EU 2021/914) issued by the European Commission on 4 June 2021, as amended from time to time, including their Annexes I–III, form part of this Agreement and apply to international data transfers in accordance with the respective roles of the Parties.

(3) The following additional provisions shall apply:

  1. The Controller’s right to approve or reject the engagement of Subprocessors in third countries remains unaffected.
  2. Where personal data is transferred to a Subprocessor located in a third country, the Processor undertakes to ensure that the appropriate module of the Standard Contractual Clauses is concluded between the Processor and the Subprocessor.
  3. In the event of any conflict between this Agreement and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.

(4) Upon request, the Processor shall provide the Controller with a copy of the then-current Standard Contractual Clauses, including the relevant Annexes.

19. Final Provisions

(1) If the Controller’s property at the Processor is endangered by third-party measures (e.g., seizure, attachment), insolvency, or similar events, the Processor will promptly inform the Controller and notify creditors that the data are processed on behalf of a controller.

(2) Side agreements require written form.

(3) If any provision is invalid, the remainder remains effective.

(4) This Agreement shall be governed by and construed in accordance with the laws of the Federal Republic of Germany. The courts of Berlin (Germany) shall have exclusive jurisdiction over all disputes arising out of or in connection with this Agreement.

Annex 1 – Description of Processing

Subject matter and purpose of processing

  • Hosting (provision, update, maintenance, backup, and monitoring) of wiki instances for the Controller’s use
  • Support and administrative services related to operation, configuration, and troubleshooting
  • Provision of initial migration
  • Communication with authorized users for support purposes

Types of personal data

  • User account data (username, email address, password hash)
  • Access and usage data (login time, IP address, browser type, etc.)
  • Content data entered by users, if it contains personal data (text, attachments, comments, revision history)
  • Support correspondence data (emails, ticket information)

Categories of data subjects

  • Users of the hosted wiki (employees, contractors, partners, contributors)
  • Controller’s administrators and technical contacts
  • Data subjects mentioned within the wiki content

Instruction Channels & Contacts

  • Documented Instructions. We act only on documented instructions from the Controller: (i) this DPA and any Order Forms/SOWs; (ii) emails from an address at the Controller’s domain to privacy@professional.wiki.
  • Updates. The Controller may update its instruction channels or contacts by email from an official Controller domain; such updates take effect upon receipt and amend Annex 1 without further formalities.
  • Notices. All notices, including breach notices, go to privacy@professional.wiki.

Annex 2 – Sub-processors

Hetzner Online GmbH

  • Purpose:
    Primary infrastructure hosting and server operation
  • Location:
    Germany, European Union
  • Legal basis/safeguards:
    Art. 28 GDPR, processing within the EU
  • Address:
    Industriestr. 25, 91710 Gunzenhausen, Germany

Used since 2024-02-15.

Scaleway SAS

  • Purposes:
    • Outgoing transactional email (SMTP)
    • Encrypted off-site backup storage
  • Location:
    France, European Union
  • Legal basis/safeguards:
    Art. 28 GDPR, processing within the EU
  • Address:
    8 rue de la Ville l'Evêque, 75008 Paris, France

Used since 2025-11-07.

Cloudflare, Inc.

  • Purpose:
    Optional CDN / WAF / DDoS protection and edge caching. Our clients can opt out of Cloudflare fronting on a per-wiki basis.
  • Location:
    Global anycast network. HTTPS traffic is typically served at the nearest Cloudflare data center.
  • Legal basis/safeguards:
    Art. 28 GDPR for processing within the EU; Standard Contractual Clauses (EU 2021/914) for international transfers.
  • Address:
    101 Townsend St., San Francisco, CA 94107, USA.

Used since 2025-10-30.

Annex 3 – Technical and Organizational Measures

Current as of 2025-12-03

Scope & updates

These measures apply to our Hetzner-based wiki hosting. Measures may evolve without materially reducing protection.

Data Location

Customer Data is stored and processed in the EU/EEA. We do not engage sub-processors outside the EEA without documented customer instructions.

1) Confidentiality

  • Staff confidentiality; access limited to least-privilege / need-to-know.
  • ISO 27001-certified data centers (Hetzner) with staffed access control, CCTV, and environmental protections.
  • Strict access control with SSH keys. Password auth disabled. Firewalls restrict inbound traffic to required ports only.
  • Multi-factor authentication (MFA) is enforced for all administrative access.
  • Access governance: Offboarding checklist for access revocation, including rotation of long-lived credentials; removals within one business day. For involuntary separations, pre-notification production/admin access revocation.
  • Staff use dedicated password vaults/keychains.
  • 2FA with hardware keys (preferred), or TOTP using seeds stored in dedicated password-protected apps.
  • Single-tenant architecture: each customer runs on dedicated virtual servers; no shared compute or databases between customers.
  • The Service supports 2FA, SSO (OAuth 2), and standard MediaWiki role-based permissions for user and rights management.
  • TLS 1.2 or 1.3 encryption for data in transit, plus HSTS.
  • Primary production volumes are not encrypted at rest; backups are encrypted before upload. This decision is risk-based, given dedicated servers per tenant, ISO-27001–certified data centers, and strong access controls.
  • Backup encryption keys and Scaleway retention/immutability controls are held by only three designated DevOps personnel.
  • Quarterly review of access rights.

2) Integrity

  • Infrastructure-as-Code for system changes; changes tracked in git.
  • Peer review for changes and CI checks before deployment.
  • Regular security updates and vulnerability scans.
  • Critical security patches applied within one week.

3) Availability

  • Uptime objective: 99.99% per year.
  • Provider redundancy: Data center facilities provide redundant power, cooling, and network paths to minimize downtime caused by facility issues.
  • Edge delivery (Cloudflare-fronted wikis): Traffic is served via Cloudflare's global anycast network with edge caching, reducing origin load and helping ride out regional congestion.
  • DDoS tolerance (Cloudflare-fronted wikis): Network- and application-layer attack mitigation at the edge helps maintain availability during traffic spikes and abuse.
  • 24/7 automated monitoring with alerting for critical system components.
  • Capacity management: CPU, memory, disk, and I/O utilization are monitored; we maintain headroom and resize servers as needed to avoid resource exhaustion.
  • Status communications: For service-affecting incidents, we provide progress updates until the incident is resolved.

4) Resilience (BC/DR, restore/testing)

  • Daily automated offsite backups to Scaleway (fr-par). Encrypted (AES-256) before upload, in-region redundancy, backup client has no delete permission (append-only). Retention: 8 daily, 6 weekly, 6 monthly.
  • Daily automated server-level backups, managed by Hetzner, immutable. Retention: 7 daily.
  • Disaster-recovery procedures are tested quarterly.
  • Data deletion: On written instruction or contract termination, production copies of Customer Data are deleted within 30 days. Residual data in backups is deleted upon backup expiry per the retention schedule. Deletion confirmation available on request.
  • Annual evaluation of TOM effectiveness.