Data Processing Agreement (DPA)
pursuant to Art. 28 GDPR
This Data Processing Agreement ("DPA") is incorporated into and forms part of the Pacefy Terms of Service between the customer ("Controller") and Malte Hoffmann, operating as Micro-SaaS Solutions, Am Salzstadel 13, 83022 Rosenheim, Germany ("Processor", "Pacefy"). By accepting the Terms of Service or using the Service to process personal data, the Controller enters into this DPA. A countersigned copy is available on request at info@getpacefy.com.
Where this DPA conflicts with the Terms of Service, this DPA prevails in matters of data protection.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given to them in the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). Subprocessor means any processor engaged by the Processor.
2. Subject matter and scope
(1) The Processor processes personal data on behalf of and on the documented instructions of the Controller solely to provide the Pacefy service (budget pacing for marketing teams, the "Service").
(2) The subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
(3) The duration of the processing corresponds to the term of the Terms of Service, subject to the deletion and return obligations under this DPA.
3. Roles and responsibilities
(1) The Controller is responsible, as between the parties, for compliance with applicable data protection law, in particular for the lawfulness of disclosing personal data to the Processor and of the processing as such.
(2) The Processor processes personal data exclusively within the scope of this DPA and the Controller's instructions, unless required to do otherwise by Union or Member State law; in that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits this on grounds of important public interest.
4. Obligations of the Processor
The Processor shall:
- (a) Instructions. Process the personal data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do so by law as set out in section 3(2). This DPA and the Controller's use of the Service constitute the Controller's initial documented instructions.
- (b) Notice of unlawful instructions. Inform the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions. The Processor may suspend execution of the affected instruction until it is confirmed or amended.
- (c) Confidentiality. Ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation survives termination.
- (d) Security. Implement the technical and organisational measures required under Art. 32 GDPR. The current state is set out in Annex 2. The Processor may modify these measures provided the level of protection is not reduced.
- (e) Data subject rights. Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in responding to requests by data subjects under Art. 12–23 GDPR. If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay.
- (f) Controller's obligations. Assist the Controller, taking into account the nature of processing and the information available to the Processor, in ensuring compliance with Art. 32–36 GDPR (security, breach notification, data protection impact assessments, prior consultation).
- (g) Deletion and return. At the Controller's choice, delete or return all personal data after the end of the provision of services, as set out in section 9.
- (h) Audits. Make available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR and allow for and contribute to audits as set out in section 8.
- (i) Data protection officer. The Processor is not required by law to appoint a data protection officer. Contact point for data protection matters: info@getpacefy.com.
5. Subprocessors
(1) The Controller grants the Processor general written authorisation to engage subprocessors. The subprocessors engaged at the time of conclusion of this DPA are listed in Annex 3 and are thereby approved.
(2) The Processor informs the Controller of any intended addition or replacement of a subprocessor with at least 30 days' prior notice (e.g. by email or via the Service), giving the Controller the opportunity to object on reasonable data protection grounds within that period.
(3) The Processor imposes on each subprocessor, by contract, the same data protection obligations as set out in this DPA (Art. 28(4) GDPR). Where a subprocessor fails to fulfil its obligations, the Processor remains fully liable to the Controller for the performance of that subprocessor's obligations.
(4) Ancillary services obtained by the Processor as a minor adjunct to the main service (e.g. telecommunications, maintenance) are not considered subprocessing.
6. International transfers
The Processor transfers personal data to a third country only where the requirements of Chapter V GDPR are met, in particular where there is an adequacy decision (e.g. the EU–US Data Privacy Framework) or appropriate safeguards (e.g. the EU Standard Contractual Clauses). The third-country transfers identified in Annex 3 are covered accordingly.
7. Personal data breach
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA. The notification includes, to the extent available, the information required under Art. 33(3) GDPR.
8. Audits
(1) The Processor demonstrates compliance with this DPA primarily through current self-assessments, an existing security concept, or certificates / attestations of recognised bodies (e.g. ISO 27001 of the hosting provider).
(2) Where these are insufficient, the Processor allows the Controller, or an auditor mandated by the Controller and bound to confidentiality, to carry out audits, including inspections, during normal business hours, after reasonable prior notice (at least 30 days) and without disrupting operations. Reasonable effort for supporting on-site audits may be charged separately.
9. Deletion and return
(1) After the end of the provision of services, the Processor deletes all personal data processed on behalf of the Controller or returns it at the Controller's choice, unless Union or Member State law requires storage.
(2) The Controller may export its data via the Service for up to 30 days after termination. Thereafter, data is deleted within 30 days, and any backups are overwritten within 30 days as part of the regular backup cycle.
(3) Deletion is confirmed in text form on request.
10. Liability
Liability is governed by Art. 82 GDPR. In all other respects, the liability provisions of the Terms of Service apply, to the extent they do not conflict with mandatory data protection law.
11. Duration, precedence, governing law
(1) This DPA remains in force for as long as the Processor processes personal data on behalf of the Controller under the Terms of Service.
(2) In the event of conflict, this DPA prevails over the Terms of Service in matters of data protection.
(3) This DPA is governed by the law of the Federal Republic of Germany. If individual provisions are invalid, the remainder of the DPA remains unaffected.
Annex 1 — Description of the processing
Subject matter. Provision and operation of the Pacefy SaaS for monitoring and managing advertising budgets (budget pacing).
Nature and purpose of the processing. Storing, organising, reading and displaying budget and campaign data; automatic mapping of campaigns to budgets; calculation of plan/actual pacing; sending of notifications (e.g. unmapped campaigns, pacing deviations); management of user accounts and authentication.
Types of personal data.
- Account data: email address; for Sign in with Google, additionally name and Google account identifier
- Authentication data: one-time login codes (OTP), session tokens (no passwords are stored)
- Usage and log data: IP address, timestamps, log data
- Budget and campaign data uploaded by the Controller: campaign names/identifiers, spend, impressions, clicks (predominantly non-personal; a personal reference may arise from campaign names in individual cases)
How the data reaches the Processor. Budget and campaign data is imported via CSV files that the Controller exports from its own advertising platforms (e.g. Google Ads, Microsoft Advertising, Meta, TikTok, Reddit, LinkedIn) and uploads to the Service. The Processor does not connect to these platforms' APIs and stores no advertising-platform access tokens.
Categories of data subjects. Employees / users of the Controller with access to the Service.
Duration. For the term of the Terms of Service, plus the deletion/return periods under section 9.
Annex 2 — Technical and organisational measures (Art. 32 GDPR)
1. Confidentiality
- Physical access control: operation in data centres of the hosting provider (Hetzner Online GmbH, Germany/EU) with physical access controls; the provider holds ISO 27001 certification.
- System access control: individual user accounts; passwordless authentication via one-time email codes (OTP) and/or Sign in with Google; no passwords are stored; session management via signed tokens (JWT) in httpOnly cookies.
- Data access control: role-based permissions following the principle of least privilege; server access exclusively via SSH key authentication; administrative access limited to the operator (Malte Hoffmann).
- Separation: logical multi-tenant separation of data per organisation at database level (every record scoped by organisation identifier); separation of production and development environments.
- Encryption: all data in transit encrypted via TLS (HTTPS through Caddy, TLS 1.2+); OAuth tokens and other sensitive secrets encrypted at rest.
2. Integrity
- Transfer control: encrypted transmission (TLS) between client, application and connected services.
- Input control: logging of security-relevant events and administrative access.
3. Availability and resilience
- Availability control: application error tracking and monitoring of the production environment. [Automated database backups are not yet implemented — to be added before relying on this DPA.]
- Recoverability: documented restore procedure (dependent on the backup regime above).
4. Procedures for regular review and evaluation
- Timely application of security updates to operating system, container images and dependencies.
- Subprocessors are contractually bound under Art. 28 GDPR (see Annex 3).
Annex 3 — Approved subprocessors
| Subprocessor | Service | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting and data storage | Germany / EU | — (EU) |
| Resend, Inc. | Transactional email (OTP codes, alerts, system messages) | USA | EU–US DPF where certified, otherwise EU SCCs |
| Cloudflare, Inc. | DNS / domain services | USA | EU–US DPF where certified, otherwise EU SCCs |
Not subprocessors under this DPA:
- Stripe — payment processing relates to the billing relationship between the Processor and the Controller; for that, the Processor acts as an independent controller, not as the Controller's processor. Addressed in Pacefy's own privacy policy.
- Google (Sign in with Google) — where a user authenticates via Sign in with Google, Google acts as an independent controller for the authentication, not as a subprocessor.
Last updated: June 2026