Data Processing Agreement (DPA) pursuant to Art. 28 GDPR
Draft — legal review required before production use. This template data processing agreement was prepared to satisfy the requirements of Art. 28 GDPR and must be reviewed and approved by a qualified IT lawyer before use. The German version ("Auftragsverarbeitungsvertrag") is legally binding.
Last updated: August 2026
Preamble and Parties
This Data Processing Agreement (the "DPA") specifies the data protection obligations of the parties in connection with the use of the BlenSite platform. It is concluded between
the Customer as controller within the meaning of Art. 4 No. 7 GDPR (the "Controller")
and
BlenCode GmbH, Boschstraße 10, 73734 Esslingen am Neckar, Germany, as processor within the meaning of Art. 4 No. 8 GDPR (the "Processor").
The DPA takes effect upon conclusion of a paid contract for the BlenSite platform and acceptance of this DPA. It forms part of the main contract (Terms and Conditions) concluded between the parties.
1. Subject Matter, Scope and Duration
The subject matter is the provision of the BlenSite platform, in particular the creation, hosting and delivery of the Controller's website and the processing of enquiries received via the website's contact form. The nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
The duration of the processing corresponds to the term of the main contract and ends upon its termination, subject to Section 8.
2. Instructions (Art. 28(3)(a) GDPR)
The Processor processes personal data solely on the documented instructions of the Controller, including with regard to transfers to third countries, unless required to do so by Union or Member State law. Use of the platform in accordance with the contractual settings constitutes a documented instruction; further individual instructions are to be sent in text form to info@blencode.com. The Processor immediately informs the Controller if it considers that an instruction infringes the GDPR or other data protection provisions.
3. Confidentiality (Art. 28(3)(b) GDPR)
The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation continues after termination of the contract.
4. Technical and Organisational Measures (Art. 28(3)(c), Art. 32 GDPR)
The Processor takes all measures required under Art. 32 GDPR to ensure a level of security appropriate to the risk. The measures are described in Annex 2. The Processor may further develop the measures provided that the agreed level of protection is not reduced.
5. Sub-processors (Art. 28(2) and (4) GDPR)
The Controller grants the Processor general authorisation to engage sub-processors. At the time of conclusion of the contract, the Processor uses the following sub-processors:
| Sub-processor | Service | Location |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, database, email dispatch (SES) | EU (Frankfurt, eu-central-1) |
| Amazon CloudFront (AWS) | Delivery / CDN | worldwide edge locations |
| CCM19 (self-hosted, consent.blencode.com) | Cookie consent | EU |
| fal.ai (Features & Labels, Inc.) | AI image/video generation | USA (Art. 46 GDPR, Standard Contractual Clauses) |
| Pexels (Canva Germany GmbH) | Stock images | EU |
If the Processor intends to engage additional sub-processors or replace existing ones, it will inform the Controller in advance in text form. The Controller may object to a change on important, data-protection-related grounds within 14 days. The Processor imposes on each sub-processor, by contract, the same data protection obligations as those set out in this DPA and remains liable to the Controller for compliance.
6. Assistance with Data Subject Rights (Art. 28(3)(e) GDPR)
The Processor assists the Controller, as far as possible and by appropriate technical and organisational measures, in fulfilling requests from data subjects exercising their rights under Chapter III of the GDPR (Art. 12 to 23). If data subjects contact the Processor directly, it forwards the request to the Controller without undue delay.
7. Assistance with Further Obligations (Art. 28(3)(f) GDPR)
The Processor assists the Controller in complying with the obligations under Art. 32 to 36 GDPR, in particular security of processing (Art. 32), notification of personal data breaches (Art. 33, 34), the data protection impact assessment (Art. 35) and prior consultation (Art. 36). The Processor notifies the Controller of any personal data breach that becomes known to it without undue delay.
8. Deletion and Return (Art. 28(3)(g) GDPR)
After the end of the provision of the processing services, the Processor, at the Controller's choice, deletes or returns all personal data and deletes existing copies, unless Union or Member State law requires storage.
9. Evidence and Audits (Art. 28(3)(h) GDPR)
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it. Audits take place with reasonable prior notice and during normal business hours.
10. Liability
Liability is governed by Art. 82 GDPR and the liability provisions of the main contract (Terms and Conditions), unless this DPA provides otherwise.
11. Final Provisions
The law of the Federal Republic of Germany applies. If individual provisions of this DPA are invalid, the validity of the remaining provisions remains unaffected. In the event of conflicts between this DPA and the main contract, the provisions of this DPA prevail on data protection matters.
Annex 1 — Description of Processing
- Nature of processing: collection, storage, hosting, delivery, transmission (contact form), deletion of personal data.
- Purpose: provision, operation and delivery of the Controller's website and forwarding of contact enquiries to the Controller.
- Types of personal data: contact data (e.g. name, email address, optionally phone number from the contact form), content data (message text), usage and metadata (e.g. IP address, timestamps, server/CDN access logs).
- Categories of data subjects: visitors to the Controller's website and persons using the contact form.
Annex 2 — Technical and Organisational Measures (Art. 32 GDPR)
- Confidentiality: access and entry controls; role-based access rights; encryption in transit (TLS) and at rest (AWS-managed encryption).
- Integrity: input and transfer controls; separation of customer data (tenant isolation).
- Availability and resilience: redundant AWS infrastructure in the EU region; backups; recoverability.
- Procedures for regular review, assessment and evaluation: logging, monitoring, regular review of the measures.