This is a convenience translation. Only the German version is legally binding: German version.
Version 1.2 of 7 October 2026. Customers conclude this agreement electronically in ManualPass under "Privacy & DPA" (Art. 28(9) GDPR). There, the concluded version, including both contracting parties, can be printed or saved as a PDF at any time.
Contracting parties
Controller: the customer, with the details it enters in ManualPass when concluding the agreement (hereinafter the "Controller").
Processor: Berke Mersin, Digitalagentur Gruppe Digital, Kaiser-Joseph-Str. 254, 79098 Freiburg im Breisgau, Germany, email: support@manualpass.eu (hereinafter the "Processor").
§ 1 Subject matter and duration
(1) The Processor provides the Controller with the ManualPass software on the basis of the General Terms and Conditions (main contract). In doing so, it processes personal data on behalf of the Controller. This agreement governs the data protection obligations of the parties pursuant to Art. 28 GDPR.
(2) The term of this agreement corresponds to the term of the main contract, including the trial period. It does not end as long as the Processor still processes personal data of the Controller, in particular during the post-contractual period under § 11.
(3) In the event of conflicts, this agreement takes precedence over the main contract in matters of data protection.
§ 2 Nature, purpose and scope of the processing
The nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1. The Processor processes the data exclusively in order to provide the contractually owed services. No processing for its own purposes takes place.
§ 3 Instructions
(1) The Processor processes personal data only on documented instructions from the Controller, unless it is required to do so by Union or Member State law; in such a case, it shall inform the Controller of that legal requirement before processing, unless that law prohibits such information.
(2) The instructions are initially set out in this agreement, the main contract and the Controller's use of the functions of ManualPass (for example uploading, publishing, archiving or deleting). The Controller issues further instructions in text form to support@manualpass.eu.
(3) If the Processor is of the opinion that an instruction infringes data protection provisions, it shall inform the Controller without undue delay. It may suspend the execution of the instruction until the Controller confirms or amends it.
§ 4 Confidentiality
The Processor only deploys persons who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality and who are familiar with the relevant data protection provisions. This obligation continues beyond the end of their activity.
§ 5 Security of processing
(1) The Processor implements the technical and organisational measures pursuant to Art. 32 GDPR described in Annex 2.
(2) The measures are subject to technical progress. The Processor may replace them with equivalent or better measures. The agreed level of protection must not be undercut in the process. It documents significant changes.
§ 6 Sub-processors
(1) The Controller grants general authorisation to engage other processors (sub-processors). The sub-processors engaged at the time the agreement is concluded are listed in Annex 3 and are deemed approved.
(2) The Processor shall inform the Controller in text form or in the application at least four weeks in advance of any intended addition or replacement. The Controller may object within this period for an important reason relating to data protection. If the parties cannot reach an agreement, the Controller may terminate the main contract extraordinarily with effect from the date of the change.
(3) The Processor shall contractually impose on each sub-processor the same data protection obligations as set out in this agreement. It is liable to the Controller for compliance with these obligations by the sub-processor.
(4) Ancillary services that the Processor obtains from third parties, such as pure telecommunications or postal services, are not deemed sub-processing.
§ 7 Place of processing
Processing takes place in the European Union or the European Economic Area. A transfer to a third country only takes place if the conditions of Art. 44 et seq. GDPR are met and the Controller has been informed in accordance with § 6(2).
§ 8 Assistance to the Controller
(1) The Processor assists the Controller by appropriate technical and organisational measures in fulfilling the rights of data subjects (Art. 12 to 22 GDPR). If a data subject contacts the Processor directly, the Processor shall forward the request to the Controller without undue delay and shall not respond to it itself, unless the Controller instructs otherwise.
(2) Taking into account the information available to it, the Processor assists the Controller in ensuring compliance with the obligations under Art. 32 to 36 GDPR (security, notification of personal data breaches, data protection impact assessment, prior consultation).
(3) For assistance that goes beyond the functions of ManualPass and is not based on a breach by the Processor, the Processor may demand reasonable remuneration based on effort, provided it announces this in advance.
§ 9 Personal data breaches
(1) The Processor shall notify the Controller of a personal data breach without undue delay, if possible within 48 hours after becoming aware of it, by email to the account owner's address stored in the account.
(2) The notification shall contain, insofar as known, the nature of the breach, the categories concerned and the approximate number of data subjects and data records concerned, the likely consequences and the measures taken and proposed. Information that is not yet available shall be provided subsequently without undue delay.
(3) The Processor shall take the necessary measures without undue delay to secure the data and to mitigate possible adverse consequences.
§ 10 Evidence and audits
(1) Upon request, the Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR.
(2) The Controller may carry out audits, including inspections, itself or through an auditor who is bound to confidentiality and is not a competitor of the Processor. Inspections must be announced with reasonable notice, generally two weeks, and carried out during normal business hours without avoidable disruption of operations. Evidence may primarily be provided through information, documentation or certificates, including those of the sub-processors.
(3) The Processor shall inform the Controller without undue delay of any inspections or measures by a supervisory authority insofar as they relate to this processing.
§ 11 Deletion and return
(1) During the term of the agreement, the Processor shall delete data when the Controller initiates this via the functions of ManualPass or instructs it in writing, unless a statutory retention obligation prevents this.
(2) After the end of the main contract, the Processor shall return the uploaded documents to the Controller at its request, as provided in the main contract. No later than 90 days after the end of the contract, it shall delete all personal data of the Controller, unless Union or Member State law requires storage. Data in backups is overwritten within the regular backup cycle.
(3) Deletion shall be confirmed in text form upon request.
§ 12 Liability and final provisions
(1) Art. 82 GDPR applies to liability. In all other respects, the liability provisions of the main contract apply between the parties, insofar as they are permissible under Art. 82 GDPR.
(2) Amendments to this agreement require text form. If this agreement is amended, the Processor shall make the new version available in ManualPass; until it is concluded, the most recently concluded version continues to apply.
(3) Should individual provisions be invalid, the validity of the remaining provisions shall remain unaffected.
(4) The law of the Federal Republic of Germany applies. The place of jurisdiction, insofar as permissible, is Freiburg im Breisgau.
Annex 1 – Subject matter of the processing
Nature and purpose of the processing: Storing, organising, providing, transmitting and deleting data within the ManualPass software: management of machine types and documents (instructions for use, EU declarations of conformity and other documents), provision via QR code and public scan page, receipt and forwarding of requests for a paper copy, user and rights management, approval workflow, logging of changes, publication of safety notices and receipt and forwarding of vulnerability reports with documentation of reporting deadlines (Security & Support). When the ManualPass Service add-on is used, additionally: keeping machine records per serial number, creating, archiving and sending service reports, maintenance reminders, service and spare parts requests, sending safety notices to operators with confirmation of receipt and access for service technicians and operators.
Categories of data subjects:
- Employees and agents of the Controller who use ManualPass (users)
- End customers and users of machines who request a paper copy via the scan page
- Persons whose data is contained in the documents or manufacturer information uploaded by the Controller (for example signatories of a declaration of conformity, contact persons)
- Visitors to the public scan pages (technical access data)
- Persons who report a possible vulnerability via the scan page
- Service technicians of the Controller and contact persons of operators (customers of the Controller) who are given access to ManualPass Service
- Persons who sign a service report or are recognisable in photos in service reports
Types of personal data:
- User data: name, email address, role, language setting, encrypted password (hash), login times, change log entries with IP address
- Data from paper copy requests: name, company (optional), address, country, email address, serial number (optional), language, time, processing status
- Content of the uploaded documents and manufacturer information, insofar as it contains personal data (for example names, positions, signatures, contact details)
- Data from ManualPass Service: name and email address of service technicians and operator contacts, company and address of operators, machine location, content of service reports (technician's name, name and signature of the signing person, photos, free text, measured values, spare parts, defects) service and spare parts requests with message, items and order reference, and confirmations of safety notices (name, time)
- Data from vulnerability reports: email address, optionally name, organisation and affected version, description, time, IP address as a non-reversible hash
- Technical access data for scan pages in the host's server log files (IP address, time, requested address, browser identifier)
Special categories of personal data pursuant to Art. 9 GDPR are not the subject of the processing. The Controller does not upload such data.
Annex 2 – Technical and organisational measures (Art. 32 GDPR)
Confidentiality
- Physical access control: operation in the host's data centres (Annex 3) with its physical security measures. The Processor does not operate its own servers.
- System access control: personal user accounts; passwords with at least 10 characters, stored exclusively as a hash using the current method of the PHP password functions; limitation of failed login attempts; session cookie only via HTTPS, not readable by scripts and protected against cross-site requests; password links single-use and valid for 60 minutes; administrative access at the host with strong passwords.
- Data access control: role model (owner, approver, editor, reader); protection of all modifying actions by CSRF tokens; access by the Processor's support staff to a customer account is recorded in the customer's change log.
- Separation control: logical client separation; every data access is bound to the Controller's account.
- Pseudonymisation and encryption: transport encryption via TLS (HTTPS with HSTS) for the application, scan pages and email dispatch via SMTP with encryption; passwords only as a hash; file names on the server are assigned randomly.
Integrity
- Transfer control: transmission exclusively in encrypted form; documents can only be accessed publicly if they have been published by the Controller.
- Input control: change log with time, user, action and IP address; the entries are protected against undetected changes by chained checksums and can be exported as CSV; a SHA-256 checksum is stored for each document version; optional four-eyes approval workflow.
Availability and resilience
- regular backup of the database and files at the host, as well as additional backup by the Processor
- version archive: earlier document versions are retained
- timely installation of security updates for the software used
Procedures for regular review
- review of the measures in the event of significant changes to the application, at least once a year
- automated tests before each release of new versions
- data protection by default: scan pages without tracking and without cookies, scan statistics only as anonymous daily counters without IP address; deletion of login attempts and expired password links after 24 hours
Annex 3 – Sub-processors
| Company | Service | Place of processing |
|---|---|---|
| TrafficPlex GmbH (lima-city), Konsul-Smidt-Str. 90, 28217 Bremen | Hosting of the application, database and files, email dispatch | Germany |
Payment processing via Stripe only concerns the contract and payment data of the customer itself. It is not processing on behalf of the Controller and is therefore not listed here; details can be found in the privacy policy.