Feature

Data protection and DPA: GDPR-compliant provision

You conclude the data processing agreement online in the app. The scan page works without cookies and tracking, and paper copy requests are anonymised automatically.

app.manualpass.eu/app/datenschutzInteractive preview

The contract under Art. 28 GDPR is ready in the app – to read and sign.

Controller
Sägewerk Muster GmbH
Processor
ManualPass
Server in Germany
DE
Sub-processor
lima-city (TrafficPlex GmbH, Bremen)

At first glance, digital instructions for use process hardly any personal data. But as soon as users request a paper copy or your team works in the app, names, addresses, email addresses and login data are involved. This page explains how ManualPass handles them. Technical safeguards such as encryption and tenant separation are described on the Security page.

Which personal data is involved?

Area Typical data Handling in ManualPass
Your team Name, email address, logins Log with time, person and IP address
Paper copy requests Name, address, email address of the requester automatic anonymisation after a selectable period
Visitors to the scan page Access to the documents no cookies, no tracking
Security data failed logins, expired password links deletion after 24 hours

Who is the controller, who is the processor?

The controller within the meaning of the GDPR is whoever determines the purposes and means of processing. The processor is whoever processes personal data on behalf of and on the instructions of the controller.

Role Who Task
Controller You as the customer decide which data is processed for which purpose
Processor ManualPass processes the data on your instructions
Sub-processor lima-city (TrafficPlex GmbH, Bremen) provides hosting in Germany

Conclude the DPA online in the app

A data processing agreement (DPA) governs, under Article 28 GDPR, how a service provider processes personal data on behalf of a customer. With ManualPass, you conclude it directly in the application:

  1. In the app, open the “Data protection & DPA” section.
  2. Review the text of the agreement with the technical and organisational measures (TOMs) in Annex 2.
  3. Conclude the agreement electronically.
  4. Save the concluded agreement as a PDF for your records.

The electronic form is sufficient: in addition to written form, Article 28(9) GDPR expressly permits an electronic format. The audit log records the conclusion of the DPA with time and person.

Practical tip

Would your data protection officer like to read the agreement beforehand? The full text is publicly available under DPA, without logging in.

Where is the data processed?

All data is stored on servers in Germany: documents, log, team and account data as well as the details from paper copy requests. The only sub-processor is the hosting provider lima-city (TrafficPlex GmbH, Bremen).

Scan page without cookies and without tracking

The scan page is the public web page that users see after scanning the QR code. It sets no cookies and uses no tracking. Your customers are therefore not tracked while reading the instructions.

Paper copy requests: data minimisation through anonymisation

If a user requests a paper copy, the manufacturer needs their name and address for dispatch. After that, these details are no longer required. ManualPass therefore anonymises paper copy requests automatically after dispatch:

  • Selectable period: 6, 12, 24 or 36 months after dispatch.
  • Retained: the date, machine and status of the request.
  • Removed: the requester's personal details.

This way, you can still prove that requests were handled on time without keeping address data longer than necessary. The Paper copy request page describes the request process.

Security data deleted after 24 hours

ManualPass stores failed login attempts and expired password reset links only briefly to prevent misuse. This data is deleted after 24 hours. Only the entries in the audit log, such as successful logins, are kept longer, because they serve as proof of who performed which action and when.

Text module for your privacy policy

As the controller, you must inform users about the processing, so ManualPass provides a text module in the app. You include it in your own privacy policy and adapt it to your company. The module describes that you use a service provider to provide the documents and handle paper copy requests. Check the adapted text with your data protection officer.

Data protection checklist

  • Conclude the DPA in the app under “Data protection & DPA” and file it as a PDF
  • Set the anonymisation period for paper copy requests
  • Include the text module in your own privacy policy
  • Enter ManualPass and its sub-processor in your record of processing activities

Common misconception

“With the DPA, data protection is completely taken care of.” The DPA only governs the relationship between you and ManualPass. Your information obligations towards users and your own record of processing activities remain your responsibility as the controller.

Frequently asked questions

How do I conclude the DPA with ManualPass?

In the app under “Data protection & DPA”. The agreement under Article 28 GDPR is concluded electronically, which Article 28(9) GDPR expressly permits, and can then be saved as a PDF. You can read the text of the agreement publicly beforehand.

Who is the sub-processor?

Only the hosting provider lima-city (TrafficPlex GmbH, Bremen). The servers are located in Germany. ManualPass does not use any other sub-processors to process your data.

Does the scan page use cookies or tracking?

No. The public scan page works without cookies and without tracking. Anyone who accesses instructions for use is not tracked.

How long is data from paper copy requests stored?

After dispatch, paper copy requests are automatically anonymised after a period of your choice: 6, 12, 24 or 36 months. The date, machine and status are retained as proof; the personal details are removed.