# Data protection and DPA: GDPR-compliant provision

> Anyone who provides digital instructions for use with ManualPass concludes the data processing agreement under Article 28 GDPR online, directly in the app under “Data protection & DPA”. The only sub-processor is the hosting provider lima-city with servers in Germany; the scan page works without cookies and without tracking, and personal data from paper copy requests is automatically anonymised after a selectable period.

Source: https://manualpass.eu/en/features/gdpr-dpa/ · Updated: 07/10/2026 · ManualPass (https://manualpass.eu)

At first glance, digital instructions for use process hardly any personal data. But as soon as users request a paper copy or your team works in the app, names, addresses, email addresses and login data are involved. This page explains how ManualPass handles them. Technical safeguards such as encryption and tenant separation are described on the [Security](https://manualpass.eu/en/security/) page.

## Which personal data is involved?

| Area | Typical data | Handling in ManualPass |
|---|---|---|
| Your team | Name, email address, logins | Log with time, person and IP address |
| Paper copy requests | Name, address, email address of the requester | automatic anonymisation after a selectable period |
| Visitors to the scan page | Access to the documents | no cookies, no tracking |
| Security data | failed logins, expired password links | deletion after 24 hours |

## Who is the controller, who is the processor?

The controller within the meaning of the GDPR is whoever determines the purposes and means of processing. The processor is whoever processes personal data on behalf of and on the instructions of the controller.

| Role | Who | Task |
|---|---|---|
| Controller | You as the customer | decide which data is processed for which purpose |
| Processor | ManualPass | processes the data on your instructions |
| Sub-processor | lima-city (TrafficPlex GmbH, Bremen) | provides hosting in Germany |

## Conclude the DPA online in the app

A data processing agreement (DPA) governs, under Article 28 GDPR, how a service provider processes personal data on behalf of a customer. With ManualPass, you conclude it directly in the application:

1. In the app, open the **“Data protection & DPA”** section.
2. Review the text of the agreement with the technical and organisational measures (TOMs) in Annex 2.
3. Conclude the agreement electronically.
4. Save the concluded agreement as a PDF for your records.

The electronic form is sufficient: in addition to written form, Article 28(9) GDPR expressly permits an electronic format. The [audit log](https://manualpass.eu/en/features/audit-trail/) records the conclusion of the DPA with time and person.

!!! tipp "Practical tip"
    Would your data protection officer like to read the agreement beforehand? The full text is publicly available under [DPA](https://manualpass.eu/en/dpa/), without logging in.

## Where is the data processed?

All data is stored on servers in Germany: documents, log, team and account data as well as the details from paper copy requests. The only sub-processor is the hosting provider lima-city (TrafficPlex GmbH, Bremen).

## Scan page without cookies and without tracking

The scan page is the public web page that users see after scanning the QR code. It sets no cookies and uses no tracking. Your customers are therefore not tracked while reading the instructions.

## Paper copy requests: data minimisation through anonymisation

If a user requests a paper copy, the manufacturer needs their name and address for dispatch. After that, these details are no longer required. ManualPass therefore anonymises paper copy requests automatically after dispatch:

- **Selectable period:** 6, 12, 24 or 36 months after dispatch.
- **Retained:** the date, machine and status of the request.
- **Removed:** the requester's personal details.

This way, you can still prove that requests were handled on time without keeping address data longer than necessary. The [Paper copy request](https://manualpass.eu/en/features/paper-copy-request/) page describes the request process.

## Security data deleted after 24 hours

ManualPass stores failed login attempts and expired password reset links only briefly to prevent misuse. This data is deleted after 24 hours. Only the entries in the audit log, such as successful logins, are kept longer, because they serve as proof of who performed which action and when.

## Text module for your privacy policy

As the controller, you must inform users about the processing, so ManualPass provides a text module in the app. You include it in your own privacy policy and adapt it to your company. The module describes that you use a service provider to provide the documents and handle paper copy requests. Check the adapted text with your data protection officer.

## Data protection checklist

- ☐ Conclude the DPA in the app under “Data protection & DPA” and file it as a PDF
- ☐ Set the anonymisation period for paper copy requests
- ☐ Include the text module in your own privacy policy
- ☐ Enter ManualPass and its sub-processor in your record of processing activities

!!! achtung "Common misconception"
    “With the DPA, data protection is completely taken care of.” The DPA only governs the relationship between you and ManualPass. Your information obligations towards users and your own record of processing activities remain your responsibility as the controller.

## Frequently asked questions

**How do I conclude the DPA with ManualPass?**
In the app under “Data protection & DPA”. The agreement under Article 28 GDPR is concluded electronically, which Article 28(9) GDPR expressly permits, and can then be saved as a PDF. You can read the text of the agreement publicly beforehand.

**Who is the sub-processor?**
Only the hosting provider lima-city (TrafficPlex GmbH, Bremen). The servers are located in Germany. ManualPass does not use any other sub-processors to process your data.

**Does the scan page use cookies or tracking?**
No. The public scan page works without cookies and without tracking. Anyone who accesses instructions for use is not tracked.

**How long is data from paper copy requests stored?**
After dispatch, paper copy requests are automatically anonymised after a period of your choice: 6, 12, 24 or 36 months. The date, machine and status are retained as proof; the personal details are removed.

---
Note: general information, not legal advice.
