Data Processing Agreement
Version 1 · Last updated: August 2026
This English text is a convenience translation. The agreement is concluded in German; in case of discrepancies, the German version prevails.
This agreement is entered into between the customer as recorded in the user account (the controller) and SKAJ Ventures GmbH, Sonnenlandstrasse 4, 14471 Potsdam, Germany, represented by its managing director Stefan Köhn, HRB 27911 P (the processor).
Section 1 – Subject matter and duration
(1) The processor provides the customer with the RateMind SaaS application. The controller uses it to collect feedback from their own customers, evaluate it, and direct satisfied customers to external review platforms.
(2) Where personal data of the controller's customers is processed in doing so, this happens solely on the controller's behalf and on their instructions. This agreement gives effect to Art. 28 GDPR.
(3) Processing is tied to the term of the main contract and ends with it. This agreement cannot be terminated separately from the main contract.
(4) For the controller's own contract data – name, email address, password hash, sign-in times, subscription and billing data – the processor is itself the controller. That processing is governed by the privacy policy and is not the subject of this agreement.
Section 2 – Nature, purpose, data categories, data subjects
(1) Nature and purpose: collection, storage, organisation, retrieval, use, transmission and erasure of personal data for the purpose of collecting feedback, sending email invitations, reminding recipients who have not responded, evaluating the feedback, and forwarding to external review platforms.
(2) Categories of personal data:
| Category | How it is stored |
|---|---|
| End customer email addresses | Encrypted with AES-256-GCM, plus a keyed hash for lookups |
| Ratings and free-text answers | In the clear, as they constitute the purpose of the contract |
| Delivery information (sent, delivered, bounced) | In the clear, with the associated address encrypted |
| Open and click timestamps | Only where the controller has explicitly enabled it (Section 4(4)) |
| Unsubscribe records | Address encrypted, plus a hash |
| Contents of business correspondence sent by BCC | Only temporarily, see Section 3 |
(3) Categories of data subjects: customers, prospects and other business contacts of the controller whose email addresses the controller transmits to the processor, or who open a feedback form.
(4) Special categories of personal data under Art. 9 GDPR are not the subject of this agreement. The controller ensures through the design of their questions that such data is not collected. The processor advises respondents on the feedback pages not to enter health data or other sensitive details; voluntary entries in free-text fields cannot be prevented technically.
Section 3 – The BCC mechanism
(1) The controller may place an address assigned to them in the BCC field of their own business emails. The processor retrieves those messages from a mailbox it operates in order to obtain the recipient addresses and create feedback invitations from them.
(2) In doing so the processor necessarily receives the full content of the message. It processes only the recipient addresses from it. The message content is not evaluated, stored or otherwise used.
(3) Messages are deleted once the invitation has been created. Where a message could not be processed, it is deleted within seven days at the latest.
(4) The controller decides which of their messages to transmit this way. They ensure that they are entitled to do so and do not transmit correspondence subject to a special duty of secrecy.
Section 4 – Instructions
(1) The processor processes the data solely on the controller's documented instructions. This agreement, the main contract, and the settings the controller applies in the application or through the API constitute documented instructions.
(2) The controller confirms verbal instructions in text form without undue delay.
(3) Where the processor considers an instruction unlawful, it says so without undue delay. It may suspend execution until the matter is resolved.
(4) Open and click tracking in invitation emails is disabled by default. Where the controller enables it for a survey, that constitutes an instruction, and the controller warrants that they hold the recipients' consent required for it (Section 25 TDDDG).
(5) The controller warrants that they are entitled to contact each transmitted email address for the purpose of a satisfaction survey. Clause 7 of the terms of service applies in addition.
Section 5 – Confidentiality
(1) The processor uses only personnel who are bound to confidentiality or subject to an appropriate statutory duty of secrecy.
(2) That obligation survives the end of their engagement.
(3) Access is granted only to those who need it to perform their tasks.
Section 6 – Technical and organisational measures
(1) The processor implements the measures described in Annex 1 pursuant to Art. 32 GDPR and maintains them for the term of the agreement.
(2) The measures may be developed further as long as the level of protection is not reduced. The processor documents material changes and discloses them on request.
Section 7 – Sub-processors
(1) The controller grants general authorisation for the engagement of sub-processors. Those engaged at the time of conclusion are listed in Annex 2 and are thereby authorised.
(2) The processor notifies intended changes in text form at least 30 days in advance. The controller may object within 14 days of receipt on important data protection grounds.
(3) If the controller objects, the processor may discontinue the affected part of the service. Where the service can no longer be provided as agreed, both parties have a right of extraordinary termination.
(4) The processor binds each sub-processor to a level of protection equivalent to this agreement and is liable for their conduct as for its own.
(5) Ancillary services without a connection to the processed data, such as telecommunications or cleaning, do not constitute sub-processing.
Section 8 – Assisting with data subject rights
(1) Where a data subject approaches the processor directly, the processor forwards the request to the controller without undue delay and does not answer it itself.
(2) The processor provides the controller with the following functions to fulfil data subject rights themselves:
| Right | Function |
|---|---|
| Access and portability (Art. 15, 20) | Full data export as JSON in account settings and through the API |
| Rectification (Art. 16) | Editing in the dashboard |
| Erasure (Art. 17) | Erasure of all data held for a single email address, in account settings and through the API |
| Objection (Art. 21) | Unsubscribe link in every invitation email; unsubscribed recipients are permanently excluded from further sends |
(3) When a single data subject is erased, the unsubscribe record is retained. Otherwise the same person could be contacted again. Only the encrypted address and its hash remain for that purpose.
(4) Where these functions are not sufficient, the processor assists further to a reasonable extent. Effort beyond the functions provided may be charged where the controller is responsible for it.
Section 9 – Assisting with Art. 32 to 36 GDPR
(1) The processor notifies the controller of any personal data breach without undue delay after becoming aware of it, as a rule within 24 hours, in text form to the address recorded in the account.
(2) The notification includes, as far as known: the nature of the breach, the categories and records affected, the likely consequences, the measures taken and proposed, and a point of contact. Missing details are supplied without undue delay.
(3) Notification of the supervisory authority under Art. 33 GDPR and communication to data subjects under Art. 34 GDPR are the controller's responsibility. The processor assists.
(4) The processor assists as required with a data protection impact assessment under Art. 35 GDPR and with prior consultation under Art. 36 GDPR, in particular by providing information about the measures in place.
Section 10 – Erasure and return
(1) On termination of the contractual relationship the processor erases all data processed on the controller's behalf. The controller may instead request its return, for which the data export under Section 8(2) is available.
(2) Where the controller closes their account, it is first suspended and can be restored for 30 days. After that period all associated personal data is permanently deleted.
(3) Independently of termination, the following standard periods apply, which the controller may shorten in the settings:
| Data | Period |
|---|---|
| Delivery records | 12 months |
| Invitation data | 24 months |
| Feedback data | For as long as the account exists, unless configured shorter |
| Messages in the BCC mailbox | Until processed, at most 7 days |
| API logs | Payloads 30 days, entries 90 days |
(4) Excluded from erasure is data subject to a statutory retention obligation, as well as the record of the erasure itself (Art. 5(2) GDPR). That record contains no addresses in the clear, only hash values.
Section 11 – Evidence and audits
(1) The processor demonstrates compliance with this agreement on request, in particular by providing the current Annex 1 and information about the sub-processors engaged.
(2) The controller may satisfy themselves of compliance during normal business hours after giving at least four weeks notice. Audits are conducted so as not to unreasonably disrupt operations, and at most once a year unless there is specific cause.
(3) The processor may provide evidence through appropriate certifications or audit reports from independent bodies, to the extent these cover the subject of the audit.
(4) Effort for audits beyond one per year and not justified by specific cause may be charged.
Section 12 – Processing outside the European Union
(1) Processing generally takes place within the European Union. Where sub-processors listed in Annex 2 process in a third country, this is marked there.
(2) Appropriate safeguards under Chapter V GDPR are in place for those transfers, namely certification under the EU-US Data Privacy Framework or the European Commission's standard contractual clauses together with supplementary measures.
Section 13 – Liability
(1) Art. 82 GDPR governs the relationship between the parties.
(2) The liability provisions of the main contract apply accordingly, except where this would limit liability towards data subjects.
Section 14 – Final provisions
(1) Amendments require text form. This also applies to any waiver of this form requirement.
(2) In case of conflict between this agreement and the main contract, this agreement prevails as regards processing on the controller's behalf.
(3) German law applies. The exclusive place of jurisdiction, where permitted, is Potsdam, Germany.
(4) Should any provision be invalid, the remainder of the agreement remains effective.
Annex 1 – Technical and organisational measures
Measures pursuant to Art. 32 GDPR, as at August 2026.
1. Confidentiality
Physical access. No servers are operated in-house. The application and database run at Vercel and Neon, email at netcup GmbH. Physical protection of the data centres is the responsibility of those providers.
System access. Sign-in with email address and password; passwords stored only as a bcrypt hash with cost factor 12. Sign-in only after the email address has been confirmed (double opt-in). Sessions managed through signed tokens in an HttpOnly cookie. Rate limiting on the authentication endpoints. API access through keys stored only as a hash and shown in the clear only at creation.
Data access. Tenant separation at application level: every query is bound to the user's account membership. Per-account role model with owner and member roles; erasure, data export and acceptance of this agreement are reserved to the owner. End customer email addresses are stored encrypted with AES-256-GCM – in invitations, delivery records and unsubscribe entries alike; no plaintext column for recipient addresses exists. Lookups run against keyed hashes (HMAC-SHA-256). Full addresses are never delivered to the browser; they appear masked in reports and exports. API logs redact headers and query parameters against an allowlist.
Separation. Customer data is separated by account membership; every erasure and every export is scoped to one account. Separate development and production environments with their own databases and their own keys.
Pseudonymisation. Recipient addresses are held encrypted, with hashes allowing attribution without disclosure. Records of erasures contain hash values only.
2. Integrity
Transmission. All connections to the application over TLS only; database connections encrypted; email sent over authenticated, encrypted SMTP. The unsubscribe link carries the address encrypted rather than in the clear, so it does not appear in server and proxy logs. Redirects from emails are validated against open redirection.
Input. All input is validated server-side against a schema. Changes to accounts and surveys are traceable through timestamps. Erasures at account level and for individual data subjects are logged (time, initiating person, scope, address hash). Acceptance of this agreement is recorded with version, time and accepting person.
3. Availability and resilience
Operation on a managed platform with redundant delivery. Database with automated backup and point-in-time recovery provided by the vendor.
4. Regular review
Automated tests on every change, including checks that explicitly guard privacy properties: that recipient addresses are not stored in the clear, that the unsubscribe link does not expose the address, that every erasure job is actually scheduled, and that the privacy policy makes no promise the application does not keep. In addition, static analysis and type checking on every change, and binding internal rules on encryption, retention and erasure.
5. Erasure
The standard periods are set out in Section 10. Erasure is carried out by automated jobs running daily and applies regardless of the plan booked.
6. Oversight of processing
Sub-processors solely as per Annex 2, each contractually bound to an equivalent level of protection. All persons with data access are bound to confidentiality.
Annex 2 – Sub-processors
On conclusion of this agreement the controller authorises the engagement of the following sub-processors.
| Company | Service | Data processed | Location |
|---|---|---|---|
| Vercel Inc. | Application hosting and delivery | All data processed on the controller's behalf while being processed; server access logs including IP address | United States |
| Vercel Inc. (Blob Storage) | Storage of uploaded logos | Image files of the controller | United States |
| Neon Inc. | Database operation | All data processed on the controller's behalf | United States |
| netcup GmbH | Email delivery and the BCC mailbox | End customer email addresses, invitation email content, messages sent by BCC | Germany |
| Stripe | Subscription payment processing | Controller contract data only, no end customer data | United States / Ireland |
Appropriate safeguards under Chapter V GDPR are in place for transfers to the United States, as set out in Section 12 of this agreement.
Not treated as sub-processing: the Google Places API, used solely in the free public tools on the website and receiving no data processed on the controller's behalf; and any SMTP server the controller configures themselves, whose provider is then their own processor.
Changes are notified at least 30 days in advance under Section 7(2).