Data Processing Agreement (DPA) — Art. 28(3) GDPR

Version 2026-08-03b · ChurnScope · Patrick Rößner

Parties to the Agreement

This Data Processing Agreement ("DPA") forms an integral part of the General Terms and Conditions or User Agreement governing the Software-as-a-Service solution "ChurnScope" and specifies the data protection obligations of the parties pursuant to Art. 28(3) GDPR.

Data Processor: Patrick Rößner, trading as "PepDev", Untere Halle-Kasseler-Straße 11, 99752 Bleicherode, Germany; Sole Proprietorship (not entered in the commercial register). Phone: +49 1522 4854825, Email: info@churnscope.de, Website: https://churnscope.de.

Data Controller: The respective customer using ChurnScope and accepting this DPA (Business entity / Entrepreneur within the meaning of § 14 BGB).

Preamble

This Agreement specifies the data protection obligations arising from the Principal Agreement concerning the use of ChurnScope (Terms of Service, Pilot Agreement, or Subscription Agreement). It applies to all activities in connection with the Principal Agreement where the Processor or persons authorized by the Processor process personal data on behalf of the Controller.

Section 1: Subject Matter, Duration, and Specification of Processing

The subject matter is the provision and operation of the web application "ChurnScope" for analyzing churn risks based on the Controller's CRM data (in particular HubSpot), including dashboards, recommended action playbooks, quota management, and—where activated—writing notes/tasks or updates back into the Controller's CRM.

The duration of this DPA corresponds to the term of the Principal Agreement.

Categories of Data Nature and Purpose of Processing Categories of Data Subjects
CRM / HubSpot-related data (e.g., company data, deal/pipeline data, ticket/service data, activity and communication metadata, contact details of points of contact), insofar as connected or transmitted by the Controller. Operation of ChurnScope: Risk analysis, display within the application, technical support, logging, quota/subscription management; upon instruction, writing back into HubSpot. Customers, prospective leads, and contact persons of the Controller; employees of the Controller to the extent contained in the CRM data.
Usage and account data of the Controller (e.g., Portal ID, company name, email address, agreement consents, feedback). Contract execution, authentication, billing, quota management, support, verification of license grant. Authorized users and contact persons on the Controller's side.

Section 2: Scope and Responsibility

(1) The Processor processes personal data exclusively on behalf of the Controller. The Controller remains solely responsible for compliance with statutory data protection laws, in particular for the lawfulness of the data transfer and processing ("Controller" pursuant to Art. 4(7) GDPR).

(2) Documented instructions are initially determined by the Principal Agreement and the functional use of ChurnScope. Individual instructions may subsequently be issued or amended in text form (e.g., via info@churnscope.de).

Section 3: Obligations of the Processor

(1) The Processor shall process data only on documented instructions from the Controller, unless required to do so by applicable Union or Member State law. The Processor shall inform the Controller immediately if an instruction infringes data protection provisions.

(2) The Processor implements appropriate technical and organizational measures (TOMs) pursuant to Art. 32 GDPR (see Annex) to ensure a level of security appropriate to the risk.

(3) The Processor shall assist the Controller in fulfilling its obligations to respond to data subjects' requests (Chapter III GDPR) and compliance with Art. 33 to 36 GDPR.

(4) The Processor ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

(5) The Processor shall notify the Controller without undue delay upon becoming aware of a personal data breach affecting the Controller's data.

(6) Contact person for data protection inquiries: Patrick Rößner, Email: info@churnscope.de, Phone: +49 1522 4854825.

(7) Upon termination of the service, the Processor shall, at the choice of the Controller, delete or return all personal data, unless statutory retention obligations apply.

Section 4: Obligations of the Controller

(1) The Controller shall inform the Processor immediately and fully of any errors or irregularities detected regarding data protection provisions.

(2) The Controller designates a contact person for data protection inquiries (generally the email address provided during registration).

Section 5: Data Subject Requests

If a data subject contacts the Processor directly with requests regarding access, rectification, or erasure, the Processor shall forward the request to the Controller without undue delay and shall not respond independently unless instructed to do so.

Section 6: Audits and Demonstrating Compliance

(1) The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA, primarily through documentation of TOMs and self-audits.

(2) Inspections by the Controller or an appointed auditor shall be carried out during normal business hours with reasonable advance notice, without disrupting operations, and may be subject to a non-disclosure agreement regarding other customers' data.

Section 7: Subprocessors

(1) The Controller grants consent to the engagement of the following subprocessors:

Subprocessor Subcontracted Activity Location / Safeguards
Vercel Inc. Web application hosting and serverless API USA / Safeguards pursuant to Art. 46 GDPR (SCCs/DPF) as applicable
Supabase (Supabase Inc. / EU Region Frankfurt) Database and backend services (usage & contract data) Primarily EU (Frankfurt, Germany) / EEA
Celonis, Inc. d/b/a Make (Make.com) Automation and integration platform (HubSpot webhooks) EU data processing available / Safeguards pursuant to Art. 46 GDPR
Functional Software, Inc. d/b/a Sentry Error monitoring and technical diagnostics Safeguards pursuant to Art. 46 GDPR as applicable
Formspree, Inc. Transmission of contact and pilot request forms Safeguards pursuant to Art. 46 GDPR as applicable

(2) The Controller acknowledges that HubSpot is the Controller's own CRM system and does not constitute a subprocessor of the Processor.

(3) The Processor shall inform the Controller of any intended changes concerning the addition or replacement of subprocessors with a 14-day objection period.

Section 8: Miscellaneous, Governing Law & Jurisdiction

(1) In case of contradictions between this DPA and the Principal Agreement, the provisions of this DPA shall prevail regarding data protection matters.

(2) This DPA shall be governed by and construed in accordance with the laws of the Federal Republic of Germany.

(3) Language Clause: In the event of any discrepancies or contradictions between the German version and this English version, the German version shall prevail.

Annex — Technical and Organizational Measures (TOMs) (Art. 32 GDPR)

The Processor implements the following technical and organizational measures:

Access Control: Administrative access restricted to authorized personnel; strong authentication mechanisms enforced; strict credential management.

Transmission Control: End-to-end transport encryption via TLS/HTTPS; API endpoints and webhooks secured via authenticated secrets.

Input / Traceability Control: Technical event logging and error monitoring; database records proving consent to Terms and DPA.

Availability & Resilience: Hosting and database operations provided by enterprise cloud infrastructure with automated snapshot backups; core database location set to EU (Frankfurt).

Data Separation: Processing strictly isolated per customer account and Portal ID.

Erasure: Deletion or anonymization of CRM data upon termination of the service or instruction.