Skip to the agreement
Back to home

Article 28 GDPR

Data Processing Agreement

Contract terms for the processing of personal data in customer workspaces, with the processing description, safeguards, and current subprocessors in one place.

Version 1.0 · Effective 4 August 2026

Contract status

This DPA forms part of the HansaChat service agreement.

It becomes binding when the Customer accepts a Service Agreement or order that incorporates it, accepts the updated Terms, or otherwise agrees to it electronically. The Customer is identified by its order, subscription, workspace, or account record. A wet-ink signature is not required.

  • Customer: controller (or processor acting for another controller)
  • HansaChat: processor for Customer Personal Data in the workspace
  • HansaChat remains controller for its own billing, account, security, and legal-compliance data

Data-location summary

Primary workspace data is stored in Germany.

Live application databases, uploaded files, and the self-hosted call service run on IONOS Cloud in Germany. Backup copies encrypted by HansaChat before transfer are stored in Frankfurt, Stockholm, and London. Optional email and mobile-push delivery involve the subprocessors and locations listed in Annex 3.

Encrypted backup copies remain personal data under the GDPR because HansaChat retains the means to restore them. London is covered by the European Commission’s current UK adequacy decision; Stockholm is within the EU.

Article 28 GDPR

Parties and scope

This Data Processing Agreement (“DPA”) is entered into between the following parties and supplements the agreement under which HansaChat provides the service (“Service Agreement”). “Customer Personal Data” means personal data that HansaChat processes on the Customer’s behalf in connection with the service.

Customer / controller
The natural or legal person identified as the customer in the applicable order, subscription, workspace, or HansaChat account record, including its authorised affiliates where the Service Agreement covers them.
Processor
Igor Tverdokhleb, trading as HansaChat, Barkentinenstr. 20, 23558 Lübeck, Germany · igor@hansa.chat

If this DPA conflicts with the Service Agreement on the processing of Customer Personal Data, this DPA prevails. The German version prevails if the English and German versions conflict.

1. Subject matter, duration, and roles

This DPA governs HansaChat’s processing of Customer Personal Data to provide the service. The subject matter, nature, purpose, categories of data, data subjects, and duration are specified in Annex 1.

The Customer determines the purposes and essential means of processing workspace content. HansaChat processes that data on the Customer’s behalf. This DPA does not cover personal data that HansaChat processes as an independent controller for billing, account administration, service security, abuse prevention, support administration, or compliance; that processing is described in the Privacy Policy.

2. Documented instructions and lawfulness

HansaChat shall process Customer Personal Data only on documented instructions from the Customer, including the Service Agreement, this DPA, the Customer’s use and configuration of the service, and subsequent instructions sent in text form. HansaChat may process data where Union or Member State law requires it and shall inform the Customer before doing so unless the law prohibits that notice for important reasons of public interest.

HansaChat shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable Union or Member State data-protection law and may suspend the affected instruction until it is confirmed or amended.

3. Confidentiality and access

HansaChat ensures that each person authorised to process Customer Personal Data is bound by confidentiality or an appropriate statutory duty and receives access only where necessary for service operation, maintenance, troubleshooting, security, abuse prevention, legal compliance, or Customer-requested support.

Where section 3 of the German Telecommunications Digital Services Data Protection Act (TDDDG) applies, HansaChat also protects the content and circumstances of communications as telecommunications secrecy. HansaChat shall not obtain knowledge beyond what is necessary to provide the communication service or protect its technical systems, and shall use such knowledge for another purpose only where a law expressly permits that use in relation to telecommunications.

The confidentiality obligation continues after the person’s work and after the Service Agreement ends.

4. Security of processing

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, HansaChat shall maintain appropriate technical and organisational measures under Article 32 GDPR. The current measures are described in Annex 2 and on the Security page.

HansaChat may update those measures as technology and risk change, provided the overall level of protection is not materially reduced during the Service Agreement.

5. Subprocessors

The Customer grants HansaChat general written authorisation to use the subprocessors in Annex 3. HansaChat shall impose substantially the same data-protection obligations on each subprocessor, remain responsible for its performance under this DPA, and keep the list current.

HansaChat shall give at least 30 days’ advance notice by email to the Customer’s account contact or through a prominent service notice before adding or replacing a subprocessor that processes Customer Personal Data. A shorter period may be used where necessary to address an urgent security, legal, or availability risk; HansaChat will then provide notice as soon as reasonably possible.

The Customer may object during the notice period on reasonable data-protection grounds. The parties shall work in good faith on a commercially reasonable solution. If none is available, the Customer may terminate the affected service before the new subprocessor begins processing, without penalty for the unused prepaid period of that affected service.

6. Processing locations and international transfers

Primary workspace storage is located in Germany. Encrypted Restic backup copies are stored in Frankfurt, Stockholm, and London. Network delivery and optional supporting features may involve other locations as stated in Annex 3.

HansaChat shall not transfer Customer Personal Data to a third country or international organisation unless instructed by the Customer, necessary to provide an enabled service feature, or required by law, and only where the requirements of Chapter V GDPR are met. Applicable safeguards may include an adequacy decision, the European Commission’s Standard Contractual Clauses, and supplementary technical and organisational measures.

7. Data-subject requests and compliance assistance

If HansaChat receives a request from a data subject concerning Customer Personal Data, it shall promptly forward the request to the Customer and shall not respond unless authorised by the Customer or required by law.

Taking into account the nature of processing and the information available, HansaChat shall reasonably assist the Customer with data-subject rights and with the Customer’s obligations under Articles 32 to 36 GDPR, including security, breach assessment, data-protection impact assessments, and prior consultation.

8. Personal-data breaches

HansaChat shall notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. The notice shall include the information available to HansaChat that the Customer reasonably needs for its obligations under Articles 33 and 34 GDPR, and further information may be provided in phases as it becomes available.

HansaChat shall take reasonable steps to contain, investigate, remediate, and mitigate the breach and shall cooperate with the Customer. Notification is not an admission of fault or liability.

9. Return and deletion

At the Customer’s choice, HansaChat shall return or delete Customer Personal Data after the processing services end and delete existing copies, unless Union or Member State law requires retention. The Customer must request return before the workspace deletion date; if the Customer gives no instruction, deletion is selected.

Paid workspaces become read-only after cancellation and are deleted after 30 days. Demo workspaces are deleted after 24 hours, and free workspaces after 60 days of inactivity. Uploaded files are deleted with the workspace. Backup copies age out under the schedule in Annex 2; backups containing deleted workspace data are deleted 30 days after the last backup containing that data.

10. Information and audits

HansaChat shall make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. The Customer may audit the covered processing itself or through an independent, qualified auditor bound by confidentiality.

Audits should ordinarily begin with available documentation and remote review. On-site inspection is available where documentation is insufficient or there are reasonable indications of non-compliance, with reasonable advance notice and without compromising other customers, security, or trade secrets. The Customer bears reasonable audit costs unless an audit identifies a material breach by HansaChat. Supervisory-authority powers are not limited.

11. Customer obligations

  • Ensure that Customer Personal Data is collected and processed lawfully and that instructions comply with applicable law.
  • Provide required notices, choose a valid legal basis, and obtain any necessary consents or employee-representation approvals.
  • Configure access, invitations, channels, retention, mobile push notifications, and integrations appropriately for the Customer’s risks.
  • Do not place special-category or criminal-offence data in HansaChat unless the Customer has assessed the necessity, legal basis, and safeguards.
  • Maintain accurate account contacts and promptly report suspected security or data-protection issues to igor@hansa.chat.

12. Term, termination, and governing terms

This DPA begins when it becomes binding under the Contract status section and remains in effect until HansaChat has deleted all Customer Personal Data. If HansaChat cannot comply with this DPA, it shall promptly inform the Customer. The Customer may suspend processing or terminate the affected service where a material breach is not remedied within a reasonable period.

Liability, governing law, and venue follow the Service Agreement except where mandatory data-protection law requires otherwise. Nothing in this DPA limits the rights of data subjects or the powers of a competent supervisory authority.

Article 28 GDPR

Annex 1 · Description of processing

Subject matter
Providing and operating the HansaChat workspace communication service on the Customer’s behalf.
Duration
For the term of the Service Agreement and the deletion/return period described in section 9 and Annex 2.
Nature of processing
Collection, recording, organisation, structuring, storage, retrieval, consultation, display, transmission between authorised users, email and push delivery, backup, support access when required, restriction, export, and deletion.
Purposes
Authentication; workspace and membership administration; channels and direct messages; message delivery, search, reactions, mentions, files, calls and screen sharing; notifications; security; support; continuity; and deletion.
Data subjects
Customer personnel, contractors, workspace members, invited guests, invitees, external collaborators, and any identifiable persons whose data users place in workspace content.
Personal-data categories
Names, email addresses, profile and role data, password hashes and authentication records, workspace memberships, messages and replies, files, reactions, mentions, channel and call metadata, device and push tokens, IP/request/security metadata, and support material supplied by the Customer.
Frequency
Continuous for active workspaces and otherwise as initiated by authorised users, scheduled backups, retention jobs, or support instructions.

Special categories and criminal-offence data

HansaChat is not designed specifically for Article 9 or Article 10 data. Users may nevertheless place such data in free-form messages or files. The Customer controls whether that occurs and must establish the legal basis, necessity, access rules, and any additional safeguards. HansaChat applies this DPA and the Annex 2 measures to such data without using it for another purpose.

Article 28 GDPR

Annex 2 · Technical and organisational measures

These measures describe the current service. They are proportionate safeguards, not a claim of end-to-end encryption, independent certification, or a published penetration test.

Access and confidentiality

  • Need-to-know operator access limited to operation, maintenance, troubleshooting, security, legal compliance, or Customer-requested support.
  • Confidentiality obligations for persons authorised to process Customer Personal Data, including telecommunications secrecy under section 3 TDDDG where applicable.
  • bcrypt password hashing with automatic salts, optional user two-factor authentication, encrypted session cookies, inactivity expiry, and session-ID regeneration after login.
  • Workspace, public/private-channel, direct-message, membership, and role-based access rules.

Isolation and infrastructure

  • Each workspace has a separate application database; free and demo databases may share the underlying managed database service, while paid workspaces receive a separate managed database.
  • Primary databases, uploaded files, and the self-hosted LiveKit media service run on IONOS Cloud in Germany.
  • Uploaded files are stored separately in IONOS Object Storage with AES-256 server-side encryption at rest.
  • Connections between clients and HansaChat use HTTPS/TLS. HansaChat is not end-to-end encrypted and retains technical access where operation requires it.

Availability, backup, and restoration

  • IONOS MariaDB DBaaS provides provider-managed backups retained for seven days and point-in-time recovery.
  • HansaChat creates compressed Restic snapshots every six hours and encrypts them before transfer to backup object storage.
  • Restic copies are held in Frankfurt, Stockholm, and London. All snapshots are kept for 7 days, then one daily for 30 days, one weekly for 12 weeks, and one monthly for 12 months.
  • Backups containing deleted workspace data are deleted 30 days after the last backup containing that data.

Monitoring and review

  • Operational and security logging for errors, authentication, requests, and abuse-prevention signals, with personal data limited where practicable.
  • Incident investigation, containment, remediation, and Customer notification under section 8.
  • Dependency, configuration, and access controls are reviewed as the service changes; measures may be updated without materially reducing overall protection.
  • Deletion jobs implement the workspace lifecycles stated in section 9, with separate ageing of encrypted backups.
Read the detailed Security page

Article 28 GDPR

Annex 3 · Authorised subprocessors

The following entities may process Customer Personal Data to provide HansaChat. Optional services process data only when the relevant feature is used.

IONOS Cloud GmbH

Service and data
Primary hosting, managed MariaDB, Object Storage for uploads, Kubernetes, networking, and self-hosted LiveKit call infrastructure. Processes all Customer Personal Data required to provide the core service.
Processing location
Germany for HansaChat primary/live services.
Safeguard
Article 28 DPA; processing in selected German IONOS locations; provider technical and organisational measures.

BunnyWay d.o.o. (bunny.net)

Service and data
CDN, DNS/proxy delivery, DDoS protection, limited request metadata, and object storage for Restic-encrypted backup copies.
Processing location
Global edge transit; encrypted backup copies in Frankfurt (Germany), Stockholm (Sweden), and London (UK).
Safeguard
Article 28 DPA; data minimisation and encrypted backup content; EU/EEA processing, UK adequacy decision, and Chapter V safeguards where required.

Vercom S.A. (EmailLabs)

Service and data
Transactional and service email, including workspace invitations, verification, and password-reset messages. Processes recipient address, sender details, email content, and delivery metadata.
Processing location
European Economic Area, primarily Poland, Germany, and Ireland according to the provider documentation.
Safeguard
Article 28 DPA and EEA processing commitments.

Google Ireland Limited and Google affiliates (Firebase Cloud Messaging)

Service and data
Optional mobile push notifications. Processes device tokens, workspace/channel/sender identifiers, and a message preview sent in the notification payload.
Processing location
Google and its subprocessors may process globally. This processing occurs only for registered mobile push devices.
Safeguard
Firebase Data Processing and Security Terms; adequacy mechanisms and/or European Commission Standard Contractual Clauses with supplementary measures where required.

Services outside this subprocessor list

Creem (billing), HansaChat account administration, and HansaChat’s own security/compliance records are governed by the Privacy Policy because HansaChat determines those purposes as controller. The self-hosted LiveKit server is part of HansaChat’s IONOS infrastructure and is not a separate cloud subprocessor.

Primary legal and provider references

These links support due diligence. They do not replace or narrow the commitments in this DPA.

Privacy contact

Questions, instructions, or audit requests

Send data-protection instructions, data-subject requests, incident questions, and audit requests to the address below. Include the workspace domain and an authorised Customer contact.

igor@hansa.chat