Data Processing Agreement (Art. 28 GDPR)
This agreement is available in German and English. In case of discrepancies, the German version (AVV) is solely authoritative; this English version is provided for convenience.
Version 0.2 · July 2026 · This DPA forms part of the Terms of Service between the customer ("Controller") and Sixty One GmbH, Lange-Feld-Str. 77B, 30926 Seelze, Germany ("Processor") and is concluded by accepting the Terms.
1. Subject matter and duration
The Processor processes personal data on behalf of the Controller as necessary to provide the Charterfile platform. Duration follows the term of the main contract.
2. Nature and purpose of processing
Hosting, storage, transmission and display of data entered by the Controller for the purpose of managing its charter business: CRM, quoting, document generation, client-facing booking pages, communications and reporting.
3. Categories of data and data subjects
Data subjects: the Controller's clients and prospects, passengers, the Controller's own staff, and counterparties (brokers/operators).
Data categories: contact and identification data (name, email, phone, company, address); passenger identity and travel-document data (date of birth, nationality, passport number and validity); booking and deal data (routes, dates, prices); communication content and metadata; consent and unsubscribe records.
Travel-document data are sensitive in practice; the Processor stores the fields listed in Annex 1 encrypted at rest.
4. Obligations of the Processor
The Processor shall: (a) process personal data only on documented instructions of the Controller — the functions of the platform as used by the Controller constitute such instructions; (b) ensure persons authorised to process are bound to confidentiality; (c) implement the technical and organisational measures in Annex 1; (d) assist the Controller, insofar as possible, with data-subject requests (Art. 12–23 GDPR) and with obligations under Art. 32–36 GDPR; (e) notify the Controller without undue delay of any personal-data breach concerning the Controller's data; (f) delete or return all personal data after the end of the services as set out in the Terms (§13.3), unless storage is required by law; (g) make available information necessary to demonstrate compliance and allow audits as set out in §7.
5. Instructions
Individual instructions beyond the platform's functionality must be in text form. The Processor will inform the Controller if, in its opinion, an instruction infringes data-protection law.
6. Subprocessors
6.1 The Controller grants general authorisation for the subprocessors in Annex 2. The Processor will inform the Controller of intended changes at least four weeks in advance; the Controller may object on justified data-protection grounds. If no agreement is reached, either party may terminate the affected services.
6.2 The Processor imposes data-protection obligations on subprocessors equivalent to those in this DPA. For subprocessors outside the EU/EEA, transfers occur only with appropriate safeguards (adequacy decision or standard contractual clauses).
7. Audits
The Controller may verify compliance by requesting meaningful documentation (certifications, TOM summaries, reports). On-site audits are limited to once per year with reasonable notice during business hours, unless a breach or supervisory authority requires otherwise, and at the Controller's cost.
8. Liability
Liability follows Art. 82 GDPR and the liability clause of the Terms (§12).
Annex 1 — Technical and organisational measures (summary)
- Tenant isolation: row-level security enforced in the database for every tenant-owned table; cross-tenant access is technically prevented.
- Encryption in transit: TLS for all connections.
- Encryption at rest: passenger travel-document fields (passport number, date of birth, expiry, nationality, notes) and all integration credentials are encrypted at application level (AES-256-GCM); disks are hosted in ISO-27001 certified data centres in Germany.
- Access control: password + email one-time-code (2FA) login; role-based permissions; staff access limited and logged.
- Availability: daily off-site backups; documented restore procedure.
- Data minimisation: uploaded passport images for OCR are processed in memory and not stored.
- Logging: security-relevant events and administrative actions are logged (audit trail).
Annex 2 — Approved subprocessors
- Hosting: Hetzner Online GmbH, Gunzenhausen, Germany — infrastructure and data storage in data centres in Germany (Falkenstein/Nuremberg).
- Transactional email: [Brevo — Sendinblue GmbH, Berlin, Germany / to be confirmed at go-live] — delivery of platform emails.
Notice of intended subprocessor changes under §6.1 is given by email to the Controller's account owner.
For clarity: Stripe Payments Europe Ltd. processes the Controller's own subscription billing data with the Processor acting as controller (see the privacy notice); Stripe does not process the Controller's client or passenger data and is therefore not a subprocessor under this DPA. Where the Controller connects its own third-party accounts (its payment provider, its accounting software such as Lexware, its social accounts), those providers act on the Controller's behalf under the Controller's own agreements and are not subprocessors of the Processor.