Back

    Legal

    Data Processing Agreement (Art. 28 GDPR)

    1. Parties

    • Data Controller: Customer
    • Data Processor: Alexandi Software Solutions, Emin Alexandi

    2. Subject Matter & Duration

    (1) Processing of personal data in connection with the use of the SaaS platform "zeig".

    (2) Processing takes place for the duration of the main contract.

    3. Nature of Processing

    • Hosting
    • Storage of files (PDFs, thumbnails)
    • Provision via password-protected or time-limited links
    • Logging of technical access
    • Sending emails via connected Google accounts (optional, user-initiated)

    4. Categories of Data Subjects & Data

    Data Subjects

    • Customers
    • External recipients of shared content

    Data Types

    • Contact information
    • Business documents
    • Usage and metadata

    For Email Sending via Google (optional)

    • Sender account (email address of the connected Google account)
    • Recipient addresses
    • Email content (subject, body, attachments)
    • Technical metadata (timestamps, delivery status)

    5. Sub-processors

    The provider uses the following sub-processors:

    • Railway (Application and database hosting, EU)
    • Cloudflare R2 (Object storage for uploaded files, EU)
    • Cloudflare (CDN & Security)
    • Google LLC: Google Sign-In / Gmail API (Authentication, email sending, USA / global)
    • DodoPayments (Payment processing for subscriptions, USA)
    • Umami Analytics (Web analytics for marketing pages, self-hosted on Railway in the EU; no separate third-party data transfer)

    (2) Application and database hosting as well as storage of uploaded files take place exclusively within the European Union. Where individual sub-processors (in particular Google APIs and DodoPayments) process data in third countries, transfers are based on EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR.

    The complete list of sub-processors can be found on our Sub-processors page.

    6. Technical & Organizational Measures (TOMs)

    • TLS encryption
    • Password protection & expiration dates for links
    • Role-based access controls
    • Logging of security-relevant events
    • Database backup capability up to 7 days retroactively
    • Encrypted storage of OAuth tokens (AES-256-GCM) for Google integrations
    • Access restriction on tokens (authorized users only)

    7. Obligations of the Processor

    • Processing only on documented instructions
    • Support for data subject rights
    • Notification of data breaches without delay, at the latest within 72 hours

    8. Deletion

    After the end of the contract, personal data will be deleted after 30 days, unless legal retention obligations require otherwise.

    9. Final Provisions

    German law applies.