Legal
Data Processing Agreement (Art. 28 GDPR)
1. Parties
- Data Controller: Customer
- Data Processor: Alexandi Software Solutions, Emin Alexandi
2. Subject Matter & Duration
(1) Processing of personal data in connection with the use of the SaaS platform "zeig".
(2) Processing takes place for the duration of the main contract.
3. Nature of Processing
- Hosting
- Storage of files (PDFs, thumbnails)
- Provision via password-protected or time-limited links
- Logging of technical access
- Sending emails via connected Google accounts (optional, user-initiated)
4. Categories of Data Subjects & Data
Data Subjects
- Customers
- External recipients of shared content
Data Types
- Contact information
- Business documents
- Usage and metadata
For Email Sending via Google (optional)
- Sender account (email address of the connected Google account)
- Recipient addresses
- Email content (subject, body, attachments)
- Technical metadata (timestamps, delivery status)
5. Sub-processors
The provider uses the following sub-processors:
- Railway (Application and database hosting, EU)
- Cloudflare R2 (Object storage for uploaded files, EU)
- Cloudflare (CDN & Security)
- Google LLC: Google Sign-In / Gmail API (Authentication, email sending, USA / global)
- DodoPayments (Payment processing for subscriptions, USA)
- Umami Analytics (Web analytics for marketing pages, self-hosted on Railway in the EU; no separate third-party data transfer)
(2) Application and database hosting as well as storage of uploaded files take place exclusively within the European Union. Where individual sub-processors (in particular Google APIs and DodoPayments) process data in third countries, transfers are based on EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR.
The complete list of sub-processors can be found on our Sub-processors page.
6. Technical & Organizational Measures (TOMs)
- TLS encryption
- Password protection & expiration dates for links
- Role-based access controls
- Logging of security-relevant events
- Database backup capability up to 7 days retroactively
- Encrypted storage of OAuth tokens (AES-256-GCM) for Google integrations
- Access restriction on tokens (authorized users only)
7. Obligations of the Processor
- Processing only on documented instructions
- Support for data subject rights
- Notification of data breaches without delay, at the latest within 72 hours
8. Deletion
After the end of the contract, personal data will be deleted after 30 days, unless legal retention obligations require otherwise.
9. Final Provisions
German law applies.