Data Processing Agreement (DPA)
Auftragsverarbeitungsvertrag (AVV) according to Art. 28 GDPR
As of: April 2026
Controller
[Kunde / Firma]
[Anschrift]
[Vertretungsberechtigte Person]
Processor
Der KI Flüsterer
Inhaber: Halil Aksit
Pickertstr. 45
24143 Kiel
Deutschland
E-Mail: kontakt@derkifluesterer.de
jointly also referred to as the "Parties".
1. Subject Matter and Relationship
1.1 This Data Processing Agreement specifies the data protection obligations of the parties under Art. 28 GDPR in connection with the services provided by the Processor for the Controller within the framework of ImmoVision AI.
1.2 This DPA applies to all activities in which the Processor processes personal data on behalf of the Controller.
1.3 This DPA supplements the main contract existing between the parties regarding the use of ImmoVision AI, including any tariffs, offers, service descriptions, enterprise agreements, white-label agreements, or other project-related agreements.
1.4 In the event of contradictions between this DPA and the main contract, the provisions of this DPA shall prevail with regard to data processing.
2. Roles of the Parties
2.1 The Controller is responsible for the lawfulness of the processing of personal data, in particular for:
- the existence of a legal basis,
- the safeguarding of data subject rights,
- the fulfillment of information obligations,
- the admissibility of the data transmitted to the Processor,
- the lawfulness of any recordings, transcriptions, or AI-supported evaluations, insofar as these are initiated by the Controller.
2.2 The Processor processes personal data exclusively on behalf of, within the framework of the documented instructions, and for the purposes described in this DPA.
2.3 Processing operations in which the Processor itself is the controller or otherwise independently responsible under data protection law are not the subject of this DPA. This concerns in particular:
- the establishment, execution, and billing of the contractual relationship with the Controller,
- own receivables management,
- verification, documentation, and statutory retention obligations,
- ensuring the security, integrity, stability, and abuse prevention of its own systems,
- the pursuit of its own legal claims or defense against claims,
- legally mandatory disclosures,
- own compliance, audit, security, and governance purposes,
- the processing of own invoice, contract, wallet, or payment data outside of the actual data processing.
3. Nature, Purpose, and Scope of Processing
3.1 The nature, purpose, subject matter, categories of personal data, and categories of data subjects result from this DPA, the main contract, and in particular from Annex 1.
3.2 The Processor processes personal data in particular for the provision and execution of the contractually owed SaaS services of ImmoVision AI, in particular in connection with:
- Lead capture and lead processing,
- CRM, dashboard, and workflow functions,
- Exposé, microsite, and object inquiries,
- User accounts, teams, roles, and rights management,
- Appointment and communication functions,
- Media, exposé, microsite, object, and content management,
- AI-supported functions, insofar as these are used on behalf of the Controller for its data,
- Transcription, summarization, structuring, and workflow processes,
- Hosting, storage, provision, processing, and technical output of content and data of the Controller,
- Billing-relevant usage events, insofar as these concern order-related data or processes.
3.3 The Processor processes personal data only to the extent necessary for the provision of the agreed services.
4. Right of Instruction of the Controller
4.1 The Processor processes personal data exclusively on the documented instruction of the Controller, unless it is obliged to process it by Union law or the law of a Member State. In such a case, the Processor shall inform the Controller of these legal requirements before processing, unless the relevant law prohibits such information for an important public interest.
4.2 Instructions of the Controller are initially determined by this DPA, the main contract, the service description, and other expressly included contract documents.
4.3 Individual instructions of the Controller must be at least in text form, unless another form is required for reasons of urgency. Oral instructions must be confirmed immediately in text form.
4.4 If the Processor is of the opinion that an instruction violates data protection law, it shall inform the Controller immediately. The Processor is entitled to suspend the execution of the relevant instruction until confirmation or modification by the Controller.
5. Confidentiality and Access Restriction
5.1 The Processor ensures that the persons authorized to process personal data are committed to confidentiality or are subject to an appropriate statutory duty of confidentiality.
5.2 The Processor guarantees that access to personal data is only granted to those persons who need this data to fulfill the contractually owed services.
5.3 The Processor takes appropriate organizational measures to appropriately restrict responsibilities, roles, and access rights internally.
6. Technical and Organizational Measures
6.1 The Processor takes appropriate technical and organizational measures in accordance with Art. 32 GDPR to ensure a level of protection appropriate to the risk.
6.2 The technical and organizational measures existing at the time of the conclusion of the contract result from Annex 2 of this DPA.
6.3 The Processor is entitled to further develop, adapt, or replace technical and organizational measures with equivalent measures, provided that the contractually agreed level of protection is not fallen short of.
6.4 Insofar as hosting, infrastructure, or AI service providers are used within the framework of data processing, the Processor ensures that appropriate data protection agreements exist with these – insofar as necessary. For Google Cloud, Google provides a Cloud Data Processing Addendum. Google also publishes current Google Cloud Subprocessors separately.
6.5 Insofar as Google Cloud Vertex AI / Gemini is used on behalf, this is done in accordance with the respectively configured cloud and security architecture. Google documents for Vertex AI, among other things, conditions for data retention, limited retention scenarios, and configurations for reducing or avoiding retention.
7. Support Obligations of the Processor
7.1 The Processor supports the Controller within the scope of what is reasonable in the fulfillment of requests from data subjects according to Chapter III GDPR, insofar as the Controller cannot fulfill its obligations itself with reasonable effort.
7.2 The Processor supports the Controller, taking into account the nature of the processing and the information available to it, in complying with the obligations under Art. 32 to 36 GDPR, in particular in connection with:
- Security of processing,
- Reporting of personal data breaches,
- Data protection impact assessments,
- Prior consultations with supervisory authorities.
7.3 Insofar as the Controller is obliged to provide information to data subjects and it is dependent on information from the Processor for this purpose, the Processor shall provide this information within the scope of what is reasonable.
8. Reporting of Data Breaches
8.1 The Processor informs the Controller immediately as soon as it becomes aware of a personal data breach affecting data that it processes on behalf of the Controller.
8.2 The notification shall be made with the information available to the Processor, in particular, as far as possible, regarding:
- Nature of the breach,
- Affected data categories,
- Affected groups of persons,
- Likely consequences,
- Remedial measures already taken or proposed.
8.3 The Processor will support the Controller within the scope of what is reasonable in the further clarification and treatment of the incident.
9. Subprocessors
9.1 The Controller grants the Processor general permission to use further processors (subprocessors), provided that the requirements of this DPA and Art. 28 GDPR are complied with.
9.2 The subprocessors used at the time of the conclusion of the contract result from Annex 3.
9.3 The Processor will inform the Controller of intended changes regarding the addition or replacement of subprocessors in text form.
9.4 The Controller may object to such changes within 14 calendar days after receipt of the information in text form for an important data protection reason.
9.5 If the Controller does not object in a timely manner, the change shall be deemed approved.
9.6 If the Controller objects in a timely manner and the further provision of services without the affected subprocessor is not possible for the Processor or not possible under reasonable conditions, the Processor may restrict the affected service or terminate the main contract or the affected part of the service with a reasonable period of notice.
9.7 The Processor will only involve subprocessors on the basis of a contract that imposes essentially the same data protection obligations on them as are provided for in this DPA.
10. Third-Country Processing
10.1 Processing of personal data outside the European Union or the European Economic Area only takes place insofar as this is contractually provided for, instructed by the Controller, or permissible under data protection law.
10.2 Insofar as the Processor or a subprocessor processes data outside the EEA, the Processor ensures that there is a permissible data protection basis for this, in particular an adequacy decision or appropriate guarantees.
10.3 Insofar as Google Cloud / Vertex AI / Speech-to-Text are used for processing on behalf, the specific region, configuration, and data protection classification must be documented in the respective appendix, in the service description, or in the technical documentation. Google provides cloud data protection documents, subprocessor information, and product-specific documentation for this purpose.
11. Verification and Audit Rights
11.1 The Processor provides the Controller with the information necessary to prove compliance with the obligations laid down in Art. 28 GDPR upon request.
11.2 The Controller is entitled to carry out audits or inspections after reasonable prior notice and taking into account the confidentiality and security interests of the Processor, or to have them carried out by independent auditors committed to confidentiality.
11.3 Audits are to be restricted to the necessary extent and must not unreasonably impair the business operations of the Processor.
11.4 The Processor can also fulfill the fulfillment of verification obligations by appropriate current verifications, certifications, audit reports, certificates, security documentations, or comparable documents, insofar as these are sufficient for appropriate verification.
11.5 Insofar as the effort of an audit or support exceeds the usual and legally owed measure, the Processor can demand appropriate compensation for this, provided that it points this out to the Controller in advance.
12. Return and Erasure after End of Contract
12.1 After termination of the contractual services, the Processor will, at the choice of the Controller, either erase or return the personal data processed on behalf, unless there is a legal obligation to store it.
12.2 Statutory retention obligations, legitimate interests in providing evidence, and technically required backup and recovery cycles remain unaffected. In these cases, the relevant data will be blocked for other purposes and only kept to the extent legally required.
12.3 The Controller is responsible for exporting or otherwise securing data and content in good time before the end of the contract, insofar as export or retrieval functions are provided or an export is technically reasonably possible.
13. Liability and Relationship to the Main Contract
13.1 For the liability of the parties, the main contract applies supplementarily, insofar as this DPA does not contain a more specific regulation and insofar as this is permissible under data protection law.
13.2 Statutory liability regulations, in particular from Art. 82 GDPR, remain unaffected.
14. Final Provisions
14.1 Changes and supplements to this DPA must be at least in text form, unless a stricter form is prescribed by law.
14.2 Should individual provisions of this DPA be or become invalid in whole or in part, the validity of the remaining provisions shall remain unaffected.
14.3 In all other respects, the provisions of the main contract shall apply.
14.4 This DPA enters into force upon conclusion of the main contract or upon commencement of the order-related processing.
Annex 1 – Description of Processing
1. Subject Matter of Processing
Provision and execution of the SaaS services of ImmoVision AI booked by the Controller.
2. Nature of Processing
Collecting, recording, storing, organizing, structuring, ordering, reading out, using, disclosing by transmission within the framework of service provision, providing, matching, linking, restricting, erasing, and destroying personal data, insofar as this is necessary for the contractually agreed services.
3. Purpose of Processing
Processing of personal data of the Controller for the provision of ImmoVision AI, in particular for:
- Lead capture and lead processing,
- CRM, dashboard, and workflow functions,
- Exposé and microsite management,
- Object and media management,
- User accounts and roles management,
- Appointment and communication functions,
- AI-supported functions, insofar as these are used on behalf of the Controller,
- Image processing, virtual staging, and media outputs,
- Transcription, summarization, and workflow processes,
- Technical storage, hosting, output, and management of client-side content and data,
- Billing-relevant usage events, insofar as these concern order-related data or processes.
4. Categories of Data Subjects
Depending on use, in particular:
- Prospects,
- Customers of the Controller,
- Users and employees of the Controller,
- Contact persons,
- Other persons whose data the Controller processes within the framework of the platform.
5. Categories of Personal Data
Depending on use, in particular:
- Master data,
- Contact details,
- Communication data,
- Object and process data,
- User account data,
- Role and authorization data,
- Appointment and status data,
- Content from forms, exposés, microsites, or CRM entries,
- Uploaded media and associated metadata,
- Audio content, transcripts, and structured information derived therefrom, insofar as corresponding functions are used,
- Technical usage and protocol data, insofar as these serve the order-related provision.
6. Special Categories of Personal Data
Processing of special categories of personal data within the meaning of Art. 9 GDPR is generally not intended. Insofar as the Controller nevertheless processes or uploads such data, it remains responsible for its admissibility and any special protection requirements.
7. Duration of Processing
For the duration of the main contract and beyond that only insofar as statutory retention obligations, legitimate interests in providing evidence, or technically required backup cycles require this.
Annex 2 – Technical and Organizational Measures (TOMs)
The Processor implements appropriate technical and organizational measures according to Art. 32 GDPR. These include in particular, insofar as respectively relevant:
- Access control to server, hosting, and administration environments,
- Access control through authentication and authorization concepts,
- Access control according to the role and rights principle,
- Transport encryption,
- Password hashing and secure authentication procedures,
- Logging of security-relevant processes,
- Data backup and recovery concepts,
- Separation of tenants and roles, insofar as provided by the system,
- Measures to ensure confidentiality, integrity, availability, and resilience,
- Procedures for regular review, assessment, and evaluation of the effectiveness of security measures,
- Processes for handling security incidents and data breaches,
- Restriction of administrative access,
- Secure development, maintenance, and updating of the systems used,
- Careful selection and contractual binding of subprocessors.
Insofar as hosting services are provided via Hetzner, the TOMs agreed with Hetzner and the currently valid technical documentation of the product used apply supplementarily.
Insofar as Google Cloud / Vertex AI / Gemini / Speech-to-Text are used, the security and data protection measures agreed in the respective cloud and contract configuration apply supplementarily. Google refers in this regard to its Cloud Data Processing Addendum, its subprocessor documentation, and product-specific security and retention notes.
Annex 3 – Subprocessors
Subprocessors used or intended at the time of the conclusion of the contract can be in particular:
1. Hetzner Online GmbH
Service: Hosting, server, storage, and infrastructure services
Processing Location: Germany / European Union, depending on the booked infrastructure
Role: Subprocessor, insofar as personal data is processed on behalf
2. Google Cloud / Google Cloud Platform / Vertex AI
Service: Cloud, AI, and transcription infrastructure, in particular insofar as Google Cloud, Vertex AI, Gemini, or Speech-to-Text are used for order-related processing
Processing Location: Depending on the booked region / configuration
Role: Subprocessor, insofar as personal data is processed on behalf
3. Further technical subprocessors
Service: Security, support, communication, storage, dispatch, monitoring, or integration services
Processing Location: Depending on the service provider
Role: Subprocessor, insofar as personal data is processed on behalf
Service providers or processing operations in which ImmoVision or the respective third-party provider is independently responsible are not considered subprocessors within the framework of this DPA, in particular in the area of: establishment, execution, and billing of the contractual relationship, payment processing, fraud prevention, own compliance and legal purposes, own security and abuse prevention purposes. This can in particular concern Stripe, insofar as Stripe acts independently responsibly in connection with payment processing, fraud prevention, or regulatory obligations.