This is a convenience translation. Only the German version is legally binding.
This data processing agreement pursuant to Art. 28 GDPR ("DPA", German: Auftragsverarbeitungsvertrag – AVV) applies to entrepreneurs (Unternehmer, § 14 BGB – German Civil Code) who use Macreto and have personal data processed for which they themselves are responsible – for example recordings in which employees, customers or other persons can be seen or heard.
Parties and conclusion
Controller ("Client", Auftraggeber): the entrepreneur who uses Macreto (customer).
Processor ("Contractor", Auftragnehmer): Hees & Rosenbusch CodeLabs GbR, owner Oliver Hees, Alina Rosenbusch, Das Ortfeld 7, 21394 Westergellersen, e-mail: info@hr-codelabs.de.
This DPA becomes part of the user agreement when the customer, as an entrepreneur, agrees to the Terms and Conditions during registration or booking or accepts the DPA in the account settings. It is concluded in electronic format (Art. 28(9) GDPR). On request, we will provide a countersigned version as a PDF.
§ 1 Subject matter and duration
(1) The subject matter is the processing of personal data by the Contractor on behalf of the Client in the provision of the services described in the Terms and Conditions (Macreto: storage, transcription, AI analysis, editing and creation of videos and accompanying content and – on instruction – publication via connected social media accounts).
(2) The term of this DPA corresponds to the term of the user agreement. It ends with the deletion of all processing data in accordance with § 9.
§ 2 Nature, purpose and scope of processing
(1) Nature of processing: collection (upload), storage, transcription, analysis, editing (cutting, compilation), transfer to sub-processors, provision for retrieval, publication on instruction, deletion.
(2) Purpose: exclusively the provision of the contractual services to the Client.
(3) Types of personal data:
- image and video recordings of persons (appearance, facial expressions, surroundings);
- voice and audio recordings, transcripts created from them;
- data visible on screen recordings (e.g. names, e-mail addresses, user names, application content);
- information contained in project details, scripts, titles, descriptions and social media posts;
- access credentials (tokens) and identifiers of the Client's connected social media accounts.
The processing of special categories of personal data (Art. 9 GDPR) is not the subject matter of this agreement. The Client ensures that such data is only uploaded if it has a legal basis for doing so. No biometric analysis for the unique identification of persons takes place.
(4) Categories of data subjects: the Client itself or its employees and agents, third parties identifiable in recordings (e.g. guests, customers, interviewees), persons whose data is visible on screen recordings.
§ 3 Instructions of the Client
(1) The Contractor processes the data only on documented instructions from the Client, unless it is required to do so by Union or Member State law; in that case, the Contractor informs the Client of that legal requirement before processing, unless that law prohibits such information (Art. 28(3)(a) GDPR).
(2) The instructions are conclusively set out in the Terms and Conditions, this DPA and the Client's use of Macreto's functions (e.g. upload, starting the analysis, correction requests, approval, scheduling a publication, deletion). The Client issues further instructions in text form to info@hr-codelabs.de. Instructions that go beyond the contractual scope of services may be remunerated separately.
(3) If the Contractor is of the opinion that an instruction infringes data protection provisions, it informs the Client without undue delay. It may suspend execution of the instruction until the Client confirms or amends it.
§ 4 Obligations of the Contractor
(1) The Contractor ensures that all persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR).
(2) The Contractor takes the technical and organisational measures pursuant to Art. 32 GDPR described in Annex 1. It may develop them further provided that the level of protection is not reduced. It documents material changes.
(3) Taking into account the nature of the processing, the Contractor assists the Client, insofar as possible, by appropriate technical and organisational measures in fulfilling the rights of data subjects (Art. 12 to 22 GDPR). For this purpose, the Client has access in particular to functions for deleting projects, exporting and deleting the account. If a data subject contacts the Contractor directly, the Contractor forwards the request to the Client without undue delay.
(4) Taking into account the nature of the processing and the information available to it, the Contractor assists the Client in complying with the obligations under Art. 32 to 36 GDPR (security, notification of personal data breaches, data protection impact assessment, prior consultation).
(5) Personal data breaches: The Contractor notifies the Client of personal data breaches affecting processing data without undue delay, where possible within 48 hours of becoming aware of them, by e-mail to the address stored in the customer account. The notification contains, insofar as known, the information pursuant to Art. 33(3) GDPR; missing information will be provided subsequently.
(6) The Contractor does not process the processing data for its own purposes, in particular not for advertising purposes, as a reference or for training its own AI models. The creation of anonymised usage statistics that cannot be traced back to persons or the Client (e.g. number of videos, processing time) for improving and billing the service remains permissible.
(7) The Contractor has not appointed a data protection officer, as it is not obliged to do so. Contact person for data protection: Oliver Hees, Alina Rosenbusch, info@hr-codelabs.de.
§ 5 Obligations of the Client
(1) The Client is responsible for the lawfulness of the processing, in particular for the existence of a legal basis (e.g. consent of the persons recorded), and for safeguarding the rights of data subjects.
(2) It informs the Contractor without undue delay if it detects errors or irregularities in the processing.
(3) It is responsible for the publication of content; upon publication (including via auto-posting), the data leaves the Contractor's area of responsibility.
§ 6 Sub-processors
(1) The Client grants general authorisation to engage other processors (sub-processors, Unterauftragsverarbeiter). The sub-processors engaged at the time the agreement is concluded are listed at https://app.macreto.com/unterauftragsverarbeiter and are deemed approved.
(2) The Contractor informs the Client by e-mail at least four weeks before adding or replacing a sub-processor. Within this period, the Client may object in text form for an important reason relating to data protection law. If the parties cannot reach an agreement, the Client may terminate the user agreement extraordinarily with effect from the time of the change; fees already paid in advance for the period thereafter will be refunded pro rata. In urgent cases (e.g. failure of a service provider, security reasons), the period may be shortened.
(3) The Contractor contractually obliges sub-processors to comply with data protection obligations that essentially correspond to those of this DPA (Art. 28(4) GDPR). It is liable to the Client for the sub-processor's compliance with its obligations.
(4) A transfer to third countries only takes place if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision (e.g. EU-US Data Privacy Framework) or EU Standard Contractual Clauses.
(5) Ancillary services such as telecommunications services, postal and transport services or hardware maintenance, in which no processing data is processed, do not constitute sub-processing within the meaning of this section. Nor are the social media platforms on which the Client publishes content sub-processors of the Contractor; the Client has its own contractual relationship with them.
§ 7 Evidence and audits
(1) On request, the Contractor makes available to the Client all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR, in particular a current description of the TOMs (technical and organisational measures) and evidence regarding the sub-processors (e.g. certificates such as ISO 27001 of the data centre operator).
(2) The Client is entitled to carry out audits, including inspections, itself or through an auditor bound to confidentiality who is not a competitor of the Contractor. Inspections must be announced with reasonable notice (as a rule four weeks), carried out during normal business hours and must not disproportionately disrupt operations. Data centres of sub-processors are generally audited via their certificates and audit reports. The Contractor may demand reasonable compensation for its expenses for inspections that exceed one per calendar year or are not prompted by a specific occasion (e.g. a personal data breach).
§ 8 Place of processing
The processing data is stored in data centres in Germany. Processing outside the EU or EEA only takes place with the sub-processors marked at https://app.macreto.com/unterauftragsverarbeiter and only in accordance with § 6(4).
§ 9 Deletion and return
(1) Raw data (uploaded recordings) is automatically deleted 30 days after the last activity in the respective project. Results are deleted when the Client deletes them, at the latest upon deletion of the account (backups up to 28 days). Until then, the Client can download its data via the export function (return).
(2) Database backups are retained for 28 days and then overwritten. Deletion in backups takes place upon their expiry.
(3) Statutory retention obligations remain unaffected; as a rule, they do not concern processing data.
(4) The Contractor confirms the deletion in text form on request.
§ 10 Liability and final provisions
(1) Art. 82 GDPR applies to liability. In the internal relationship, the liability rules of the Terms and Conditions apply, insofar as Art. 82 GDPR does not preclude this.
(2) In the event of contradictions, the provisions of this DPA take precedence over the Terms and Conditions insofar as the protection of personal data is concerned.
(3) Amendments to this DPA are made in accordance with the procedure provided for entrepreneurs in the Terms and Conditions. German law applies; the place of jurisdiction is, to the extent permissible, the Contractor's registered office.
(4) Should any provision be invalid, the remainder of the agreement remains valid.
Annex 1: Technical and organisational measures (Art. 32 GDPR)
Last updated: [STAND fehlt]
1. Confidentiality
Physical access control (data centre): The servers are located in data centres of Hetzner Online GmbH in Germany (Nuremberg/Falkenstein). Hetzner secures the data centres by means including an electronic access control system, video surveillance, security personnel and access only for authorised persons; the operator is certified to ISO/IEC 27001. The Contractor itself has no physical access.
System access control:
- administrative server access exclusively via SSH with keys (no password login), root login disabled;
- firewall; only required ports publicly accessible; database and internal services not publicly accessible;
- two-factor authentication for the accounts at Hetzner, Stripe, code hosting and all AI providers;
- user passwords are stored exclusively as a cryptographic hash (e.g. scrypt/Argon2, with salt);
- sessions via secure, HttpOnly cookies with limited lifetime.
Data access control:
- strict tenant separation: every request for projects, files and results is checked on the server side against the logged-in account; customers can only access their own data;
- files in object storage are not public; retrieval only takes place via time-limited, signed links;
- access by the Contractor to customer content only in individual cases, insofar as necessary for support, troubleshooting or abuse prevention;
- API keys and secrets are not stored in the source code but in protected environment variables.
Separation control: logical separation of customer data via account IDs; separate environments for development and production; test data is not real data.
Pseudonymisation / data minimisation: Only text prompts without personal reference are transmitted to providers for image, sound and music generation. Transcription locally on our own servers by default. Error monitoring and web analytics are self-hosted; web analytics without cookies and without storing IP addresses.
2. Integrity
Transfer control: All connections between users and Macreto as well as to service providers are TLS-encrypted (HTTPS, at least TLS 1.2). Transfers to sub-processors only via their encrypted APIs.
Input control: Logging of security-relevant events (logins, changes to account and subscription, deletions) and of the processing steps per project with timestamps. Server logs are retained for 14 days.
3. Availability and resilience
- daily automatic backup of the database; retention 28 days;
- raw data and results in the data centre operator's object storage with its redundancy;
- data centre with UPS, emergency power supply, air conditioning and fire protection (Hetzner);
- monitoring of services and errors (GlitchTip, self-hosted) with notification;
- regular security updates of the operating system and dependencies;
- restoration from backups is tested regularly.
4. Procedures for regular testing, assessment and evaluation
- Deletion concept: automatic deletion of raw data 30 days after the last activity in the project, of results upon deletion of the account, backups after 28 days, server logs after 14 days;
- review of the TOMs at least annually and in the event of material changes;
- the record of processing activities and the list of sub-processors are kept up to date;
- selection of service providers according to data protection and security criteria; conclusion of data processing agreements;
- data protection by default (Art. 25 GDPR): no publication without approval; auto-posting only after actively connecting an account;
- process for reporting and handling personal data breaches (detection, assessment, notification to the supervisory authority within 72 hours or to the Client without undue delay).
5. Processing control
Sub-processors are only engaged under an agreement pursuant to Art. 28 GDPR; a current list is published at https://app.macreto.com/unterauftragsverarbeiter.