This is a translation for information only. Only the German version is legally binding. Deutsch
Data Processing Agreement
Draft – to be legally reviewed before launch.
between the studio that uses Pioqor (controller, “studio”) and Bheppo GmbH (Pioqor), Kleine Reichenstraße 5, 20457 Hamburg, Germany (processor, “we”).
This agreement is concluded by confirmation during registration or in the app and forms part of the contract of use under our terms. The time and version of the confirmation are stored. This satisfies the form requirement of Art. 28 (9) GDPR (electronic format).
§ 1 Subject matter and duration
- We process personal data on behalf of the studio in order to provide Pioqor as software (hosting, storage, technical processing, support).
- The agreement applies for the term of the contract of use, including the trial, and beyond that for as long as we process data of the studio.
§ 2 Nature and purpose of processing, data and data subjects
- Nature and purpose: collecting, storing, organising, displaying, changing, transmitting (for example sending login emails) and deleting data, exclusively to provide the functions of Pioqor to the studio.
- Categories of data subjects: clients of the studio (including prospective clients and legal guardians), staff, artists and guest artists, persons on contact lists uploaded by the studio.
- Types of data:
- Master and contact data: name, phone number, email address, language, date of birth
- Appointment and service data: appointments, services, notes, gift cards
- Payment and accounting data within the studio: amounts, deposits, payment methods, settlements with artists
- Consent and registration forms including health information (special categories under Art. 9 GDPR), where the studio asks for it
- Communication data: contact and marketing consents, campaign status
- User data of staff: name, email, role, working hours, stock withdrawals
- Technical data: timestamps, log data
§ 3 Instructions
- We process the data only on documented instructions from the studio. The instructions result from this agreement, the terms and the use of the functions of Pioqor. The studio gives further instructions in text form to kontakt@pioqor.com.
- If processing is required by law, we inform the studio beforehand, unless the law prohibits this.
- If we consider an instruction to be unlawful, we inform the studio without delay and may suspend its execution until it is confirmed.
§ 4 Confidentiality
All persons who have access to the data on our side are bound to confidentiality or are subject to a statutory duty of secrecy. We access the studio’s data only insofar as this is necessary for operation, troubleshooting or at the studio’s request (support).
§ 5 Security of processing
We take the technical and organisational measures under Art. 32 GDPR described in Annex 1. We may develop them further as long as the level of protection is not reduced.
§ 6 Sub-processors
- The studio gives general authorisation to engage sub-processors. The sub-processors engaged when the agreement is concluded are listed in Annex 2 and are deemed approved.
- We inform the studio of intended changes at least 30 days in advance, in text form or in the app. The studio may object for an important data protection reason. If we cannot remedy the objection, the studio may terminate the contract as of the date of the change.
- We contractually bind sub-processors to data protection obligations that correspond to this agreement.
- Processing outside the EU / EEA or by providers based in third countries only takes place if the requirements of Art. 44 et seq. GDPR are met, for example by an adequacy decision (EU-US Data Privacy Framework) or EU standard contractual clauses.
§ 7 Support for the studio
- We support the studio with appropriate measures in responding to requests from data subjects (Art. 15 to 22 GDPR). The studio can implement many rights directly in Pioqor, for example viewing, correcting or deleting data. If a request reaches us directly, we forward it to the studio.
- We support the studio in its obligations under Art. 32 to 36 GDPR (security, notification of personal data breaches, data protection impact assessment, prior consultation).
§ 8 Personal data breaches
We inform the studio without delay, if possible within 24 hours, after becoming aware of a breach of the protection of its personal data. The notification contains, as far as known, the information under Art. 33 (3) GDPR. We take measures without delay to remedy the breach and mitigate its consequences.
§ 9 Deletion and return
- After the end of the contract, the studio can request a copy of its data in a common, machine-readable format within 30 days.
- We then delete all data of the studio within a further 60 days at the latest, unless there is a statutory obligation to store it. Data in backups is overwritten in the regular backup cycle.
- On request we confirm the deletion in text form.
§ 10 Evidence and audits
On request we provide the studio with the information necessary to demonstrate compliance with this agreement, in particular the current description of the measures and the certifications of our sub-processors. On-site audits are possible after timely notice, during usual business hours and without disrupting operations; the resulting effort may be charged at a reasonable rate.
§ 11 Liability and final provisions
- Liability is governed by Art. 82 GDPR. Otherwise the liability rules of the terms apply.
- In the event of contradictions between this agreement and other agreements, this agreement takes precedence in matters of data protection.
- German law applies. The contract language is German; translations are for information only.
Annex 1 – Technical and organisational measures
Confidentiality
- Data centres of the sub-processors with access control and certifications (including ISO 27001 / SOC 2); we do not operate our own servers.
- Access to Pioqor only with a personal account; passwords are stored only as a hash.
- Role and permission concept in the app (admin, manager, artist, guest); artists only see what their role allows.
- Strict tenant separation: every database query is limited to the studio’s own data by row level security policies.
- Administrative access to the database, hosting and payment service only for the provider’s managing directors, with two-factor authentication.
Integrity
- Encrypted transmission of all data (TLS / HTTPS).
- Encryption of stored data at the hosting provider (AES-256).
- Public forms (for example self-registration) only work through narrowly limited functions with rate limits and have no read access to other data.
- Software changes are tested before release; database changes are versioned.
Availability and resilience
- Daily automatic backup of the database.
- Delivery of the app through a globally distributed network with protection against overload attacks.
Review procedure
- Regular review of the measures and sub-processors, at least once a year.
- Privacy-friendly defaults: no tracking or advertising cookies, no analytics tools, fonts and libraries served from our own server.
Annex 2 – Sub-processors
| Provider | Service | Place of processing | Basis for third-country transfer |
|---|---|---|---|
| Supabase, Inc., USA | Database, login, server functions | Frankfurt am Main (EU) | EU standard contractual clauses |
| Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA | Delivery of website and app, protection against attacks, email forwarding | globally distributed network | EU-US Data Privacy Framework, EU standard contractual clauses |
| Plus Five Five, Inc. (Resend), USA | Sending system emails (login, password, invitations) | Ireland (EU) | EU-US Data Privacy Framework, EU standard contractual clauses |
Stripe is not a sub-processor for the data of the studio’s clients: only payment and invoicing of the Pioqor subscription run through Stripe, and Stripe acts as an independent controller.