dpa
Version 3.2 (Final) • Effective Date: September 25, 2026 • Viewnamic (Dreher, Weiß GbR)
This Data Processing Addendum ("DPA" or "Agreement") governs the processing of personal data in connection with the provision and use of the Viewnamic platform and constitutes an integral component of the Viewnamic Terms of Service ("Principal Agreement").
BETWEEN:
The Customer subscribing to or utilizing the services of Viewnamic (hereinafter referred to as "Controller" or "Customer"),
AND:
Dreher, Weiß GbR, Oeynhauser Weg 28, 33100 Paderborn, Germany, represented by the partners Felix Dreher and Daniel Weiß, VAT ID: DE303700917, Email: info@viewnamic.com (hereinafter referred to as "Processor" or "Viewnamic"),
individually referred to as a "Party" and collectively as the "Parties".
Section 1: Scope, Statutory Roles, and Purpose of Processing
(1) Scope: This DPA specifies the data protection rights and obligations of the Parties pursuant to Article 28 of Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR) whenever Viewnamic processes personal data on behalf of the Customer in the context of providing the digital publishing software, web viewer, hosting infrastructure, and viewer interaction analytics.
(2) Statutory Roles: The Customer acts as the Data Controller within the meaning of Art. 4 No. 7 GDPR, determining the purposes and means of processing Customer Content. Viewnamic acts strictly as a Data Processor within the meaning of Art. 4 No. 8 GDPR.
(3) Independent Operations: Processing activities where Viewnamic determines the purposes and means independently—specifically the administration of Customer corporate accounts, billing execution, and primary website security logs—are conducted under Viewnamic's own responsibility as an independent controller and are governed by Viewnamic's Privacy Policy.
Section 2: Scope, Nature, and Duration of Processing
(1) Nature and Purpose: Viewnamic processes personal data exclusively to provide the software functionalities under the Principal Agreement, specifically: storing and delivering uploaded PDF documents, overlaying interactive multimedia elements, hosting and serving digital publications via project URLs or embeds, administering access restrictions (passwords/links), providing public kiosk overview pages, generating aggregated viewer interaction analytics, and executing data backups.
(2) Duration: The processing shall endure for the term of the Principal Agreement plus the technical grace period and statutory retention cycles defined in Section 9 of this DPA.
Section 3: Categories of Data Subjects and Types of Personal Data
(1) Categories of Data Subjects: Depending on the files and media uploaded by the Customer, data subjects may include: Customer employees, representatives, authors, photographers, contractors, business partners, subjects depicted or identified in documents, and readers or visitors viewing published documents.
(2) Types of Personal Data:
- Customer Content: Personal data contained within uploaded PDF files, images, videos, or multimedia assets (names, contact details, biographical information, portraits, corporate collateral).
- Sharing and Access Telemetry: Recipient identifiers, access credentials, and document authorization status for protected links.
- Viewer Interaction Data: Non-identifying session telemetry including randomized project-specific session IDs, pages viewed, scroll depth, viewing durations, interaction timestamps, video/multimedia interaction events, external link clicks, and download requests.
- Technical Telemetry: Ephemeral connection logs, browser family, operating system, and device category.
(3) IP Addresses: Complete IP addresses are processed in volatile memory solely for network transmission and real-time security defense. Complete IP addresses are not permanently stored as a queryable metric in the document interaction analytics database.
(4) Special Categories of Data: Viewnamic's service is not designed for the intentional processing of special categories of personal data pursuant to Art. 9 GDPR. The Customer bears sole responsibility for ensuring a lawful statutory legal basis if Customer Content contains such sensitive data.
Section 4: Instructions of the Controller
(1) Documented Instructions: Viewnamic shall process personal data solely on documented instructions from the Customer, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law to which Viewnamic is subject. The configurations selected by the Customer within the software dashboard and the Principal Agreement constitute complete documented instructions.
(2) Notification of Unlawful Instructions: Viewnamic shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
Section 5: Confidentiality and Personnel Obligations
(1) Confidentiality: Viewnamic ensures that persons authorized to process the personal data (including partners, employees, and contracted personnel) have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
(2) Need-to-Know Principle: Access to Customer personal data is restricted strictly to authorized individuals who require such access for the technical execution and support of the platform services.
Section 6: Technical and Organizational Measures (TOMs)
(1) Implementation of Security: Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Viewnamic implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk pursuant to Art. 32 GDPR.
(2) Specification: The technical and organizational measures currently implemented are specified in detail in Annex 1 to this Agreement.
(3) Security Evolution: The Customer acknowledges that technical measures are subject to continuous technical progress. Viewnamic is permitted to update and modify security measures provided that the agreed security standard is not degraded.
Section 7: Sub-processors (Unterauftragsverarbeiter)
(1) General Authorization: The Customer grants Viewnamic general written authorization to engage sub-processors to perform infrastructure, hosting, security, and communication functions necessary for platform operation. The sub-processors approved upon execution are listed in Annex 2.
(2) Notification of Changes: Viewnamic shall notify the Customer of any intended changes concerning the addition or replacement of other sub-processors at least fourteen (14) days prior to engagement via email or through the user administration portal, thereby giving the Customer the opportunity to object to such changes.
(3) Objection: The Customer may object to a new sub-processor on reasonable data protection grounds within fourteen (14) days of notification. If no mutually agreeable solution is achieved, either Party may terminate the affected service under reasonable notice.
(4) Contractual Flow-Down: Where Viewnamic engages a sub-processor, Viewnamic imposes data protection obligations no less protective than those set out in this DPA by way of a binding contract pursuant to Art. 28(4) GDPR.
Section 8: Assistance with Data Subject Rights and Incident Management
(1) Data Subject Rights: Taking into account the nature of the processing, Viewnamic shall assist the Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III GDPR (e.g., access, rectification, erasure, restriction, objection).
(2) Direct Inquiries: If a data subject addresses a request directly to Viewnamic regarding Customer Content, Viewnamic shall forward such request to the Customer without undue delay.
(3) Breach Notification: Viewnamic shall notify the Customer in text form without undue delay (and no later than 48 hours) upon becoming aware of a confirmed personal data breach affecting Customer data processed under this DPA. Viewnamic shall provide reasonable assistance to the Customer in complying with its reporting obligations under Articles 33 and 34 GDPR.
Section 9: Deletion, Return, and Data Retention
(1) Termination of Services: Following the termination of the Principal Agreement, Viewnamic maintains Customer assets and configurations in a deactivated state for a grace period of thirty (30) calendar days to permit the Customer to export or reactivate their projects.
(2) Permanent Deletion: After the 30-day grace period has elapsed, Viewnamic shall permanently delete all Customer files, uploaded media, and associated configuration data from active production databases, unless Union or Member State law requires storage of the personal data.
(3) Viewer Analytics Retention: Detailed session-level document analytics data is retained for a maximum duration of twelve (12) months. Thereafter, detailed session telemetry is permanently deleted or irreversibly aggregated into non-identifying statistical sums.
(4) Backup Overwrite: Data archived in automated off-site disaster recovery backups shall be overwritten and permanently purged in accordance with standard automated backup rotation schedules.
Section 10: Audits and Demonstrating Compliance
(1) Compliance Documentation: Viewnamic shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR.
(2) Audits: Viewnamic shall allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer. Audits shall be agreed upon with at least fourteen (14) business days prior written notice, conducted during normal business hours, and executed without unreasonably disrupting platform operations or breaching third-party confidentiality. Existing audit certificates, third-party certifications, or self-assessment questionnaires may be utilized to satisfy audit inquiries.
Section 11: Final Provisions
(1) Hierarchy: In case of contradictions between this DPA and the Principal Agreement (Terms of Service), the provisions of this DPA shall take precedence regarding data processing obligations under Art. 28 GDPR.
(2) Electronic Form: This Agreement is concluded electronically upon the Customer's registration or subscription acceptance of the Terms of Service pursuant to Art. 28(9) GDPR, or by mutual signature in writing.
ANNEX 1: Technical and Organizational Measures (TOMs) pursuant to Art. 32 GDPR
Viewnamic implements and maintains the following technical and organizational security measures:
- Physical Access Control (Zutrittskontrolle): Production servers are hosted in ISO/IEC 27001-certified high-security data centers operated by IONOS SE in Germany. Multi-factor physical security controls, electronic badge access, 24/7 video surveillance, and perimeter alarms at all data center facilities.
- System Access Control (Zugangskontrolle): Modern user authentication with salted and hashed passwords (bcrypt/Argon2). Optional secure OAuth 2.0 Single Sign-On via Google and Microsoft. Cloudflare Turnstile bot and brute-force mitigation on authentication endpoints. Two-Factor Authentication (2FA) enforced on administrative server and cloud console accounts.
- Data Access & Authorization Control (Zugriffskontrolle): Strict role-based access control (RBAC); customers have access exclusively to their own project assets and user workspaces. Logical database separation preventing cross-tenant data access. Administrative access restricted strictly to authorized founders/developers via encrypted SSH keys.
- Transmission Control (Übertragungskontrolle): Compulsory end-to-end transport encryption via modern TLS (TLS 1.2 / TLS 1.3) with HTTPS enforcement and HSTS. Encrypted database connections and API token management. Payment data processed directly via PCI-DSS Level 1 certified gateways (Stripe); Viewnamic never captures or stores credit card numbers.
- Input Control (Eingabekontrolle): Comprehensive technical logging of administrative changes, deployment events, and system errors. Security audit trails protected against unauthorized tampering.
- Availability & Disaster Recovery (Verfügbarkeitskontrolle): Automated regular off-site database and snapshot backups via UpdraftPlus to dedicated, access-restricted Google Cloud / Google Drive storage. Daily snapshot rotations with rapid restoration procedures and continuous disaster recovery planning. High-availability infrastructure with redundant power supply, fire detection, and cooling systems in data centers.
- Data Minimization and Privacy by Design (Art. 25 GDPR): No persistent storage of full IP addresses in document analytics databases. Randomized session identifiers for viewer analytics that expire after document interaction. Fixed 12-month retention period for detailed interaction logs followed by automated aggregation or deletion. Absence of third-party commercial advertising trackers or cross-site profiling cookies in the document viewer.
ANNEX 2: Authorized Sub-processors
The Controller approves the engagement of the following sub-processors as of the Effective Date:
| Sub-processor | Purpose & Service | Location | Data Transfer Safeguards |
|---|---|---|---|
| IONOS SE Elgendorfer Str. 57, 56410 Montabaur, Germany | Primary web hosting, server infrastructure, application hosting, and live database storage | Germany / EU | Data Processing Agreement pursuant to Art. 28 GDPR |
| Cloudflare, Inc. 101 Townsend St., San Francisco, CA 94107, USA | Bot mitigation, anti-abuse, spam protection (Cloudflare Turnstile), and CDN edge security | EU / USA | Data Processing Addendum incorporating EU Standard Contractual Clauses (SCCs) & EU-U.S. Data Privacy Framework (DPF) |
| Google Ireland Limited / Google LLC Gordon House, Dublin 4, Ireland / Mountain View, CA, USA | Automated off-site disaster recovery backups (Google Cloud Storage / Google Drive via UpdraftPlus) | EU / USA | Data Processing Agreement & EU-U.S. Data Privacy Framework (DPF) |
| Sendinblue GmbH (Brevo) Köpenicker Str. 126, 10179 Berlin, Germany | Transactional system emails (registration, password recovery, billing notifications) | Germany / EU | Data Processing Agreement pursuant to Art. 28 GDPR |
