Data Processing Agreement under Art. 28 GDPR
This data processing agreement applies to the hosted Mark-a-Spot service provided by Civic Patches GmbH and forms part of the principal agreement for the issue management service.
A signed copy of this agreement can be requested from Civic Patches GmbH.
This data processing agreement is provided in English and German. The English version below is binding for international customers.
Processor
This platform is technically operated by:
Civic Patches GmbH
Pingsdorfer Straße 88-92, 50321 Brühl, Germany
Email: info@civicpatches.de
Civic Patches GmbH provides the technical infrastructure for the Mark-a-Spot platform.
Controller
The controller is the operator of the respective map:
Berlin
Civic Patches GmbH, Pingsdorfer Straße 88-92, 50321 Brühl
Email: info@civic-patches.com
1. Subject matter and duration
The processor processes personal data on behalf of the controller solely to provide the services agreed in the principal agreement, including operation, maintenance, and support of the issue management service. The subject matter, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are described below.
The term of this agreement corresponds to the term of the principal agreement. It ends automatically when the principal agreement ends, without prejudice to continuing duties concerning deletion or return of data.
2. Nature and purpose of processing
Processing serves the receipt and handling of reports from residents, status communication, and analysis. It comprises the following operations:
- Collection of reports and associated information.
- Storage, display, and modification of report and case data.
- Transmission through agreed interfaces and communications.
- Deletion in accordance with the principal agreement and documented instructions.
3. Types of data and categories of data subjects
The following types of personal data may be processed:
- Location data relating to reports.
- Photographs that may contain personal data and free-text descriptions.
- Optional contact details of reporting persons.
- Case and processing data, and contact details of responsible staff, including name, email address, and username.
The categories of data subjects are:
- Residents and other persons submitting reports.
- Third parties who may be depicted or mentioned in a report.
- Employees and other authorised users handling reports for the controller.
4. Documented instructions
The processor processes personal data only on documented instructions from the controller, including the processing specified in this agreement and the principal agreement. Instructions are normally documented through the channels described in the service and support arrangements. If the processor considers an instruction unlawful, it informs the controller without undue delay.
5. Obligations of the processor
- Only persons committed to confidentiality are authorised to process personal data.
- The processor implements the measures required by Art. 32 GDPR in accordance with the technical and organisational measures below.
- The processor notifies the controller of a personal data breach without undue delay after becoming aware of it so that the controller can meet its obligations under Arts. 33 and 34 GDPR.
- The processor designates a contact person for data protection matters and provides the information required to demonstrate compliance with this agreement.
6. Technical and organisational measures
The measures are based on the data protection concept and the processor information for AI processing. They include in particular:
- Encryption in transit using TLS.
- Role-based access control and separation of tenants and organisations.
- Removal of personal contact data, including email addresses, telephone numbers, and IBANs, from text before any AI processing.
- Automatic anonymisation of faces and vehicle registration plates in accordance with the configuration agreed in the principal agreement. Extended name recognition can optionally be enabled per instance. Pre-processing is self-hosted in Germany.
- Logging in accordance with the data minimisation principle.
- Regular data backups.
- Operation in a German data centre certified to ISO/IEC 27001 and audited against BSI C5. The current hosting provider is Hetzner.
7. Sub-processors and international transfers
- The controller grants general authorisation for the engagement of sub-processors.
- The processor informs the controller of intended additions or replacements. The controller may object on reasonable data protection grounds.
- The processor imposes on each sub-processor the same data protection obligations set out in this agreement, as required by Art. 28(4) GDPR.
- Processing outside the EU or EEA takes place only where the requirements of Arts. 44 et seq. GDPR are met, in particular through standard contractual clauses where applicable. Optional AI processing takes place in the EU data zone, with the resource in Germany West Central.
View the current list of sub-processors
8. Data subject rights and regulatory assistance
Taking into account the nature of the processing, the processor assists the controller through appropriate technical and organisational measures in responding to requests under Arts. 12 to 23 GDPR. It also assists with the controller's obligations under Arts. 32 to 36 GDPR, including security, breach notifications, data protection impact assessments, and prior consultation.
9. Deletion and return
After completion of the services, the processor deletes or returns the personal data at the controller's choice, unless Union or Member State law requires storage.
The open and transferable basis of the service, including the GPL-licensed backend and the complete configuration and data in the project repository, facilitates return and migration without vendor lock-in.
10. Evidence and audits
The processor makes available all information necessary to demonstrate compliance and permits and contributes to audits, including inspections, conducted by the controller or an auditor mandated by the controller in accordance with Art. 28(3)(h) GDPR.
11. Liability
Liability is governed by the principal agreement and applicable law, in particular Art. 82 GDPR.
12. Final provisions
Amendments must be made in text form. If any provision is or becomes ineffective, the remaining provisions remain unaffected.
German law applies.
Version 2026-06-07, published 2 September 2026.