Data Processing Agreement (Auftragsverarbeitung, Art. 28 GDPR)
Last updated: 11 June 2026
This Data Processing Agreement (“DPA”, German: Auftragsverarbeitungsvertrag / “AVV”) supplements the Terms of Service between David Miler (Einzelunternehmen, sole proprietorship), c/o IP-Management #6108, Ludwig-Erhard-Straße 18, 20459 Hamburg, Germany (“Processor”, “we”) and the business customer (“Controller”, “you”). It applies where, in providing the managed email service, we process personal data on your behalf within the meaning of Art. 4(8) and Art. 28 GDPR. Where it conflicts with the Terms on the subject of data processing, this DPA prevails.
It applies only to business customers (Controllers). For consumers and for the data we process as our own controller (your order, registrant, payment, and account data), our Privacy Policy applies instead.
1. Subject matter, nature and purpose
Subject matter: the provision of managed professional email hosting on your domain (creating and operating mailboxes, routing, storage, and the related DNS), as described in the Terms and the relevant product page. Nature and purpose of processing: hosting and transmitting email and associated data so that you can send, receive, and store messages. Processing is carried out only to provide that service and on your documented instructions.
2. Duration
This DPA runs for as long as we provide the managed email service to you and for any wind-down or export period agreed thereafter.
3. Type of personal data and categories of data subjects
Type of personal data: the contents of email messages and attachments, email addresses, names, and any other personal data that you or your correspondents include in messages or mailbox configuration. Special categories of data (Art. 9 GDPR) are not intended to be processed and should not be transmitted unless strictly necessary and lawful.
Categories of data subjects: your staff and mailbox users, your customers, suppliers, and any other persons who send mail to or receive mail from your mailboxes.
4. Controller’s instructions
We process the personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by Union or Member State law; in such a case we will inform you of that legal requirement before processing, unless the law prohibits it. Your instructions are set out in this DPA and the Terms; further instructions must be given in text form. We will inform you if, in our opinion, an instruction infringes the GDPR or other data-protection law.
5. Confidentiality
We ensure that persons authorized to process the personal data are bound to confidentiality and are instructed in their data-protection obligations. As set out in our Privacy Policy, we treat mailbox contents as confidential and access them only to provide, secure, repair, or migrate the service, to prevent or investigate abuse, or where required by law.
6. Security of processing (Art. 32 GDPR)
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as relevant: encryption of data in transit (TLS) and of stored credentials/secrets at rest; access controls and the principle of least privilege; network and platform security through our infrastructure providers; logging and monitoring; resilience and backup through our subprocessors; and regular review of these measures. Connection to mailboxes requires authentication over encrypted protocols only.
7. Subprocessors
You grant a general authorization for us to engage subprocessors to provide the service. We impose data-protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for their performance. The current subprocessors relevant to the managed email service are:
- Migadu (Migadu Email, Switzerland; mail servers in the EU) — email hosting (mailbox storage and mail transmission).
- Cloudflare — DNS for your domain and network security/hosting.
- Supabase — our application database and authentication.
- Resend — transactional (outgoing) notification email.
We will inform you of any intended addition or replacement of a subprocessor in text form (for example by email or an update to this page) in good time, giving you the opportunity to object on reasonable data-protection grounds. If you reasonably object and we cannot offer a comparable alternative, you may terminate the affected service.
8. Assistance with data-subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection). If a data subject contacts us directly regarding your data, we will refer them to you.
9. Assistance with the Controller’s obligations (Art. 32–36)
Taking into account the nature of processing and the information available to us, we assist you in ensuring compliance with your obligations regarding security of processing, notification of personal data breaches, communication of breaches to data subjects, data protection impact assessments, and prior consultation. We will notify you without undue delay after becoming aware of a personal data breach affecting your data and provide the information reasonably available to us to support your own notification obligations.
10. Deletion or return of data
At your choice, we delete or return all the personal data to you after the end of the provision of the service, and delete existing copies, unless Union or Member State law requires storage of the personal data. Before termination you may request a reasonable export/migration of your mailboxes as set out in the Terms.
11. Audits and information
We make available to you the information necessary to demonstrate compliance with Art. 28 GDPR and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you. Audits are limited to what is reasonably necessary, scheduled with reasonable prior notice, conducted so as not to disrupt operations, and subject to confidentiality; we may first satisfy a request by providing relevant documentation or our providers’ third-party certifications/reports where available.
12. International transfers
Where processing involves a transfer of personal data to a country outside the EU/EEA without an adequacy decision, such transfer is safeguarded by the EU Standard Contractual Clauses together with additional measures where appropriate. Details of provider locations are in our Privacy Policy. You can request a copy of the relevant safeguards from us.
13. How to put this agreement in place
This DPA forms part of our contract with business customers and applies automatically to the extent we process personal data on your behalf. If you require a separately signed copy or your own DPA form for your records, contact us at contact@mildnode.com and we will arrange it.