Contrato de encargo del tratamiento

Versión del 03/10/2026: la versión vigente.

Suma de comprobación del texto en alemán (SHA-256): 2523d4d42dd5ea830a4a8f9e1ad6174f2ebfe4b1afea5c64e444d4917c628d48

El texto siguiente es una versión de lectura en inglés, solo a título informativo. Solo la versión en alemán es jurídicamente vinculante.

1. Parties, subject matter and duration

This agreement applies between the customer using VentionDesk (controller, “Customer”) and Kutvention – Inh. Aykut Bicak, Seewenjestraße 175A, 28237 Bremen, email support@ventiondesk.com (processor, “Provider”). It governs the processing of personal data that the Provider carries out on behalf of the Customer when providing VentionDesk under the general terms and conditions (“Main Contract”). It is concluded together with the Main Contract and confirmed in the Software at registration by a person authorised to act for the Customer; this electronic format is sufficient (Art. 28(9) GDPR). It applies for the term of the Main Contract including the trial period; the obligations under clauses 9 and 10 continue to apply until they have been fulfilled. Version of 2026-10-03.

2. Nature, purpose, data and data subjects

  • Purpose: storing, displaying and processing the data that the Customer creates in VentionDesk or receives via its intakes (email, form, app component, customer portal); sending messages triggered by the Customer; synchronisation with services connected by the Customer; generating documents, export and deletion.
  • Types of data: names, contact details, addresses, contents of requests and messages including attachments and screenshots, project and task contents, times, quote, invoice and payment data, users’ sign-in data (email address, role, session, second factor, connections to AI apps), technical metadata (browser identifier, page address, timestamp).
  • Data subjects: employees of the Customer and persons working for it, its customers and their contact persons, users of its customer portal, persons who send requests via the Customer’s websites and apps.

The Software is not intended for the systematic processing of special categories under Arts. 9 and 10 GDPR. If the Customer records such data in individual cases, the Provider processes it in accordance with this agreement; the Customer ensures that it has a legal basis for doing so. The Provider does not process the data for its own purposes, in particular not for training AI models. The Software does not make automated individual decisions within the meaning of Art. 22 GDPR.

3. Instructions

The Provider processes the data only on documented instructions from the Customer, including with regard to a transfer to a third country, unless it is required to do so by Union law or the law of a Member State; in that case it informs the Customer of that legal requirement beforehand, unless that law prohibits this.

This agreement and the settings that the Customer makes in the Software itself count as instructions — roles and access, connections and their keys, the default for AI apps, sending of messages, releases in the customer portal, export and deletion. Further instructions are given by the Customer’s owner and its legal representatives in text form to support@ventiondesk.com. If the Provider considers an instruction to be unlawful, it informs the Customer without undue delay and may suspend its execution until the Customer confirms or changes it.

4. Access by the Provider and confidentiality

The database itself separates each Customer; outside the access cases named in this clause, the Software grants the Provider no insight into a Customer’s content. The Provider accesses a Customer’s data only to avert a malfunction, to restore data, to provide support at the Customer’s request, on its express instruction or to review reported illegal content under Regulation (EU) 2022/2065, and only to the extent necessary for this; the Customer hereby gives a general instruction for these cases. Before reviewing reported content, the Provider informs the Customer, insofar as this does not defeat the remedy.

For these reasons, the Provider can open a support access to the Customer’s area via the Software and work in it with the rights of an owner. Consent to contract texts, taking out, changing and cancelling the subscription, payment data, inviting and removing users, changing roles, creating keys and the export remain closed to it. The Provider informs the Customer’s owner by email of the start of the access, stating the reason and justification, and of its end, stating the duration and the number of logged changes. What the Software logs during this time appears in the Customer’s log with the Provider as the author. The access ends as soon as its purpose has been fulfilled.

The Provider records every access with time, reason and scope in a log whose entries cannot be changed afterwards — a support access at its start and end, a direct access to the database or file storage immediately afterwards — and provides the Customer with information about it on request.

All persons at the Provider who have access to the data are bound to confidentiality. No data protection officer has been appointed; the Provider answers questions on data protection at support@ventiondesk.com.

5. Services connected by the Customer

If the Customer connects a service with its own access — such as an AI tool via the programming interface or a hosting, email, error-tracking or payment service —, this service is a recipient of the Customer and not a sub-processor of the Provider. The Provider transfers to it only what the Customer triggers with the connection. The Customer alone is responsible for the lawfulness of the transfer and for the contract with the service. Corrections and deletions in VentionDesk do not affect data that a connected service has already received. If the Customer withdraws the access, the transfer ends.

This includes AI apps (such as Claude, ChatGPT or Cursor) that the Customer’s users connect via the VentionDesk sign-in (OAuth). The Customer’s owner determines in the Software which rights staff members may grant to such an app; the owner can grant any right that the Software provides for AI apps. Each connection is based on the consent of the individual person, who selects rights and projects in the process; the app receives only these rights and not the person’s rights. Users of the customer portal cannot connect an AI app. A connection can be disconnected at any time — by the person themselves and by the Customer’s owner for every connection in its area —, and it ends after 90 days without use. The Software logs the app, person, rights, projects and the times of connection, last use and disconnection. The providers of these apps are recipients of the Customer within the meaning of sentence 1; the sign-in itself runs via the service for sign-in and database named in the annex.

6. Technical and organisational measures

The Provider takes the following measures under Art. 32 GDPR. It may replace them with equivalent or better ones; the level of protection must not decrease in the process. Organisational measures within the Customer’s sphere — assignment of roles, protection of its own devices and access credentials — are taken by the Customer.

  • System access control: Sign-in via a code or link sent to the registered email address, without a password; a second factor (one-time code from an authenticator app) can be set up for every account; accounts of staff members and customers are created only by invitation; keys for the programming interface are stored only as a hash.
  • Data access control: Row-level security of the database on every table; the roles owner, staff member, customer and agent with least privilege; financial data only for the owner; customers see in the portal only what their workspace releases. The permission setup is checked automatically against a freshly built database on every change to the database schema.
  • Separation control: Every row and every file belongs to exactly one workspace; the database itself rejects access across the boundary of a workspace; a new workspace starts without data.
  • Transfer control: Transmission exclusively encrypted (TLS); file storage not public, files only via signed links valid for 60 seconds; keys for connected services encrypted in the database’s key vault; error reports without cookies, IP address or request content; no analytics or advertising tools.
  • Input control: History of every case and every task with the author and time of entries and responses; invoices are locked against changes when they are finalised.
  • Availability and resilience: Managed database operation in Frankfurt am Main with a daily backup by the operator, retained for seven days; daily backup of all stored files with a second provider in the EU, encrypted with AES-256-GCM before transfer, the key held solely by the Provider, file names only as a non-reversible hash; deleted and changed files remain there for 30 days and are then deleted; restoration of individual files or of a day’s state; scheduled jobs with a lock against duplicate execution; rate limiting and bot checks at public intakes; monitoring of errors and availability.
  • Review: Before every release, checks of code, types, tests and permissions; checks of the database for security advisories on every schema change; public reporting channel for security vulnerabilities.
  • Data minimisation and erasure: Contents of incoming reports and technical metadata are cleared after fixed periods; availability checks are deleted after 30 days; a workspace’s area 30 days after the end of the contract.

7. Sub-processors

The Customer authorises the following sub-processors (general authorisation under Art. 28(2) GDPR). The Provider imposes the same data protection obligations on each of them and is liable for their compliance.

  • Supabase Pte. Ltd., Singapore — database, file storage and sign-in. Location: storage in Frankfurt am Main (EU); access for maintenance and support also possible from countries outside the EU, including the USA. Safeguard: standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914).
  • Render Services, Inc., San Francisco, USA — operation of the programming interface, the intakes and the scheduled jobs. Location: Frankfurt am Main (EU). Safeguard: EU-US Data Privacy Framework, supplemented by standard contractual clauses.
  • Vercel Inc., Covina, USA — delivery of the web interface and the customer portal. Location: server functions in Frankfurt am Main (EU); delivery via locations worldwide. Safeguard: EU-US Data Privacy Framework, supplemented by standard contractual clauses.
  • Plus Five Five, Inc. (Resend), San Francisco, USA — sending and receiving email. Location: sending from Ireland (EU); messages and delivery logs in the USA. Safeguard: EU-US Data Privacy Framework, supplemented by standard contractual clauses.
  • Functional Software, Inc. (Sentry), San Francisco, USA — error reports and availability monitoring. Location: storage in the EU. Safeguard: EU-US Data Privacy Framework, supplemented by standard contractual clauses.
  • Cloudflare, Inc., San Francisco, USA — bot check (Turnstile) on public forms, network service in front of the programming interface and encrypted backup of the files (R2, EU). Location: bot check and network service worldwide (location close to the requesting person); backup in the EU (R2 storage with EU jurisdiction), encrypted only, the key held solely by the Provider. Safeguard: EU-US Data Privacy Framework, supplemented by standard contractual clauses.

The corporate groups of these service providers are headquartered in the USA. Authorities there may, under the law applicable there, demand access to data to which the companies have access, even if the data is stored in the EU.

The Provider announces new or changed sub-processors in text form at least four weeks in advance. The Customer may object within two weeks for an important reason under data protection law; if the Provider maintains the change, either party may terminate the Main Contract with effect from the date of the change. If a sub-processor sets the Provider a shorter period, the Provider informs the Customer without undue delay after becoming aware of it; the right of termination remains unaffected. Ancillary services without access to the data, such as telecommunications and name services, are not sub-processing.

8. Assistance and notifications

The Provider assists the Customer with requests from data subjects under Arts. 15 to 22 GDPR; the Software provides rectification, erasure and the export of the data stock for this purpose. If such a request reaches the Provider, it forwards it to the Customer without undue delay and does not answer it itself. During a suspension under clause 5 or 8a of the general terms and conditions, in which the Customer cannot rectify or erase data itself, the Provider implements requests from data subjects for rectification or erasure on the Customer’s instruction. It also assists the Customer with the obligations under Arts. 32 to 36 GDPR, in particular with a description of the processing for a data protection impact assessment.

The Provider notifies a personal data breach affecting the Customer’s data without undue delay, at the latest within 48 hours of becoming aware of it, by email to the Customer’s owner, with the information under Art. 33(3) GDPR insofar as known; it provides whatever is missing without undue delay. If the group of affected customers cannot be reliably narrowed down, every customer is deemed affected. The Customer decides whether the breach must be notified to the supervisory authority or to the data subjects.

9. Evidence and audits

The Provider makes available to the Customer the information necessary to demonstrate compliance with its obligations under Art. 28 GDPR. The Customer or an auditor commissioned by it and bound to confidentiality may verify compliance, including through inspections, with at least two weeks’ notice, during normal business hours and without disrupting operations more than necessary; after a personal data breach also without this notice period. Each party bears its own costs. The Provider demonstrates compliance by sub-processors through their audit reports or certificates (such as SOC 2 Type II or ISO/IEC 27001).

10. Return and deletion

The data is returned through the export, which the Customer’s owner can download at any time under “Settings › Subscription”, or on the suspension page if access is suspended: a ZIP file with all business data in machine-readable form (JSON), all stored files (documents, attachments, invoice and cancellation documents) and an index that assigns each file to its record and identifies unreadable files. Which data the export contains and how it is structured is described by the Provider at ventiondesk.com/export. After the end of the Main Contract (in the case of a switch of provider under clause 6a of the general terms and conditions: after the transition period), access is suspended; the data is then kept for 30 days (retrieval period), and the export remains possible during this time. The Provider then deletes the Customer’s area with all records and files completely, unless there is a statutory obligation to retain them, and confirms the deletion in text form on request. At the Customer’s request, the Provider deletes the area before the 30 days have expired and confirms the deletion in text form. The daily backups at the database operator expire no later than seven days thereafter; the encrypted backup of the files is deleted 30 days after the deletion with the next daily backup run.

11. Liability and final provisions

Art. 82 GDPR applies to damage suffered by data subjects; as between the parties, each bears the damage to the extent to which it is responsible for its cause, otherwise the liability rule of the Main Contract applies. In matters of data protection, this agreement takes precedence over the Main Contract. Amendments require text form; an amended version is presented to the Customer’s owner at the next sign-in, the owner can accept or reject it, and the Software remains usable in either case. If the owner rejects it, the previous version continues to apply; termination is governed by the Main Contract. German law applies; the place of jurisdiction is Bremen, insofar as permissible.

Encargo del tratamiento | VentionDesk