← Back to the homepageDeutsche Fassung

Data Processing Agreement (DPA)

Annex 1 to the Terms and Conditions for TrackIn GTM Monitor

Version 1.0 · As of 29 September 2026

This is a convenience translation. In case of discrepancies, the German version at monitor.track-in.de/avv prevails.


Preamble

This Data Processing Agreement (the “DPA”) sets out the obligations of the parties under Article 28 GDPR for the processing of personal data carried out by the processor on behalf of the controller.

Controller is the customer as defined in the Terms and Conditions.

Processor is:

Turan Saat, Saat Online Performance Goethestraße 4 56410 Montabaur, Germany Email: turan@track-in.de

The DPA is concluded in text form together with the main contract. A signature is not required under Article 28(9) GDPR; the customer confirms its validity during checkout. On request, the processor will provide a separately signed copy.


§ 1 Subject matter, duration and instructions

(1) The subject matter is the provision of the “TrackIn GTM Monitor” service: the automated, recurring inspection of the websites and tag manager containers designated by the controller, and the presentation of the results in the customer area.

(2) This DPA runs for the term of the main contract and ends automatically with it.

(3) The processor processes personal data solely on documented instructions from the controller. The settings made by the controller in the customer area (monitored domains, container IDs, scan intervals, alert destinations) constitute instructions, as do instructions in text form sent to the email address above.

(4) Where the processor is exceptionally required by Union or Member State law to process data beyond those instructions, it will inform the controller before processing, unless that law prohibits such information on important grounds of public interest.

(5) If the processor believes an instruction infringes data protection law, it will inform the controller without undue delay and may suspend execution until the instruction is confirmed or amended.


§ 2 Types of data, purpose and categories of data subjects

(1) Purpose: detecting errors, outages and privacy risks in the controller’s tracking setup, and notifying the controller about them.

(2) Types of data processed:

(3) Special note on measurement data: the scan visits the controller’s website like an anonymous first-time visitor. No user accounts of the controller are used and no forms are submitted. Before storage and before any transfer to the AI provider, values that indicate personal data are removed (in particular email addresses, phone numbers, names, postal addresses, user, customer and click identifiers, and hashed contact data). A residual risk that free-text fields in the controller’s own configuration contain personal data cannot be fully excluded by technical means.

(4) Categories of data subjects:

(5) Special categories of personal data under Article 9 GDPR are not subject to this agreement and, to the processor’s knowledge, are not processed.


§ 3 Place of processing and international transfers

(1) Processing and storage take place in the Federal Republic of Germany (data centre in Falkenstein, Saxony).

(2) A transfer to a third country takes place solely for the AI-assisted analysis of technical measurement data by Anthropic PBC (USA), based on the EU Standard Contractual Clauses (Implementing Decision 2021/914) including the supplementary measures assured by the provider. Only the technical measurement data described in § 2(2), filtered as described in § 2(3), is transferred. The data is not used to train AI models.

(3) The controller may object to the transfer under paragraph 2. In that case the AI analysis is omitted; all other checks remain unaffected.


§ 4 Technical and organisational measures

(1) The processor implements the technical and organisational measures set out in Annex B pursuant to Article 32 GDPR and maintains them for the term of the agreement.

(2) Measures are subject to technical progress. The processor may adapt them as long as the agreed level of protection is not reduced. Material changes are documented and disclosed on request.


§ 5 Confidentiality

(1) The processor treats the data as confidential and engages only persons bound to confidentiality and familiarised with the applicable data protection rules.

(2) The processor is a sole proprietorship without employees. The owner is personally bound to confidentiality. Should employees be engaged in future, they will be bound before starting work.

(3) A data protection officer is not required under Article 37 GDPR / § 38 BDSG. The contact for data protection matters is Turan Saat, turan@track-in.de.


§ 6 Sub-processors

(1) The controller grants general authorisation for the sub-processors listed in Annex A.

(2) The processor will inform the controller in text form at least 30 days before engaging an additional sub-processor or replacing an existing one.

(3) The controller may object within 14 days of receiving that information on substantiated data protection grounds. In the event of an objection, the processor may terminate the contract with one month’s notice to the end of the month; prepaid fees are refunded pro rata.

(4) The processor imposes on each sub-processor a level of protection equivalent to this agreement and remains responsible towards the controller.

(5) Services used by the processor without access to the controller’s data, and services for which the controller is itself responsible — in particular its own Google account and the tag manager it operates — do not constitute sub-processing.


§ 7 Assistance to the controller

(1) The processor assists the controller, to a reasonable extent, in fulfilling data subject rights (Articles 12 to 23 GDPR). If a data subject contacts the processor directly, the processor forwards the request to the controller without undue delay and does not respond itself.

(2) The processor assists the controller with the obligations under Articles 32 to 36 GDPR, in particular data protection impact assessments and notification duties.

(3) The processor notifies the controller of any personal data breach without undue delay and no later than 48 hours after becoming aware of it, in text form, including the information required under Article 33(3) GDPR as far as available.

(4) Such assistance is provided free of charge where the underlying circumstance is attributable to the processor. Otherwise the processor may charge documented effort at its usual rates.


§ 8 Evidence and audits

(1) On request, the processor demonstrates compliance with this agreement, in particular by providing information in text form and documentation of the technical and organisational measures.

(2) The controller may verify compliance, including by on-site audits. Audits must be announced at least 14 days in advance, limited to what is necessary and conducted so as not to disproportionately disrupt operations; normally one audit per calendar year is sufficient.

(3) For audits going beyond information in text form and not triggered by a specific incident at the processor, the processor may charge a reasonable fee.


§ 9 Deletion and return

(1) After the main contract ends, the processor deletes the data processed on behalf within 30 days, unless the controller has requested its return beforehand or a statutory retention obligation applies.

(2) During the term and within 30 days after it ends, the controller can view its data in the customer area and request it in a common format.

(3) Backups are overwritten on a rolling basis and finally deleted no later than 90 days after the contract ends.

(4) Data the processor must retain under commercial or tax law (in particular invoice data) is exempt from deletion and blocked for other purposes.

(5) Deletion is confirmed in text form on request.


§ 10 Liability and final provisions

(1) Liability is governed by the main contract and Article 82 GDPR.

(2) In the event of conflicts between this DPA and the main contract, this DPA prevails in matters of data protection.

(3) Amendments require text form, including any waiver of this requirement.

(4) Should any provision be invalid, the remaining provisions remain unaffected.

(5) German law applies. Place of jurisdiction is, as far as permissible, the registered seat of the processor.


Annex A — Sub-processors

Company Service Place of processing Data processed
Hetzner Online GmbH, Gunzenhausen (DE) server operation, storage, backups Falkenstein, Germany all data listed in § 2
Anthropic PBC, San Francisco (US) AI-assisted analysis of scan results USA (Standard Contractual Clauses) technical measurement data after filtering (§ 2(3))
Brevo GmbH, Berlin (DE) / Sendinblue SAS, Paris (FR) delivery of alerts and system emails European Union email address, name, message content

Not sub-processors:


Annex B — Technical and organisational measures (Article 32 GDPR)

Confidentiality

Integrity

Availability and resilience

Procedure for regular review