Data Processing Agreement (AVV)

Updated: 2026-09-02

Agreement on the processing of personal data on behalf of the controller pursuant to Art. 28 GDPR. It becomes part of the modwall contract upon its conclusion and applies without separate signature; a signed version is provided on request.

§ 1 Parties and subject matter

The controller is the customer. The processor is Adam Koch, Weißensteinstr. 44, 58093 Hagen, Germany. The subject matter is the processing of personal data that the customer submits for automated content assessment when using modwall.

§ 2 Nature, purpose and duration

(1) Nature of processing: receipt of submitted content, automated assessment by machine learning models, generation of assessment and log data, provision of results via API, widget, customer area and webhooks, and retention of borderline cases in the review queue where enabled by the customer.

(2) Purpose: performance of the main contract — supporting the customer in moderating content.

(3) Duration: for the term of the main contract.

§ 3 Categories of data subjects and types of data

(1) Data subjects: users of the customer's platform whose content is submitted for assessment, and the customer's staff using the customer area and review queue.

(2) Types of data: personal data contained in images and text (including possible depictions of individuals), technical metadata, identifiers of the customer's content, timestamps, assessment results, and access and log data of customer area users.

(3) The customer does not submit special categories of personal data under Art. 9 GDPR unless this is the purpose of the assessment and a legal basis exists; the customer ensures that no content whose possession is a criminal offence is submitted.

§ 4 Right to issue instructions

The processor processes the data solely on the documented instructions of the customer. Instructions are given through the settings in the customer area (thresholds, operating modes, categories, retention periods), through the API calls themselves, and through written notices in text form. If the processor considers an instruction unlawful, it will say so and may suspend execution.

§ 5 Confidentiality

The processor obliges the persons involved in the processing to maintain confidentiality (Art. 28 (3) (b) GDPR) and ensures that access is granted only to the extent necessary.

§ 6 Technical and organisational measures

The processor maintains the measures described in Annex 1 pursuant to Art. 32 GDPR and may develop them further as long as the level of protection is not reduced.

§ 7 Sub-processors

(1) The customer approves the use of the following sub-processors:

  • Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany — hosting of the application and database and encrypted backups (Object Storage). Place of processing: Germany / EU.
  • Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, the Netherlands — delivery of transactional e-mails. Place of processing: the provider's EU data centre; support access from third countries based on standard contractual clauses.

Payments are processed by Stripe Payments Europe, Limited, Dublin, Ireland. The payment service provider acts as a separate controller and not as a sub-processor; it does not receive personal data contained in the content submitted for moderation.

(2) The processor will give at least 30 days' notice before replacing or adding a sub-processor. The customer may object for important data protection reasons; in that case the customer may terminate the main contract with effect from the date of the change.

(3) The processor imposes on sub-processors a level of protection equivalent to this agreement.

§ 8 Place of processing

Processing takes place in Germany (data centres of Hetzner Online GmbH) and otherwise within the European Union. Transfer to a third country occurs only where the requirements of Art. 44 et seq. GDPR are met and after prior notice to the customer.

§ 9 Assistance to the customer

The processor provides reasonable assistance to the customer in responding to data subject requests (Art. 12–23 GDPR), in data protection impact assessments (Art. 35), in consultations with the supervisory authority (Art. 36) and in complying with the obligations under Art. 32–34 GDPR. Data subject requests received directly by the processor are not answered by it but forwarded to the customer.

§ 10 Notification of breaches

The processor informs the customer without undue delay, and at the latest within 48 hours of becoming aware, of any personal data breach and provides the information required for notification under Art. 33 GDPR.

§ 11 Audit rights

The customer may verify compliance with this agreement. Verification is normally carried out by providing information and suitable evidence; on-site inspections are possible with reasonable prior notice, during business hours and without unreasonable disruption of operations.

§ 12 Deletion and return

(1) Images are not stored permanently; after assessment they are not written to any storage medium.

(2) Assessment and log data are deleted in accordance with the periods configured in the customer area or stated in the Privacy Policy.

(3) After termination of the main contract, the processor deletes the data processed on behalf of the customer or returns it at the customer's choice, unless a statutory retention obligation applies. Audit log entries serving as a diligence trail are exported at the customer's request.

§ 13 Liability and final provisions

(1) Liability is governed by the provisions of the main contract and Art. 82 GDPR.

(2) German law applies; the place of jurisdiction is Hagen.

(3) In the event of conflict between this agreement and the main contract, the provisions of this agreement prevail in data protection matters.

Annex 1 — Technical and organisational measures (Art. 32 GDPR)

Confidentiality: transport encryption (TLS) for all connections; access to the customer area only with an account, access to the API only with a secret key that can be revoked at any time; role and permission concept for team members; passwords stored only as hashes; tenant separation at application level; internal services (inference) not reachable from the internet.

Integrity: validation of incoming requests and of webhook signatures; continuous audit log of decisions; protection against bulk querying through rate limiting and quotas.

Availability and resilience: operation in German data centres of Hetzner Online GmbH; service monitoring; regular, encrypted database backups retained in Hetzner Object Storage (EU); limiting of concurrent assessments to protect against overload.

Data minimisation: images are not stored; logs contain only metadata and results; automatic deletion once retention periods expire.

Control of processing: written basis for instructions in this agreement; obligations imposed on sub-processors; no use of customer content for own purposes, in particular no training of models on customer content without a separate agreement.

Courtesy translation. The binding version is the German text (Deutsch), as the contract is governed by German law.