Product: tapinomahub. Schedules 1 to 4 form an integral part of this Agreement.
Parties
| Controller / Customer | Processor |
|---|---|
| Company: Address: Register / number: Authorised representative: — “Customer” — | gobecom GmbH Malzstraße 6 68309 Mannheim, Germany Local Court Mannheim, HRB 743853 Managing Director: Serhat Göl — “gobecom” — |
Contact points
Instructions, data-subject requests and notifications under this Agreement are exchanged through the following contact points.
| Matter | Customer | gobecom |
|---|---|---|
| Instructions and contract matters | Name / role: Email: | Serhat Göl, Managing Director [email protected] |
| Data protection and data-subject rights | Contact: Email: | [email protected] |
| Personal-data-breach notifications | Email: | [email protected] |
Preamble
The Customer uses the tapinomahub software product. To the extent that gobecom GmbH processes personal data on the Customer’s behalf, this Agreement specifies the parties’ data-protection obligations. It supplements the principal agreement; for processing on behalf of the Customer, the data-protection provisions of this Agreement prevail in case of conflict.
§ 1 Subject matter, scope and duration
(1) The subject matter and details of the processing are set out in the principal agreement and Schedule 1. Processing is functionally limited to providing and operating tapinomahub.
(2) The term corresponds to the term of the principal agreement. Obligations that by their nature survive continue until the personal data have been fully deleted or returned.
(3) The Customer remains the controller within the meaning of Article 4(7) GDPR. gobecom acts as processor within the meaning of Article 4(8) GDPR.
§ 2 Instructions
(1) gobecom processes personal data only on documented instructions from the Customer, including with regard to transfers to third countries, unless processing is required by law. The principal agreement, this Agreement and the documented use and configuration of the product constitute the initial instructions.
(2) Instructions shall normally be issued in text form via the agreed contact channels. Oral instructions shall be documented without undue delay.
(3) If gobecom considers an instruction to infringe data-protection law, it shall inform the Customer without undue delay and may suspend implementation pending confirmation or amendment. Legally required processing shall be notified in advance where permitted.
§ 3 Customer obligations
(1) The Customer ensures lawfulness, transparency, data minimisation and accuracy of the data processed in tapinomahub. In particular, the Customer is responsible for the legal basis, information duties and the lawfulness of external links or files it provides.
(2) The Customer shall report errors, irregularities and data-protection risks without undue delay and shall issue only lawful instructions.
§ 4 Confidentiality and personnel
(1) gobecom uses only persons who have been bound to confidentiality and appropriately trained before beginning their work. Access rights are granted according to role and need-to-know.
(2) There is no routine support access to customer data. Any exceptionally necessary access shall occur only on documented request or instruction, be limited in time and scope and be performed by authorised persons.
§ 5 Security of processing
(1) gobecom implements the technical and organisational measures described in Schedule 2 in accordance with Article 32 GDPR, taking into account the state of the art, implementation costs and the nature, scope, context, purposes and risks of the processing.
(2) Measures may be further developed provided that the agreed protection level is not reduced. The Customer will be informed of material adverse changes.
§ 6 Assistance and data-subject rights
(1) Taking into account the nature of the processing and information available, gobecom shall reasonably assist the Customer with data-subject requests and compliance with Articles 32 to 36 GDPR.
(2) Requests from data subjects shall not be answered independently but shall be forwarded to the Customer without undue delay, unless a legal obligation requires a direct response.
(3) Work beyond the contractually included standard assistance may be charged only on the basis of a prior written agreement or separate quotation, unless the cause lies within gobecom’s area of responsibility.
§ 7 Personal data breaches
(1) gobecom shall notify the Customer without undue delay after becoming aware of a personal data breach within the meaning of Article 4(12) GDPR. To the extent available, the notice shall describe the nature and scope of the breach, affected data and data-subject groups, likely consequences, measures taken or proposed and a contact point.
(2) gobecom shall document incidents and assist the Customer with assessment and notifications under Articles 33 and 34 GDPR. A notification does not constitute an admission of a breach of duty.
§ 8 Sub-processors
(1) The Customer grants general written authorisation for the sub-processors listed in Schedule 3. gobecom shall impose substantially equivalent data-protection obligations by contract and remains responsible to the Customer for their performance.
(2) Intended changes to the list shall be announced in text form at least 30 days before use. The Customer may object within 14 days for an important data-protection reason. The parties shall seek a reasonable solution; if none is possible, the affected service may be terminated in accordance with the principal agreement.
(3) Transfers to third countries shall occur only in compliance with Articles 44 et seq. GDPR, in particular on the basis of an adequacy decision or appropriate safeguards, including standard contractual clauses and any required supplementary measures.
§ 9 Evidence and audits
(1) gobecom shall make available all information necessary to demonstrate compliance with Article 28 GDPR. Current certifications, audit reports, questionnaires and other suitable evidence may be used as a priority.
(2) Audits by the Customer or a confidentiality-bound auditor are permitted for justified cause or generally once per year, upon reasonable prior notice and during normal business hours. They must not disproportionately impair security, confidentiality, third-party rights or operations.
(3) The Customer bears the cost of routine controls, except where a material breach within gobecom’s responsibility is identified.
§ 10 Return and deletion
(1) At the end of processing, gobecom shall delete or, at the Customer’s option, return the personal data unless retention is required by law. Details are set out in Schedule 4.
(2) Productively processed image and file content is generally retrieved via external links and is not stored permanently in tapinomahub. Technically unavoidable transient copies are discarded after processing.
(3) Backups are overwritten or deleted in the controlled backup cycle; the maximum retention period is 90 days. Until then, they remain protected and are not processed productively except for restoration.
§ 11 Responsibility and liability
(1) The statutory allocation of responsibility and liability, in particular under Article 82 GDPR, remains unaffected. The liability provisions of the principal agreement apply to the extent not precluded by mandatory data-protection law.
§ 12 Final provisions
(1) Amendments and supplements must at least be made in text form unless a stricter form is required. This also applies to amendments to the Schedules.
(2) If individual provisions are or become invalid, the remaining provisions remain effective.
(3) The governing law and venue specified in the principal agreement apply unless mandatory law provides otherwise.
Contract components
- Schedule 1 — Description of processing activities
- Schedule 2 — Technical and organisational measures under Article 32 GDPR
- Schedule 3 — Approved sub-processors
- Schedule 4 — Deletion and retention concept
Schedule 1
Description of processing activities
This Schedule describes the permitted processing framework. Customer-specific configuration and instructions may restrict the scope further but may not expand it without an amendment to the Agreement.
1. Subject matter and purpose
Provision and operation of tapinomahub for automated receipt, analysis, extraction, classification and structured return of information from images, documents, PDF files and other files provided by the Customer. Content is regularly retrieved through external links supplied by the Customer.
2. Nature of processing
- Retrieval through external links; transmission, transient caching and provision in working memory where technically required.
- Image analysis, OCR, object recognition, classification, extraction, plausibility checks and structured output.
- Use of local components and models (proprietary models, OpenCV, YOLO and OpenOCR) on infrastructure controlled by gobecom.
- Demand-based API processing by OpenAI Ireland Limited via the OpenAI API with EU data residency (Responses and Vision) and by Google Cloud EMEA Limited via Vertex AI as described in Schedule 3.
- Logging of technical events and backup of operationally necessary system and database content to the required extent.
- Deletion, overwriting or return in accordance with Schedule 4.
2.1 Product modules and functions
The actual scope depends on the order, activation and use. A module name does not mean that it is active for every Customer. The data listed below is included only to the extent that it constitutes personal data under Article 4(1) GDPR.
| Module | Function and possible data |
|---|---|
| Document Intelligence | Extraction from linked documents; document, vehicle, financial, repair, parts, labour and paint data. |
| Registration Document Scanner | Analysis of registration documents; in particular VIN, registration number and technical vehicle data. |
| Label Intelligence | Recognition of parts, manufacturer and product numbers on labels and packaging. |
| VIN Intelligence | VIN decoding and processing of vehicle, equipment and parts information. |
| OE & Parts Intelligence | OE and reference numbers, vehicle applications, parts enrichment and interchange information. |
| Market & Price Intelligence | Price evaluation, marketplace queries, SEO and category data, and statistical market information. |
3. Categories of personal data
| Category | Examples and possible content |
|---|---|
| Master and contact data | Name, address, telephone number, email address |
| Vehicle and identification data | Registration number, vehicle identification number (VIN), data from registration documents |
| Transaction and contract data | Damage reports, invoices, document content, case numbers, metadata |
| Image and media data | Vehicle, damage, document and other images supplied by the Customer |
| Technical data | External links, timestamps, technical request and error data; IP addresses only where technically generated |
| Free text and other document data | Personal data in PDFs, OCR content and other files |
Special categories of personal data under Article 9 GDPR are not intended. If they nevertheless occur in free text, images or documents, the Customer must ensure lawfulness and the required safeguards.
4. Categories of data subjects
- Customers, prospects and contacts of the Customer
- Vehicle keepers, owners, drivers and other persons involved in a transaction
- Injured parties, claimants, policyholders and insured persons
- Experts and contacts at workshops, insurers and service providers
- Employees and other persons whose data is contained in transmitted materials
5. Duration and frequency
Processing occurs on an event basis while tapinomahub is used and for the duration of the principal agreement. Original files retrieved through external links are not retained as an independent permanent file store. Schedule 4 applies to structured results, operational data and backups.
6. Roles and responsibilities
| Party | Role and principal duty |
|---|---|
| Customer | Controller; determines purposes and essential means and ensures legal bases, transparency and instructions. |
| gobecom GmbH | Processor; operates tapinomahub and processes data only within the documented framework. |
| Providers in Schedule 3 | Sub-processors for the service scope described for each provider. |
7. Processing results and return
Results are provided to the Customer in structured form through the agreed interfaces. The Customer shall review automatically generated results before decisions with legal or material economic effects. tapinomahub is not intended to make solely automated decisions with legal effect within the meaning of Article 22 GDPR.
8. Data locations and transfers
Primary hosting, including production databases and backups, is provided in DigitalOcean FRA1 (Frankfurt am Main). netcup is used for email, DNS, database, web server and backups. When OpenAI Ireland Limited (OpenAI API with EU data residency) or Google Cloud EMEA Limited (Vertex AI) is used, transfers or access outside the EEA may arise depending on service and model support, project, endpoint and location configuration, and provider structure; these must be safeguarded by the guarantees listed in Annex 3 and the applicable provider DPAs.
Schedule 2
Technical and organisational measures
The following measures constitute the agreed minimum standard for processing personal data in tapinomahub.
1. Security organisation and risk management
- Clear responsibilities for operations, information security and data protection; periodic review of measures.
- Confidentiality obligations for authorised persons and incident-based training.
- Documented assessment and appropriate treatment of material security and privacy risks.
- Selection and regular review of sub-processors based on appropriate privacy and security evidence.
2. Physical access security
- Physical data-centre security is provided by selected hosting providers and supported contractually or by security evidence.
- gobecom has no routine physical access to production data-centre hardware.
- Workplaces and endpoints are protected against unauthorised use and viewing.
3. Logical access control
- Personal user accounts; no routine shared use of administrative credentials.
- Role and authorisation concept based on least privilege and need-to-know; periodic review and prompt removal of obsolete rights.
- Strong authentication for administrative access; multi-factor authentication where supported.
- Secure management of passwords, API keys and secrets; no storage in publicly accessible source-code repositories.
- No routine support access to customer data; exceptional access only upon documented request, limited and traceable.
4. Transmission, input and disclosure controls
- TLS-encrypted transmission for web access, APIs and external data retrieval.
- Validation and restriction of interfaces and authentication of incoming requests.
- Documentation of permitted recipients and sub-processors; no further disclosure without instruction or legal basis.
- Appropriate logging of security-relevant administrative and technical events; logs protected against unauthorised change and access.
- External links are used only for instructed processing; content is not adopted as a permanent file store.
5. Storage and encryption controls
- Encrypted databases using the technically implemented encryption-at-rest method.
- Encrypted backups with segregated, access-restricted storage.
- Protected management and defined renewal or revocation procedures for keys and secrets.
- Transient processing of image and file content; unavoidable temporary copies are discarded after completion.
6. Availability, resilience and recovery
- Daily backups of operationally necessary data with a maximum retention of 90 days.
- Monitoring of material services and resources and alerting for relevant operational disruptions.
- Firewall and network rules restrict exposed services to what is necessary.
- Controlled recovery from backups; recovery procedures are tested and documented on a risk basis.
- Risk-based change, patch and vulnerability management.
7. Separation and data minimisation
- Logical separation of customer contexts and production system components through application, database and authorisation controls.
- Separation of development, test and production where technically relevant; no production data for testing without documented necessity.
- Processing limited to the data and providers required for the respective operation.
- Local processing by proprietary models, OpenCV, YOLO and OpenOCR where used; these components do not have an independent recipient role.
8. Privacy-friendly defaults
- No permanent storage of the retrieved original file as an independent file set; persisted links, extraction results and raw provider responses are subject to binding deletion rules.
- OpenAI API with EU data residency; Responses and Vision are used only with a documented ZDR or MAM project configuration. Application-side storage of the response remains unaffected.
- For Vertex AI, select a supported EU region and privacy-appropriate project, endpoint, logging and retention settings; no use of customer data for training without documented instruction.
- Logs should not contain complete VINs, external links, content data, provider responses or stack traces unless strictly necessary; sensitive values are masked or hashed.
9. Incident response and effectiveness review
- Defined notification and escalation routes for security and privacy incidents.
- Preservation of relevant information, containment, root-cause analysis, remediation and documented follow-up.
- Prompt information to the Customer as required by this Agreement.
- Periodic effectiveness review through technical controls, recovery tests, authorisation reviews and incident-based audits.
Schedule 3
Approved sub-processors
| Sub-processor | Purpose | Location and safeguard |
|---|---|---|
| DigitalOcean, LLC | Hosting, production databases and backups | Frankfurt am Main (FRA1); DPA and, if required, EU–US Data Privacy Framework and/or Standard Contractual Clauses |
| netcup GmbH | Mail, DNS, database, web server and backups | Germany / EU; Article 28 GDPR data-processing agreement |
| TecAlliance GmbH (TecDoc) | VIN-based vehicle identification and parts data where enabled | Germany / EU; Article 28 GDPR data-processing agreement |
| ProDevelop GmbH | VIN, vehicle and parts queries where enabled | Germany; Article 28 GDPR data-processing agreement |
| Deutsche Automobil Treuhand GmbH (DAT), Hellmuth-Hirth-Straße 1, 73760 Ostfildern, Germany | VIN queries, vehicle identification, valuation and calculation where enabled. | Germany; contractual data-protection terms and, where DAT processes personal data on behalf, an Article 28 GDPR data processing agreement. |
| Schwacke GmbH | Vehicle identification, valuation and calculation where enabled | Germany; agreed data-protection terms and, where required, safeguards under Articles 44 et seq. GDPR |
| OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (OpenAI API – EU data residency) | AI-supported document and image analysis via the Responses API, including vision features. | Europe (EEA and Switzerland) via eu.api.openai.com where supported by the service and model; OpenAI DPA; ZDR or MAM per project configuration; any further transfers based on SCCs or an adequacy decision. |
| Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland (Vertex AI) | AI-supported document and image analysis and model inference via Vertex AI. | Supported EU region or EU multi-region depending on project, model and endpoint configuration; Google Cloud CDPA; global or excluded features may involve processing elsewhere; appropriate safeguards including SCCs under Articles 44 et seq. GDPR. |
Changes and data-protection requirements
- Providers are contractually bound to the data-protection obligations required by Article 28 GDPR.
- Third-country transfers occur only in accordance with Articles 44 et seq. GDPR.
- New or replacement sub-processors are announced under § 8; the current list is provided in text form.
Schedule 4
Deletion and retention concept
Principle: image and file content is processed through external links and is not stored permanently in tapinomahub. Statutory retention duties and documented Customer instructions take precedence but shall be implemented restrictively.
1. Principles
- Purpose limitation, data minimisation and storage limitation.
- Deletion or irreversible overwriting when processing purpose and legal basis cease.
- Separation of production data, transient processing data, logs and backups.
- Deletion rights restricted to authorised persons; material deletion events documented without unnecessary content data.
2. Data classes and periods
| Data class | Rule and period | Deletion mechanism |
|---|---|---|
| Externally linked original files | No permanent tapinoma storage. Access only for the processing operation; deletion in the source system is the Customer’s responsibility. | Do not reuse link or content after completion; discard transient copies. |
| Temporary image and file copies | Only where technically necessary; deletion immediately after completion or cancellation. | Automated cleanup of memory, temporary storage and processing queues. |
| Structured processing results | Stored only as necessary for the commissioned product function; deletion when purpose ceases, upon instruction or at contract end. | Time-controlled deletion including related indexes and links. |
| OpenAI API content (EU project) | EU data residency via eu.api.openai.com for supported services and models; Zero Data Retention where approved and enabled for the project in use. | Provider-side processing under the documented EU/ZDR or MAM configuration; service-specific exceptions remain reserved. |
| Vertex AI content | Retention under the supported EU location and project configuration; no training use without instruction. | Global endpoints and unnecessary storage, caching, grounding and logging functions are not used or are restricted where technically available. |
| Technical logs | Only as long as required for security, error analysis, billing or operational stability. | Automated rotation or deletion; sensitive content avoided, masked or pseudonymised. |
| Support data | No routine customer-data access; exceptional data only for the documented support case. | Deletion when the case closes unless a legal evidence duty applies. |
| Backups | Daily; rolling retention for no more than 90 days. | Automatic overwrite or deletion after expiry; no selective productive use. |
| Security and incident records | Only as necessary for evidence, defence and legal claims; content minimised. | Deletion after closure and expiry of relevant legal or contractual retention interests. |
3. End of contract
- On instruction, gobecom provides exportable personal data in an agreed common format where supported by the product function.
- After confirmation of return or expiry of an agreed transition period, remaining production data is deleted unless retention is required by law.
- Residual backup copies are overwritten or deleted within 90 days through the regular cycle and remain blocked except for restoration.
- If a backup is restored, deletion operations that are already due are reapplied.
- Completion may be confirmed in an appropriate form upon request.
4. Data-subject requests and individual deletion
The Customer verifies identity and legal basis and issues a clear instruction with identifiers, scope and deadline. gobecom searches for and deletes locatable data within its agreed responsibility or explains technical or legal limitations. Restoration solely to delete one item from rolling backups is generally not required if backups are blocked and expire on schedule.
5. Exceptions and deletion holds
- Statutory retention duties or administrative or judicial orders.
- Required preservation for establishment, exercise or defence of legal claims.
- Short technical delays in the documented backup or replication cycle.
- Blocked data is used only for the exceptional purpose, specially protected and deleted promptly when the reason ceases.
6. Responsibilities
- The Customer determines customer-specific retention needs and is responsible for deletion in its source systems.
- gobecom implements the agreed deletion rules within tapinomahub and manages the engaged sub-processors.
- Each party documents necessary exceptions and deletion holds within its area of responsibility.