Data Processing Agreement

Last updated: 28 August 2026

This agreement applies between you as controller and the Provider as processor as soon as you process third-party personal data in BenchTool — for instance by creating customer records or issuing invoices. It becomes part of your contract upon use of those features. A signed copy for your records is available on request at support@benchtool.de.

1. Subject matter and duration

The subject matter is the processing of personal data entered by the controller when using BenchTool, solely for the purpose of delivering the agreed services. This agreement runs for the term of the main contract; retention obligations under section 9 remain unaffected.

2. Nature and purpose of processing

Storing, organising, retrieving, altering, transmitting in the form of generated documents and erasing personal data for the purpose of managing customer records, producing quotes, invoices and electronic invoices, and documenting projects.

3. Types of data

4. Categories of data subjects

Customers and prospects of the controller, their suppliers and subcontractors, payment parties appearing in bank transactions uploaded by the controller (such as customers, suppliers or other third parties) and, under the workshop licence, the members of the workshop.

4a. Workshop team

Where the controller invites further people into the workshop account, those people access the same personal data within the rights assigned to them. They act for the controller, not for the processor. The controller selects the members, obliges them to confidentiality and removes them as soon as access is no longer required.

The processor ensures technically that projects and customer records are visible only within the respective workshop, that invoices created by other members cannot be altered, and that departing members lose access immediately. Invoices already issued remain with the workshop for commercial and tax retention purposes.

4b. Identity details and statutory retention

Where the controller collects identity details — which German anti-money-laundering law requires above certain amounts when buying precious metal (§§ 10, 11 GwG) — the processor handles the text fields only. Storage of reproductions is not provided for; the camera function operates without transmitting the image.

The copy or digitised capture of the document required by § 8(2) GwG therefore stays with the controller and is retained outside the application. The processor does not owe it.

The processor removes the identity details and the seller's address automatically five years after the end of the calendar year of the purchase. This deletion takes place without separate instruction because it is required by law and cannot be waived by the controller. Photos from repair intake are removed one year after collection. Photos of items bought in follow the record itself and are removed five years after the end of the calendar year of the purchase.

Judging whether an identification duty arises in a given case is a matter for the controller. The application flags the threshold and prevents completion without full details, but does not replace the controller's own assessment.

5. Obligations of the processor

  1. Processing only on documented instructions from the controller. Operating the application constitutes such an instruction. If the processor considers an instruction unlawful, it will say so without delay.
  2. All persons authorised to process the data are bound to confidentiality.
  3. Implementation of the technical and organisational measures under Art. 32 GDPR set out in section 10.
  4. Assistance to the controller in responding to data subject requests and in impact assessments and notification duties, where necessary and with reasonable effort.
  5. Notification of any personal data breach to the controller without undue delay, as a rule within 24 hours of becoming aware, including all information required for notification under Art. 33 GDPR.
  6. Evidence of compliance on request; audits are enabled in accordance with section 8.

6. Rights and obligations of the controller

The controller is responsible for the lawfulness of the processing and for safeguarding data subject rights. Instructions are generally issued in text form to support@benchtool.de, where changes of contact persons should also be notified.

7. Sub-processors

The controller grants general authorisation for the sub-processors listed below. They are contractually bound to a level of protection equivalent to this agreement.

CompanyServicePlace of processing
Supabase Inc., USADatabase, authentication, file storageFrankfurt am Main (eu-central-1)
Vercel Inc., USAHosting and delivery of the applicationEU locations
Stripe Payments Europe Ltd., IrelandPayment processingEU

Changes are notified in text form at least four weeks in advance. The controller may object on substantial data protection grounds; if the service cannot then be provided, either party may terminate. Where processing takes place outside the EU, it is based on the EU Standard Contractual Clauses.

8. Audit rights

The controller may satisfy itself of compliance, as a rule by reviewing evidence and certifications of the providers used. On-site audits are possible with reasonable notice during normal business hours and without disrupting operations.

9. Deletion and return

After the main contract ends, the processor deletes or returns the data once it is no longer needed for performance. Export functions are available in the application. Data subject to statutory retention — in particular invoices for up to eight years under § 14b German VAT Act and § 147 Fiscal Code — is retained in blocked form until the period expires and deleted thereafter.

10. Technical and organisational measures (Art. 32 GDPR)

These measures are subject to technical progress. The Provider may adapt them provided the level of protection is not reduced.

11. Liability

Art. 82 GDPR applies. Between the parties, the liability provisions of the Terms of Use apply in addition.