Data Processing Agreement
This agreement applies between you as controller and the Provider as processor as soon as you process third-party personal data in BenchTool — for instance by creating customer records or issuing invoices. It becomes part of your contract upon use of those features. A signed copy for your records is available on request at support@benchtool.de.
1. Subject matter and duration
The subject matter is the processing of personal data entered by the controller when using BenchTool, solely for the purpose of delivering the agreed services. This agreement runs for the term of the main contract; retention obligations under section 9 remain unaffected.
2. Nature and purpose of processing
Storing, organising, retrieving, altering, transmitting in the form of generated documents and erasing personal data for the purpose of managing customer records, producing quotes, invoices and electronic invoices, and documenting projects.
3. Types of data
- Master data: name, company, address, customer number, buyer reference or routing ID
- Contact data: e-mail address, telephone number
- Contract and billing data: orders, service descriptions, amounts, tax attributes, VAT identification number
- Project content: titles, notes, work steps, times and any photos
- Plans and sketches for a job: title, type, notes, file name and the file itself (drawing, sketch, 3D model, technical drawing), where assigned to a customer
- Repair jobs: details of the piece, description of the work, prices, dates and photos of its condition at intake
- Purchases: items, material, fineness, weight, amounts, method of payment and photos of the items bought
- Details entered by the controller's customers themselves through the customer form: salutation, name, address, email address, telephone number and optional notes on the desired piece
- Accounting data: business expenses with date, amounts, tax attributes, category and supplier details, recurring cost items, and receipt files (photo or PDF) uploaded by the controller
- Bank transaction data from account statement files uploaded by the controller: booking date, amount, name of the payment party, payment reference. There is no connection to banks or payment service providers; only the file provided by the controller is processed
- Identity document details, insofar as the controller collects them: type and number of the document, date and place of birth, nationality, issuing authority, expiry date. Images or scans of identity documents are not processed — the application provides no storage for them
4. Categories of data subjects
Customers and prospects of the controller, their suppliers and subcontractors, payment parties appearing in bank transactions uploaded by the controller (such as customers, suppliers or other third parties) and, under the workshop licence, the members of the workshop.
4a. Workshop team
Where the controller invites further people into the workshop account, those people access the same personal data within the rights assigned to them. They act for the controller, not for the processor. The controller selects the members, obliges them to confidentiality and removes them as soon as access is no longer required.
The processor ensures technically that projects and customer records are visible only within the respective workshop, that invoices created by other members cannot be altered, and that departing members lose access immediately. Invoices already issued remain with the workshop for commercial and tax retention purposes.
4b. Identity details and statutory retention
Where the controller collects identity details — which German anti-money-laundering law requires above certain amounts when buying precious metal (§§ 10, 11 GwG) — the processor handles the text fields only. Storage of reproductions is not provided for; the camera function operates without transmitting the image.
The copy or digitised capture of the document required by § 8(2) GwG therefore stays with the controller and is retained outside the application. The processor does not owe it.
The processor removes the identity details and the seller's address automatically five years after the end of the calendar year of the purchase. This deletion takes place without separate instruction because it is required by law and cannot be waived by the controller. Photos from repair intake are removed one year after collection. Photos of items bought in follow the record itself and are removed five years after the end of the calendar year of the purchase.
Judging whether an identification duty arises in a given case is a matter for the controller. The application flags the threshold and prevents completion without full details, but does not replace the controller's own assessment.
5. Obligations of the processor
- Processing only on documented instructions from the controller. Operating the application constitutes such an instruction. If the processor considers an instruction unlawful, it will say so without delay.
- All persons authorised to process the data are bound to confidentiality.
- Implementation of the technical and organisational measures under Art. 32 GDPR set out in section 10.
- Assistance to the controller in responding to data subject requests and in impact assessments and notification duties, where necessary and with reasonable effort.
- Notification of any personal data breach to the controller without undue delay, as a rule within 24 hours of becoming aware, including all information required for notification under Art. 33 GDPR.
- Evidence of compliance on request; audits are enabled in accordance with section 8.
6. Rights and obligations of the controller
The controller is responsible for the lawfulness of the processing and for safeguarding data subject rights. Instructions are generally issued in text form to support@benchtool.de, where changes of contact persons should also be notified.
7. Sub-processors
The controller grants general authorisation for the sub-processors listed below. They are contractually bound to a level of protection equivalent to this agreement.
| Company | Service | Place of processing |
|---|---|---|
| Supabase Inc., USA | Database, authentication, file storage | Frankfurt am Main (eu-central-1) |
| Vercel Inc., USA | Hosting and delivery of the application | EU locations |
| Stripe Payments Europe Ltd., Ireland | Payment processing | EU |
Changes are notified in text form at least four weeks in advance. The controller may object on substantial data protection grounds; if the service cannot then be provided, either party may terminate. Where processing takes place outside the EU, it is based on the EU Standard Contractual Clauses.
8. Audit rights
The controller may satisfy itself of compliance, as a rule by reviewing evidence and certifications of the providers used. On-site audits are possible with reasonable notice during normal business hours and without disrupting operations.
9. Deletion and return
After the main contract ends, the processor deletes or returns the data once it is no longer needed for performance. Export functions are available in the application. Data subject to statutory retention — in particular invoices for up to eight years under § 14b German VAT Act and § 147 Fiscal Code — is retained in blocked form until the period expires and deleted thereafter.
10. Technical and organisational measures (Art. 32 GDPR)
- Encryption: TLS in transit throughout; database and file storage encrypted at rest.
- Access control (system): password authentication with passwords stored only as hashes; limit on concurrently used devices.
- Access control (data): tenant separation at database level through row level security, so each account can read and write only its own records; file storage is non-public and reachable only via time-limited signed links.
- Input control: time of change and changing user are logged; finalised invoices are protected against subsequent modification by a database rule.
- Availability: daily backups by the database provider; the application works offline so work can continue locally.
- Separation: production and development environments are separated.
- Review: regular review of access rules and automated database security checks.
These measures are subject to technical progress. The Provider may adapt them provided the level of protection is not reduced.
11. Liability
Art. 82 GDPR applies. Between the parties, the liability provisions of the Terms of Use apply in addition.