Zur StartseiteBack to Homepage

Auftragsverarbeitungsvertrag (AVV) gem. Art. 28 DSGVO Data Processing Agreement (DPA) pursuant to Art. 28 GDPR

Stand: 10.06.2026
Anbieter: Plotter-FIX GmbH, Felix-Wankel-Straße 15, 53859 Niederkassel, Deutschland
Version date: 10.06.2026
Provider: Plotter-FIX GmbH, Felix-Wankel-Straße 15, 53859 Niederkassel, Deutschland

Parteien dieses Vertrages

Auftragsverarbeiter (AV):
Plotter-FIX GmbH, vertreten durch den Geschäftsführer David Kresinski
Felix-Wankel-Straße 15, 53859 Niederkassel
E-Mail: support@auto-dress.de

Verantwortlicher (V):
Das Unternehmen, das sich als Nutzer bei FlowSNX registriert hat oder den Hauptvertrag anderweitig mit dem AV geschlossen hat.

§ 1 Gegenstand, Art und Dauer der Verarbeitung

(1) Der AV verarbeitet personenbezogene Daten ausschließlich im Auftrag und nach dokumentierten Weisungen des V im Rahmen der Nutzung der SaaS-Plattform FlowSNX.

(2) Zweck der Verarbeitung ist die Bereitstellung der vertraglich vereinbarten SaaS-Leistungen, insbesondere Tourenplanung, Disposition, Live-Status und Live-Standort, Kundenkommunikation per SMS, E-Mail und Tracking-Link, Nachrichten- und Bewertungsfunktionen, Push-Benachrichtigungen, Freigabe von Aufträgen an externe Beteiligte (WorkGroups), PDF-Protokollerstellung und digitale Unterschriftenerfassung.

(3) Die Dauer der Auftragsverarbeitung entspricht der Laufzeit des Hauptvertrages einschließlich gesetzlicher oder vertraglich vorgesehener Aufbewahrungs- und Löschfristen.

§ 2 Kategorien personenbezogener Daten und betroffener Personen

(1) Verarbeitet werden insbesondere folgende Kategorien personenbezogener Daten:

  • Stammdaten von Endkunden des V, insbesondere Name, Anschrift, Telefonnummer und optionale E-Mail-Adresse,
  • Touren-, Stop-, Geo- und ETA-Daten, soweit vom V veranlasst,
  • Standortdaten von Fahrern bei aktivierter Standortfreigabe sowie daraus abgeleitete ETA-Werte,
  • digitale Unterschriften von Endkunden und Fahrern,
  • Foto-Dokumentation zu Einsätzen und Zustellungen einschließlich zugehöriger Aufnahme-Metadaten,
  • Daten von Fahrern und Mitarbeitern des V, insbesondere Name, Fahrzeugbezug, Kennzeichen, Fahrzeugklasse und arbeitsbezogene Einsatzinformationen,
  • Inhalte der Status-, Nachrichten- und optionalen Bewertungsfunktionen im Zusammenhang mit Tracking-Links,
  • technische Benachrichtigungsdaten für Web Push (Endpoints, Subscription-Schlüssel, Browser-/Geräteinformationen),
  • Inhalte von Liefer-, Service-, Arbeits- und Checklistenprotokollen sowie sonstige vom V eingestellte Inhalte.

(2) Betroffene Personen sind insbesondere Endkunden, Ansprechpartner, Fahrer, Mitarbeiter und sonstige durch den V in die Plattform eingebrachte Personen.

(3) Die Verarbeitung besonderer Kategorien personenbezogener Daten im Sinne des Art. 9 DSGVO ist nicht Gegenstand dieses Standardvertrages. Der V darf solche Daten nur nach vorheriger ausdrücklicher Freigabe und auf gesonderter Grundlage verarbeiten lassen.

§ 3 Weisungsrecht des Verantwortlichen

(1) Der AV verarbeitet personenbezogene Daten ausschließlich auf dokumentierte Weisung des V, auch im Hinblick auf Übermittlungen an ein Drittland oder eine internationale Organisation, sofern er nicht durch Unionsrecht oder das Recht der Mitgliedstaaten zu einer Verarbeitung verpflichtet ist.

(2) Weisungen können innerhalb der Plattform, über administrative Einstellungen oder in Textform an support@auto-dress.de erteilt werden.

(3) Hält der AV eine Weisung für rechtswidrig, informiert er den V unverzüglich. Der AV ist berechtigt, die Umsetzung offensichtlich rechtswidriger Weisungen bis zur Klärung auszusetzen.

(4) Mündliche Weisungen sind unverzüglich in Textform zu bestätigen. Erfolgt keine Bestätigung, darf der AV sie unberücksichtigt lassen.

§ 4 Pflichten des Verantwortlichen

(1) Der V ist für die Rechtmäßigkeit der Verarbeitung, die Wahrung der Betroffenenrechte, die Zulässigkeit der Kontaktaufnahme mit Endkunden und die datenschutzkonforme Nutzung der Plattform verantwortlich.

(2) Der V stellt sicher, dass er für sämtliche an den AV übermittelten Daten über die erforderlichen Rechtsgrundlagen, Informationen, Einwilligungen oder sonstigen Berechtigungen verfügt.

(3) Der V bleibt für die Prüfung der fachlichen Plausibilität, der Inhaltserstellung sowie der Richtigkeit und Aktualität seiner Daten verantwortlich.

§ 5 Vertraulichkeit und technisch-organisatorische Maßnahmen

(1) Der AV verpflichtet alle mit der Verarbeitung betrauten Personen auf Vertraulichkeit oder stellt sicher, dass diese einer angemessenen gesetzlichen Verschwiegenheitspflicht unterliegen.

(2) Der AV trifft angemessene technisch-organisatorische Maßnahmen gemäß Art. 32 DSGVO, insbesondere Maßnahmen zur Zugangskontrolle, Zugriffsbeschränkung, Mandantentrennung, Transportverschlüsselung, Sicherung der Verfügbarkeit, Backup- und Wiederherstellungsfähigkeit sowie Protokollierung sicherheitsrelevanter Vorgänge.

(3) Die zum Zeitpunkt des Vertragsschlusses bestehenden wesentlichen Maßnahmen umfassen insbesondere Authentifizierungskonzepte, rollenbezogene Zugriffsbeschränkungen, HTTPS/TLS, abgesicherte Tracking-Links, Prepared Statements/Input-Sanitisierung, Backups und Löschroutinen. Der AV darf diese Maßnahmen fortentwickeln, solange das Schutzniveau insgesamt nicht abgesenkt wird.

§ 6 Einsatz von Unterauftragsverarbeitern

(1) Der V erteilt dem AV die allgemeine Genehmigung zum Einsatz der folgenden Unterauftragsverarbeiter, soweit diese im Rahmen der Leistungserbringung personenbezogene Daten des V verarbeiten:

Unterauftragsverarbeiter Sitz / Standort Zweck
dogado GmbHDeutschlandHosting, Datenbank- und Dateibetrieb sowie E-Mail-Versand (SMTP)
Auth0 / Okta EMEA Ltd.Irland (EU-Tenant)Authentifizierung und Session-Management
Seven.io GmbHDeutschlandVersand von SMS-Nachrichten an Endkunden des V
Browser-Push-Dienste (Google LLC, Mozilla Corporation, Apple Inc. – abhängig vom Browser des Empfängers)je nach Anbieter, ggf. USAtechnische Zustellung von Web-Push-Benachrichtigungen an Nutzer und Fahrer des V
HeiGIT gGmbH (OpenRouteService)DeutschlandRoutenberechnung
Google Ireland Ltd. / Google LLCIrland / USAKartendarstellung, Geocoding und Routing
Stripe Payments Europe Ltd.Irland / USAAbrechnung und Zahlungsabwicklung in Bezug auf Geschäftskontakt- und Abrechnungsdaten des V

(2) Der AV schließt mit Unterauftragsverarbeitern vertragliche Vereinbarungen, die den Anforderungen des Art. 28 DSGVO entsprechen.

(3) Beabsichtigte Änderungen oder Ergänzungen der Unterauftragsverarbeiterliste teilt der AV dem V mindestens vier Wochen vor ihrem Wirksamwerden in Textform mit.

(4) Erhebt der V innerhalb dieser Frist aus datenschutzrechtlich nachvollziehbaren Gründen Widerspruch, werden die Parteien versuchen, eine zumutbare Alternative zu finden. Soweit dies nicht möglich oder wirtschaftlich unzumutbar ist, steht beiden Parteien ein Sonderkündigungsrecht hinsichtlich der betroffenen Leistung oder – sofern eine Teilkündigung nicht möglich ist – des Hauptvertrages zu.

§ 7 Drittlandtransfers

(1) Soweit Unterauftragsverarbeiter oder deren Konzernunternehmen Daten in Drittländern verarbeiten, stellt der AV sicher, dass hierfür eine zulässige datenschutzrechtliche Grundlage besteht, etwa Angemessenheitsbeschlüsse, Zertifizierungen nach dem EU-US Data Privacy Framework oder Standardvertragsklauseln in der jeweils gültigen Fassung.

(2) Der AV wird den V auf Anfrage über die wesentlichen Schutzmechanismen für Drittlandtransfers informieren, soweit dem keine Geheimhaltungs- oder Sicherheitsinteressen entgegenstehen.

§ 8 Unterstützungspflichten des Auftragsverarbeiters

(1) Der AV unterstützt den V unter Berücksichtigung der Art der Verarbeitung und der ihm zur Verfügung stehenden Informationen bei der Erfüllung von Betroffenenrechten gemäß Art. 12 bis 22 DSGVO.

(2) Der AV unterstützt den V ferner bei der Einhaltung der Pflichten aus Art. 32 bis 36 DSGVO, insbesondere im Zusammenhang mit Sicherheit der Verarbeitung, Meldung von Datenschutzverletzungen, Datenschutz-Folgenabschätzungen und vorherigen Konsultationen.

(3) Soweit Unterstützungsleistungen über die vertraglich geschuldete Standardleistung hinausgehen und nicht auf einer Pflichtverletzung des AV beruhen, kann der AV hierfür eine angemessene Vergütung nach Aufwand verlangen.

§ 9 Meldung von Datenschutzverletzungen

(1) Der AV informiert den V über Verletzungen des Schutzes personenbezogener Daten unverzüglich nach Bekanntwerden, grundsätzlich innerhalb von 24 Stunden, soweit ihm die dafür erforderlichen Informationen bereits vorliegen.

(2) Die Meldung enthält – soweit verfügbar – zumindest die Art der Verletzung, betroffene Datenkategorien, die voraussichtlichen Folgen sowie die bereits ergriffenen oder vorgeschlagenen Gegenmaßnahmen.

(3) Soweit noch nicht alle Informationen vorliegen, werden diese ohne unangemessene Verzögerung nachgereicht.

§ 10 Löschung, Rückgabe und Aufbewahrung nach Vertragsende

(1) Nach Beendigung des Hauptvertrages ermöglicht der AV dem V für 14 Tage einen Abruf verfügbarer Exporte, soweit dies technisch vorgesehen und wirtschaftlich zumutbar ist.

(2) Spätestens 30 Tage nach Vertragsende löscht oder anonymisiert der AV die produktiven personenbezogenen Daten des V, sofern keine gesetzliche Aufbewahrungspflicht oder berechtigte Beweissicherungsinteressen hinsichtlich abrechnungs- oder vertragsrelevanter Kontakt- und Geschäftsdaten bestehen. Soweit dabei Daten vollständig anonymisiert werden (insbesondere aggregierte Touren- und Auftragskennzahlen ohne jeden Personenbezug), unterliegen diese nicht mehr der DSGVO; der AV löscht auch diese anonymen Restdaten spätestens 12 Monate nach Vertragsende.

(3) Gesetzlich aufzubewahrende Abrechnungs-, Vertrags- und Nachweisdaten werden nur in dem Umfang und für die Dauer gespeichert, wie dies nach Handels-, Steuer- oder sonstigem zwingenden Recht erforderlich ist.

(4) Backup-Daten werden im Rahmen der regulären Backup-Zyklen überschrieben und nicht gesondert produktiv weiterverwendet.

(5) Auf Anforderung des V bestätigt der AV die Löschung der produktiven Daten in Textform.

§ 11 Prüfungs- und Nachweisrechte

(1) Der AV stellt dem V auf Anfrage alle Informationen zur Verfügung, die erforderlich sind, um die Einhaltung der Pflichten aus diesem AVV und Art. 28 DSGVO nachzuweisen.

(2) Vor-Ort-Prüfungen durch den V oder einen von ihm beauftragten Prüfer sind nur zulässig, soweit sie erforderlich sind, der laufende Geschäftsbetrieb des AV nicht unangemessen beeinträchtigt wird und angemessene Geheimhaltungs- und Sicherheitsvorkehrungen gewahrt bleiben.

(3) Prüfungen sind grundsätzlich mindestens vier Wochen vorher anzukündigen, auf einmal pro Kalenderjahr beschränkt und vorrangig anhand vorhandener Unterlagen, Nachweise, Zertifikate oder Remote-Auskünfte durchzuführen. Weitergehende Prüfungen sind nur bei konkretem Anlass zulässig.

(4) Soweit Prüfungen nicht auf einer Pflichtverletzung des AV beruhen, kann der AV den hierdurch entstehenden angemessenen Aufwand in Rechnung stellen.

§ 12 Haftung und internes Verhältnis

(1) Die Haftung gegenüber betroffenen Personen richtet sich nach Art. 82 DSGVO.

(2) Im Innenverhältnis gilt ergänzend: Der V haftet für die Rechtmäßigkeit seiner Weisungen, die Zulässigkeit der von ihm veranlassten Verarbeitung und die von ihm bereitgestellten Inhalte und Daten. Der AV haftet für Verstöße gegen datenschutzrechtliche Pflichten, soweit diese in seinem eigenen Verantwortungs- oder Pflichtenkreis liegen.

(3) Soweit mehrere Parteien an einem Schaden beteiligt sind, erfolgt ein interner Ausgleich entsprechend dem jeweiligen Verursachungs- und Verantwortungsanteil. Im Übrigen gelten die Haftungsregelungen des Hauptvertrages ergänzend, soweit sie nicht im Widerspruch zu zwingendem Datenschutzrecht stehen.

§ 13 Schlussbestimmungen

(1) Dieser AVV ergänzt den Hauptvertrag. Bei Widersprüchen zwischen Hauptvertrag und AVV gehen in datenschutzrechtlichen Fragen die Regelungen dieses AVV vor.

(2) Änderungen und Ergänzungen dieses AVV bedürfen mindestens der Textform.

(3) Es gilt deutsches Recht.

Parties to this Agreement

Processor (P):
Plotter-FIX GmbH, represented by Managing Director David Kresinski
Felix-Wankel-Straße 15, 53859 Niederkassel, Germany
E-Mail: support@auto-dress.de

Controller (C):
The company that has registered for FlowSNX or has otherwise entered into the main contract with the Processor.

§ 1 Subject Matter, Nature and Duration of Processing

(1) The Processor processes personal data exclusively on behalf of and in accordance with the documented instructions of the Controller in connection with the use of the FlowSNX SaaS platform.

(2) The purpose of processing is the provision of the agreed SaaS services, in particular route planning, dispatching, live status and live location, customer communication via SMS, e-mail and tracking links, messaging and rating functions, push notifications, sharing of jobs with external participants (WorkGroups), PDF report generation and digital signature capture.

(3) The duration of processing corresponds to the term of the main contract, including any statutory or contractual retention and deletion periods.

§ 2 Categories of Personal Data and Data Subjects

(1) The following categories of personal data are processed in particular:

  • master data of the Controller's end customers, especially name, address, phone number and optional e-mail address,
  • tour, stop, geo and ETA data where initiated by the Controller,
  • location data of drivers where location sharing is enabled, and ETA values derived from it,
  • digital signatures of end customers and drivers,
  • photo documentation of assignments and deliveries including related capture metadata,
  • data of drivers and employees of the Controller, especially name, vehicle references, licence plate, vehicle class and work-related assignment information,
  • contents of the status, messaging and optional rating functions connected to tracking links,
  • technical notification data for web push (endpoints, subscription keys, browser/device information),
  • contents of delivery, service, work and checklist records and other content entered by the Controller.

(2) Data subjects include in particular end customers, contacts, drivers, employees and other persons entered into the Platform by the Controller.

(3) Processing of special categories of personal data within the meaning of Art. 9 GDPR is not covered by this standard agreement. The Controller may only have such data processed with prior express approval and on a separate legal basis.

§ 3 Instructions of the Controller

(1) The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers to third countries or international organisations, unless Union or Member State law requires processing.

(2) Instructions may be issued within the Platform, through administrative settings or in text form to support@auto-dress.de.

(3) If the Processor considers an instruction to be unlawful, it shall inform the Controller without undue delay. The Processor may suspend the execution of manifestly unlawful instructions until clarification.

(4) Oral instructions must be confirmed in text form without undue delay. Absent such confirmation, the Processor may disregard them.

§ 4 Obligations of the Controller

(1) The Controller is responsible for the lawfulness of processing, data-subject rights, the permissibility of contacting end customers and the compliant use of the Platform.

(2) The Controller shall ensure that it has all required legal bases, notices, consents and permissions for the data transmitted to the Processor.

(3) The Controller remains responsible for the factual plausibility, content creation and correctness and currency of its data.

§ 5 Confidentiality and Technical and Organisational Measures

(1) The Processor shall bind all persons authorised to process personal data to confidentiality or ensure that they are subject to an appropriate statutory duty of confidentiality.

(2) The Processor shall implement appropriate technical and organisational measures pursuant to Art. 32 GDPR, in particular regarding access control, role-based restrictions, tenant separation, encrypted transmission, availability safeguards, backups and security logging.

(3) The essential measures in place at the time of contract conclusion include authentication concepts, role-based access restrictions, HTTPS/TLS, protected tracking links, prepared statements/input sanitisation, backups and deletion routines. The Processor may further develop such measures provided that the overall level of protection is not reduced.

§ 6 Engagement of Sub-Processors

(1) The Controller grants the Processor general authorisation to engage the following sub-processors where they process personal data of the Controller in connection with the service:

Sub-Processor Location Purpose
dogado GmbHGermanyHosting, database and file operations as well as e-mail delivery (SMTP)
Auth0 / Okta EMEA Ltd.Ireland (EU tenant)Authentication and session management
Seven.io GmbHGermanySMS delivery to the Controller's end customers
Browser push services (Google LLC, Mozilla Corporation, Apple Inc. – depending on the recipient's browser)Depending on the vendor, possibly USATechnical delivery of web push notifications to the Controller's users and drivers
HeiGIT gGmbH (OpenRouteService)GermanyRoute calculation
Google Ireland Ltd. / Google LLCIreland / USAMaps, geocoding and routing
Stripe Payments Europe Ltd.Ireland / USABilling and payment processing regarding business contact and billing data of the Controller

(2) The Processor shall enter into contractual arrangements with sub-processors that satisfy the requirements of Art. 28 GDPR.

(3) Intended changes or additions to the sub-processor list shall be notified to the Controller in text form at least four weeks before they take effect.

(4) If the Controller objects within this period on substantiated data-protection grounds, the parties shall seek a reasonable alternative. If no such alternative is possible or commercially reasonable, either party may terminate the affected service or, if partial termination is not feasible, the main contract.

§ 7 Third-Country Transfers

(1) Where sub-processors or their group companies process data in third countries, the Processor shall ensure that a valid transfer mechanism exists, such as adequacy decisions, certifications under the EU-US Data Privacy Framework or Standard Contractual Clauses in their current version.

(2) Upon request, the Processor shall inform the Controller about the essential safeguards for third-country transfers, unless confidentiality or security interests prevent this.

§ 8 Assistance Obligations of the Processor

(1) Taking into account the nature of the processing and the information available to it, the Processor shall assist the Controller in fulfilling data-subject rights under Arts. 12 to 22 GDPR.

(2) The Processor shall also assist the Controller with obligations under Arts. 32 to 36 GDPR, in particular regarding security, personal data breaches, data protection impact assessments and prior consultations.

(3) To the extent assistance goes beyond the standard contractual service and is not caused by a breach of duty by the Processor, the Processor may charge reasonable compensation based on time spent.

§ 9 Personal Data Breach Notification

(1) The Processor shall inform the Controller of personal data breaches without undue delay after becoming aware of them, generally within 24 hours to the extent the relevant information is already available.

(2) The notice shall include, where available, at least the nature of the breach, the categories of data concerned, the likely consequences and the measures already taken or proposed.

(3) Missing information shall be provided without undue delay as soon as available.

§ 10 Deletion, Return and Retention after Contract End

(1) After termination of the main contract, the Processor shall provide the Controller with 14 days to retrieve available exports, provided this is technically foreseen and commercially reasonable.

(2) No later than 30 days after contract end, the Processor shall delete or anonymise productive personal data of the Controller unless statutory retention obligations or legitimate evidentiary interests require retention of billing, contract or proof-related business-contact data. Where data is fully anonymised in this process (in particular aggregated tour and order metrics without any personal reference), such data is no longer subject to the GDPR; the Processor will nevertheless delete these anonymous residual data no later than 12 months after contract end.

(3) Billing, contract and proof-related data subject to statutory retention obligations shall only be retained to the extent and for the duration required by mandatory commercial, tax or other law.

(4) Backup data will be overwritten in the ordinary backup cycle and will not be reused separately for productive purposes.

(5) Upon request, the Processor shall confirm deletion of productive data in text form.

§ 11 Audit and Demonstration Rights

(1) Upon request, the Processor shall make available all information necessary to demonstrate compliance with this DPA and Art. 28 GDPR.

(2) On-site audits by the Controller or an auditor appointed by it are only permissible where necessary, provided they do not unreasonably impair the Processor's business operations and appropriate confidentiality and security safeguards are maintained.

(3) Audits must generally be announced at least four weeks in advance, are limited to once per calendar year and shall primarily be carried out on the basis of existing documentation, evidence, certificates or remote information. Additional audits are permissible only for concrete cause.

(4) Unless the audit is caused by a breach of duty by the Processor, the Processor may invoice the reasonable costs incurred.

§ 12 Liability and Internal Allocation

(1) Liability vis-à-vis data subjects is governed by Art. 82 GDPR.

(2) As between the parties, the Controller is responsible for the lawfulness of its instructions, the permissibility of the processing initiated by it and the content and data supplied by it. The Processor is responsible for infringements of data-protection obligations falling within its own sphere of responsibility.

(3) Where several parties contributed to a loss, internal recourse shall reflect the respective share of causation and responsibility. Otherwise, the liability provisions of the main contract apply supplementarily to the extent they do not conflict with mandatory data-protection law.

§ 13 Final Provisions

(1) This DPA supplements the main contract. In the event of conflicts between the main contract and this DPA, the provisions of this DPA take precedence in data-protection matters.

(2) Amendments and supplements to this DPA require at least text form.

(3) German law applies.