Legal

Data Processing Agreement (DPA)

pursuant to Art. 28 GDPR between HejData and the customer

Version 2026-07-06 · As of July 6, 2026

Note on this translation

This English translation is for informational purposes only. The German version is legally binding.

1. Contracting parties

Processor: Lars Macario, Klingnberg 11, 25451 Quickborn, Deutschland

Controller: The organization that uses HejData and accepts this DPA.

2. Subject matter and duration

The Processor processes personal data on behalf of the Controller within the scope of the HejData platform.

Processing begins upon acceptance of this DPA and ends upon termination of the main contract (Terms of Service) or deletion of the affected data.

3. Nature and purpose of processing

Categories of data processed and purposes:

  • Supabase end users: email, metadata, registration and login timestamps — user management and ops KPIs
  • Analytics events: visitor/session IDs, paths, referrer, UTM parameters, device/browser/OS, geo data, optional email hash — traffic analysis
  • Revenue events: amounts, hashed customer emails, Stripe IDs — revenue tracking
  • Alert configuration: encrypted recipient email — threshold notifications
  • Connection secrets: encrypted API keys — technical integration

4. Obligations of the Processor

The Processor agrees to:

  • Process personal data only on documented instructions from the Controller
  • Ensure confidentiality of all persons involved in processing
  • Implement appropriate technical and organizational measures (TOMs)
  • Engage sub-processors only with the Controller's consent (list at /en/subprocessors)
  • Assist the Controller with data subject requests
  • Report data breaches without undue delay
  • Delete or return data after the contract ends

5. Obligations of the Controller

The Controller is responsible and ensures that:

  • A legal basis exists for processing end-user data
  • Data subjects are informed (own privacy policy)
  • Required cookie/tracking notices are observed when using analytics
  • Only authorized Supabase keys are connected

6. Technical and organizational measures

The Processor implements measures including:

  • TLS encryption for data transmission
  • AES-256-GCM encryption for connection secrets and alert emails
  • Row level security and role-based access control
  • Service role keys used server-side only
  • Audit logging of security-relevant actions
  • Regular backups via Supabase

7. Subprocessors

The Controller grants general authorization for the service providers listed at /en/subprocessors.

The Controller will be informed of material changes and may object.

8. Deletion and return

Upon termination of the agreement, the Controller's personal data will be deleted within 30 days unless statutory retention obligations apply.

The Controller may request an export before deletion.

9. Audit rights

The Controller is entitled to verify compliance with this DPA through appropriate evidence (e.g. certifications, TOMs documentation).

Please direct inquiries to: hej@macario.dev