Data Processing Agreement
Version 1.5 · as of 29 September 2026 · under Art. 28 GDPR
Do you actually need this agreement?
For the free service: no. If you sign up yourself with your own address, we are the controller for it — not your processor — and a DPA would be the wrong contract. It becomes necessary the moment your organisation stores other people's addresses with us: team members in patchletter Pro, and distribution addresses without a login. That is exactly what this agreement covers.
1. Parties
Processor: patchletter UG (haftungsbeschränkt), Meisterweg 16, 45896 Gelsenkirchen, Germany, represented by its Managing Director Kolja Sagorski — legal@patchletter.com (referred to below as “we”).
Controller: the customer named in the order, i.e. the organisation that holds a patchletter Pro subscription (referred to below as “you”).
We have not appointed a data protection officer; with our headcount we are not required to (§ 38 BDSG). Data protection enquiries reach the Managing Director directly at the address above.
2. Subject matter, nature and purpose
We operate patchletter as a software service: we monitor releases, end-of-life dates and security advisories for the products you select, and notify the people you have registered — by email and, if you set one up, to a webhook target of your choosing. Processing personal data is not the purpose of the service; it is a by-product of delivering notifications to named recipients. We process only for that purpose and for no purpose of our own.
The processing is carried out automatically by our systems. Manual access by the operator takes place only for operations and support — see section 13.
3. What this agreement does not cover
For your billing data — company name, address, VAT ID, billing email, invoices — we are a controller in our own right, not your processor. We are bound by our own commercial and tax obligations there (in particular the retention periods of § 147 AO), and no instruction from you can override them. The same applies to data we process about the person who signs the contract on your side. That processing is described in our privacy policy.
A webhook target you set up yourself is also outside this agreement. We do not choose it and we are not its processor — you instruct us to deliver there, and what the receiving service does with the message is governed by your relationship with it. The messages contain product data only, no account data.
4. Types of data and categories of data subjects
We process on your behalf:
- email addresses of the members you invite and of distribution addresses you enter
- role within your organisation (owner, admin, member) and per-member notification settings
- the time an invitation was issued, accepted or revoked, and the time of the last sign-in
- a log of the emails sent to those addresses (subject, referenced releases where applicable, provider ID) and the delivery events reported back to us (bounce, complaint)
- the products subscribed and, where entered, the version in use — this is an infrastructure inventory rather than a personal detail, but it is tied to an account and therefore listed here
Categories of data subjects: your employees and contractors who use patchletter, and the holders of the distribution addresses you enter. There is no special category of data under Art. 9 GDPR, and the service asks for none.
The email address is the only mandatory personal detail. We ask for no name, no telephone number and no job title, and there is no field to supply one.
5. Duration
This agreement runs for as long as your subscription does, and ends with it. Sections 12 and 13 survive termination for as long as they need to.
6. Instructions
We process the data only on your documented instructions (Art. 28(3)(a) GDPR). Your instructions are: this agreement, the order, and the settings you make in the product. Instructions beyond that are given in text form to legal@patchletter.com. If an instruction requires effort beyond ordinary operation, we will say so before carrying it out.
If we believe an instruction infringes data protection law, we will tell you and may suspend that instruction until you confirm it (Art. 28(3) sentence 3 GDPR).
We transfer the data to a third country only on your instruction or where required by law; in the latter case we notify you beforehand unless the law forbids it.
7. Confidentiality
Every person authorised to process the data is bound to confidentiality beyond the end of their engagement and has been instructed in data protection (Art. 28(3)(b) GDPR). At present that circle is the Managing Director; should it grow, the obligation is signed before access is granted, not afterwards.
8. Technical and organisational measures
We take the measures required by Art. 32 GDPR. They are listed in Annex 2 and reflect the state of our systems on the date of this version. We may change individual measures as long as the level of protection does not fall below the one described.
9. Sub-processors
You give general authorisation to engage the sub-processors listed in Annex 1 (Art. 28(2), (4) GDPR). We impose data protection obligations on each of them that are no weaker than those in this agreement.
We announce any intended change — a new sub-processor or a replacement — at least 30 days in advance, in text form to your billing address. You may object within those 30 days on reasonable data protection grounds. If we cannot resolve the objection, you may terminate the subscription with effect from the date the change takes effect, and we will refund any prepaid amount for the remainder of the term.
10. Assisting with data subject rights
Where a data subject turns to us directly, we forward the request to you without undue delay and do not answer it ourselves. On your request we assist with access, rectification, erasure, restriction, portability and objection (Art. 28(3)(e) GDPR) — as far as possible through functions you can operate yourself in the product.
One right is exercised without you: every email carries a one-click unsubscribe link (RFC 8058). If a recipient uses it, delivery to that address stops immediately. We consider that correct — an objection to advertising-like messages must not have to travel through an administrator first — and you should know it happens.
11. Assisting with security, breaches and impact assessments
We support you in complying with Art. 32 to 36 GDPR (Art. 28(3)(f) GDPR). We notify you of a personal data breach affecting your data without undue delay, and at the latest 24 hours after we become aware of it, with the information available to us at that point — we do not wait for a complete picture, because your 72-hour deadline under Art. 33 GDPR starts running before we have one.
You can report a suspected vulnerability to us at any time; the contacts and our PGP key are published in our security.txt.
12. Erasure and return
After the end of the subscription we delete the data processed on your behalf, unless a legal obligation requires us to keep it (Art. 28(3)(g) GDPR). Deletion in live operation is a hard delete, not a flag.
Out of the backups the data rolls off after 30 days, at both destinations: the encrypted copies at the storage service and the second copy on our separate monitoring machine. We do not delete out of backups selectively — doing so would mean breaking the backup chain, which is the worse trade for everyone whose data is in it.
Before the end of the term you can export your data yourself in the product. On request we will provide it once in a common, machine-readable format.
13. Evidence and audits
We provide you with the information needed to demonstrate compliance with Art. 28 GDPR and allow audits (Art. 28(3)(h) GDPR). In the first instance that is done through this page, our privacy policy and the operations page — which is not a marketing text but names every component with its operator and its place, so our claims can be checked from outside.
Beyond that you may audit on site, once per calendar year, with 30 days' notice, during business hours and without disrupting operations. You may have the audit carried out by an independent third party who is not a competitor of ours and who is bound to confidentiality. We bear our own costs; a second audit within the same year is at your expense unless a breach gave cause for it.
One limit belongs here plainly: our servers stand in third-party data centres. We can grant an audit of our systems and our processes; access to the data centre floor is a matter for the sub-processors named in Annex 1, and their audit reports are what is available there.
14. Place of processing
Application, database and object storage run on our own server in Germany, in a data centre in Nuremberg. All emails, sign-in links included, go out via a relay in Germany, and if the regular path fails, via the EU standby path named in Annex 1. Error monitoring, analytics and the electronic signing of this agreement run on the same server; incoming mail is held by a German provider. Uptime monitoring runs on a separate machine at a different provider, likewise in Germany. The backups lie in two places, both in Germany: a client-side encrypted copy at a German storage service, and a second, encrypted copy on the separate monitoring machine. All providers are named in Annex 1. All processing named above takes place within the EU; the authoritative name servers of the domain are run by a French provider that operates only within the EU. A transfer to a third country does not take place.
15. Liability and final provisions
Liability follows Art. 82 GDPR and the terms of the underlying subscription. German law applies. Should a provision be invalid, the remainder stays in force. Where this agreement and the underlying subscription terms conflict on data protection, this agreement prevails.
16. How the agreement is concluded
The DPA is part of patchletter Pro — you do not order it separately and it does not cost extra. After the subscription starts we send it to you for electronic signature and you receive the countersigned PDF back. The signing runs on our own instance on our own server in Nuremberg (Germany); no signature provider is involved, and therefore none appears in Annex 1.
If your procurement requires its own template, send it to legal@patchletter.com. We will read it, and we will say plainly which clauses we cannot meet rather than signing them.
Annex 1 — Sub-processors
As of the date of this version. This list is the data-protection view of the same setup our privacy policy describes in section 3.
- netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany (Amtsgericht Mannheim HRB 705547) — hosting: one server we run ourselves, in a data centre in Nuremberg. It runs the application with its database and object storage, error monitoring, analytics, the electronic signing of this agreement, and the mail server that hands outgoing email to the relay named below. Processing in Germany.
- Scaleway SAS, 8, rue de la Ville-l’Évêque, 75008 Paris, France — authoritative name servers and registration of the domain. Until 28 September 2026 the provider carried our hosting; the data remaining there (servers, database, backups in the Paris and Amsterdam regions) was deleted on 29 September 2026. The provider operates only within the EU.
- Heinlein Hosting GmbH (mailbox.org), Schwedter Str. 8/9b, 10119 Berlin, Germany — mailbox and receipt of incoming email, and storage of our off-site backups. Sign-in links, invitations and confirmation emails went out through this provider from 25 to 29 August 2026. Those backups are encrypted client-side before they leave our server; the provider holds ciphertext only. Processing in Germany.
- LOGIN SystemHaus GmbH, Hagenauer Str. 55, 65203 Wiesbaden, Germany (Amtsgericht Wiesbaden HRB 12713) — delivery of all outgoing email via the mailbridge relay, sign-in links and confirmations included. Processing exclusively in Germany.
- Mailjet SAS (Sinch group), 13-13 bis rue de l’Aubrac, 75012 Paris, France — standby path for sending, used only if the path above fails. Processing in EU data centres (Frankfurt and Saint-Ghislain). It is listed although it is not the regular path: the access is set up and takes over the moment the regular path fails, and naming a processor only once it is actually in use would be naming it too late.
- IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany — separate machine at a different provider: uptime monitoring of our services (status page), and a second, encrypted backup of our data, rotated after 30 days. No personal data arises for the monitoring itself. Processing in Germany.
The same list, with company details, categories of data, places of processing and safeguards per provider, is public at our register of sub-processors — quotable for your own record of processing activities.
Not on this list, deliberately: our payment provider. It processes billing data, for which we are a controller in our own right (section 3) — it is not a sub-processor for the data we handle on your behalf. Analytics (Umami) and error monitoring (Bugsink) we run ourselves, on the same instance as the application; the ALTCHA challenge for bot protection is issued and verified by the application itself. No third-party service is involved there — the host of that instance is Scaleway, named above.
Annex 2 — Technical and organisational measures
Under Art. 32 GDPR, as of the date of this version. Where a measure is absent, it says so — an annex that lists only what is in place is not evidence, it is advertising.
Physical access
We operate no server room of our own. The machines stand in the data centres of the providers named in Annex 1, with their access controls and their audit reports.
System access
- The product has no passwords: sign-in works via a one-time link valid for 30 minutes. There is nothing to reuse, to phish out of a password manager or to find in a credential dump.
- Administrative access to the servers only via SSH key, no password login; repeated failed handshakes are penalised by the SSH daemon itself.
- The database and the object storage run as separate containers on our server with no port open to the internet: they are reachable only from the application’s internal network, and the database additionally from the separated network of our automation service.
- Registration and sign-in are protected by a self-hosted proof-of-work check (ALTCHA) instead of a third-party captcha.
Data access
- Roles within your organisation: owner, admin, member. Rights are checked centrally on every protected page, and a missing right redirects rather than hides the page — a hidden page is still reachable.
- Invoices, which carry your address and VAT ID, are visible to owner and admin only — not to every member with a login.
- The operator can reach account data through the admin interface, for operations and support. That access is not technically ruled out, and we do not claim otherwise.
Separation
Every row that belongs to an organisation carries its identifier, and every query is bound to it. Deleting an organisation cascades to members, invitations, notification settings and billing rows in the same transaction, so no orphaned row survives the account it belonged to.
Transmission
- The website is served over TLS only, with certificates from a certification authority in the EU. HSTS is active.
- Email is sent with transport encryption; SPF, DKIM and DMARC are published, and the DMARC reports on our own domains are received on our own server and evaluated in our own application — no third-party service is involved.
- Emails contain no open trackers. Exactly two links act on click and therefore identify the account: the unsubscribe link and the one that records a version. No other link is redirected or counted.
Availability and recovery
- We back the database up ourselves every 15 minutes. Every backup is checked for readability right after it is written — without that check an empty or truncated dump would sit in the rotation looking like a backup.
- That copy goes off-site to a German storage service, named in Annex 1, and is kept there for 30 days; it is encrypted client-side before it leaves the server, so that service holds ciphertext only. Once a day all our data is additionally copied, encrypted, to a separate machine at a different provider; our server can add to that copy but cannot delete from it.
- Independent uptime monitoring runs on a separate machine at a different provider, not on any of the machines it monitors, and alerts by email and push.
- Deliberately not operated by us: WAL streaming and point-in-time recovery. Our recovery point is therefore the last quarter-hourly backup, not the last second.
Encryption at rest
Stated plainly because it is the question a careful reader asks: the production database and the object storage on our server are not encrypted at rest, and neither are the working copies of the backups on that server. Both off-site copies leave the server encrypted. At the German storage service only ciphertext lies; the key stays with us. For the second copy on our separate monitoring machine the key is on that machine as well, because the rotation after 30 days has to run there. We would rather write that down than let an annex imply otherwise.
Data minimisation
The email address is the only mandatory personal detail; there is no field for a name. Retention periods are enforced by scheduled jobs, not by intention: notification log 12 months, delivery events 24 months, server logs 14 days, unconfirmed registrations 48 hours.
Review
Dependencies are scanned continuously, errors are collected by a self-hosted error monitor, and the operations page names every component with its operator and its place, so the claims made here can be checked from outside.
Version 1.5, as of 29 September 2026. Related: privacy policy, operations & data protection, procedural documentation.