Data Processing Agreement
Version 1.0 · as of 27 August 2026 · under Art. 28 GDPR
Do you actually need this agreement?
For the free service: no. If you sign up yourself with your own address, we are the controller for it — not your processor — and a DPA would be the wrong contract. It becomes necessary the moment your organisation stores other people's addresses with us: team members in patchletter Pro and MSP, and distribution addresses without a login. That is exactly what this agreement covers.
1. Parties
Processor: patchletter UG (haftungsbeschränkt) i. G., represented by its Managing Director Kolja Sagorski, Meisterweg 16, 45896 Gelsenkirchen, Germany — legal@patchletter.com (referred to below as “we”).
Controller: the customer named in the order, i.e. the organisation that holds a patchletter Pro or MSP subscription (referred to below as “you”).
We have not appointed a data protection officer; with our headcount we are not required to (§ 38 BDSG). Data protection enquiries reach the Managing Director directly at the address above.
2. Subject matter, nature and purpose
We operate patchletter as a software service: we monitor releases, end-of-life dates and security advisories for the products you select, and notify the people you have registered — by email and, if you set one up, to a webhook target of your choosing. Processing personal data is not the purpose of the service; it is a by-product of delivering notifications to named recipients. We process only for that purpose and for no purpose of our own.
The processing is carried out automatically by our systems. Manual access by the operator takes place only for operations and support — see section 13.
3. What this agreement does not cover
For your billing data — company name, address, VAT ID, billing email, invoices — we are a controller in our own right, not your processor. We are bound by our own commercial and tax obligations there (in particular the retention periods of § 147 AO), and no instruction from you can override them. The same applies to data we process about the person who signs the contract on your side. That processing is described in our privacy policy.
A webhook target you set up yourself is also outside this agreement. We do not choose it and we are not its processor — you instruct us to deliver there, and what the receiving service does with the message is governed by your relationship with it. The messages contain product data only, no account data.
4. Types of data and categories of data subjects
We process on your behalf:
- email addresses of the members you invite and of distribution addresses you enter
- role within your organisation (owner, admin, member) and per-member notification settings
- the time an invitation was issued, accepted or revoked, and the time of the last sign-in
- a log of the emails sent to those addresses (subject, referenced releases where applicable, provider ID) and the delivery events reported back to us (bounce, complaint)
- the products subscribed and, where entered, the version in use — this is an infrastructure inventory rather than a personal detail, but it is tied to an account and therefore listed here
Categories of data subjects: your employees and contractors who use patchletter, and the holders of the distribution addresses you enter. There is no special category of data under Art. 9 GDPR, and the service asks for none.
The email address is the only mandatory personal detail. We ask for no name, no telephone number and no job title, and there is no field to supply one.
5. Duration
This agreement runs for as long as your subscription does, and ends with it. Sections 12 and 13 survive termination for as long as they need to.
6. Instructions
We process the data only on your documented instructions (Art. 28(3)(a) GDPR). Your instructions are: this agreement, the order, and the settings you make in the product. Instructions beyond that are given in text form to legal@patchletter.com. If an instruction requires effort beyond ordinary operation, we will say so before carrying it out.
If we believe an instruction infringes data protection law, we will tell you and may suspend that instruction until you confirm it (Art. 28(3) sentence 3 GDPR).
We transfer the data to a third country only on your instruction or where required by law; in the latter case we notify you beforehand unless the law forbids it.
7. Confidentiality
Every person authorised to process the data is bound to confidentiality beyond the end of their engagement and has been instructed in data protection (Art. 28(3)(b) GDPR). At present that circle is the Managing Director; should it grow, the obligation is signed before access is granted, not afterwards.
8. Technical and organisational measures
We take the measures required by Art. 32 GDPR. They are listed in Annex 2 and reflect the state of our systems on the date of this version. We may change individual measures as long as the level of protection does not fall below the one described.
9. Sub-processors
You give general authorisation to engage the sub-processors listed in Annex 1 (Art. 28(2), (4) GDPR). We impose data protection obligations on each of them that are no weaker than those in this agreement.
We announce any intended change — a new sub-processor or a replacement — at least 30 days in advance, in text form to your billing address. You may object within those 30 days on reasonable data protection grounds. If we cannot resolve the objection, you may terminate the subscription with effect from the date the change takes effect, and we will refund any prepaid amount for the remainder of the term.
10. Assisting with data subject rights
Where a data subject turns to us directly, we forward the request to you without undue delay and do not answer it ourselves. On your request we assist with access, rectification, erasure, restriction, portability and objection (Art. 28(3)(e) GDPR) — as far as possible through functions you can operate yourself in the product.
One right is exercised without you: every email carries a one-click unsubscribe link (RFC 8058). If a recipient uses it, delivery to that address stops immediately. We consider that correct — an objection to advertising-like messages must not have to travel through an administrator first — and you should know it happens.
11. Assisting with security, breaches and impact assessments
We support you in complying with Art. 32 to 36 GDPR (Art. 28(3)(f) GDPR). We notify you of a personal data breach affecting your data without undue delay, and at the latest 24 hours after we become aware of it, with the information available to us at that point — we do not wait for a complete picture, because your 72-hour deadline under Art. 33 GDPR starts running before we have one.
You can report a suspected vulnerability to us at any time; the contacts and our PGP key are published in our security.txt.
12. Erasure and return
After the end of the subscription we delete the data processed on your behalf, unless a legal obligation requires us to keep it (Art. 28(3)(g) GDPR). Deletion in live operation is a hard delete, not a flag.
Out of the backups the data rotates on the ordinary schedule: hourly dumps after 30 days, the dump taken on the first of the month after a year at most. We do not delete out of backups selectively — doing so would mean breaking the backup chain, which is the worse trade for everyone whose data is in it.
Before the end of the term you can export your data yourself in the product. On request we will provide it once in a common, machine-readable format.
13. Evidence and audits
We provide you with the information needed to demonstrate compliance with Art. 28 GDPR and allow audits (Art. 28(3)(h) GDPR). In the first instance that is done through this page, our privacy policy and the operations page — which is not a marketing text but prints the commands with which you can verify our claims yourself.
Beyond that you may audit on site, once per calendar year, with 30 days' notice, during business hours and without disrupting operations. You may have the audit carried out by an independent third party who is not a competitor of ours and who is bound to confidentiality. We bear our own costs; a second audit within the same year is at your expense unless a breach gave cause for it.
One limit belongs here plainly: our servers stand in third-party data centres. We can grant an audit of our systems and our processes; access to the data centre floor is a matter for the sub-processors named in Annex 1, and their audit reports are what is available there.
14. Place of processing
Application, database, object storage and email delivery run in Germany. Uptime monitoring and the backup copies run on a second machine, likewise in Germany. There is one transfer to the USA and it is named in Annex 1: authoritative DNS. No account data and no email content is transmitted in the process.
15. Liability and final provisions
Liability follows Art. 82 GDPR and the terms of the underlying subscription. German law applies. Should a provision be invalid, the remainder stays in force. Where this agreement and the underlying subscription terms conflict on data protection, this agreement prevails.
16. How the agreement is concluded
The DPA is part of patchletter Pro and MSP — you do not order it separately and it does not cost extra. After the subscription starts we send it to you for electronic signature and you receive the countersigned PDF back. The signing runs on our own instance on our own server in Germany; no signature provider is involved, and therefore none appears in Annex 1.
If your procurement requires its own template, send it to legal@patchletter.com. We will read it, and we will say plainly which clauses we cannot meet rather than signing them.
Annex 1 — Sub-processors
As of the date of this version. This list is the data-protection view of the same setup our privacy policy describes in section 3.
- manitu GmbH, Welvertstraße 2, 66606 St. Wendel, Germany — server hosting: application, database and object storage. Processing exclusively in Germany.
- Heinlein Hosting GmbH (mailbox.org), Schwedter Str. 8/9b, 10119 Berlin, Germany — mailbox and receipt of incoming email, and delivery of sign-in links, invitations and confirmation emails. Processing in Germany.
- LOGIN SystemHaus GmbH, Hagenauer Str. 55, 65203 Wiesbaden, Germany (Amtsgericht Wiesbaden HRB 12713) — delivery of update, newsletter and security emails via the mailbridge relay. Processing exclusively in Germany.
- Mailjet SAS (Sinch group), 13-13 bis rue de l’Aubrac, 75012 Paris, France — standby path for sending, used only if the path above fails. Processing in EU data centres (Frankfurt and Saint-Ghislain). It is listed although it is not the regular path: the access is set up and takes over the moment the regular path fails, and naming a processor only once it is actually in use would be naming it too late.
- IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany — second machine: uptime monitoring and storage of the database backups. Processing in Germany.
- Cloudflare, Inc., USA — authoritative DNS for patchletter.com only. This resolves domain names; no account data and no email content is transmitted. Basis for the transfer: Standard Contractual Clauses (Art. 46 GDPR) and, where the provider is certified, the EU-US Data Privacy Framework. The domain is subject to a transfer lock until early September 2026; a move to a German registrar is planned.
Not on this list, deliberately: our payment provider. It processes billing data, for which we are a controller in our own right (section 3) — it is not a sub-processor for the data we handle on your behalf. Analytics (Umami), error monitoring (Bugsink) and bot protection (ALTCHA) we run ourselves on the same server, so no third party is involved there either.
Annex 2 — Technical and organisational measures
Under Art. 32 GDPR, as of the date of this version. Where a measure is absent, it says so — an annex that lists only what is in place is not evidence, it is advertising.
Physical access
We operate no server room of our own. The machines stand in the data centres of the providers named in Annex 1, with their access controls and their audit reports.
System access
- The product has no passwords: sign-in works via a one-time link valid for 30 minutes. There is nothing to reuse, to phish out of a password manager or to find in a credential dump.
- Administrative access to the servers only via SSH key, no password login; repeated failed handshakes are penalised by the SSH daemon itself.
- Registration and sign-in are protected by a self-hosted proof-of-work check (ALTCHA) instead of a third-party captcha.
Data access
- Roles within your organisation: owner, admin, member. Rights are checked centrally on every protected page, and a missing right redirects rather than hides the page — a hidden page is still reachable.
- Invoices, which carry your address and VAT ID, are visible to owner and admin only — not to every member with a login.
- The operator can reach account data through the admin interface, for operations and support. That access is not technically ruled out, and we do not claim otherwise.
Separation
Every row that belongs to an organisation carries its identifier, and every query is bound to it. Deleting an organisation cascades to members, invitations, notification settings and billing rows in the same transaction, so no orphaned row survives the account it belonged to.
Transmission
- The website is served over TLS only, with a certificate from a German certification authority. HSTS is active.
- Email is sent with transport encryption; SPF, DKIM and DMARC are published, and the DMARC reports on our own domains are evaluated on our own server.
- Emails contain no open trackers. Exactly two links act on click and therefore identify the account: the unsubscribe link and the one that records a version. No other link is redirected or counted.
Availability and recovery
- The database is backed up hourly. Every backup is checked for readability right after it is written — without that check an empty or truncated dump would sit in the rotation for 30 days looking like a backup.
- A copy goes to the second machine. No cloud storage provider is involved. Off-site copies to external storage are encrypted client-side before they leave the machine.
- Independent uptime monitoring runs on the second machine, not on the machine it monitors, and alerts by email and push.
- Deliberately not in place: WAL streaming and point-in-time recovery. The recovery point is therefore the last hourly backup, not the last second.
Encryption at rest
Stated plainly because it is the question a careful reader asks: the production database and the object storage are not encrypted at rest beyond what the hosting provider does at the storage layer. What is encrypted are the off-site backup copies. We would rather write that down than let an annex imply otherwise.
Data minimisation
The email address is the only mandatory personal detail; there is no field for a name. Retention periods are enforced by scheduled jobs, not by intention: notification log 12 months, delivery events 24 months, server logs 14 days, unconfirmed registrations 48 hours.
Review
Dependencies are scanned continuously, errors are collected by a self-hosted error monitor, and the operations page prints the commands with which the claims made here can be verified from outside.
Version 1.0, as of 27 August 2026. Related: privacy policy, operations & data protection, procedural documentation.