Data Processing Agreement

Version 1.0 · as of 27 August 2026 · under Art. 28 GDPR

Do you actually need this agreement?

For the free service: no. If you sign up yourself with your own address, we are the controller for it — not your processor — and a DPA would be the wrong contract. It becomes necessary the moment your organisation stores other people's addresses with us: team members in patchletter Pro and MSP, and distribution addresses without a login. That is exactly what this agreement covers.

1. Parties

Processor: patchletter UG (haftungsbeschränkt) i. G., represented by its Managing Director Kolja Sagorski, Meisterweg 16, 45896 Gelsenkirchen, Germany — legal@patchletter.com (referred to below as “we”).

Controller: the customer named in the order, i.e. the organisation that holds a patchletter Pro or MSP subscription (referred to below as “you”).

We have not appointed a data protection officer; with our headcount we are not required to (§ 38 BDSG). Data protection enquiries reach the Managing Director directly at the address above.

2. Subject matter, nature and purpose

We operate patchletter as a software service: we monitor releases, end-of-life dates and security advisories for the products you select, and notify the people you have registered — by email and, if you set one up, to a webhook target of your choosing. Processing personal data is not the purpose of the service; it is a by-product of delivering notifications to named recipients. We process only for that purpose and for no purpose of our own.

The processing is carried out automatically by our systems. Manual access by the operator takes place only for operations and support — see section 13.

3. What this agreement does not cover

For your billing data — company name, address, VAT ID, billing email, invoices — we are a controller in our own right, not your processor. We are bound by our own commercial and tax obligations there (in particular the retention periods of § 147 AO), and no instruction from you can override them. The same applies to data we process about the person who signs the contract on your side. That processing is described in our privacy policy.

A webhook target you set up yourself is also outside this agreement. We do not choose it and we are not its processor — you instruct us to deliver there, and what the receiving service does with the message is governed by your relationship with it. The messages contain product data only, no account data.

4. Types of data and categories of data subjects

We process on your behalf:

Categories of data subjects: your employees and contractors who use patchletter, and the holders of the distribution addresses you enter. There is no special category of data under Art. 9 GDPR, and the service asks for none.

The email address is the only mandatory personal detail. We ask for no name, no telephone number and no job title, and there is no field to supply one.

5. Duration

This agreement runs for as long as your subscription does, and ends with it. Sections 12 and 13 survive termination for as long as they need to.

6. Instructions

We process the data only on your documented instructions (Art. 28(3)(a) GDPR). Your instructions are: this agreement, the order, and the settings you make in the product. Instructions beyond that are given in text form to legal@patchletter.com. If an instruction requires effort beyond ordinary operation, we will say so before carrying it out.

If we believe an instruction infringes data protection law, we will tell you and may suspend that instruction until you confirm it (Art. 28(3) sentence 3 GDPR).

We transfer the data to a third country only on your instruction or where required by law; in the latter case we notify you beforehand unless the law forbids it.

7. Confidentiality

Every person authorised to process the data is bound to confidentiality beyond the end of their engagement and has been instructed in data protection (Art. 28(3)(b) GDPR). At present that circle is the Managing Director; should it grow, the obligation is signed before access is granted, not afterwards.

8. Technical and organisational measures

We take the measures required by Art. 32 GDPR. They are listed in Annex 2 and reflect the state of our systems on the date of this version. We may change individual measures as long as the level of protection does not fall below the one described.

9. Sub-processors

You give general authorisation to engage the sub-processors listed in Annex 1 (Art. 28(2), (4) GDPR). We impose data protection obligations on each of them that are no weaker than those in this agreement.

We announce any intended change — a new sub-processor or a replacement — at least 30 days in advance, in text form to your billing address. You may object within those 30 days on reasonable data protection grounds. If we cannot resolve the objection, you may terminate the subscription with effect from the date the change takes effect, and we will refund any prepaid amount for the remainder of the term.

10. Assisting with data subject rights

Where a data subject turns to us directly, we forward the request to you without undue delay and do not answer it ourselves. On your request we assist with access, rectification, erasure, restriction, portability and objection (Art. 28(3)(e) GDPR) — as far as possible through functions you can operate yourself in the product.

One right is exercised without you: every email carries a one-click unsubscribe link (RFC 8058). If a recipient uses it, delivery to that address stops immediately. We consider that correct — an objection to advertising-like messages must not have to travel through an administrator first — and you should know it happens.

11. Assisting with security, breaches and impact assessments

We support you in complying with Art. 32 to 36 GDPR (Art. 28(3)(f) GDPR). We notify you of a personal data breach affecting your data without undue delay, and at the latest 24 hours after we become aware of it, with the information available to us at that point — we do not wait for a complete picture, because your 72-hour deadline under Art. 33 GDPR starts running before we have one.

You can report a suspected vulnerability to us at any time; the contacts and our PGP key are published in our security.txt.

12. Erasure and return

After the end of the subscription we delete the data processed on your behalf, unless a legal obligation requires us to keep it (Art. 28(3)(g) GDPR). Deletion in live operation is a hard delete, not a flag.

Out of the backups the data rotates on the ordinary schedule: hourly dumps after 30 days, the dump taken on the first of the month after a year at most. We do not delete out of backups selectively — doing so would mean breaking the backup chain, which is the worse trade for everyone whose data is in it.

Before the end of the term you can export your data yourself in the product. On request we will provide it once in a common, machine-readable format.

13. Evidence and audits

We provide you with the information needed to demonstrate compliance with Art. 28 GDPR and allow audits (Art. 28(3)(h) GDPR). In the first instance that is done through this page, our privacy policy and the operations page — which is not a marketing text but prints the commands with which you can verify our claims yourself.

Beyond that you may audit on site, once per calendar year, with 30 days' notice, during business hours and without disrupting operations. You may have the audit carried out by an independent third party who is not a competitor of ours and who is bound to confidentiality. We bear our own costs; a second audit within the same year is at your expense unless a breach gave cause for it.

One limit belongs here plainly: our servers stand in third-party data centres. We can grant an audit of our systems and our processes; access to the data centre floor is a matter for the sub-processors named in Annex 1, and their audit reports are what is available there.

14. Place of processing

Application, database, object storage and email delivery run in Germany. Uptime monitoring and the backup copies run on a second machine, likewise in Germany. There is one transfer to the USA and it is named in Annex 1: authoritative DNS. No account data and no email content is transmitted in the process.

15. Liability and final provisions

Liability follows Art. 82 GDPR and the terms of the underlying subscription. German law applies. Should a provision be invalid, the remainder stays in force. Where this agreement and the underlying subscription terms conflict on data protection, this agreement prevails.

16. How the agreement is concluded

The DPA is part of patchletter Pro and MSP — you do not order it separately and it does not cost extra. After the subscription starts we send it to you for electronic signature and you receive the countersigned PDF back. The signing runs on our own instance on our own server in Germany; no signature provider is involved, and therefore none appears in Annex 1.

If your procurement requires its own template, send it to legal@patchletter.com. We will read it, and we will say plainly which clauses we cannot meet rather than signing them.

Annex 1 — Sub-processors

As of the date of this version. This list is the data-protection view of the same setup our privacy policy describes in section 3.

Not on this list, deliberately: our payment provider. It processes billing data, for which we are a controller in our own right (section 3) — it is not a sub-processor for the data we handle on your behalf. Analytics (Umami), error monitoring (Bugsink) and bot protection (ALTCHA) we run ourselves on the same server, so no third party is involved there either.

Annex 2 — Technical and organisational measures

Under Art. 32 GDPR, as of the date of this version. Where a measure is absent, it says so — an annex that lists only what is in place is not evidence, it is advertising.

Physical access

We operate no server room of our own. The machines stand in the data centres of the providers named in Annex 1, with their access controls and their audit reports.

System access

Data access

Separation

Every row that belongs to an organisation carries its identifier, and every query is bound to it. Deleting an organisation cascades to members, invitations, notification settings and billing rows in the same transaction, so no orphaned row survives the account it belonged to.

Transmission

Availability and recovery

Encryption at rest

Stated plainly because it is the question a careful reader asks: the production database and the object storage are not encrypted at rest beyond what the hosting provider does at the storage layer. What is encrypted are the off-site backup copies. We would rather write that down than let an annex imply otherwise.

Data minimisation

The email address is the only mandatory personal detail; there is no field for a name. Retention periods are enforced by scheduled jobs, not by intention: notification log 12 months, delivery events 24 months, server logs 14 days, unconfirmed registrations 48 hours.

Review

Dependencies are scanned continuously, errors are collected by a self-hosted error monitor, and the operations page prints the commands with which the claims made here can be verified from outside.

Version 1.0, as of 27 August 2026. Related: privacy policy, operations & data protection, procedural documentation.