B
BizBrew

Data Processing Agreement

If your business stores personal data of customers or staff in BizBrew, we process that data on your behalf. The GDPR requires a data processing agreement for this.

Get the agreement

NOT CONFIGURED: LEGAL_DPA_URL

To receive a countersigned copy, write to [email protected]

1. Roles

A business that uses BizBrew (a "tenant") decides why and how its customers' and staff's personal data are processed and is the controller for that data. The provider named in the legal notice (BizBrew UG (haftungsbeschränkt) i.G.) processes that data only on the tenant's behalf, as processor under Art. 28 GDPR.

2. What the agreement covers

The agreement sets out the points required by Art. 28(3) GDPR, including:

  • subject matter, duration, nature and purpose of the processing;
  • types of personal data and categories of data subjects (for example clients, bookings, payments, staff records, and, for healthcare tenants, clinical notes);
  • processing only on documented instructions of the tenant;
  • confidentiality of the persons authorised to process the data;
  • the technical and organisational measures (section 3);
  • the conditions for engaging sub-processors (see the sub-processor list);
  • assistance with data subject requests, security, breach notification and impact assessments;
  • deletion or return of the data at the end of the service;
  • information and audit rights of the tenant.

3. Technical and organisational measures in place

  • All traffic is encrypted in transit with TLS; custom domains receive TLS certificates automatically.
  • Tenant isolation: every record carries a tenant ID. The application backend filters every query by the tenant of the signed-in user and checks that user's membership and role. Direct database access is closed to users, and PostgreSQL row-level security is enabled on every table as an extra safeguard.
  • Role- and permission-based access for tenant administrators and staff.
  • Audit logging of significant administrative actions.
  • Daily database backups, kept on the server for 7 days and off-site for 30 days.
  • Server hardening: web traffic is accepted only through Cloudflare, internal service ports are blocked from the internet, SSH access is key-only and protected against brute force.
  • Payment card data is handled by Stripe and never stored on BizBrew servers.