Data Processing Agreement
Last updated October 02, 2026
This Data Processing Agreement ("DPA") is concluded between the customer ("Customer", controller) and Mustafa Serhat Dündar, trading as Konfidant, Bergstraße 70, 10115 Berlin, Germany("Konfidant", processor), pursuant to Art. 28 GDPR. It consists of the provisions below and Annexes 1 (details of processing), 2 (technical and organizational measures) and 3 (sub-processors).
Customers who need a countersigned copy can request one at [email protected].
1. Subject Matter, Conclusion and Scope
This DPA applies to all personal data that Konfidant processes on behalf of the Customer when providing the Services under the Terms of Service (the "Main Agreement"). It is concluded when the Customer accepts the Terms and forms part of the Main Agreement. The subject matter, duration, nature and purpose of processing, the types of personal data and the categories of data subjects are set out in Annex 1.
Data that Konfidant processes as an independent controller (in particular account, billing and website data) is not covered by this DPA; it is described in the Privacy Policy. Terms used in this DPA have the meaning given in the GDPR.
2. Instructions
Konfidant processes personal data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by Union or Member State law; in that case, Konfidant informs the Customer of that legal requirement before processing, unless the law prohibits such information (Art. 28 (3) (a) GDPR).
The Main Agreement, this DPA, and the Customer's use and configuration of the Services (for example, creating a share, choosing its expiry time and storage region, enabling audit logs or verified burn) are the Customer's complete instructions. Further instructions must be given in text form and are subject to agreement on any additional cost. Konfidant informs the Customer without undue delay if it considers that an instruction infringes data protection law and may suspend its execution until it is confirmed or changed.
The Customer is responsible for the lawfulness of the processing, including the legal basis for sharing personal data with recipients and the information of data subjects.
3. Confidentiality and Professional Secrecy
Konfidant ensures that all persons authorized to process the personal data are committed to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28 (3) (b) GDPR). Share content is encrypted on the sender's device and Konfidant never receives the key, so Konfidant cannot access the content of shares.
Professional secrecy. If the Customer is subject to professional secrecy (for example, under § 203 German Criminal Code (StGB), § 43e Federal Lawyers' Act (BRAO) or § 62a Tax Advisors Act (StBerG)), Konfidant acknowledges that it may become aware of information protected by such secrecy when providing the Services. Konfidant undertakes to maintain secrecy about such information, to obtain knowledge of it only to the extent required to provide the Services, and to commit any persons involved in the provision of the Services, including sub-processors, to secrecy in text form. Konfidant has been informed that a breach of this obligation may be punishable under § 203 (4) StGB.
4. Security of Processing
Konfidant implements the technical and organizational measures described in Annex 2 to ensure a level of security appropriate to the risk (Art. 28 (3) (c), Art. 32 GDPR). The measures are subject to technical progress; Konfidant may replace them with adequate alternatives, provided that the level of security of the specified measures is not reduced. Material changes will be documented.
5. Sub-Processors
The Customer grants general authorization for Konfidant to engage sub-processors (Art. 28 (2) GDPR). The sub-processors listed in Annex 3 are approved when this DPA is concluded.
Konfidant informs the Customer of any intended addition or replacement of sub-processors at least 30 days in advance by email or by updating Annex 3 with a notice in the dashboard. The Customer may object on reasonable grounds relating to data protection within 30 days. If Konfidant cannot address the objection, either party may terminate the affected Services with effect from the change; fees paid in advance for the period after termination are refunded on a pro-rata basis. In urgent cases (for example, the failure of a provider), Konfidant may engage a replacement immediately and inform the Customer without undue delay.
Konfidant imposes data protection obligations on each sub-processor that offer an equivalent level of protection to this DPA (Art. 28 (4) GDPR) and remains responsible to the Customer for its sub-processors.
6. Transfers to Third Countries
Konfidant transfers personal data to a third country only in compliance with Chapter V GDPR. Where sub-processors in the USA are certified under the EU-U.S. Data Privacy Framework, transfers are based on the adequacy decision of the European Commission (Art. 45 GDPR); in addition, or where there is no certification, the Standard Contractual Clauses (Module 3, processor to processor) adopted by Commission Implementing Decision (EU) 2021/914 apply (Art. 46 (2) (c) GDPR).
The storage region for files selected by the Customer determines where encrypted files are stored. Delivery through Cloudflare's global network may take place outside the EU. Only encrypted content is transferred; the keys remain with the sender and recipient.
7. Assistance to the Customer
Taking into account the nature of the processing, Konfidant assists the Customer by appropriate technical and organizational measures in responding to requests from data subjects (Chapter III GDPR), and in complying with the obligations under Art. 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available to Konfidant (Art. 28 (3) (e) and (f) GDPR).
Konfidant forwards data subject requests it receives to the Customer without undue delay and does not respond to them itself, except as instructed. Because Konfidant cannot read share content, assistance relating to share content is limited to deleting or disabling shares and providing metadata.
Konfidant may charge reasonable compensation for assistance that goes beyond the functions of the Services, unless the assistance is required because of a breach by Konfidant.
8. Personal Data Breaches
Konfidant notifies the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting the Customer's data (Art. 33 (2) GDPR). The notification contains, to the extent available, the information under Art. 33 (3) GDPR; information that is not yet available is provided in phases. Konfidant takes the measures necessary to secure the data and mitigate possible adverse consequences and documents the breach. Notifications are sent to the email addresses of the Customer's organization administrators.
9. Deletion and Return
Encrypted share content is deleted automatically when it is opened or expires, as described in Annex 1. Because of the nature of the Services, Konfidant cannot return share content.
After the end of the Main Agreement, Konfidant deletes all remaining personal data processed on behalf of the Customer within 30 days, unless Union or Member State law requires storage (Art. 28 (3) (g) GDPR). The Customer can export audit logs before the end of the Main Agreement on request.
10. Evidence and Audits
Konfidant makes available to the Customer all information necessary to demonstrate compliance with Art. 28 GDPR, in particular this DPA, Annex 2 and written answers to reasonable security questionnaires (Art. 28 (3) (h) GDPR).
If this information is not sufficient, the Customer may carry out an audit, or have it carried out by an independent auditor bound to confidentiality who is not a competitor of Konfidant, after at least 30 days' notice, during normal business hours, without disrupting operations, and not more than once per calendar year unless there are concrete indications of a breach. Each party bears its own costs; Konfidant may charge reasonable compensation for its effort for audits that exceed one working day. Audits of sub-processors take place by reviewing their certifications and audit reports (for example, SOC 2 or ISO 27001 reports of Cloudflare).
11. Liability and Term
The liability provisions of the Main Agreement apply to this DPA, without prejudice to Art. 82 GDPR. This DPA remains in force for as long as Konfidant processes personal data on behalf of the Customer.
12. Final Provisions
If the Customer's data is endangered by seizure, insolvency or other events or measures of third parties, Konfidant informs the Customer without undue delay, unless prohibited by law. If there is a conflict between this DPA and the Main Agreement, this DPA prevails for the processing of personal data. If individual provisions are invalid, the validity of the remaining provisions remains unaffected. German law applies; the place of jurisdiction is determined by the Main Agreement.
Annex 1 — Details of Processing
| Item | Description |
|---|---|
| Subject matter and purpose | Provision of the Konfidant Services: encryption, temporary storage and one-time delivery of texts and files shared by the Customer to recipients; organization management features such as audit logs and verified burn. |
| Nature of processing | Receiving content that was encrypted on the sender's device, storing it in encrypted form, delivering it once to the holder of a valid link for decryption on the recipient's device; recording metadata; deleting content. Konfidant does not receive the decryption keys. |
| Duration | Share content: until it is opened or expires (maximum time to live depending on the plan, currently up to 30 days). Metadata and audit logs: for the term of the Main Agreement, unless deleted earlier by the Customer. |
| Types of personal data | Any personal data contained in shared texts and files (determined solely by the Customer, possibly including credentials, contact details, contractual, financial, employment or health data and other special categories of data); share metadata (creating user, organization, size of the encrypted content, creation, expiry and access times); audit log entries (acting user, email address, action, time). |
| Categories of data subjects | Users of the Customer; recipients of shares; persons whose data is contained in shared content (for example, employees, clients, patients, business partners of the Customer). |
Annex 2 — Technical and Organizational Measures (Art. 32 GDPR)
1. Encryption and key management (Art. 32 (1) (a) GDPR)
- All connections to the Services use TLS (minimum TLS 1.2), including download pages on custom domains.
- Each share is encrypted on the sender's device with AES-256-GCM in authenticated chunks, using a random 256-bit key generated for that share. File names and file types are encrypted together with the content.
- The key is only part of the share link's URL fragment, which browsers do not transmit to servers. Konfidant does not receive, store or log keys.
- Access to the ciphertext is controlled by a single-use, expiring HashiCorp Vault response-wrapping token. Once the token is used or expires, the ciphertext can no longer be retrieved and is deleted.
- API keys are stored only as bcrypt hashes; the full key is shown once at creation.
2. Confidentiality (Art. 32 (1) (b) GDPR)
- Physical access control: processing takes place in the data centers of Hetzner (Germany) and Cloudflare, which are certified to ISO/IEC 27001 and apply physical access controls (access systems, video surveillance, staffed security). Konfidant operates no own server rooms.
- System access control: administrative access to servers and provider accounts is limited to the operator and protected by SSH key authentication and multi-factor authentication. User authentication for the Services is handled by Clerk, with optional multi-factor authentication.
- Data access control: role-based access within organizations (administrators and members); API keys with scopes; internal service endpoints authenticated with shared secrets compared in constant time; single-use links; Konfidant cannot view share content because it never holds the keys.
- Separation: data of different customers is logically separated by organization identifiers; file storage is separated by region (EU and US buckets).
- Data minimization: share links are delivered once and are not stored; file names and types are only contained in the encrypted payload; no analytics or tracking on download pages or in the dashboard.
- Code integrity on download pages: download pages load no third-party code and are served with a nonce-based Content Security Policy, no-referrer policy and framing protection.
3. Integrity (Art. 32 (1) (b) GDPR)
- AES-GCM authenticated encryption detects any modification of stored ciphertext.
- Upload URLs are pre-signed, short-lived and bound to the declared size; uploads are checked for a valid encrypted-format header before a link is issued.
- Webhooks from payment and identity providers are verified by signature.
- Security-relevant events are recorded in audit logs.
4. Availability and resilience (Art. 32 (1) (b) and (c) GDPR)
- DDoS protection and rate limiting through Cloudflare and application-level rate limits per API key.
- Availability monitoring with a public status page.
- By design, share content is not backed up; this is part of the agreed service and is not a deficiency in availability.
5. Procedures for regular testing and evaluation (Art. 32 (1) (d) GDPR)
- Automated test suite and continuous integration for every change.
- Automated dependency updates and security fixes.
- Review of these measures at least once a year and after security incidents.
- A published process for reporting security vulnerabilities (Terms of Service).
6. Order control
- Sub-processors are selected with regard to their security measures and bound by data processing agreements.
- The operator is personally bound to confidentiality; no further personnel currently have access.
Annex 3 — Sub-Processors
| Sub-processor | Service | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Hosting of the web application, database and HashiCorp Vault (single-use access tokens), including encrypted text shares and share metadata | Germany | No transfer outside the EU |
| Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA | Storage and delivery of encrypted files (R2, Workers), content delivery, DDoS protection, TLS termination and custom domain certificates | Encrypted files: storage region selected by the customer (EU or US); delivery: Cloudflare global network, including the USA | EU-U.S. Data Privacy Framework (Art. 45 GDPR); Standard Contractual Clauses (Art. 46 (2) (c) GDPR) in the Cloudflare DPA |
Account and billing data of the Customer's users is processed by Konfidant as a controller and is therefore not listed here; the providers used for it (such as Clerk and Stripe) are listed in the Privacy Policy.