Data processing agreement (DPA)
This is a courtesy translation – the German version is legally binding.
pursuant to Art. 28 (3) DSGVO between the website operator (controller) and Sveov e.K., owner Patrik Piszkor, Sonnenfeld 39, 83395 Freilassing, Germany (processor, operator of Sveov Forms). Users accept this DPA upon registration; a signed copy is provided on request via sve@sveov.com.
§ 1 Subject and duration
The processor operates a form backend for the controller (receiving, storing and forwarding form data). The agreement applies for the duration of account use and ends with the deletion of the account.
§ 2 Nature and purpose of processing
Receiving form submissions via HTTPS, storage in a database, email notification, optional forwarding via webhook, provision of a management dashboard including export and deletion functions.
§ 3 Categories of data subjects and data
- Data subjects: persons submitting forms on the controller's websites.
- Data: the content entered into the form (typically: name, contact details, message), optional file attachments, referrer/UTM, optional (anonymised) IP address and browser identifier.
§ 4 Obligations of the processor
- Processing only on documented instructions of the controller (the configuration in the dashboard counts as an instruction).
- Confidentiality: access only for persons bound to confidentiality.
- Technical and organisational measures pursuant to Art. 32 DSGVO (see TOM annex).
- Support with data subject rights (built-in export/deletion tools).
- Notification of personal data breaches without undue delay.
- Deletion of all data after the end of the agreement (account deletion removes all data permanently after the 30-day recovery period).
§ 5 Sub-processors
The following sub-processors are engaged:
- Tube-Hosting (owner: Ferdinand Zink), Schlesierstr. 7, 97631 Bad Königshofen, Germany – server operation (data centre location: Germany).
- Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg – email delivery (Amazon SES) exclusively via the region eu-central-1 (Frankfurt am Main, Germany).
- Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland – payment processing for Premium subscriptions only (no form data).
The controller is informed of changes in advance (right to object).
§ 6 Place of processing
Form data is processed exclusively on servers in Germany. No transfer to third countries occurs – unless the controller itself enables third-party services (e.g. Google reCAPTCHA, own webhook targets); the controller is responsible for those.
Annex: technical and organisational measures (TOM)
- Transport encryption (TLS) for all connections, HSTS
- Password hashing (bcrypt), encryption of secrets (AES-256-GCM)
- Two-factor authentication available for accounts
- Role/permission concept (owner / team member), session management with expiry
- Rate limiting, CSRF protection, input sanitisation, security headers (CSP etc.)
- Data minimisation: IP storage off by default, anonymisation, configurable retention periods with automatic deletion
- Daily backups with limited retention (14 days); logging of email delivery and webhook deliveries
- Server access only via SSH key, firewall restricted to necessary ports


