Data processing agreement pursuant to Art. 28 GDPR

Translation for information only. This English text is a convenience translation. Only the German version (Vertrag zur Auftragsverarbeitung) is legally binding.

between the customer of the “Planago with hosting” offer as controller (hereinafter “customer”) and Hölter Digital, owner Patrick Hölter, Osteroder Str. 21, 42277 Wuppertal, Germany, as processor (hereinafter “provider”). The agreement is concluded when the customer accepts it during the order by ticking the corresponding checkbox.

1. Subject matter and duration

The subject matter is the operation of a Planago installation for the customer in accordance with the hosting terms (“main contract”). The duration of this agreement corresponds to the term of the main contract; obligations to delete and return data continue to apply beyond this until they have been fulfilled.

2. Nature and purpose of the processing

The provider stores and processes data to the extent necessary for the operation, backup, updates and support of the Planago installation. The customer operates the online appointment booking itself under their own responsibility.

3. Types of data and categories of data subjects

4. Instructions

The provider processes the data only on documented instructions from the customer, which initially result from this agreement and the main contract, unless the provider is required by law to process the data; in that case, the provider informs the customer of the legal requirement beforehand, unless the law prohibits this. The customer issues further instructions in text form. If the provider considers an instruction to be unlawful, the provider informs the customer.

5. Confidentiality

Only the owner of the provider has access to the servers. He is bound to confidentiality. If further persons are deployed in the future, the provider commits them to confidentiality beforehand.

6. Technical and organisational measures

The provider takes appropriate measures in accordance with Art. 32 GDPR, in particular:

The provider may further develop the measures, provided that the level of protection is not reduced.

7. Sub-processors

The customer agrees that the provider uses the following sub-processors:

The provider informs the customer in advance in text form of any intended changes; the customer may object for an important reason relating to data protection. Emails from the installation are sent via the mailbox stored by the customer; its provider is not a sub-processor of the provider.

8. Assistance to the customer

The provider assists the customer to a reasonable extent in responding to requests from data subjects (Art. 12 to 23 GDPR) and in complying with the obligations under Art. 32 to 36 GDPR. The customer can handle many requests, such as requests for information or the deletion of individual bookings, themselves in the admin area.

9. Personal data breaches

The provider notifies the customer of a personal data breach without undue delay after becoming aware of it, with the information available to the provider, so that the customer can fulfil their notification obligations.

10. Deletion and return

After the end of the main contract, the provider provides the customer with a copy of the data free of charge on request and deletes the installation 30 days after the end of the contract. Remaining backup copies are deleted automatically no later than 30 days thereafter, and the data centre operator's backups after 7 days, unless there is a legal obligation to retain them.

11. Evidence and audits

On request, the provider makes available to the customer the information necessary to demonstrate compliance with this agreement and allows audits to a reasonable extent after prior agreement.

12. Final provisions

German law applies. Otherwise, the provider's hosting terms and general terms apply; in the event of contradictions, this agreement takes precedence insofar as the protection of personal data is concerned.

Version: 29 September 2026