Data Processing Agreement (DPA)

between the user of the ManualHQ platform in their role as manufacturer (hereinafter "Controller") and Zerocom GmbH, Nelkenstr. 9, 52134 Herzogenrath, Germany (hereinafter "Processor") — agreement on the processing of personal data on behalf of the Controller pursuant to Art. 28 GDPR.

Section 1: Subject Matter and Duration

The Processor provides the Controller with the SaaS platform ManualHQ for the protected distribution of product documentation. In the course of this service, the Processor processes personal data of the Controller's end customers on the Controller's behalf.

This agreement forms part of the platform usage agreement for ManualHQ and applies automatically upon its conclusion. Its duration corresponds to the term of the usage agreement.

Section 2: Nature, Purpose and Scope of Processing

The purpose of the processing is the provision, access control and logging of access to the Controller's product documentation.

Data subjects: end customers and employees of the Controller who access shared documents.

Categories of personal data:

  • Master data (name, email address)
  • Access credentials (password hash, 2FA configuration)
  • Usage and log data (document views, downloads, timestamps, IP address)
  • Access grant data (which documents/chapters, expiry dates)

Special categories of personal data (Art. 9 GDPR) are not processed.

Section 3: Obligations of the Processor

  • Processing only on documented instructions of the Controller; use of the platform features constitutes such instructions.
  • All persons involved in processing are bound to confidentiality.
  • Implementation and maintenance of the technical and organisational measures set out in Annex 1 (Art. 32 GDPR).
  • Notification of the Controller if the Processor considers an instruction to infringe the GDPR.
  • No processing of the Controller's data for the Processor's own purposes.

Section 4: Sub-processors

The Controller approves the engagement of the following sub-processors:

  • Hetzner Online GmbH, Gunzenhausen (Germany) — hosting and storage (servers and object storage located in Germany)
  • Brevo (Sendinblue GmbH), Berlin (Germany) — transactional email delivery
  • Cloudflare, Inc., USA — DNS and attack protection (transfers based on the EU-US Data Privacy Framework and Standard Contractual Clauses)

The Processor will inform the Controller of intended changes to sub-processors at least 4 weeks in advance by email. The Controller may object on substantial data protection grounds; in the event of an objection, both parties have an extraordinary right of termination.

Note: billing of the usage agreement is handled by Stripe Payments Europe Ltd. acting as an independent controller; it is not part of this data processing agreement.

Section 5: Assistance to the Controller

The Processor assists the Controller with appropriate technical and organisational measures in fulfilling data subject rights (Art. 12–23 GDPR), in particular through data export and deletion features built into the platform, and in complying with the obligations under Art. 32–36 GDPR.

Section 6: Personal Data Breach Notification

The Processor will notify the Controller of any personal data breach affecting the Controller's data without undue delay, at the latest within 48 hours of becoming aware of it, and will assist the Controller in fulfilling its notification obligations under Art. 33 and 34 GDPR.

Section 7: Deletion and Return

Upon termination of the usage agreement, the Processor will delete all data processed on behalf of the Controller, unless statutory retention obligations apply. The Controller can export its data via the platform's export features before the end of the agreement. Backups are overwritten according to the regular rotation cycles (max. 60 days).

Section 8: Evidence and Audit Rights

The Processor will make available to the Controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR. On-site audits are possible during normal business hours with at least 14 days' prior notice, provided that legitimate confidentiality interests of other customers are not affected.

Section 9: Final Provisions

This agreement is governed by the laws of the Federal Republic of Germany. In the event of conflicts between this agreement and the usage agreement, this agreement prevails with regard to the processing of personal data. Should individual provisions be invalid, the validity of the remaining provisions remains unaffected.

Annex 1: Technical and Organisational Measures (Art. 32 GDPR)

  • Encryption: TLS for all transfers; encrypted storage of credentials (state-of-the-art password hashing).
  • Access control: mandatory registration, role-based permissions, optional two-factor authentication (TOTP + backup codes), rate limiting.
  • Authorisation control: document- and chapter-level access grants with expiry dates; tenant-separated data storage.
  • Logging: tamper-evident audit log of views and downloads with automatic retention limits.
  • Availability: daily backups with offsite copy (data centre in Germany), documented recovery procedure.
  • Location: hosting and data storage exclusively in data centres in Germany.
  • Organisational: staff confidentiality obligations, least-privilege principle, defined security update process.

Last updated: July 2026