Data Processing Agreement
Version: 2026.07.24
This agreement under Article 28 GDPR is entered into between the organization identified during organization checkout as controller and Cryon UG (haftungsbeschränkt), Landsberger Str. 35, 04157 Leipzig, Germany, as processor. It covers personal data which the organization processes in Werkzeu.ge for its own purposes. Cryon remains a controller for account administration, billing, security, and its own communications.
1. Subject matter and precedence
Cryon provides the subscribed Werkzeu.ge functions and processes organization data only on documented instructions unless Union or German law requires otherwise. This DPA supplements the Terms. It prevails for conflicts concerning processing on behalf of the organization.
Electronic acceptance during organization checkout records the agreement, version, accepting person, organization, and time. The accepting person represents that they are authorized to bind the organization.
2. Duration
Processing begins when organization functions are activated and continues while Cryon processes organization data on the organization's behalf. Statutory retention duties for data which Cryon needs as a controller remain unaffected.
3. Instructions
- Use of product functions and settings constitutes documented instructions.
- Authorized organization owners may send further instructions to info@werkzeu.ge.
- Cryon will promptly inform the organization if it considers an instruction to violate data protection law and will suspend it pending clarification.
- Additional work for individual instructions may be charged after prior agreement.
4. Cryon's duties
- Process data only for the agreed purposes and on instructions.
- Bind every authorized person to confidentiality.
- Implement and regularly review appropriate technical and organizational measures.
- Assist with data subject rights, impact assessments, consultations, and evidence where the processing is concerned.
- Inform the organization promptly about a known personal data breach involving organization data, with the available information under Article 33(3) GDPR.
- Do not use organization content for advertising profiles, data trading, or training generative AI models.
5. Organization duties
- The organization determines permitted purposes, legal bases, inputs, deletion periods, and access roles.
- It fulfils transparency duties and handles data subject requests as controller.
- It enters special-category data only with a valid legal basis and suitable safeguards.
- It keeps accounts, roles, devices, and credentials secure and promptly reports unauthorized access.
- Free-text fields must not contain data which is unnecessary for their purpose.
6. Data subject rights
Where technically available, Cryon provides search, export, correction, and deletion functions. If Cryon receives a request which clearly concerns organization data, it forwards the request to the organization and does not respond independently unless legally required. The organization remains responsible for the substance and timing of its response.
7. Subprocessors
The organization grants general authorization for the subprocessors listed below. Cryon informs the contractual contact address before appointing a new subprocessor. The organization may object on substantiated data protection grounds. If no reasonable solution is available, the organization may terminate the affected function for cause.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Data centre, servers, network, and object storage | Germany |
| INWX GmbH | SMTP relay for emails sent by Werkzeu.ge and DNS | Germany |
| Functional Software, Inc. (Sentry) | Technical error analysis; content and known sensitive fields are filtered before transmission | United States and international infrastructure |
Payment providers, Google sign-in, and hCaptcha process data for their own or jointly determined purposes and are not subprocessors for content placed by the organization in personnel, CRM, file, or communication functions.
8. International processing
The core application, database, and file storage operate in Germany. Where a subprocessor processes data outside the EEA, Cryon establishes a valid transfer mechanism before processing, in particular an applicable adequacy decision or EU Standard Contractual Clauses, and assesses necessary supplementary measures.
9. Security
- TLS-encrypted external transfer and encrypted internal administration connections.
- Encrypted server disks, separated credentials, and restricted administrative access.
- Tenant and organization-bound authorization checks, roles, and logs for security-relevant changes.
- Data-minimized logging, secret management, recovery, and backup procedures.
- Availability monitoring, security updates, and an incident process.
- Client-side encryption where a function expressly identifies that property.
Further details can be provided confidentially where this does not compromise security measures or the rights of others.
10. Deletion and return
During the term, the organization can manage data through the provided export and deletion functions. At the end of processing, Cryon deletes or returns organization data at the organization's choice. Without a different instruction, primary data is removed after the technical deletion queue completes; remaining backup copies rotate out within the documented backup cycle of no more than 30 days. Billing and evidence data subject to statutory retention is restricted and used only for that purpose.
11. Audits and evidence
Cryon provides reasonable information demonstrating compliance on request. Audits require reasonable notice, are generally limited to once per year, and must not impair security, confidentiality, or other customers' operations. Cause-based audits after a material incident remain possible.
Annex 1: Processing details
| Purposes | File and document work, collaboration, personnel and absence administration, CRM, booking, mailbox connections, communications, and other tools enabled by the organization |
|---|---|
| Data types | Master and contact data, organization roles, files, documents, messages, appointments and bookings, working time and absence, health and sick-note data, payroll, tax, bank and social-insurance data, technical metadata, and encrypted credentials |
| Data subjects | Employees, applicants, customers, prospects, suppliers, business partners, booking guests, communication partners, and other people recorded by the organization |
| Operations | Collection, recording, organization, storage, alteration, retrieval, use, transmission on instruction, restriction, export, and erasure |

DE
EN