Data Processing Agreement (DPA)
Effective: July 7, 2026
This Data Processing Agreement pursuant to Art. 28 GDPR (the "DPA") forms part of the Terms and Conditions of ELLUME GmbH, Marktplatz 1, 71334 Waiblingen ("ELLUME") and applies between ELLUME and the User. It is accepted electronically upon registration or upon activation of the public booking page and covers all processing of personal data that the User stores and manages through the ellume app, including the existing client and appointment management.
§ 1 Subject Matter and Duration
The subject matter of the processing is the provision of the services described in the Terms and Conditions (client, appointment and studio management, including public booking pages and related notifications). The duration of the processing corresponds to the term of the main contract. § 9 of this DPA remains unaffected.
§ 2 Nature and Purpose of the Processing, Data Types, Data Subjects
The processing comprises collecting, storing, organizing, displaying, transmitting (in particular sending transactional emails on the User's behalf), restricting and erasing personal data in the app and on the public booking pages. The sole purpose is the performance of the contract with the User.
Data types processed:
- Contact data of the User's clients and leads (name, phone number, email address, address where provided)
- Appointment and booking data (including booking requests submitted via the public booking page with the contact data and optional message provided there)
- Further content and records the User keeps about their own clients
- Communication data from sending transactional emails (recipient address, delivery status)
Categories of data subjects: clients and leads of the User, and persons submitting an appointment request via the User's public booking page.
The User shall ensure that no special categories of personal data within the meaning of Art. 9 GDPR are collected through the app unless a legal basis exists.
§ 3 Right of Instruction
ELLUME processes the data exclusively on the User's documented instructions. Use of the app's functions by the User constitutes an instruction. Supplementary instructions require text form. If ELLUME considers an instruction to violate data protection law, ELLUME will inform the User without undue delay and may suspend execution until clarified.
§ 4 Confidentiality
ELLUME engages only persons who have committed themselves to confidentiality or are subject to an appropriate statutory obligation of secrecy.
§ 5 Technical and Organizational Measures
ELLUME implements the technical and organizational measures described in Annex 1 pursuant to Art. 32 GDPR and develops them in line with the state of the art. Measures may be replaced by equivalent or more effective measures; material changes are documented.
§ 6 Subprocessing
The User grants general authorization for the subprocessors listed in Annex 2. ELLUME will inform the User in text form of intended changes (addition or replacement) at least 30 days before they take effect. The User may object to a change for an important data-protection reason within 14 days of receiving the information. If the parties cannot reach agreement following an objection, both parties have an extraordinary right of termination regarding the affected service.
ELLUME binds subprocessors by contract to a level of data protection substantially equivalent to the obligations of this DPA. Where processing takes place in third countries, ELLUME ensures appropriate safeguards under Chapter V GDPR, in particular EU Standard Contractual Clauses.
§ 7 Assistance to the User
ELLUME supports the User with appropriate technical and organizational means in fulfilling data-subject rights (Art. 12 to 23 GDPR). Requests from data subjects that reach ELLUME directly are forwarded to the User without undue delay where the request can be attributed to the User. ELLUME further assists the User, taking into account the nature of the processing and the information available to ELLUME, with the obligations under Art. 32 to 36 GDPR.
§ 8 Notification of Personal Data Breaches
ELLUME notifies the User of breaches concerning personal data processed on the User's behalf without undue delay after becoming aware of them. The notification contains, where available, the information listed in Art. 33(3) GDPR.
§ 9 Deletion and Return
Upon termination of the main contract, ELLUME deletes all personal data processed for the User unless statutory retention obligations require otherwise. Until termination, the User may request the return of the data in a common machine-readable format. Deletion takes place no later than 30 days after contract end; upon request, ELLUME confirms deletion in text form. For booking requests submitted via the public booking page, the retention and deletion settings configurable in the app additionally apply; declined, canceled and expired requests are deleted automatically after 30 days by default.
§ 10 Evidence and Audit Rights
ELLUME provides the User on request with the information necessary to demonstrate compliance with this DPA, in particular the current versions of Annexes 1 and 2 and available attestations and certificates of the subprocessors. Further audits including inspections are possible after prior notice within a reasonable period during normal business hours; they must not unreasonably disrupt operations. ELLUME may charge a reasonable fee for audits that go beyond providing existing evidence.
§ 11 Liability
Liability is governed by § 7 of the Terms and Conditions. Liability under Art. 82 GDPR remains unaffected.
§ 12 Final Provisions
In the event of conflicts between this DPA and the Terms and Conditions, this DPA prevails with regard to data-protection obligations. The law of the Federal Republic of Germany applies.
Annex 1: Technical and Organizational Measures (Art. 32 GDPR)
Confidentiality and integrity:
- Encryption of data in transit and at rest
- Access to personal data restricted to authorized persons; each studio's data is separated from that of others
Availability and resilience:
- Operation on managed cloud infrastructure with regular backups and the ability to restore data
- Protection of the public forms against abuse
Regular review:
- Logging and monitoring of security-relevant events
- Review of changes to data structures and access rules before production rollout
Annex 2: Subprocessors
Generally authorized subprocessors within the meaning of § 6:
| Company | Purpose | Data types | Processing location |
|---|---|---|---|
| Supabase Pte. Ltd, Singapore (downstream support: Supabase, Inc., USA) | Database, authentication, file storage | All data types listed in § 2 | AWS eu-central-1 (Frankfurt, confirmed 2026-07-07); third-country transfers via EU Standard Contractual Clauses per the Supabase DPA (dated June 1, 2026, signed 2026-07-07) |
| PowerSync Cloud (Journey Mobile, Inc.) | Synchronization between app and database | All data types listed in § 2 | EU (confirmed 2026-07-07) |
| Vercel Inc., USA | Hosting of the booking pages and related interfaces | Booking request data, technical connection data | USA/global (Edge), EU Standard Contractual Clauses (Decision 2021/914) |
| Expo (650 Industries, Inc.), USA, including Cloudflare, Inc. (own DPA with SCCs) | Hosting of app interfaces, delivery of push notifications (downstream Apple APNs, Google FCM) | Client-related content of requests and notifications, technical connection data | USA/global, EU Standard Contractual Clauses |
| united-domains AG | Sending transactional emails | Recipient address, appointment details in the email | Germany |
| Upstash, Inc., USA | Rate limiting of the public forms | IP addresses, hashed rate-limit keys | Frankfurt (region fra1), EU Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Error and stability monitoring | Technical error data, limited to technical details | EU |
| Google LLC, OpenAI, L.L.C. | AI-assisted features initiated by the User | Client data the User provides to these features | USA, EU Standard Contractual Clauses, no use for training |
Service providers that process only the User's own data and no data of the User's clients (for example a provider for the User's own subscription management) are not subprocessors within the meaning of this DPA; in that respect ELLUME acts as an independent controller.