Data Processing Agreement (DPA)
The German version of this DPA is the authoritative version; this English version is a courtesy translation. In case of discrepancies, the German version prevails.
This agreement specifies the parties' obligations to ensure data protection pursuant to Art. 28 GDPR. It applies between you ("controller") and Nolte Nußbaum Digital GbR, Panoramastr. 82, 73207 Plochingen, Germany ("Editkraft", "processor"), and supplements Editkraft's Terms of Service. It automatically becomes part of the contract as soon as you use the Service and thereby have personal data processed by Editkraft via your own Supabase instance — no separate signature is required. If you would like a countersigned copy for your own records, contact hi@editkraft.com.
1. Subject matter and duration
The subject matter is Editkraft's processing of personal data on behalf of the controller in the course of providing the Editkraft studio: technical access to the Supabase instance operated and controlled by the controller for the purposes of preview rendering, content editing and generating homepage screenshots for the dashboard. Editkraft does not keep a persistent copy of website content; data sovereignty remains entirely with the controller. This agreement applies for the duration of the main contract and ends automatically when that contract ends.
2. Nature of processing, data and data subjects
Nature of processing: automated, technical read/write access to the database of the controller's own website (e.g. to load and save page content, translations and structural migrations). Categories of affected data and data subjects follow entirely from what the controller stores in their own website database (e.g. contact-form submissions, comments or a shop's customer data) — Editkraft has no influence over and no knowledge of the actual data content beyond the technical access itself.
One exception: the current homepage screenshot of the (publicly reachable) website is permanently stored as an image file in Editkraft's own storage bucket, in order to display a preview image in the studio dashboard. To the extent the homepage visibly displays personal data (e.g. a photo in a testimonial), it is contained in that screenshot.
3. Processing on instructions
Editkraft processes personal data solely on documented instructions from the controller. These instructions are given by using the Service within its agreed functionality (Terms, product description). Instructions exceeding the Service's functionality require text form and may be declined by Editkraft if they would violate applicable law.
4. Confidentiality
Editkraft binds everyone who may have access to data processed on behalf of the controller to confidentiality or an equivalent statutory duty of secrecy.
5. Technical and organizational measures
Editkraft implements the measures required under Art. 32 GDPR, in particular:
- End-to-end encryption of data in transit (TLS).
- The credentials for the controller's Supabase instance, entered when connecting the website, are stored encrypted at Editkraft (AES-256-GCM) and decrypted only at runtime — never logged or returned to clients.
- Tenant isolation within Editkraft's own account management (per-organization database access rules, Row Level Security).
- Payment processing via Stripe using narrowly scoped API permissions (Restricted Keys); full payment method details never reach Editkraft's systems.
- Signed, stateless, short-lived access tokens for security-sensitive flows (e.g. account recovery, cancellation confirmation).
- Rate limiting on security-sensitive endpoints.
- Logging of security-relevant actions (audit log).
Open item, disclosed here transparently:To access the controller's Supabase instance, Editkraft uses the service-role key the controller provides when connecting the website. This key is project-wide privileged (it fully bypasses the database's access rules), since Supabase currently does not offer a more narrowly scoped credential type for this use case. Editkraft limits the resulting risk through the encryption described above and by restricting which operations its own application code actually performs — not through a database-enforced permission boundary.
6. Sub-processors
Editkraft uses the following sub-processors to operate the Service: Vercel Inc. (hosting), Supabase, Inc. (database/ authentication), Stripe Payments Europe, Ltd. (payment processing) and Resend, Inc. (email delivery) — details and addresses in the Privacy Policy. Data processing agreements are in place with all four. Editkraft will inform the controller with reasonable advance notice before engaging any further sub-processor. The controller may object to a new sub-processor for good cause within 14 days; if the objection cannot be resolved through an alternative solution, either party may terminate the affected part of the Service for cause.
7. Assistance with data subject rights
Since website content resides exclusively in the controller's own Supabase instance, the controller can generally handle data subject requests (Art. 15–22 GDPR) regarding that data directly. Editkraft assists the controller on request to the extent technically possible and reasonable, for example with technical questions about the data model.
8. Notification of personal data breaches
If Editkraft becomes aware of a breach of the protection of personal data arising from this processing, Editkraft will notify the controller without undue delay and assist the controller in meeting its obligations under Art. 33 and 34 GDPR.
9. Deletion and return after contract end
After the main contract ends, Editkraft deletes all personal data arising from this processing that remains with Editkraft — in particular the homepage screenshot and the encrypted credentials for the controller's Supabase instance. Since website content itself is never stored by Editkraft, no separate return of such content is required. Statutory retention periods (6–10 years under German commercial and tax law) apply to invoicing data from completed payment transactions, as described in the Privacy Policy.
10. Controller's audit rights
The controller may request evidence of Editkraft's compliance with the measures listed in Section 5, for example through this agreement and a supplementary self-disclosure. Given Editkraft's size, an on-site audit is only possible by prior arrangement and against reimbursement of reasonable costs.
11. Final provisions
German law applies. Should individual provisions of this agreement be invalid, the validity of the remaining provisions remains unaffected. This agreement is available in German and English; the German version prevails.
Last updated: July 2026