Data Processing Agreement (DPA)

Data processing agreement pursuant to Art. 28 GDPR for tour-flow customers.


Last updated: October 2026

This English version is provided for information only. The German version is legally binding.

This Data Processing Agreement (“DPA”) is entered into between

the tour-flow customer (holder of a tour-flow account or workspace with an active service agreement) – hereinafter the “Controller” –

and

Lauritz Leiber, sole proprietor
Ernst-Barlach-Str. 2A, 76227 Karlsruhe, Germany
Email: it@tour-flow.net – hereinafter the “Processor” –


Preamble

The Processor provides the Controller with tour-flow, a software-as-a-service platform (web app and mobile app) for planning and organizing tours, events and productions (the “Main Agreement”, consisting of the Terms & Conditions and the selected plan).

When using tour-flow, the Controller stores and processes personal data of third parties, e.g. crew members, artists, contacts and guests. With regard to this data, the Processor acts solely on behalf of and on the instructions of the Controller. This DPA sets out the parties’ data protection obligations pursuant to Art. 28 of the General Data Protection Regulation (“GDPR”).

Where the Processor processes data for its own purposes as a controller (in particular account data for contract performance, billing, website visits and the newsletter), only the Privacy Policy applies.


§ 1 Conclusion and Scope

  1. This DPA is concluded in electronic form (Art. 28 (9) GDPR). It takes effect as soon as the Controller enters into the Main Agreement or uses tour-flow to process personal data of third parties, and forms part of the Main Agreement.
  2. If the Controller requires a countersigned copy, it can request one by email to it@tour-flow.net.
  3. In the event of conflict between this DPA and the Main Agreement, this DPA prevails with respect to data protection.

§ 2 Subject Matter, Duration, Nature and Purpose of Processing

  1. Subject matter is the provision, operation, maintenance and support of tour-flow. Details of the nature and purpose of processing, the types of data and the categories of data subjects are set out in Annex 1.
  2. Duration: This DPA applies for the term of the Main Agreement. It ends automatically with the Main Agreement but continues to apply for as long as the Processor still processes personal data of the Controller.
  3. Processing generally takes place within the European Union or the European Economic Area. Transfers to third countries take place only under the conditions of § 8.

§ 3 Controller’s Instructions

  1. The Processor processes personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law. In that case, the Processor informs the Controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
  2. Instructions are given conclusively by this DPA, the Main Agreement and the Controller’s use of tour-flow’s features and settings (e.g. creating, sharing or deleting data). Further instructions are given in text form (e.g. by email).
  3. The Processor informs the Controller immediately if, in its opinion, an instruction infringes data protection law. The Processor may suspend execution of the instruction until the Controller confirms or changes it.
  4. Instructions that go beyond the contractually agreed scope of services are treated as a request for a change of services.

§ 4 Obligations of the Controller

  1. The Controller is solely responsible for the lawfulness of the processing, in particular for having a legal basis and for informing data subjects (Art. 13, 14 GDPR).
  2. The Controller ensures that it does not process special categories of personal data (Art. 9 GDPR, e.g. health data such as allergies, or identity documents containing biometric data) in tour-flow without a legal basis for doing so. Such data is not the subject of tour-flow’s standard features but may be contained in free-text fields, notes, chats or uploaded files.
  3. The Controller informs the Processor immediately if it detects errors or irregularities regarding data protection provisions.

§ 5 Obligations of the Processor

  1. Confidentiality: The Processor ensures that all persons authorized to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28 (3) (b) GDPR). This obligation continues after their engagement ends.
  2. Security of processing: The Processor implements the technical and organizational measures required under Art. 32 GDPR (Annex 2). The measures are subject to technical progress; the Processor may replace them with equivalent or better measures provided the level of protection is not reduced.
  3. Data breaches: The Processor notifies the Controller of a personal data breach without undue delay, and no later than 48 hours after becoming aware of it, by email to the address stored in the account. The notification contains, to the extent known, the information set out in Art. 33 (3) GDPR. The Processor promptly takes appropriate measures to contain and remedy the breach.
  4. Contact for data protection matters is Lauritz Leiber, it@tour-flow.net. The Processor is not required to appoint a data protection officer (§ 38 BDSG). Should this change, the Processor will provide the Controller with the officer’s contact details.
  5. The Processor maintains a record of processing activities pursuant to Art. 30 (2) GDPR where legally required.
  6. The Processor does not use the Controller’s data for its own purposes, in particular not for advertising or for training AI models.

§ 6 Assistance to the Controller

  1. Data subject rights: Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organizational measures, insofar as possible, in responding to requests from data subjects (Art. 12–23 GDPR). The Controller can view, correct and delete most data directly in tour-flow. The Processor provides a copy of the data on request (§ 10 (1)).
  2. If a data subject contacts the Processor directly, the Processor refers them to the Controller where attribution is possible and forwards the request without undue delay.
  3. Taking into account the nature of processing and the information available to it, the Processor assists the Controller in complying with its obligations under Art. 32–36 GDPR (security, breach notification, data protection impact assessment, prior consultation).
  4. The Processor may charge reasonable compensation for assistance that goes beyond providing tour-flow’s features and is not caused by a breach on the Processor’s part.

§ 7 Sub-processors

  1. The Controller grants the Processor general authorization to engage further processors (“Sub-processors”). The Sub-processors engaged at the time of conclusion are listed in Annex 3 and are deemed approved.
  2. The Processor informs the Controller at least 30 days before adding or replacing a Sub-processor, by email or by updating this page together with an email notification. The Controller may object to the change in text form within this period on reasonable data protection grounds. If the parties cannot reach agreement, the Controller may terminate the Main Agreement for cause effective as of the date the change takes effect. Fees already paid for the period after termination are refunded pro rata.
  3. The Processor imposes on each Sub-processor by contract substantially the same data protection obligations as set out in this DPA (Art. 28 (4) GDPR). Where a Sub-processor fails to fulfil its obligations, the Processor remains liable to the Controller in accordance with Art. 28 (4) sentence 2 GDPR.
  4. Ancillary services used by the Processor that do not require access to the Controller’s personal data (e.g. pure telecommunication services) do not constitute sub-processing within the meaning of this section.

§ 8 Transfers to Third Countries

  1. Personal data is transferred to a country outside the EU or EEA only if the specific conditions of Art. 44 et seq. GDPR are met.
  2. Transfers are based in particular on
    • an adequacy decision of the European Commission (Art. 45 GDPR), for the USA in particular the decision on the EU-U.S. Data Privacy Framework, insofar as the respective recipient is certified under it, and/or
    • the European Commission’s Standard Contractual Clauses pursuant to Implementing Decision (EU) 2021/914 (Art. 46 (2) (c) GDPR), supplemented by additional safeguards where necessary.
  3. The applicable basis for each Sub-processor is stated in Annex 3. Should a transfer mechanism cease to be valid (e.g. due to a ruling of the Court of Justice of the European Union), the Processor will switch to another permissible basis without undue delay and inform the Controller.

§ 9 Evidence and Audits

  1. The Processor makes available to the Controller on request all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR.
  2. Evidence may be provided in particular through self-assessments, documentation of the technical and organizational measures, and certifications and audit reports of the Sub-processors used (e.g. SOC 2, ISO 27001).
  3. If such evidence is insufficient in an individual case, the Controller may, with at least 30 days’ prior notice, during normal business hours, without disrupting operations and no more than once per calendar year, conduct an audit itself or have it conducted by an auditor bound by confidentiality. Audits triggered by a data breach or ordered by a supervisory authority remain unaffected. The auditor must not be a competitor of the Processor.
  4. The Controller bears the costs of an on-site audit unless it reveals a material breach by the Processor.

§ 10 Deletion and Return after Termination

  1. The Controller can delete its data at any time during the term via tour-flow’s features. On request by email to it@tour-flow.net, the Processor provides the Controller with a copy of its data in a common, machine-readable format (e.g. JSON or CSV), including uploaded files, within 30 days. This also applies to requests made within 30 days after termination.
  2. After termination of the Main Agreement or deletion of the account, the Processor deletes all personal data of the Controller within 30 days, unless Union or Member State law requires storage. On request, the Processor confirms deletion in text form.
  3. Data in backups is overwritten or deleted in the regular rotation cycle, at the latest 30 days after deletion from production systems. Until then it is protected from any further processing.
  4. Data stored by other workspace members in their own workspaces is not covered by this deletion insofar as they are themselves controllers of that data.

§ 11 Liability

The parties’ liability towards data subjects is governed by Art. 82 GDPR. As between the parties, the liability provisions of the Main Agreement apply unless mandatory statutory provisions provide otherwise.


§ 12 Final Provisions

  1. Amendments to this DPA must be made in text form. The Processor may amend this DPA where required by changes in law or a change of Sub-processors (§ 7), provided the level of protection for the Controller is not reduced.
  2. Should any provision of this DPA be or become invalid, the validity of the remaining provisions remains unaffected. The invalid provision is replaced by the legally permissible provision that comes closest to its purpose.
  3. This DPA is governed by the laws of the Federal Republic of Germany. Place of jurisdiction is Karlsruhe, to the extent legally permissible.
  4. The German version of this DPA is authoritative. The English version is for information only.

Annex 1 – Description of Processing

Nature and purpose of processing

Storing, organizing, displaying, synchronizing between the web and mobile app, making available to people invited by the Controller, sending notifications (email, push) and deleting data for the Controller’s tour, event and production planning. This includes in particular:

  • Tour and event planning (schedules, rundowns, setlists, production data, checklists, tasks)
  • Crew and contact management, invitations and crew requests
  • Travel and accommodation planning (flights, travel days, hotels, routes)
  • Guest lists including QR check-in
  • Communication (chats, crew messages, comments) and notifications
  • Sharing tour booklets with recipients
  • Storing uploaded files and audio recordings
  • Tour financial planning
  • AI-assisted recognition of content from text pasted by the Controller (“Smart Paste”), if the Controller uses this feature
  • Support, error analysis and ensuring system security

Categories of data subjects

  • Users and workspace members of the Controller
  • Crew members, artists, musicians and technicians
  • Contact persons (e.g. promoters, venues, hotels, agencies, service providers)
  • Guests on guest lists
  • Recipients of shared booklets and notifications

Categories of personal data

  • Master and contact data: name, role/position, email address, phone number, company, profile picture
  • Planning and assignment data: assignment to tours and events, schedules, tasks, notes
  • Travel and accommodation data: flight numbers and times, itineraries, hotels and room assignments, addresses
  • Guest list data: first and last name, email, phone, company, access type, number of tickets, check-in time
  • Communication data: content of chats, messages, comments and reactions
  • Content of uploaded files and audio recordings
  • Tour financial data (e.g. fee and cost items), no payment card data
  • Technical data: device and push tokens, notification settings, log and activity data, IP addresses

Special categories of personal data (Art. 9 GDPR) are not processed as a matter of course, see § 4 (2).


Annex 2 – Technical and Organizational Measures (Art. 32 GDPR)

1. Confidentiality

  • Physical access control: No own server rooms. All systems run in data centers of the Sub-processors (Annex 3), which maintain physical access controls in line with ISO 27001 or SOC 2.
  • System access control: Passwords are stored only as bcrypt hashes. Optional two-factor authentication, sign-in via Google OAuth, bot protection on registration and sign-in (Cloudflare Turnstile), rate limiting of sign-in and API requests, automatic lockout after repeated failed verification-code attempts. Administrative access to infrastructure services is protected with two-factor authentication.
  • Data access control: Tenant separation by workspace; role-based permissions (Admin, Editor, Viewer) and server-side workspace membership checks on every request. Files are delivered via signed URLs. The Processor accesses production data only where necessary for operation, support or troubleshooting.
  • Separation control: Logical separation of different customers’ data; separate development and production environments. Development does not use production data.
  • Encryption: All data in transit is encrypted (TLS/HTTPS). Data at rest in the database and file storage is encrypted by the respective providers. API keys stored by users are additionally encrypted with AES-256-GCM.

2. Integrity

  • Transfer control: Encrypted transmission (TLS), signed webhooks and job calls, no disclosure to third parties other than the Sub-processors listed in Annex 3.
  • Input control: Logging of relevant actions in an activity log (without logging user content) and logging of email and notification deliveries.

3. Availability and Resilience

  • Operation on redundant cloud infrastructure with automatic scaling
  • Point-in-time recovery for the database, redundant file storage at the storage provider (erasure coding)
  • Review of server and error logs, abuse protection via rate limiting

4. Regular Review

  • Regular dependency updates and application of security patches
  • Code reviews and automated tests before releases
  • Regular internal security reviews of authentication and authorization logic
  • Privacy by default (Art. 25 GDPR): data is visible only within the user’s own workspace by default; sharing requires an active step.
  • Selection of Sub-processors taking their security certifications into account, and conclusion of data processing agreements with them

Annex 3 – Sub-processors

Sub-processorServiceLocation of processingTransfer mechanism
Neon Inc., San Francisco, USAPostgreSQL database (storage of all application data)EU – Frankfurt am Main (AWS eu-central-1)For support and remote access: EU-U.S. Data Privacy Framework / Standard Contractual Clauses
Backblaze, Inc., San Mateo, USAStorage of uploaded files, profile pictures and audio recordingsEU – Amsterdam (eu-central)For support and remote access: EU-U.S. Data Privacy Framework / Standard Contractual Clauses
Vercel Inc., San Francisco, USAHosting of the web app and server functions, content deliveryEU – Frankfurt am Main (fra1); static content delivered via global edge networkEU-U.S. Data Privacy Framework / Standard Contractual Clauses
Cloudflare, Inc., San Francisco, USAFile delivery (CDN), bot protection (Turnstile)Global edge network, usually nearest data centerEU-U.S. Data Privacy Framework / Standard Contractual Clauses
Supabase, Inc., San Francisco, USAReal-time sync and presence (transient transmission, no persistent storage)EU – Frankfurt am Main (AWS eu-central-1)For support and remote access: Standard Contractual Clauses
Upstash, Inc., Delaware, USAQueue for scheduled background jobs (notifications)EU – Frankfurt am MainFor support and remote access: Standard Contractual Clauses
Plus Five Five, Inc. (Resend), San Francisco, USASending system emails (invitations, notifications, booklets)USAEU-U.S. Data Privacy Framework / Standard Contractual Clauses
650 Industries, Inc. (Expo), Palo Alto, USADelivery of push notifications to the mobile appUSAStandard Contractual Clauses
Apple Inc. / Apple Distribution International Ltd., IrelandDelivery of push notifications and Live Activities to iOS devices (APNs)USA / worldwideEU-U.S. Data Privacy Framework / Standard Contractual Clauses
Google Cloud EMEA Ltd., Ireland / Google LLC, USAAI text recognition “Smart Paste” (Gemini API, only when the feature is used), address and place search, maps and routes (Google Maps Platform), push delivery to Android devices (Firebase Cloud Messaging)EU / USAEU-U.S. Data Privacy Framework / Standard Contractual Clauses

Not acting as Sub-processors: Payment processing via Stripe concerns only the contractual relationship between the Controller and the Processor; Stripe acts as an independent controller. For flight status lookups (FlightAware), only flight numbers and dates are transmitted, no personal data.