[ ARTICLE 28 GDPR / AVV ]

DATA PROCESSING AGREEMENT

[DIRECTIVE] ESTABLISHING THE LEGAL FRAMEWORK FOR PROCESSING PERSONAL DATA ON BEHALF OF PARSEHOOK USERS IN STRICT COMPLIANCE WITH ARTICLE 28 GDPR.

Last updated: August 19, 2026

1. PARTIES AND SUBJECT MATTER

This Data Processing Agreement ("DPA") is entered into between:

David Krippl
c/o flexdienst – #20185
Kurt-Schumacher-Straße 76
67663 Kaiserslautern, Germany
VAT ID: DE460098852
("Processor" or "ParseHook")

and the business entity utilizing the ParseHook services ("Controller" or "Customer").

This DPA applies to business customers. If you are a consumer, the processing is governed by our Privacy Policy and statutory rights. This DPA applies to the processing of personal data by ParseHook on behalf of the Customer in connection with the ParseHook email parsing and webhook delivery services.

2. DATA CATEGORIES AND SUBJECTS

Categories of Data Subjects:

  • Customers and their authorized users (employees, contractors).
  • Third parties whose data is contained in emails processed by the Customer (e.g., leads, customers, suppliers, support contacts).

Categories of Personal Data:

  • Inventory Data: Email address, password hash, account settings.
  • Contract Data: Plan, subscription term, invoice data.
  • Content Data: Email texts, attachments, sender/recipient data, and extracted structured JSON fields. This may include personal data of third parties submitted by the Customer. ParseHook processes this data exclusively for the provision of the parsing service and not for its own purposes.
  • Usage Data: Parsed email volume, inbox names, webhook URLs, API calls, error statuses.
  • Support Data: Contents of support requests, feedback, and refund communications.
  • Payment Data: Stripe customer IDs, transaction IDs, last 4 digits of card (processed via Stripe).
  • Meta and Log Data: IP addresses, timestamps, browser type, operating system.
  • Cookie and Consent Data: Consent logs, optional device fingerprint hash (if consented).

3. PROCESSING LOGIC AND DELETION CONCEPT

ParseHook processes incoming emails in volatile memory. Raw email bodies are not permanently stored.

In the event of a webhook delivery failure, the original email is encrypted and buffered for a maximum of 24 hours for retry purposes via exponential backoff. Once delivery succeeds or the retry chain definitively fails (6 attempts), the raw data copy is automatically and irreversibly deleted. No copy exists on disk, in logs, or in backups beyond this point.

Extracted structured data (JSON) and metadata are retained in the database for the Customer to access via the dashboard. The Customer can delete all parsed data and their entire account at any time via the Self-Service portal, triggering deletion within 30 days, except where backup cycles require a longer period, in which case data is deleted from active systems immediately and from backups within the backup rotation cycle.

4. SUB-PROCESSORS

ParseHook engages the following categories of Sub-Processors to provide the service. Appropriate safeguards (e.g., Standard Contractual Clauses) are in place for international transfers where applicable.

  • Netcup GmbH: VPS Hosting and Backend Infrastructure (Germany)
  • Supabase Inc: Database, Authentication, and Storage (EU hosted)
  • Resend Inc: Email Receiving & Parsing Infrastructure (Inbound Email Processing) and Transactional Email Delivery
  • Stripe Inc: Payment Processing and Billing
  • Enterprise AI Providers: May process email content transiently for semantic extraction. Processing occurs in volatile memory and is governed by data processing agreements where available. No AI provider trains on customer data.

5. TECHNICAL AND ORGANIZATIONAL MEASURES (TOMS)

ParseHook enforces strict TOMs in accordance with Art. 32 GDPR:

  • Access Control: Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) for all administrative access.
  • Transfer Control: TLS 1.3 encryption in transit, VPN, and strict firewall policies.
  • Input Control: Comprehensive logging of system access and data processing events for auditability.
  • Availability Control: Regular backups, continuous monitoring, and automated failover mechanisms.
  • Pseudonymization & Encryption: AES-256 encryption at rest for buffered data and HMAC-SHA256 webhook signatures.
  • Regular Review: Periodic security reviews, penetration testing, and audits of internal processes.

Core parsing and storage infrastructure is hosted in Germany. Ancillary services such as payment processing, email delivery, and AI processing may operate internationally under appropriate safeguards (e.g., Standard Contractual Clauses).