Data Processing Agreement

Auftragsverarbeitungsvertrag (AVV) per Art. 28 GDPR / § 62 BDSG

How this works: this page publishes the DPA that applies between Lifub (processor) and a business customer (controller) when the customer uses a service through which Lifub processes personal data on the customer's behalf — currently, Page Finder (website crawling + search), the IP Whois & Geolocation API when used against end-user IPs, and Site Audit when a controller directs Lifub to audit a public page that the controller owns or is expressly authorized to audit.

Accepting our Terms of Service incorporates this DPA as Art. 28 GDPR terms. If your organisation requires a signed paper copy on your template, email info@lifub.com.

1. Parties

Processor
Alexander Orlov (natural person, trading as "Lifub"), Clementine-von-Braunmühl-Weg 11, 81541 München, Germany (see Imprint).
Controller
The business customer using the service under these Terms, as identified in any applicable service order, Site Audit checkout record, or documented request.

2. Subject, nature, and purpose of processing

3. Categories of data subjects and data

4. Duration

Page Finder and IP Intelligence processing lasts for the service agreement plus up to 30 days for deletion and handover. Each server-stored Site Audit report or snapshot expires no later than 90 days after capture and may be deleted sooner on a valid controller instruction identifying its bearer UUID; the service term does not extend that 90-day TTL.

5. Obligations of the processor (Art. 28(3) GDPR)

  1. Process personal data only on documented instructions from the controller, including as set out in the service order and this DPA.
  2. Ensure persons authorised to process the data are bound by confidentiality.
  3. Implement appropriate technical and organisational measures (Annex A).
  4. Engage sub-processors only under the conditions in § 6 below.
  5. Assist the controller with data-subject requests (Art. 12–23 GDPR) and with Art. 32–36 obligations.
  6. On termination, delete or return all personal data unless EU or Member-State law requires retention.
  7. Make available all information necessary to demonstrate compliance and allow audits, including inspections, conducted by the controller or an independent auditor (§ 9).
  8. Notify the controller without undue delay of any personal data breach affecting the controller's data.
  9. Immediately inform the controller if, in the processor's opinion, an instruction infringes the GDPR or other EU / Member-State data-protection law.

6. Sub-processors

The controller grants general written authorisation for engagement of the following sub-processors:

The processor will inform the controller of any intended changes via the email address on file, giving the controller a 14-day objection period. If the controller objects on reasonable grounds, the controller may terminate the affected part of the service.

7. International transfers

The processor's own operational processing — hosting, indexing, metering and mail delivery — occurs within the EU, and every sub-processor named above is an EU or EEA entity. A sub-processor may nonetheless use infrastructure or sub-processors of its own outside the EEA; where such a transfer is unavoidable it is safeguarded by Art. 46 GDPR Standard Contractual Clauses.

8. Technical and organisational measures (Annex A)

9. Audits

Controller may audit the processor's compliance on 30 days' notice, no more than once per year unless a material breach has occurred. Audits are conducted at the controller's expense. The processor may fulfil its audit obligation by providing up-to-date third-party certifications or attestations.

10. Liability & jurisdiction

Liability follows the limits set out in the main Terms of Service § 11. German law applies; jurisdiction München, insofar as permitted between Kaufleute / juristische Personen per § 38 ZPO.