Clusterward
Clusterward

Framework data processing agreement

Under Art. 28 GDPR, with service annex A (Clusterward). Last updated: 1 October 2026.

This English version is provided for convenience. Only the German version is legally binding.

Processor ("Provider"): BitKollegen GmbH, Drostestraße 16, 30161 Hannover, Germany, Hannover Local Court (Amtsgericht Hannover), HRB 224980

Controller ("Customer"): the company that uses or commissions one or more services of the Provider on the basis of a service contract.

Structure of this agreement

This framework agreement ("Framework DPA") governs uniformly the data protection obligations for all services of the Provider in which it processes personal data on behalf of the Customer. It consists of:

  • the framework part (§§ 1 to 12),
  • Annex 1: General technical and organisational measures,
  • the service annexes A (Clusterward), B (DeskGenie), C (Compliance Master) and D (custom development, team extension and operations).

The framework part, Annex 1 and the service annexes of the services the Customer has commissioned become part of the contract.

This page contains service annex A (Clusterward).

Framework part

§ 1 Subject matter, service annexes and term

(1) The Provider provides services to the Customer on the basis of one or more contracts ("Service Contract"), for example a subscription to a software-as-a-service platform or a development or operations assignment. Insofar as it processes personal data on behalf of the Customer in doing so, this Framework DPA applies.

(2) The service annex of the respective service describes the subject matter, nature and purpose of the processing, the types of personal data, the categories of data subjects, service-specific measures and the sub-processors engaged.

(3) If the Customer commissions a further service for which a service annex exists, that annex becomes part of the Framework DPA when the Service Contract is concluded, without a new agreement being required. For services without a service annex, the parties agree on one in text form before the Provider processes personal data.

(4) The Framework DPA applies as long as a Service Contract exists and beyond that as long as the Provider processes personal data of the Customer. If an individual Service Contract ends, only the associated service annex ends.

(5) Data that the Provider processes as a controller in its own right is not subject to this Framework DPA, in particular contract, billing and communication data relating to the business relationship. The Provider's privacy policy applies to such data.

(6) The Framework DPA becomes part of the contract by reference in the Service Contract or in the Provider's general terms and conditions and takes effect when the first Service Contract is concluded, without a separate signature being required. At the Customer's request, the parties additionally sign it, also in electronic form.

§ 2 Roles of the parties

(1) The Customer is the controller within the meaning of Art. 4 No. 7 GDPR; the Provider is the processor.

(2) If the Customer in turn processes the data on behalf of third parties – for example a law firm for its clients or a software provider for its customers – the Provider is to that extent a further processor of the Customer within the meaning of Art. 28 para. 4 GDPR. The Customer ensures that its agreements with these third parties permit the use of the Provider under the terms of this Framework DPA and passes their instructions on to the Provider. The Provider accepts instructions only from the Customer.

(3) Services that the Customer uses in its own name with third parties – for example its own cloud projects, its own Microsoft 365 tenant or its own accounts with connected services – are not part of the Provider's services. Their operators are processors of the Customer, not sub-processors of the Provider. If the Provider accesses such services with the Customer's credentials, this access is processing on behalf under this Framework DPA.

§ 3 Instructions of the Customer

(1) The Provider processes personal data only on documented instructions from the Customer, unless it is required to do so by Union or Member State law. In that case, it informs the Customer of the legal requirement before processing, unless the law prohibits this.

(2) The instructions result from the Service Contract, this Framework DPA and the actions that the Customer and its users trigger in software of the Provider. The Customer issues further instructions in text form. It confirms oral instructions in text form without undue delay.

(3) If the Provider considers an instruction to infringe data protection law, it informs the Customer without undue delay. It may suspend execution until the Customer confirms or changes the instruction.

§ 4 Obligations of the Provider

(1) The Provider uses only persons who have committed themselves to confidentiality or are subject to a statutory obligation of secrecy. They receive only the access their task requires.

(2) The Provider takes the technical and organisational measures under Art. 32 GDPR described in Annex 1 and the respective service annex. It may develop them further as long as the level of protection does not decrease. It documents material changes.

(3) The Provider assists the Customer with appropriate measures in responding to requests from data subjects under Chapter III GDPR. If a data subject contacts the Provider directly, it forwards the request to the Customer without undue delay.

(4) The Provider assists the Customer with the obligations under Art. 32 to 36 GDPR, in particular with data protection impact assessments and the consultation of the supervisory authority, insofar as it has the necessary information.

(5) The Provider has not appointed a data protection officer, as there is no legal obligation to do so. The contact for data protection is the managing director Florian Apel, reachable at [email protected]. If the Provider appoints a data protection officer in the future, it informs the Customer of their contact details in text form.

§ 5 Obligations of the Customer

(1) The Customer is responsible for the lawfulness of the processing and for safeguarding the rights of the data subjects.

(2) The Customer informs the Provider in advance if it has special categories of personal data under Art. 9 GDPR or data relating to criminal convictions under Art. 10 GDPR processed, unless the service annex already provides for this.

(3) The Customer informs the Provider without undue delay if it detects errors or irregularities in the processing.

§ 6 Notification of personal data breaches

(1) The Provider notifies the Customer of a personal data breach affecting the Customer's data without undue delay, at the latest within 24 hours after becoming aware of it.

(2) The notification contains, as far as known, the information under Art. 33 para. 3 GDPR. The Provider provides missing information as soon as it is available.

(3) The Provider takes measures without undue delay to contain the breach and mitigate its adverse effects and coordinates them with the Customer.

§ 7 Sub-processors

(1) The Customer grants a general authorisation for the engagement of further processors. The service annex names the sub-processors engaged when the contract is concluded. They are deemed approved. Companies affiliated with the Provider are also deemed sub-processors insofar as they process personal data of the Customer.

(2) The Provider informs the Customer in text form at least 30 days in advance of any intended addition or replacement of a sub-processor. The Customer may object within this period for an important reason under data protection law. If the parties do not reach agreement, the Customer may terminate the affected Service Contract extraordinarily as of the date of the change.

(3) The Provider contractually obliges every sub-processor to a level of protection that corresponds to this Framework DPA. It is liable to the Customer for the sub-processor's performance of its obligations.

(4) Ancillary services such as telecommunications, postal and transport services or the disposal of data carriers are not sub-processing within the meaning of this provision, insofar as personal data of the Customer is not specifically accessed. The Provider also takes appropriate precautions for these.

§ 8 Place of processing and transfer to third countries

(1) The Provider processes personal data of the Customer in principle in the European Union or the European Economic Area. The service annex names the places of processing.

(2) A transfer to a third country takes place only if the conditions of Art. 44 et seq. GDPR are met, for example by an adequacy decision of the European Commission or by standard contractual clauses. The service annex states the recipient, country and basis of each such transfer.

(3) Remote access to the Customer's data from a third country, for example in support, operations or development, also counts as a transfer.

§ 9 Evidence and audits

(1) The Provider demonstrates compliance with its obligations on request, primarily through current certificates, in particular the ISO/IEC 27001 certificate for the Provider's company, through audit reports or by answering a questionnaire of the Customer.

(2) If this evidence is not sufficient in an individual case, the Customer may carry out on-site audits or have them carried out by an auditor bound to secrecy. It announces them at least 30 days in advance. Audits take place during business hours, do not disrupt operations disproportionately and protect the data of other customers. As a rule, one audit per calendar year is sufficient, unless there is a specific reason.

(3) The Customer bears its own costs for on-site audits. The Provider does not charge its effort for one audit per calendar year of up to one working day; the Customer pays for any further effort at the hourly rates of the Service Contract. If the audit establishes a breach of duty by the Provider, the Provider bears its own effort.

§ 10 Deletion and return

(1) After the end of a Service Contract, the Provider returns the personal data of the affected service to the Customer on request, in the form described in the service annex. It then deletes the data, at the latest 30 days after the end of the contract, unless Union or Member State law requires storage.

(2) Backup copies are overwritten after their regular retention period has expired. The service annex names the periods.

(3) The Customer fulfils its own retention obligations, for example under commercial or tax law. It secures the data required for this before the end of the contract.

(4) The Provider confirms the deletion in text form on request.

§ 11 Liability

(1) The liability of the parties towards data subjects is governed by Art. 82 GDPR.

(2) As between the parties, the liability rules, including the limitations of liability, of the respective Service Contract apply to claims arising from or in connection with this Framework DPA, to the extent permitted by law.

§ 12 Final provisions

(1) In the event of contradictions, in matters of data protection this Framework DPA takes precedence over the Service Contract, and the service annex takes precedence over the framework part.

(2) For the respective service, this Framework DPA replaces earlier data processing agreements between the parties.

(3) Amendments and additions must be made in text form.

(4) Should a provision be invalid, the rest remains valid. The invalid provision is replaced by a provision that meets the requirements of Art. 28 GDPR.

(5) German law applies. The place of jurisdiction is Hannover, insofar as the Customer is a merchant.

Annex 1: General technical and organisational measures

These measures apply to all services of the Provider. The respective service annex describes service-specific measures.

Organisation and management

  • Information security management system in accordance with ISO/IEC 27001:2022. The certificate applies to the Provider's company and covers the provision of IT services including software-as-a-service and cloud services; the individual products are not certified separately.
  • An information security officer is appointed. Risks are assessed regularly and the policies are reviewed annually.
  • Quality management in accordance with ISO 9001:2015, certified for the same scope of services. In addition, registrations under ISO/IEC/IEEE 12207:2017 (software life cycle) and ISO/IEC 25000:2014 (product quality).
  • All employees and service providers engaged are committed to confidentiality before starting their work.
  • Training on data protection and information security at least once a year.
  • Documented procedure for handling security incidents and personal data breaches.
  • Inventory of IT devices and software with a responsible person; information is classified according to its protection needs.

Confidentiality

  • Physical access control: All production systems run in data centres of Scaleway SAS in Amsterdam, Netherlands, with their certified physical access controls; emails are sent via Scaleway Transactional Email in Paris, France. The Provider does not operate its own servers.
  • Workplaces: The Provider does not operate its own office or server rooms with personal data of customers; employees work from home or in a coworking space. Screens are locked when leaving the workplace and automatically after a short period of inactivity; confidential documents and portable devices are not left unattended.
  • System access control: Access only with a personal account. Administrative access to production systems is protected with a second factor.
  • Data access control: Rights according to the principle of least privilege. Only persons whose task requires it receive access to production data. Authorisations are reviewed regularly and withdrawn when someone leaves or changes tasks.
  • Separation control: Each customer and each tenant receives its own database, its own storage in Scaleway Object Storage and its own IAM credentials. Data of different customers or tenants never resides in the same database or the same storage. Development and testing take place separately from production.
  • Encryption: Transmissions over public networks are encrypted (TLS). Credentials and secrets are stored encrypted.

Integrity

  • Transfer control: Personal data is only transmitted in encrypted form and is not copied to private devices or data carriers. Data carriers are securely erased or destroyed before disposal or reuse.
  • Input control: Sign-ins, administrative changes to production systems and changes to accounts and authorisations are logged with time and user ID.

Availability and resilience

  • Regular backups of the production systems. The service annex names the frequency and retention.
  • Monitoring of the production systems with notification in the event of outages.
  • Security updates are installed promptly; end devices are protected against malware.

Procedures for regular review

  • Internal audits and external certification audits as part of the ISO certifications.
  • Automated checks and code reviews before every release.
  • Privacy-friendly default settings in the Provider's products.

Service annex A: Clusterward

A.1 Subject matter, nature and purpose

The Provider makes Clusterward available to the Customer as software-as-a-service: a control plane ("workspace") with which the Customer sets up and operates Kubernetes clusters, applications, databases, object storage, domains and certificates in its own Scaleway projects. The processing comprises the provision, operation, maintenance and support of Clusterward, in particular:

  • storing the configuration of a workspace: users, roles, clusters, applications, environments, databases, buckets, domains, certificates and pipelines
  • executing the actions that the Customer's users trigger: deployments, builds, database and bucket management, imports and the onboarding and offboarding of tenants
  • displaying status, metrics and logs from the Customer's infrastructure and recording the usage of the applications and availability checks of their domains
  • read-only queries in the Customer's databases via the SQL console, triggered by the Customer's users; the results are only displayed and not stored
  • backing up databases and buckets during the offboarding of a tenant and providing them for download
  • nightly backups of the Customer's buckets into a backup bucket with Object Lock in the Scaleway project and region the Customer chooses; restoring a backup into a new bucket or as a single file; monthly restore tests in which a sample is read back and checked
  • creating reports and evidence for the Customer's audits, in particular access overviews, access reviews, backup evidence and change and audit logs
  • sending notifications to channels the Customer sets up
  • support at the Customer's request

A.2 The Customer's infrastructure

Clusters, databases, buckets and applications that the Customer manages with Clusterward run in the Customer's Scaleway projects on the basis of its own contract with Scaleway SAS. To that extent, Scaleway is a processor of the Customer (§ 2 para. 3). The same applies to further services that the Customer connects with its own credentials, in particular DNS zones at Cloudflare or Scaleway DNS, Git repositories and GitHub Actions and Scaleway Secret Manager: their operators are processors of the Customer, not sub-processors of the Provider. This also applies to the backup bucket of the nightly bucket backups: it resides in a Scaleway project of the Customer and in the region the Customer chooses during setup (Amsterdam, Paris or Warsaw). Clusterward accesses this infrastructure with the credentials the Customer stores, for example to roll out applications, create databases, display logs or back up data.

A.3 Types of personal data

  • User data of the workspace: email address, role and permissions, password as a hash, encrypted secret for two-factor sign-in and hashed recovery codes
  • Usage and log data: sessions with IP address and browser identifier, sign-in attempts, audit log with user, action, affected object and time, signed access reviews; for the SQL console additionally the query text and parameter values, which may contain personal data, and saved queries
  • Credentials and configuration: cloud keys, Kubernetes credentials, Git and DNS tokens, database credentials and environment variables of the applications; they are stored encrypted and may contain personal data
  • Tenant data: names, identifiers, domains and inputs that the Customer records when onboarding its own customers
  • Content data of the Customer's applications: contents of databases and buckets processed during backups, restores, restore tests, imports and offboardings, and log output of the applications displayed in Clusterward; which personal data it contains is determined solely by the Customer
  • Notification data: email addresses and webhook addresses of the notification channels

The Provider processes special categories of personal data only insofar as the Customer processes them in its applications (§ 5 para. 2).

A.4 Categories of data subjects

  • employees and agents of the Customer who use Clusterward
  • customers, clients and end users of the Customer whose data is stored in the Customer's applications
  • recipients of notifications

A.5 Service-specific measures

  • Sign-in: personal account, password with at least 12 characters and a mandatory second factor (TOTP); passwords hashed with bcrypt; an account is locked for 15 minutes after 5 failed attempts, except for sign-ins from an address the account holder has used before; an IP address is blocked for one hour after 20 failed attempts within 15 minutes, and for one day if this recurs within a week; an email to the user on a sign-in from a new address; sessions end after 2 hours of inactivity and at the latest after 12 hours
  • IP restriction: The Customer can restrict access to its workspace to its own address ranges.
  • Permissions: roles per area with the levels none, view, operate and manage, plus restriction to individual applications; functions that have not been granted are blocked
  • Separation: Each workspace has its own database, its own data key and its own backup storage in Scaleway Object Storage with its own IAM credentials.
  • Encryption: credentials, tokens, environment variables and database passwords with AES-256-GCM; credentials can no longer be read out after they have been saved.
  • Minimal rights in customer clusters: a dedicated service account which, from Kubernetes 1.30, may only write in and read secrets of the namespaces Clusterward has created for the Customer's environments; policies in the cluster enforce this. Administrator access is fetched from Scaleway only when needed and is valid for one hour.
  • Logging: Every change and every SQL console query is recorded in the audit log, never secret values. Entries are deleted after 12 months.
  • SQL console: a dedicated read-only login per database, every query in a read-only transaction, a permission of its own, blocked for API tokens; results are never stored.
  • Backups before deletion: Before a database or bucket is deleted during offboarding, a backup is created and verified; without a successful backup, nothing is deleted. Download links for backups are valid for 5 minutes.
  • Bucket backups: Every night, the objects that have changed since the last backup are copied. The copy passes through the Clusterward platform in Amsterdam without being stored there. The backup bucket has Object Lock in "governance" mode (default) or "compliance" mode; the Customer chooses a retention between 7 and 365 days (default 30 days). The nightly backup key can write objects but cannot delete them. A restore only writes into a new bucket, never into the running one; single files are provided via links valid for 5 minutes. Each backed-up bucket is checked monthly with a sample; a failed or missing backup is reported.
  • Backups of the platform: automatic backups of the managed databases at Scaleway in Amsterdam; backups are kept for 7 days and then overwritten on a rolling basis.

A.6 Places of processing and sub-processors

  • Scaleway SAS, 8 rue de la Ville l'Évêque, 75008 Paris, France: hosting of the Clusterward platform, managed databases and object storage; place of processing: Amsterdam, Netherlands
  • Scaleway SAS, 8 rue de la Ville l'Évêque, 75008 Paris, France: sending emails via Scaleway Transactional Email; place of processing: Paris, France (invitations, password links and notifications)
  • Support: via a DeskGenie operated by the Provider itself at Scaleway; no further service provider

The addresses of the workspaces are resolved via DNS without an intermediate proxy; traffic goes directly to the platform without any further service provider. No transfer to a third country takes place. Support, operations and development with access to personal data of the Customer take place exclusively from within the European Union.

A.7 Return and deletion

During the term of the contract, the Customer can delete its data in Clusterward itself and export the configuration of its workspace as a file at any time. After the end of the contract, the Provider provides this export on request within 30 days and then deletes the workspace database, data key and backup storage of the workspace, including the database and bucket backups stored during offboarding, as well as the backup key of the nightly bucket backups. Applications, databases and buckets in the Customer's Scaleway projects remain untouched; this includes the backup bucket of the nightly backups. Its copies expire with the retention the Customer has chosen; in "compliance" mode nobody can delete them earlier, not even the Provider. The Customer decides on requests from data subjects for erasure that concern these copies.