Legal information

Data processing pursuant to Art. 28 GDPR

The following contract is concluded between the Commitly customer (controller or principal) and Commitly GmbH (processor or contractor).

PREAMBLE

Between the controller and the processor there is a contract on the use by the controller of the processor’s Commitly software described in more detail in clause 1 (hereinafter the licence agreement). The processor supports the controller in the realisation of its own business purposes in connection with the service contract – a transfer of “functions” is expressly not intended.

1. SUBJECT MATTER OF THE AGREEMENT

  1. The user has the option of connecting existing bank accounts at European financial institutions to Commitly and of preparing his finances in accordance with his business requirements and, on that basis, drawing up plans for future payment flows. The connection is made by an external service provider providing an interface between the account-holding bank and Commitly.
  2. Within the framework of the optional functions “COMMITLY Account” or “COMMITLY Card”, Commitly additionally provides the customer with technical payment services via an external payment service provider. Opening a “COMMITLY Account” with a payment function requires a successful identity check by the service provider. For this purpose Commitly transmits the necessary data to the service provider. Processing is carried out in accordance with the GDPR. The service provider may reject applications or request additional documents.
  3. As part of the connection, the list of transactions of the connected account is read out in pure read access via an automated interface. Primarily the following information is taken over: date of the transaction (value date), business partner of the transaction (sender or recipient), description of the transaction (payment reference or reference), currency, amount. Technically, additional data may be transmitted by the bank.
  4. In addition to the collection, processing and use of data on behalf of the controller as the main purpose, personal data is collected, processed or used, among other things, in the context of customer, supplier and personnel administration as well as for other purposes (e.g. looking after business partners and prospective customers, help and support, analysis and improvement of Commitly’s range of services, market analyses and marketing measures).
  5. In all other respects, the subject matter of this contract follows from the existing licence agreement, to which reference is made here (hereinafter the “licence agreement”). It concerns the processing of personal data (hereinafter “data”) by the processor for the controller in connection with the use of Commitly’s software.

2. DURATION OF THE AGREEMENT

The term of this contract corresponds to the term of the licence agreement.

3. OBLIGATIONS OF THE CONTRACTOR

  1. The contractor undertakes to process data and processing results exclusively within the framework of the principal’s documented written instructions. If the contractor receives an order from a public authority to hand over the principal’s data, he must – to the extent legally permissible – inform the principal of this without delay and refer the authority to the principal. Likewise, processing of the data for the contractor’s own purposes requires a written instruction.
  2. The contractor declares in a legally binding manner that he has obliged all persons entrusted with the data processing to maintain confidentiality before they take up their activity, or that these persons are subject to an appropriate statutory obligation of secrecy. In particular, the obligation of secrecy of the persons entrusted with the data processing continues to apply after the end of their activity and after they leave the contractor.
  3. The contractor declares in a legally binding manner that he has taken all necessary measures to ensure the security of processing pursuant to Art. 32 GDPR (details can be found in Annex 1).
  4. The contractor takes the technical and organisational measures needed to enable the principal to fulfil the rights of the data subject under Chapter III of the GDPR (information, access, rectification and erasure, data portability, objection, and automated decision-making in individual cases) at any time within the statutory time limits, and provides the principal with all the information necessary for this. If a corresponding request is addressed to the contractor and that request indicates that the applicant mistakenly regards the contractor as the principal of the data processing operated by him, the contractor must forward the request to the principal without delay and inform the applicant of this.
  5. The contractor supports the principal in complying with the obligations set out in Art. 32 to 36 GDPR (data security measures, notification of personal data breaches to the supervisory authority, notification of the person affected by a personal data breach, data protection impact assessment, prior consultation).
  6. The contractor is advised that he must set up a record of processing activities pursuant to Art. 30 GDPR for the present data processing.
  7. With regard to the processing of the data provided by him, the principal is granted the right to inspect and check the data processing facilities at any time, including through third parties commissioned by him. The contractor undertakes to make available to the principal the information necessary to check compliance with the obligations set out in this agreement.
  8. After the end of this agreement, the contractor is obliged to destroy all processing results and documents containing data on the principal’s instruction. If the contractor processes the data in a special technical format, he is obliged, after the end of this agreement, to hand over the data either in that format or, at the principal’s request, in the format in which he received the data from the principal or in another common format.
  9. The contractor must inform the principal without delay if he is of the opinion that an instruction from the principal infringes data protection provisions of the Union or of the member states.

4. TECHNICAL AND ORGANISATIONAL MEASURES

  1. The contractor obliges external data centres and other sub-processors to organise their internal operations in such a way that they meet the particular requirements of data protection. In particular, data processing takes place on data processing systems for which the data centre or the other sub-processor has taken all technical and organisational measures to protect personal data.
  2. The contractor must establish security pursuant to Art. 28 (3) (c), Art. 32 GDPR, in particular in conjunction with Art. 5 (1), (2) GDPR. Overall, the measures to be taken are measures of data security and measures to ensure a level of protection appropriate to the risk with regard to the confidentiality, integrity, availability and resilience of the systems. In doing so, the state of the art, the costs of implementation and the nature, scope and purposes of the processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons within the meaning of Art. 32 (1) GDPR are to be taken into account (details in Annex 1).
  3. The technical and organisational measures are subject to technical progress and further development. In this respect the contractor is permitted to implement alternative adequate measures. In doing so, the level of security of the measures laid down may not be undercut. Material changes are to be documented.

5. SUB-PROCESSING RELATIONSHIPS

  1. Sub-processing relationships within the meaning of this contract are to be understood as those services that relate directly to the provision of the main service. This does not include ancillary services which the processor uses, for example as telecommunications services, postal/transport services, maintenance and user service or the disposal of data carriers, as well as other measures to ensure the confidentiality, availability, integrity and resilience of the hardware and software of data processing systems. The processor is, however, obliged to take appropriate and legally compliant contractual arrangements and control measures to ensure the data protection and data security of the controller’s data in the case of outsourced ancillary services as well.
  2. Outsourcing to sub-processors or a change of the existing approved sub-processors is permissible provided that the processor notifies the controller of the planned engagement of a sub-processor in writing or in text form within a reasonable period, but at least two weeks in advance, and the controller does not object to the planned outsourcing to the processor in writing or in text form by the time the data is handed over, and provided that a contractual arrangement in accordance with Art. 28 (4) GDPR is applied. In the event of an objection by the controller, the processor has an extraordinary right of termination with regard both to this agreement and to the service agreement.
  3. The controller consents to the engagement of the sub-contractors notified in Annex 2 before the start of processing, subject to the condition of a contractual arrangement in accordance with Art. 28 (4) GDPR.
  4. If the sub-contractor provides the agreed service outside the EU/the EEA and there is no decision pursuant to Art. 45 (3) GDPR, the processor establishes permissibility under data protection law by taking sufficient adequate safeguards within the meaning of Art. 46 GDPR. The transfer of the controller’s personal data to the sub-processor and the sub-processor’s first activity are only permitted once all the conditions for sub-processing are met.

ANNEX 1 – TECHNICAL AND ORGANISATIONAL MEASURES

1. CONFIDENTIALITY (ART. 32 (1) (B) GDPR)

A. Physical access control – data centre rooms:

  • Commitly customer data is processed and stored in AWS data centres in Frankfurt. All the necessary measures pursuant to Art. 32 GDPR have been taken.

B. System access control:

  • User and administrator access to the Commitly system is based on a role-based access authorisation model. Every user receives a unique ID in order to ensure that all system components can only be used by authorised users and administrators.
  • There are technical policies on password complexity and password rotation.
  • At Commitly the principle of least privilege applies. Every user receives only the access rights required to carry out his contractual activities. User accounts are always initially set up with the fewest access rights. In order to grant access rights beyond the minimum authorisation, a corresponding authorisation must be in place.
  • Use of firewall systems, virus scanners and intrusion detection systems on Commitly server systems
  • Virus scanners containing malware detection and an email filter are installed on Commitly IT equipment (e.g. notebooks)
  • Access to Commitly server systems is SSH encrypted (“public key”) through a bastion host that limits access to network devices and other cloud components.
  • All Commitly server systems store data exclusively on encrypted data carriers.

C. Data access control:

  • Access authorisation to Commitly production systems is limited to a small group of employees (“Commitly system administrators”)
  • All access to Commitly production systems by Commitly system administrators is logged with user ID, timestamp and reason and retained for 10 years in compliance with GoBD.
  • Commitly system administrators have no access to the access logs
  • There is an internal control system that ensures that the lawfulness of access to Commitly production systems is checked regularly on a random sample basis and that these sample checks are likewise logged

D. Separation control:

  • Data records of different Commitly customers are specially marked in a single database (tenant ID, multi-tenancy on the software side).
  • Test and production data are strictly separated in independent systems; development systems are likewise independent of test and production systems
  • Different domain certificates for test and production systems

2. INTEGRITY (ART. 32 (1) (B) GDPR)

A. Transfer control:

  • Data transmission between Commitly server systems takes place exclusively within delimited subsystems shielded by bastion hosts
  • Where data is transmitted to commissioned partners, these data transmission channels are always TLS encrypted
  • Where this is technically possible, VPN connections are used
  • Where possible, data is also only passed on in anonymised or pseudonymised form
  • (e.g. Google anonymizeIP)
  • Data retrievals and transmission activities are logged

B. Input control:

  • Relevant entries and processes in Commitly are logged as a function for the customer.

3. AVAILABILITY AND RESILIENCE (ART. 32 (1) (B) GDPR)

A. Availability control:

  • Automatic backup copies and backups of all Commitly customer data are created regularly
  • There is a concept for reconstructing the data holdings and, in addition, a regular check that the backups can in fact be restored (data integrity of the backups)
  • Commitly production systems are designed with multiple redundancy

B. Rapid restorability (Art. 32 (1) (c) GDPR):

  • Server systems and databases designed with multiple redundancy
  • Backups are checked regularly for restorability

4. PROCEDURE FOR REGULAR REVIEW, ASSESSMENT AND EVALUATION (ART. 32 (1) (D) GDPR; ART. 25 (1) GDPR)

  1. Data protection management is an integral part of the processes and activities of Commitly GmbH, with corresponding planning of measures for dealing with opportunities/risks and provision of appropriate resources, competences, awareness and communication.
  2. Dedicated incident response management has not been set up, but is a fixed part of data protection management.
  3. Data protection by default (Art. 25 (2) GDPR)
  4. Commissioning control:
    • No commissioned data processing within the meaning of Art. 28 GDPR without a corresponding instruction from the controller
    • Clear, unambiguous instructions
    • Prevention of access to the data by unauthorised third parties
    • Prohibition on copying data in an impermissible manner
    • Agreements on the type of data transfer and its documentation
    • Rights of control by the principal
    • Strict selection of service providers
    • Follow-up checks

Commitly GmbH (status: 22.07.2025)

ANNEX 2 – SUB-PROCESSORS

The controller consents to the engagement of the following sub-processors, subject to the condition of a contractual arrangement in accordance with Art. 28 (24) GDPR:

No.CompanyAddressService
1BANKSapi Technology GmbH (account information service)Maximilianstraße 13, 80539 MünchenUniform interface for retrieving online banking information
2finAPI GmbH (account information service)Ainmillerstraße 11, 80801 MünchenUniform interface for retrieving online banking information
3Monite GmbH (invoice & expense management)Dircksenstraße 3,
10179 Berlin
Invoicing, expense management and receipt capture
4Swan SAS
(embedded finance / electronic money institution)

95 Avenue du Président Wilson, 93100 Montreuil, Frankreich,

Registrierungsnummer 86245

Technical provision of business accounts and business cards
5Chargebee Inc.
(subscription administration)
340 S Lemon Avenue, #1537, Walnut, California 91789, USASubscription management software
6

PayPal (Europe) S.à r.l. et Cie, S.C.A., Braintree Payments

(payment processing)

22-24 Boulevard Royal L-2449, LuxembourgProcessing of payments between Commitly and its users
7GoCardless Ltd. (direct debit & payment administration)65 Portland Place, London W1B 1NB, Vereinigtes KönigreichProcessing of payments between Commitly and its users
8Intercom Inc. (customer experience)55 2nd Street, 4th Floor, San Francisco, California, 94105, USA Medium for communication and help section within our product/products
9Amazon Web Services Inc. ("AWS Frankfurt")410 Terry Avenue North, Seattle WA 98109, USAHosting and operational tasks
10Mailchimp (newsletter management)Rocket Science Group, Leon Ave NE, Suite 500, Atlanta, GA 30308, USASending our newsletter to registered prospective customers and sending transactional emails
11Pipedrive Ireland Limited
(CRM management)
4th Floor, 7–8 Wilton Terrace, Dublin 2, IrlandCustomer communication
12Google Inc.Amphitheatre Parkway, Mountain View, CA 94043, USAInternal and external communication via email and GSuite Office
13GetStream.io
(in-app messaging & activity feeds)
548 Market St PMB 62437, San Francisco, CA 94104, USAHandling of in-app messages and activity feeds
14Flatfile Inc.
(csv, xlsx import)
1550 Wewatta St, Suite 200, Denver, CO, USAData import (xlsx, csv), mapping, validation, temporary storage of imported files (commissioned data processing)

COMMITLY data processing GDPR

20250907-Auftragsverarbeitung Art 28 – DSVGO – Commitly