This is an English translation for your convenience. The German version is legally binding.Read the German version
Data processing agreement (DPA)
If you use RedeStudio to write speeches for clients, we process their personal data on your behalf. For this, we conclude a data processing agreement with you under Art. 28 GDPR. It is part of RedeStudio Pro.
You can conclude the DPA online in your account; we store the time of acceptance. Alternatively, download the template.
Last updated: 27 September 2026 [[ZU PRÜFEN: have the entire agreement legally reviewed before publication]]
Data processing agreement under Art. 28 GDPR
between the RedeStudio Pro customer (“controller”)
and Alexander Seipel, Jeseniova 2829/20, 13000 Praha, Tschechien (“processor”)
1. Subject matter and duration
(1) With RedeStudio, the processor provides the controller with software to prepare, structure, draft, edit and export speeches for third parties (service description in the terms). In doing so, the processor processes personal data on behalf of the controller.
(2) This agreement applies for as long as the controller uses RedeStudio Pro and, beyond that, for as long as the processor still processes the controller’s data.
2. Nature and purpose of processing, type of data, data subjects
(1) Nature and purpose: storing, organising, analysing and rewriting the content entered by the controller in order to create a story map, a style profile and speech drafts; providing it for editing and export; deletion according to the configured periods.
(2) Type of data: names, relationships and life events of the people the speech is about; memories, anecdotes, quotes and interview notes; where entered by the controller, special categories of personal data under Art. 9 GDPR, such as information on health or religious or philosophical beliefs; content of the controller’s previous speeches (style samples).
(3) Data subjects: the controller’s clients, their relatives and friends, and other people named in the content.
3. Instructions of the controller
(1) The processor processes the data only on documented instructions from the controller, unless required to do otherwise by law; in such a case, the processor informs the controller of that legal requirement before processing, unless the law prohibits this. The instructions result from this agreement and the controller’s use of RedeStudio’s features.
(2) If the processor considers an instruction to be unlawful, it informs the controller without delay.
4. Obligations of the processor
(1) Confidentiality: the processor only uses persons who are bound to confidentiality. Speech content cannot be viewed by administrators.
(2) Security: the processor takes the technical and organisational measures under Art. 32 GDPR described in Annex 1. It may develop them further as long as the level of protection is not reduced.
(3) Assistance: the processor assists the controller with appropriate measures in responding to requests from data subjects (Art. 12–22 GDPR) and with the obligations under Art. 32–36 GDPR. The controller can implement many rights directly in RedeStudio, for example by editing, exporting and deleting speeches.
(4) Personal data breaches: the processor notifies the controller of a personal data breach without undue delay after becoming aware of it, with the information under Art. 33(3) GDPR, as far as available.
(5) Deletion and return: at the end of the agreement or on instruction, the processor deletes the data unless there is a statutory retention obligation. The controller can export its speeches beforehand. Speeches are also deleted automatically according to the periods configured in RedeStudio. Encrypted backups are overwritten after 35 days at the latest. [[ZU PRÜFEN: align with the backup rotation]]
(6) Evidence and audits: the processor makes available to the controller all information necessary to demonstrate compliance with this agreement and allows for audits, including inspections, by the controller or an auditor mandated by it, with reasonable notice and during normal business hours. [[ZU PRÜFEN: costs and notice period for on-site audits]]
5. Sub-processors
(1) The controller authorises the sub-processors listed in Annex 2.
(2) The processor informs the controller by email at least four weeks in advance of any intended addition or replacement of a sub-processor. The controller may object for an important data protection reason; in this case, it may terminate Pro for cause.
(3) The processor contractually binds sub-processors to a level of protection equivalent to this agreement.
6. Processing outside the EU
Hosting, database and backups are located in Germany. For AI processing (Annex 2), content may be transferred to OpenAI, L.L.C. in the USA. Transfers to a third country only take place if the requirements of Art. 44 et seq. GDPR are met. [[ZU PRÜFEN: basis of the transfer to OpenAI, L.L.C. (USA); other sub-processors of OpenAI and Brevo with a third-country connection]]
7. Obligations of the controller
(1) The controller is responsible for the lawfulness of the processing, in particular for being allowed to enter its clients’ data into RedeStudio, for example on the basis of consent.
(2) It informs the processor without delay if it discovers errors or irregularities in the processing.
8. Liability and final provisions
(1) Liability is governed by Art. 82 GDPR. Otherwise, the liability provisions of the terms apply.
(2) In the event of conflicts between this agreement and the terms, this agreement takes precedence as regards the protection of personal data.
(3) This agreement is concluded electronically when the controller accepts it in its RedeStudio account; the time is stored (Art. 28(9) GDPR).
Annex 1: Technical and organisational measures
- Encryption: transmission exclusively via TLS. Speech content, notes, style samples, story maps and drafts are stored encrypted at application level with AES-256-GCM. Backups are additionally encrypted.
- Physical access control: Hetzner Online GmbH data centres in Germany with access control, video surveillance and security staff.
- System and data access control: server access only via SSH keys, firewall, no publicly accessible database. Every data query checks that the speech belongs to the signed-in account. Administrators cannot see speech content.
- Separation: separate database and credentials per application.
- Logging: logs contain no speech content. AI requests are logged with technical metadata only.
- Availability: daily encrypted backups, a documented and tested restore procedure, automatic security updates.
- Deletion: automatic deletion after fixed periods, run daily.
- AI processing: only the content needed for each step is transmitted, no use for training. The AI provider keeps requests for up to 30 days to detect abuse.
[[ZU PRÜFEN: align the description of measures with the actual infrastructure]]
Annex 2: Sub-processors
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany: hosting, database and backups in Germany.
- OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland: processing of content by an AI language model, also by OpenAI, L.L.C. in the USA (see section 6).
- Sendinblue SAS (Brevo), 106 boulevard Haussmann, 75008 Paris, France: sending emails (email address and contract information only, no speech content). [[ZU PRÜFEN: enter the SMTP provider actually used]]
- Functional Software, Inc. (Sentry), data storage in the EU: error analysis without speech content, only if enabled. [[ZU PRÜFEN: only include if Sentry is active]]