Data Processing Agreement

under Article 28(3) and (4) GDPR

for the “ReviewBird” SaaS platform

Version 2.0.0, dated September 13, 2026.

Non-binding English translation. The German version prevails.

between

the Customer under the underlying SaaS agreement for the “ReviewBird” platform

– hereinafter the “Controller” –

and

Schild Roth SEO Agentur GmbH
Bismarckstr. 1–3
50672 Cologne, Germany
represented by its Managing Director Timothy Scherman

– hereinafter the “Processor” –

also jointly referred to as the “Parties”.

Preamble

(1) The Processor provides the Controller with the “ReviewBird” Software-as-a-Service platform. ReviewBird serves in particular to import and process appointment or transaction data, automatically trigger and send review and feedback requests, and provide and evaluate feedback and review functions.

(2) To the extent that the Processor processes personal data for the Controller in doing so, processing takes place on behalf of the Controller within the meaning of Article 28 GDPR.

(3) This agreement specifies the Parties’ data protection rights and obligations. It is an independent agreement under Article 28(3) and (4) GDPR. It is not based on the standard contractual clauses under Implementing Decision (EU) 2021/915.

(4) Annex 1 further specifies the subject matter, nature, purpose and duration of processing, the categories of personal data and the categories of data subjects. The technical and organizational measures are set out in Annex 2. The authorized sub-processors are listed in Annex 3.

Section 1 Subject matter, scope and order of precedence

(1) This agreement applies to all processing operations in which the Processor processes personal data on behalf of the Controller in connection with the provision and use of ReviewBird.

(2) The Controller is responsible for the lawfulness of the processing of personal data. This applies in particular to the permissibility of collecting and transferring the data to the Processor, the existence of the necessary legal bases, compliance with statutory information obligations, obtaining and documenting the necessary consents, and the lawfulness of the instructions issued.

(3) The Processor processes personal data exclusively within the framework of this agreement, the underlying SaaS agreement and the Controller’s documented instructions.

(4) In the event of contradictions between this agreement and the SaaS agreement, the provisions of this agreement take precedence for matters concerning processing on behalf of the Controller.

(5) Supplementary agreements on the protection of secrets protected by statute or professional rules remain unaffected and take precedence with respect to the secrets they cover.

Section 2 Processing subject to instructions

(1) The Processor processes personal data only on documented instructions from the Controller, unless required to process the data by European Union or Member State law.

(2) If a statutory obligation requires the Processor to carry out processing that is not based on the Controller’s instructions, the Processor informs the Controller of the relevant legal obligation before processing, to the extent that such information is legally permissible.

(3) Documented instructions include in particular the provisions of the SaaS agreement and this agreement, the settings and configurations made by the Controller within the platform, automations configured by the Controller, documented support orders, and other instructions given in text form or through platform functions provided for that purpose.

(4) Instructions that go beyond the agreed scope of services require a separate agreement and may be subject to charges based on the effort involved.

(5) The Processor informs the Controller without undue delay if it considers that an instruction infringes the GDPR or other applicable data protection provisions. It is entitled to suspend implementation of the instruction concerned pending confirmation, amendment or clarification, insofar as this is necessary to avoid a data protection violation.

Section 3 Confidentiality and obligations of personnel

(1) The Processor ensures that persons authorized to process personal data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality.

(2) Access rights are restricted to persons whose access is necessary to perform, administer, secure, maintain or monitor the agreed services.

(3) The Processor ensures through appropriate technical and organizational measures that personal data is not viewed, altered, disclosed or otherwise processed without authorization.

(4) The obligation of confidentiality continues after the end of the respective activity and after termination of this agreement.

Section 4 Security of processing

(1) Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the varying likelihood and severity of risks to the rights and freedoms of natural persons, the Processor implements appropriate technical and organizational measures under Article 32 GDPR.

(2) The measures agreed upon conclusion of this agreement are set out in Annex 2.

(3) The technical and organizational measures may be adapted during the contract term in line with technical and organizational developments, provided that the agreed level of protection is not reduced.

(4) The Processor regularly reviews the effectiveness of the technical and organizational measures and, where necessary, adapts them to the state of the art and the risk situation.

(5) Material changes to the technical and organizational measures that may significantly affect the level of protection or the nature of processing are documented.

Section 5 Processing special categories of personal data

(1) ReviewBird is generally not intended to specifically collect special categories of personal data within the meaning of Article 9(1) GDPR or to evaluate them as such.

(2) Nevertheless, special categories of personal data may be subject to processing on behalf of the Controller for Customers in sectors where the customer relationship, an appointment connection, the nature of an institution, a transaction or other accompanying circumstances may allow conclusions to be drawn about special categories of personal data. This may apply in particular to Customers in the healthcare sector.

(3) If the Controller processes such data or causes ReviewBird to process it, the Controller is responsible for ensuring that the necessary conditions are met, in particular those under Article 9(2) GDPR.

(4) The Processor applies additional safeguards where such data may be processed. These include in particular encryption, strict access restrictions, logging of administrative access, data minimization, time limits on support access and, for professionals bound by secrecy, the additionally agreed measures to protect secrets.

Section 6 Rights of data subjects

(1) Taking into account the nature of processing, the Processor assists the Controller through appropriate technical and organizational measures in fulfilling its obligation to respond to data subjects’ requests under Articles 12 to 22 GDPR.

(2) If a data subject’s request is received directly by the Processor and concerns data processed for the Controller, the Processor informs the Controller without undue delay.

(3) The Processor does not respond to data subjects’ requests independently unless instructed by the Controller or required by law to do so.

(4) Where the platform provides functions to retrieve, rectify, restrict, erase or export personal data, the Controller may use them to fulfill its data protection obligations.

Section 7 Assistance to the Controller

(1) Taking into account the nature of processing and the information available to it, the Processor reasonably assists the Controller in complying with the obligations under Articles 32 to 36 GDPR.

(2) Assistance includes in particular information about the security measures taken, assistance in assessing and handling personal data breaches, information for data protection impact assessments, assistance with any necessary prior consultation of a supervisory authority, and information for assessing the security of processing.

(3) If, in the course of providing the contractual services, the Processor finds that personal data processed on behalf of the Controller is manifestly inaccurate or no longer current, it informs the Controller insofar as this is relevant to processing in accordance with the contract. This does not establish an independent obligation for the Processor to verify the factual accuracy or currency of the data provided by the Controller.

(4) Services that go beyond the assistance required by law and the agreed scope of services and entail significant additional effort may be remunerated separately following prior agreement.

Section 8 Personal data breaches

(1) The Processor informs the Controller without undue delay after becoming aware of a personal data breach affecting personal data covered by this agreement.

(2) To the extent available at that time, the initial notification should include in particular the nature of the breach, the categories of data affected, the categories and approximate number of data subjects, the approximate number of personal data records, the likely consequences, remedial measures already taken or proposed, and a point of contact for further information.

(3) If information is not yet complete at the time of the initial notification, it is provided subsequently without unreasonable delay.

(4) The Processor reasonably assists the Controller in fulfilling its obligations under Articles 33 and 34 GDPR.

(5) The initial notification is made without undue delay and no later than 48 hours after the Processor becomes aware of the breach.

Section 9 Sub-processors

(1) The Controller grants the Processor general authorization to engage other processors within the meaning of Article 28(2) GDPR.

(2) The sub-processors authorized upon conclusion of this agreement are listed in Annex 3.

(3) The Processor informs the Controller at least one month before the intended engagement or replacement of a sub-processor. The information may be sent to the contact address stored in the user account or provided through a platform function designated for that purpose.

(4) The Controller may object to a change within the notified period on a legitimate data protection ground.

(5) In the event of a justified objection, the Parties seek an appropriate solution. In particular, the Processor may refrain from using the sub-processor concerned, engage another suitable sub-processor or offer the Controller a technically reasonable alternative way of providing the services. If an appropriate solution is not possible and the sub-processor’s involvement is necessary to provide the services, the Controller may terminate the Subscription affected by the change for cause.

(6) The Processor contractually binds sub-processors to data protection obligations that are at least equivalent to the Processor’s obligations under this agreement and Article 28 GDPR.

(7) The Processor remains responsible to the Controller for the sub-processor’s fulfillment of its data protection obligations.

(8) Upon justified request, the Processor provides the Controller with the information about an agreement with a sub-processor necessary to verify compliance with Article 28(4) GDPR. Where necessary for this purpose, it also provides a copy of the agreement concerned. Trade secrets, confidential information and personal data may be appropriately redacted before disclosure.

(9) The Processor informs the Controller if it becomes aware that a sub-processor is materially failing to fulfill its contractual data protection obligations relevant to the processing concerned.

Section 10 Transfers to third countries

(1) Personal data is transferred to a third country or an international organization exclusively within the framework of the Controller’s documented instructions, including the general instructions given through this agreement, the SaaS agreement and the agreed scope of services, or on the basis of a statutory obligation of the Processor, and only in compliance with the requirements of Chapter V GDPR.

(2) Where the European Commission has adopted an adequacy decision for a transfer, the transfer may be based on that decision.

(3) In the absence of an adequacy decision, the Processor ensures that appropriate safeguards within the meaning of Article 46 GDPR are in place, in particular by entering into applicable standard contractual clauses for international data transfers.

(4) Where necessary, supplementary safeguards are implemented and the risks associated with the transfer are assessed.

(5) The sub-processors used, their processing locations and the relevant transfer mechanisms are set out in Annex 3 or in the current list of sub-processors referred to therein.

Section 11 Evidence, checks and audits

(1) The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR.

(2) To fulfill its obligation to provide evidence, the Processor may in particular provide suitable certifications, audit reports, assessment reports from independent bodies, security documentation, documentation of technical and organizational measures, or other suitable evidence.

(3) The Controller is entitled, at reasonable intervals and where there are concrete indications of non-compliance, to verify compliance with this agreement itself or through an independent, professionally qualified auditor bound to confidentiality. Existing certifications, assessment reports and other suitable evidence provided by the Processor shall be appropriately taken into account.

(4) Checks should primarily be carried out on the basis of suitable documentation and evidence where this allows an appropriate examination. Where this is insufficient, checks may also include inspections of the business premises or technical facilities relevant to processing on behalf of the Controller.

(5) Unless an urgent reason precludes it, checks must be carried out with reasonable advance notice and organized so that the Processor’s business operations, the security of its systems and the rights of other Customers are not disproportionately impaired.

(6) Following prior agreement, the Processor may charge reasonable fees for effort exceeding the usual provision of evidence, provided that the check was not prompted by a breach for which the Processor is responsible and statutory audit rights are not unreasonably impaired.

(7) The Processor enables the competent data protection supervisory authorities to exercise their statutory powers and, upon lawful request, provides them with the information required under this agreement and, where requested, the results of checks carried out.

Section 12 Return and erasure of personal data

(1) The Processor stores personal data only for as long as necessary to provide the agreed services and in accordance with the Controller’s documented instructions.

(2) End Customer data is erased automatically in accordance with the agreed deletion concept. The regular maximum storage period is six months after collection, unless the Controller initiates earlier erasure, a legitimate documented instruction requires longer processing, or a statutory obligation requires continued storage.

(3) Upon termination of processing on behalf of the Controller, the Processor, at the Controller’s choice, erases all personal data processed on its behalf or returns it to the Controller and erases existing copies, unless Union or Member State law requires further storage.

(4) The arrangements and formats for a data export and further portability and switching rights under Regulation (EU) 2023/2854 are additionally governed by the SaaS agreement. This does not restrict the data protection obligation to return or erase personal data under paragraph 3.

(5) Upon request, the Processor confirms to the Controller that erasure has been completed.

(6) Where personal data remains only in backup copies, it may remain stored until the end of the regular backup and overwriting cycle, provided that it is no longer available for regular business operations, is protected against further productive processing, and is erased or overwritten as part of the regular cycle.

(7) If, after the contract ends, the Processor processes certain data no longer as a processor but on the basis of its own statutory obligations or to assert, exercise or defend its own legal claims, that processing is not covered by this agreement. The Processor is itself responsible for the lawfulness of that processing.

Section 13 Professional secrets and Customers requiring particular protection

(1) For Controllers subject to statutory or professional duties of confidentiality, in particular members of the healthcare professions and the legal and tax advisory professions, merely processing the fact that a person belongs to their customer base may allow conclusions to be drawn about protected matters.

(2) Before processing legally protected secrets, the Parties conclude a supplementary agreement on confidentiality and the protection of secrets where required.

(3) The Processor ensures that persons who may be granted access to such information in the course of providing the services are bound in accordance with the applicable statutory requirements.

(4) Technical support access to such data is restricted to what is necessary.

Section 14 Administrative and support access

(1) Personal End Customer data is protected in accordance with the technical measures described in Annex 2.

(2) The Processor may access personal End Customer data administratively only insofar as necessary to handle a documented support order, remedy a disruption, avert a security threat, fulfill a documented instruction or fulfill a statutory obligation.

(3) Access must be limited to the necessary purpose, data and duration.

(4) In normal operation, the admin backend does not display End Customer data in plaintext. Support access involving decryption is set up exclusively for a specific reason, logged, and withdrawn when the reason for access ceases to exist.

Section 15 Duration, suspension and termination

(1) This agreement takes effect upon conclusion of the underlying SaaS agreement or upon its acceptance during the registration or onboarding process and applies for as long as the Processor processes personal data on behalf of the Controller.

(2) If the Processor fails to fulfill its obligations under this agreement, the Controller may require suspension of the processing concerned until processing that complies with the contract and data protection requirements has been restored.

(3) If compliance is not restored within a reasonable period, and at the latest within one month after suspension, or if there is a material or continuing breach of this agreement or of mandatory data protection obligations, the Controller may terminate the part of the contract affected by the processing for cause.

(4) If, for factual or legal reasons, the Processor is no longer able to comply with this agreement, it informs the Controller without undue delay.

(5) If the Controller insists on an instruction that, in the Processor’s opinion, violates mandatory data protection law after the Processor has pointed this out, the Processor is entitled to suspend the processing concerned and, if necessary, terminate the affected part of the contract for cause.

Section 16 Liability

(1) The Parties’ statutory liability to data subjects and supervisory authorities under the GDPR remains unaffected.

(2) The liability provisions agreed in the SaaS agreement additionally apply to the relationship between the Parties, insofar as their application to breaches of data protection obligations is legally permissible.

(3) Statutory rights of recourse and compensation between the Parties remain unaffected.

Section 17 Final provisions

(1) Amendments and supplements to this agreement, including its annexes, may be agreed in text form unless a stricter form is required by law.

(2) The Processor is entitled to update the annexes where necessary to adapt to technical or organizational changes, provided that the agreed level of protection is not reduced and the Controller’s legally required rights to information, authorization or objection are preserved.

(3) If individual provisions of this agreement are or become invalid, the validity of the remaining provisions remains unaffected.

(4) German law applies unless mandatory data protection provisions preclude this.

Annex 1 Description of processing on behalf of the Controller

1. Controller

The Controller is the respective Customer under the SaaS agreement. The following information is collected during the registration, ordering or onboarding process:

  • Name / company name
  • Address
  • Contact person and contact details
  • Data protection officer, where applicable
  • User account / customer number
  • Time and version of acceptance

2. Processor

Schild Roth SEO Agentur GmbH
Bismarckstr. 1–3
50672 Cologne, Germany
Contact: Timothy Scherman, Managing Director
Data protection contact: [email protected]

3. Subject matter of processing

Provision, operation, maintenance, security and support of the ReviewBird SaaS platform and execution of the review and feedback processes configured by the Controller.

4. Nature and purpose of processing

  • Importing data provided by the Controller
  • Retrieving data from third-party systems connected by the Controller, at its instigation
  • Storage, structuring and assignment
  • Automated processing
  • Triggering and sending SMS and email messages
  • Providing feedback and review pages
  • Recording and displaying feedback
  • Logging
  • Export
  • Blocking and erasure

5. Categories of data subjects

  • End Customers of the Controller
  • Patients
  • Clients
  • Guests
  • Buyers
  • Prospects
  • Other recipients of services
  • Contact persons of the Controller
  • Users and employees of the Controller who use ReviewBird

6. Categories of personal data

Depending on configuration, in particular:

Master and contact data

  • Name, where provided by the Controller
  • Telephone number / mobile number
  • Email address
  • Internal identifier or ID

Appointment and transaction data

  • Date and time of an appointment or transaction
  • Status
  • Category
  • Triggering event
  • Other assignment information configured by the Controller

Communication and consent data

  • Consent status
  • Withdrawal status
  • Time and channel of a declaration
  • Dispatch and delivery information
  • Blocking and frequency information

Feedback and review data

  • Feedback submitted internally
  • Reviews and review information
  • Free text where the function provides for it

Account and usage data

  • User accounts
  • Roles and permissions
  • Usage and access logs
  • Technical log data

Passwords are not stored in plaintext but exclusively in a technically suitable form that cannot be reversed.

7. Special categories of personal data

The platform is not intended for the targeted processing of special categories of personal data. Depending on the sector and the content of the information transferred by the Controller, however, information may be processed, particularly in healthcare, from which health data or other special categories of personal data can be inferred directly or indirectly. Responsibility for the permissibility of the relevant processing remains with the Controller.

8. Duration

Processing generally takes place for the duration of the respective SaaS relationship or Subscription. End Customer data is erased in accordance with the deletion concept no later than six months after collection, unless a different documented instruction or statutory obligation applies.

Annex 2 Technical and organizational measures

Taking into account the specific processing and risk situation, the Processor implements in particular the following technical and organizational measures.

1. Access control

  • Role-based authorization concept
  • Principle of least privilege
  • Personal or clearly assigned user accounts
  • Secure password storage
  • Multi-factor authentication where offered
  • Prompt blocking of access no longer required

2. Data access control

  • Access exclusively for authorized persons
  • Permissions based on area of responsibility
  • Logging of security-relevant administrative access
  • Restriction of support access to the necessary scope

3. Encryption

  • Transport encryption using TLS
  • Encryption of End Customer data at rest
  • Secure management of the keys used for this purpose
  • No storage of Customer passwords in plaintext

4. Support access

  • End Customer data is not displayed in plaintext during normal administrative operation
  • Access involving decryption only for a specific support or security reason
  • Access limited in time and scope
  • Logging of access
  • Withdrawal of extended access after completion of the measure

5. Tenant separation

  • Logical separation of the data of different Controllers
  • Technical assignment to the respective Customer accounts
  • Prevention of access by other tenants

6. Input and processing control

  • Data imports from third-party systems only on the basis of Customer configuration or instigation
  • Logging of security-relevant events
  • Use of access methods provided by the Customer in accordance with the agreed technical procedure

7. Data minimization

  • Processing only the data required for the respective purpose
  • No End Customer names in message text
  • Use of internal identifiers where sufficient
  • Frequency limits for repeated review requests
  • Automated deletion processes

8. Availability and restoration

  • Hosting by Hetzner Online GmbH in Germany
  • Regular data backups
  • Procedures for restoration after physical or technical incidents
  • Monitoring of system availability

9. Transfer control

  • Encrypted transport channels
  • Use of authorized sub-processors only
  • Documented transfer channels

10. Erasure

  • Documented deletion concept
  • Automatic deletion cycle for End Customer data
  • Secure erasure or overwriting of backup copies after expiry of the backup cycle

11. Review

  • Regular review and evaluation of technical and organizational measures
  • Adaptation to technical developments and changing risks

Annex 3 Authorized sub-processors

As of September 13, 2026

Sub-processor Registered location / purpose Third-country transfer mechanism
Hetzner Online GmbH Germany – cloud hosting and infrastructure Processing in the EEA
seven communications GmbH & Co. KG / seven.io Germany – SMS dispatch Processing in the EEA
Cloudflare, Inc. or the relevant Cloudflare contracting entity USA / international – web infrastructure, security, content delivery Adequacy decision / DPF where necessary; supplementary SCCs
AC PM LLC / ActiveCampaign / Postmark USA – delivery of transactional emails EU-US Data Privacy Framework; additional safeguards where necessary
OpenAI Ireland Ltd. Ireland – AI-assisted text and document processing, where included in the scope of services EEA contracting entity; intra-group transfers to third countries only under Chapter V GDPR
Apify Technologies s.r.o. Czech Republic – retrieval of publicly available business and review data Processing in the EEA

The current list of sub-processors is provided at https://dashboard.reviewbird.io/legal/sub-processors.

The Processor informs the Controller in accordance with Section 9 before engaging or replacing a sub-processor.

Distinction: not a sub-processor under this agreement

To the extent that the following service provider processes data exclusively for the Processor’s own purposes or processes data outside the processing covered by this agreement, it is not classified as a sub-processor under this agreement:

  • Stripe Payments Europe, Limited, insofar as only payment processing between the Processor and the Controller is concerned.

If the actual processing changes and becomes connected with personal data of the Controller, the data protection classification must be reviewed again before processing begins.

Annex 4 Acceptance and evidence

This agreement may be concluded electronically during the registration, ordering or onboarding process. The Controller accepts the agreement through the express declaration provided for this purpose.

The Processor documents at least the version used, the date and time of acceptance, the associated user account, and the identity or company name of the Controller.

The completed agreement is made permanently available to the Controller for retrieval in its user account or by other suitable means.

Controller Customer under the SaaS agreement; identity or company name as stated in the associated contractual records
Accepted on Date and time of the electronically logged acceptance
User account The user account used and logged upon acceptance
Version 2.0.0

The table describes how the acceptance record is assigned. The specific acceptance data is generated only upon actual acceptance and is assigned to the respective Customer; the public version of the agreement does not confirm that acceptance has already occurred.