under Article 28(3) and (4) GDPR
for the “ReviewBird” SaaS platform
Version 2.0.0, dated September 13, 2026.
Non-binding English translation. The German version prevails.
between
the Customer under the underlying SaaS agreement for the “ReviewBird” platform
– hereinafter the “Controller” –
and
Schild Roth SEO Agentur GmbH
Bismarckstr. 1–3
50672 Cologne, Germany
represented by its Managing Director Timothy Scherman
– hereinafter the “Processor” –
also jointly referred to as the “Parties”.
(1) The Processor provides the Controller with the “ReviewBird” Software-as-a-Service platform. ReviewBird serves in particular to import and process appointment or transaction data, automatically trigger and send review and feedback requests, and provide and evaluate feedback and review functions.
(2) To the extent that the Processor processes personal data for the Controller in doing so, processing takes place on behalf of the Controller within the meaning of Article 28 GDPR.
(3) This agreement specifies the Parties’ data protection rights and obligations. It is an independent agreement under Article 28(3) and (4) GDPR. It is not based on the standard contractual clauses under Implementing Decision (EU) 2021/915.
(4) Annex 1 further specifies the subject matter, nature, purpose and duration of processing, the categories of personal data and the categories of data subjects. The technical and organizational measures are set out in Annex 2. The authorized sub-processors are listed in Annex 3.
(1) This agreement applies to all processing operations in which the Processor processes personal data on behalf of the Controller in connection with the provision and use of ReviewBird.
(2) The Controller is responsible for the lawfulness of the processing of personal data. This applies in particular to the permissibility of collecting and transferring the data to the Processor, the existence of the necessary legal bases, compliance with statutory information obligations, obtaining and documenting the necessary consents, and the lawfulness of the instructions issued.
(3) The Processor processes personal data exclusively within the framework of this agreement, the underlying SaaS agreement and the Controller’s documented instructions.
(4) In the event of contradictions between this agreement and the SaaS agreement, the provisions of this agreement take precedence for matters concerning processing on behalf of the Controller.
(5) Supplementary agreements on the protection of secrets protected by statute or professional rules remain unaffected and take precedence with respect to the secrets they cover.
(1) The Processor processes personal data only on documented instructions from the Controller, unless required to process the data by European Union or Member State law.
(2) If a statutory obligation requires the Processor to carry out processing that is not based on the Controller’s instructions, the Processor informs the Controller of the relevant legal obligation before processing, to the extent that such information is legally permissible.
(3) Documented instructions include in particular the provisions of the SaaS agreement and this agreement, the settings and configurations made by the Controller within the platform, automations configured by the Controller, documented support orders, and other instructions given in text form or through platform functions provided for that purpose.
(4) Instructions that go beyond the agreed scope of services require a separate agreement and may be subject to charges based on the effort involved.
(5) The Processor informs the Controller without undue delay if it considers that an instruction infringes the GDPR or other applicable data protection provisions. It is entitled to suspend implementation of the instruction concerned pending confirmation, amendment or clarification, insofar as this is necessary to avoid a data protection violation.
(1) The Processor ensures that persons authorized to process personal data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality.
(2) Access rights are restricted to persons whose access is necessary to perform, administer, secure, maintain or monitor the agreed services.
(3) The Processor ensures through appropriate technical and organizational measures that personal data is not viewed, altered, disclosed or otherwise processed without authorization.
(4) The obligation of confidentiality continues after the end of the respective activity and after termination of this agreement.
(1) Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the varying likelihood and severity of risks to the rights and freedoms of natural persons, the Processor implements appropriate technical and organizational measures under Article 32 GDPR.
(2) The measures agreed upon conclusion of this agreement are set out in Annex 2.
(3) The technical and organizational measures may be adapted during the contract term in line with technical and organizational developments, provided that the agreed level of protection is not reduced.
(4) The Processor regularly reviews the effectiveness of the technical and organizational measures and, where necessary, adapts them to the state of the art and the risk situation.
(5) Material changes to the technical and organizational measures that may significantly affect the level of protection or the nature of processing are documented.
(1) ReviewBird is generally not intended to specifically collect special categories of personal data within the meaning of Article 9(1) GDPR or to evaluate them as such.
(2) Nevertheless, special categories of personal data may be subject to processing on behalf of the Controller for Customers in sectors where the customer relationship, an appointment connection, the nature of an institution, a transaction or other accompanying circumstances may allow conclusions to be drawn about special categories of personal data. This may apply in particular to Customers in the healthcare sector.
(3) If the Controller processes such data or causes ReviewBird to process it, the Controller is responsible for ensuring that the necessary conditions are met, in particular those under Article 9(2) GDPR.
(4) The Processor applies additional safeguards where such data may be processed. These include in particular encryption, strict access restrictions, logging of administrative access, data minimization, time limits on support access and, for professionals bound by secrecy, the additionally agreed measures to protect secrets.
(1) Taking into account the nature of processing, the Processor assists the Controller through appropriate technical and organizational measures in fulfilling its obligation to respond to data subjects’ requests under Articles 12 to 22 GDPR.
(2) If a data subject’s request is received directly by the Processor and concerns data processed for the Controller, the Processor informs the Controller without undue delay.
(3) The Processor does not respond to data subjects’ requests independently unless instructed by the Controller or required by law to do so.
(4) Where the platform provides functions to retrieve, rectify, restrict, erase or export personal data, the Controller may use them to fulfill its data protection obligations.
(1) Taking into account the nature of processing and the information available to it, the Processor reasonably assists the Controller in complying with the obligations under Articles 32 to 36 GDPR.
(2) Assistance includes in particular information about the security measures taken, assistance in assessing and handling personal data breaches, information for data protection impact assessments, assistance with any necessary prior consultation of a supervisory authority, and information for assessing the security of processing.
(3) If, in the course of providing the contractual services, the Processor finds that personal data processed on behalf of the Controller is manifestly inaccurate or no longer current, it informs the Controller insofar as this is relevant to processing in accordance with the contract. This does not establish an independent obligation for the Processor to verify the factual accuracy or currency of the data provided by the Controller.
(4) Services that go beyond the assistance required by law and the agreed scope of services and entail significant additional effort may be remunerated separately following prior agreement.
(1) The Processor informs the Controller without undue delay after becoming aware of a personal data breach affecting personal data covered by this agreement.
(2) To the extent available at that time, the initial notification should include in particular the nature of the breach, the categories of data affected, the categories and approximate number of data subjects, the approximate number of personal data records, the likely consequences, remedial measures already taken or proposed, and a point of contact for further information.
(3) If information is not yet complete at the time of the initial notification, it is provided subsequently without unreasonable delay.
(4) The Processor reasonably assists the Controller in fulfilling its obligations under Articles 33 and 34 GDPR.
(5) The initial notification is made without undue delay and no later than 48 hours after the Processor becomes aware of the breach.
(1) The Controller grants the Processor general authorization to engage other processors within the meaning of Article 28(2) GDPR.
(2) The sub-processors authorized upon conclusion of this agreement are listed in Annex 3.
(3) The Processor informs the Controller at least one month before the intended engagement or replacement of a sub-processor. The information may be sent to the contact address stored in the user account or provided through a platform function designated for that purpose.
(4) The Controller may object to a change within the notified period on a legitimate data protection ground.
(5) In the event of a justified objection, the Parties seek an appropriate solution. In particular, the Processor may refrain from using the sub-processor concerned, engage another suitable sub-processor or offer the Controller a technically reasonable alternative way of providing the services. If an appropriate solution is not possible and the sub-processor’s involvement is necessary to provide the services, the Controller may terminate the Subscription affected by the change for cause.
(6) The Processor contractually binds sub-processors to data protection obligations that are at least equivalent to the Processor’s obligations under this agreement and Article 28 GDPR.
(7) The Processor remains responsible to the Controller for the sub-processor’s fulfillment of its data protection obligations.
(8) Upon justified request, the Processor provides the Controller with the information about an agreement with a sub-processor necessary to verify compliance with Article 28(4) GDPR. Where necessary for this purpose, it also provides a copy of the agreement concerned. Trade secrets, confidential information and personal data may be appropriately redacted before disclosure.
(9) The Processor informs the Controller if it becomes aware that a sub-processor is materially failing to fulfill its contractual data protection obligations relevant to the processing concerned.
(1) Personal data is transferred to a third country or an international organization exclusively within the framework of the Controller’s documented instructions, including the general instructions given through this agreement, the SaaS agreement and the agreed scope of services, or on the basis of a statutory obligation of the Processor, and only in compliance with the requirements of Chapter V GDPR.
(2) Where the European Commission has adopted an adequacy decision for a transfer, the transfer may be based on that decision.
(3) In the absence of an adequacy decision, the Processor ensures that appropriate safeguards within the meaning of Article 46 GDPR are in place, in particular by entering into applicable standard contractual clauses for international data transfers.
(4) Where necessary, supplementary safeguards are implemented and the risks associated with the transfer are assessed.
(5) The sub-processors used, their processing locations and the relevant transfer mechanisms are set out in Annex 3 or in the current list of sub-processors referred to therein.
(1) The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR.
(2) To fulfill its obligation to provide evidence, the Processor may in particular provide suitable certifications, audit reports, assessment reports from independent bodies, security documentation, documentation of technical and organizational measures, or other suitable evidence.
(3) The Controller is entitled, at reasonable intervals and where there are concrete indications of non-compliance, to verify compliance with this agreement itself or through an independent, professionally qualified auditor bound to confidentiality. Existing certifications, assessment reports and other suitable evidence provided by the Processor shall be appropriately taken into account.
(4) Checks should primarily be carried out on the basis of suitable documentation and evidence where this allows an appropriate examination. Where this is insufficient, checks may also include inspections of the business premises or technical facilities relevant to processing on behalf of the Controller.
(5) Unless an urgent reason precludes it, checks must be carried out with reasonable advance notice and organized so that the Processor’s business operations, the security of its systems and the rights of other Customers are not disproportionately impaired.
(6) Following prior agreement, the Processor may charge reasonable fees for effort exceeding the usual provision of evidence, provided that the check was not prompted by a breach for which the Processor is responsible and statutory audit rights are not unreasonably impaired.
(7) The Processor enables the competent data protection supervisory authorities to exercise their statutory powers and, upon lawful request, provides them with the information required under this agreement and, where requested, the results of checks carried out.
(1) The Processor stores personal data only for as long as necessary to provide the agreed services and in accordance with the Controller’s documented instructions.
(2) End Customer data is erased automatically in accordance with the agreed deletion concept. The regular maximum storage period is six months after collection, unless the Controller initiates earlier erasure, a legitimate documented instruction requires longer processing, or a statutory obligation requires continued storage.
(3) Upon termination of processing on behalf of the Controller, the Processor, at the Controller’s choice, erases all personal data processed on its behalf or returns it to the Controller and erases existing copies, unless Union or Member State law requires further storage.
(4) The arrangements and formats for a data export and further portability and switching rights under Regulation (EU) 2023/2854 are additionally governed by the SaaS agreement. This does not restrict the data protection obligation to return or erase personal data under paragraph 3.
(5) Upon request, the Processor confirms to the Controller that erasure has been completed.
(6) Where personal data remains only in backup copies, it may remain stored until the end of the regular backup and overwriting cycle, provided that it is no longer available for regular business operations, is protected against further productive processing, and is erased or overwritten as part of the regular cycle.
(7) If, after the contract ends, the Processor processes certain data no longer as a processor but on the basis of its own statutory obligations or to assert, exercise or defend its own legal claims, that processing is not covered by this agreement. The Processor is itself responsible for the lawfulness of that processing.
(1) For Controllers subject to statutory or professional duties of confidentiality, in particular members of the healthcare professions and the legal and tax advisory professions, merely processing the fact that a person belongs to their customer base may allow conclusions to be drawn about protected matters.
(2) Before processing legally protected secrets, the Parties conclude a supplementary agreement on confidentiality and the protection of secrets where required.
(3) The Processor ensures that persons who may be granted access to such information in the course of providing the services are bound in accordance with the applicable statutory requirements.
(4) Technical support access to such data is restricted to what is necessary.
(1) Personal End Customer data is protected in accordance with the technical measures described in Annex 2.
(2) The Processor may access personal End Customer data administratively only insofar as necessary to handle a documented support order, remedy a disruption, avert a security threat, fulfill a documented instruction or fulfill a statutory obligation.
(3) Access must be limited to the necessary purpose, data and duration.
(4) In normal operation, the admin backend does not display End Customer data in plaintext. Support access involving decryption is set up exclusively for a specific reason, logged, and withdrawn when the reason for access ceases to exist.
(1) This agreement takes effect upon conclusion of the underlying SaaS agreement or upon its acceptance during the registration or onboarding process and applies for as long as the Processor processes personal data on behalf of the Controller.
(2) If the Processor fails to fulfill its obligations under this agreement, the Controller may require suspension of the processing concerned until processing that complies with the contract and data protection requirements has been restored.
(3) If compliance is not restored within a reasonable period, and at the latest within one month after suspension, or if there is a material or continuing breach of this agreement or of mandatory data protection obligations, the Controller may terminate the part of the contract affected by the processing for cause.
(4) If, for factual or legal reasons, the Processor is no longer able to comply with this agreement, it informs the Controller without undue delay.
(5) If the Controller insists on an instruction that, in the Processor’s opinion, violates mandatory data protection law after the Processor has pointed this out, the Processor is entitled to suspend the processing concerned and, if necessary, terminate the affected part of the contract for cause.
(1) The Parties’ statutory liability to data subjects and supervisory authorities under the GDPR remains unaffected.
(2) The liability provisions agreed in the SaaS agreement additionally apply to the relationship between the Parties, insofar as their application to breaches of data protection obligations is legally permissible.
(3) Statutory rights of recourse and compensation between the Parties remain unaffected.
(1) Amendments and supplements to this agreement, including its annexes, may be agreed in text form unless a stricter form is required by law.
(2) The Processor is entitled to update the annexes where necessary to adapt to technical or organizational changes, provided that the agreed level of protection is not reduced and the Controller’s legally required rights to information, authorization or objection are preserved.
(3) If individual provisions of this agreement are or become invalid, the validity of the remaining provisions remains unaffected.
(4) German law applies unless mandatory data protection provisions preclude this.
The Controller is the respective Customer under the SaaS agreement. The following information is collected during the registration, ordering or onboarding process:
Schild Roth SEO Agentur GmbH
Bismarckstr. 1–3
50672 Cologne, Germany
Contact: Timothy Scherman, Managing Director
Data protection contact: [email protected]
Provision, operation, maintenance, security and support of the ReviewBird SaaS platform and execution of the review and feedback processes configured by the Controller.
Depending on configuration, in particular:
Master and contact data
Appointment and transaction data
Communication and consent data
Feedback and review data
Account and usage data
Passwords are not stored in plaintext but exclusively in a technically suitable form that cannot be reversed.
The platform is not intended for the targeted processing of special categories of personal data. Depending on the sector and the content of the information transferred by the Controller, however, information may be processed, particularly in healthcare, from which health data or other special categories of personal data can be inferred directly or indirectly. Responsibility for the permissibility of the relevant processing remains with the Controller.
Processing generally takes place for the duration of the respective SaaS relationship or Subscription. End Customer data is erased in accordance with the deletion concept no later than six months after collection, unless a different documented instruction or statutory obligation applies.
Taking into account the specific processing and risk situation, the Processor implements in particular the following technical and organizational measures.
As of September 13, 2026
| Sub-processor | Registered location / purpose | Third-country transfer mechanism |
|---|---|---|
| Hetzner Online GmbH | Germany – cloud hosting and infrastructure | Processing in the EEA |
| seven communications GmbH & Co. KG / seven.io | Germany – SMS dispatch | Processing in the EEA |
| Cloudflare, Inc. or the relevant Cloudflare contracting entity | USA / international – web infrastructure, security, content delivery | Adequacy decision / DPF where necessary; supplementary SCCs |
| AC PM LLC / ActiveCampaign / Postmark | USA – delivery of transactional emails | EU-US Data Privacy Framework; additional safeguards where necessary |
| OpenAI Ireland Ltd. | Ireland – AI-assisted text and document processing, where included in the scope of services | EEA contracting entity; intra-group transfers to third countries only under Chapter V GDPR |
| Apify Technologies s.r.o. | Czech Republic – retrieval of publicly available business and review data | Processing in the EEA |
The current list of sub-processors is provided at https://dashboard.reviewbird.io/legal/sub-processors.
The Processor informs the Controller in accordance with Section 9 before engaging or replacing a sub-processor.
To the extent that the following service provider processes data exclusively for the Processor’s own purposes or processes data outside the processing covered by this agreement, it is not classified as a sub-processor under this agreement:
If the actual processing changes and becomes connected with personal data of the Controller, the data protection classification must be reviewed again before processing begins.
This agreement may be concluded electronically during the registration, ordering or onboarding process. The Controller accepts the agreement through the express declaration provided for this purpose.
The Processor documents at least the version used, the date and time of acceptance, the associated user account, and the identity or company name of the Controller.
The completed agreement is made permanently available to the Controller for retrieval in its user account or by other suitable means.
| Controller | Customer under the SaaS agreement; identity or company name as stated in the associated contractual records |
|---|---|
| Accepted on | Date and time of the electronically logged acceptance |
| User account | The user account used and logged upon acceptance |
| Version | 2.0.0 |
The table describes how the acceptance record is assigned. The specific acceptance data is generated only upon actual acceptance and is assigned to the respective Customer; the public version of the agreement does not confirm that acceptance has already occurred.