This Data Processing Agreement (the “DPA”, Auftragsverarbeitungsvertrag / “AVV”) is concluded under Article 28 GDPR between the Customer and Finalform GmbH. It sets out the terms on which Finalform processes personal data on the Customer’s behalf when providing the Autopage service (“Autopage” or the “Service”). It is written in plain B2B English and is intended to satisfy Article 28(3) GDPR and the guidance of the German supervisory authorities (DSK Kurzpapier Nr. 13).
This DPA forms part of, and is incorporated by reference into, the Terms of Service (the “Terms” or “main agreement”) between the Customer and Finalform. Terms used and not defined here have the meaning given in the Terms.
1. Parties, roles, and relationship to the Terms
This DPA is entered into between:
- the Customer, as the controller for the visitor personal data processed through the Autopage snippet; and
- Finalform GmbH, as the processor for that data (“Finalform”, “we”, “us”).
Processor identification. Finalform GmbH, Theodor-Heuss-Str. 106, 26129 Oldenburg, Germany. Registered in the commercial register of the Amtsgericht Oldenburg under HRB 222780. VAT identification number (USt-IdNr.) DE457693089. Managing Director (Geschäftsführer): Robin Schröder.
Roles. For the visitor personal data that Finalform processes when the Customer connects pages to Autopage and installs the snippet, the Customer determines the purposes and means of processing and is the controller, and Finalform processes only as a processor under this DPA. This DPA does not govern data for which Finalform is itself the controller (for example the Customer’s own account, billing, marketing, and website data); that processing is described in the Privacy Policy.
Precedence. This DPA is incorporated into the Terms. In the event of a conflict between this DPA and the Terms on the subject matter of data processing, this DPA prevails to the extent of the conflict (see Section 16).
2. Subject matter, duration, nature, and purpose
Subject matter. Finalform processes the visitor personal data described in Annex 1 on the Customer’s behalf, for the sole purpose of providing Autopage to the Customer.
Duration. This DPA takes effect when the Customer accepts it (Section 17) and continues for as long as Finalform processes personal data on the Customer’s behalf. It is coextensive with the main agreement and ends when the main agreement ends, subject to the deletion and return obligations in Section 11.
Nature and purpose. The nature of the processing is the automated collection, storage, analysis, and use of visitor interaction data to run A/B testing and AI-assisted optimization of the Customer’s connected pages. This includes generating page variants, serving variants to visitors, measuring results at population level, and using a large language model to rewrite the copy on the Customer’s connected pages.
Use of a large language model. Copy generation and rewriting are performed by a large language model supplied by Anthropic, PBC as a sub-processor (Annex 1, Sub-processor List). Only the Customer’s tenant brief, the baseline page copy, and population-level aggregate metrics (such as rates and medians) are sent to that model; direct identifiers are stripped and no per-visitor data (no session identifier, no IP address, no raw event) is placed in any prompt. No prompt or response content is logged by Finalform; only token-count telemetry is retained. The model provider is engaged on a no-training / zero-retention basis.
The full descriptive details of the processing are set out in Annex 1.
3. Types of personal data and categories of data subjects
The types of personal data and the categories of data subjects are set out in Annex 1: Details of processing. In summary, on the Customer’s behalf Finalform processes a pseudonymous visitor session identifier and coarse, bucketed behavioral signals (such as device class, traffic-source category, scroll depth, and time on page) relating to the Customer’s website visitors.
Finalform does not collect, store, or persist the visitor’s IP address, full user-agent string, precise geolocation, device fingerprint, raw referrer, raw UTM parameters, or any form input. A visitor IP exists only transiently (approximately 60 seconds) in memory as a rate-limiting key and is never written to any database table or log line by Autopage application code, and is never truncated, hashed, or otherwise persisted (Annex 1).
4. Processing on documented instructions
Finalform processes the personal data only on the Customer’s documented instructions, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law to which Finalform is subject. In that case Finalform informs the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Customer’s documented instructions consist of this DPA, the Terms, and the configuration the Customer sets in Autopage (for example the connected pages, the optimization settings, and the element exclusions). The Customer may issue further reasonable, documented instructions consistent with the Service during the term.
Ban on processing for own purposes. Finalform processes the personal data exclusively to provide the Service and does not process it for its own or any third party’s purposes (no weisungswidrige Verarbeitung).
Finalform informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions, and may suspend the affected processing until the instruction is confirmed or amended.
5. Self-controller warning (Art 28(10))
If Finalform infringes the GDPR by determining the purposes and means of processing, it is a controller in respect of that processing (Art 28(10)). Finalform commits not to do so and to process only on the Customer’s documented instructions under this DPA.
6. Confidentiality and data-protection contact
Confidentiality. Finalform ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process the data only on instruction (Weisungsgebundenheit). Finalform limits access to the personal data to personnel who need it to provide the Service and keeps those confidentiality commitments in place beyond the end of their engagement. Finalform maintains written confidentiality undertakings and data-protection training for its own personnel.
Data-protection contact. Questions about this DPA and data protection may be directed to support@autopage.dev. Finalform is appointing an external data protection officer before go-live, and that contact will be the designated point for data protection enquiries.
7. Security of processing (Art 32)
Finalform implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of data subjects.
These measures are set out in Annex 2: Technical and Organizational Measures (TOMs), which forms part of this DPA. Without limiting Annex 2, the measures already in place include: tenant isolation enforced in the database (PostgreSQL row-level security) and at the application layer; encryption in transit (TLS); encryption at rest for the managed database and its backups; data minimisation (no IP, user-agent, referrer, or geolocation persisted); pseudonymisation of the visitor session identifier; rate limiting; and consent gating in the snippet.
Finalform may update the measures over time, provided the level of security is not reduced below that described in Annex 2.
8. Sub-processors (Art 28(2), (4))
General written authorization. The Customer gives Finalform a general written authorization (Art 28(2)) to engage other processors (“Sub-processors”) to support the provision of Autopage. The current Sub-processors are listed in the published Sub-processor List, which operates under this general authorization and is incorporated into this DPA by reference. The Sub-processor List carries an effective date and version, and states for each Sub-processor its identity, role, the categories of personal data it receives, its hosting location, and the applicable transfer mechanism.
Change notification. Finalform gives the Customer at least 30 days’ prior notice of the addition or replacement of a Sub-processor before that Sub-processor begins processing personal data. Notice is given by updating the published Sub-processor List (with a new effective date and version) and by emailing the Customer’s registered account contact, supplemented by an in-app notice.
Objection. The Customer may object to a new or replaced Sub-processor on reasonable, data-protection-related grounds within the objection period. The advance-notice period (above) and the controller’s objection period are distinct clocks; the objection period is stated separately and is not equated to the 30-day notice period.
Consequence of objection. If the Customer objects within the period, the parties will work together in good faith to resolve the objection. If a justified, data-protection-related objection cannot be resolved, the Customer may terminate the affected service without penalty and receive a pro-rata refund of any fees prepaid for the unused, terminated portion. No objection within the period constitutes deemed approval of the new Sub-processor.
Flow-down and residual liability (Art 28(4)). Where Finalform engages a Sub-processor, it imposes on that Sub-processor, by contract, data protection obligations equivalent to those set out in this DPA, in particular providing sufficient guarantees of appropriate technical and organizational measures. Finalform remains fully liable to the Customer for the performance of each Sub-processor’s obligations.
9. Assistance to the controller (Art 28(3)(e), (f))
Data-subject rights (Chapter III). Taking into account the nature of the processing, and insofar as possible, Finalform assists the Customer by appropriate technical and organizational measures with the fulfilment of the Customer’s obligation to respond to requests for exercising the data subject’s rights under Chapter III GDPR (Articles 12 to 23). Finalform forwards to the Customer, without undue delay, any data-subject request it receives directly that concerns the Customer’s data, and does not respond to it itself except on the Customer’s instruction.
Security, breach, DPIA, prior consultation (Art 32 to 36). Taking into account the nature of the processing and the information available to Finalform, Finalform also assists the Customer in ensuring compliance with the obligations under Articles 32 to 36 GDPR, namely: security of processing (Art 32); notification of a personal data breach to the supervisory authority (Art 33); communication of a personal data breach to the data subject (Art 34); data protection impact assessments (Art 35); and prior consultation with the supervisory authority (Art 36).
Assistance included in the Service is provided at no additional charge. Assistance that goes materially beyond what the Service provides may be charged at Finalform’s reasonable cost.
10. Personal data breach (Art 28(3)(f), 33)
Finalform notifies the Customer without undue delay after becoming aware of a personal data breach affecting the personal data processed on the Customer’s behalf, and in any event in time to support the Customer’s own 72-hour notification duty under Article 33 GDPR. The notification describes, to the extent known and available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Finalform provides further information as it becomes available and supports the Customer in meeting the Customer’s own notification duties under Articles 33 and 34 GDPR.
Finalform maintains a named responsible person and a breach register and runbook to support timely assessment and notification.
11. Deletion or return of personal data (Art 28(3)(g))
In-life deletion. On the Customer’s request, or on closure of the Customer’s account, Finalform deletes all the personal data processed on the Customer’s behalf immediately and completely. Deletion is performed in a single operation that removes the data from all tenant-scoped tables; there is no soft-delete, no scheduled grace period, and no anonymised residue retained.
At the end of the provision of services (controller’s choice). At the choice of the Customer, Finalform deletes or returns all the personal data processed on the Customer’s behalf after the end of the provision of services, and deletes existing copies, unless Union or Member State law requires storage of the personal data:
- Default action, deletion. Unless the Customer elects return, Finalform deletes the Customer’s personal data after the end of the provision of services.
- Return on election. On request, Finalform provides a machine-readable export (JSON or CSV) of the Customer’s personal data.
- Window. The Customer may request export within 30 days of the end of the provision of services; after that window (or immediately on a delete election) Finalform deletes the data.
- Sub-processors. On contract end, Finalform instructs each Sub-processor to delete or return the Customer’s personal data on the same basis (Art 28(4) flow-down).
- Backups. Any residual copies in provider backups are overwritten on the backup rotation cycle; backups are not separately restored to retain deleted data, and a restore re-applies prior deletions.
- Statutory-retention carve-out. Data that Finalform must retain to meet a legal obligation (statutory billing records / Buchungsbelege, retained for 8 years under § 257 HGB / § 147 AO as amended by the Bürokratieentlastungsgesetz IV from 2025-01-01) is exempt from deletion and is held only for the statutory period in the external accounting system, then deleted.
Finalform certifies deletion to the Customer on request.
12. Retention
Finalform retains the personal data processed on the Customer’s behalf only as long as necessary to provide the Service, under the data-minimisation principle of Article 5(1)(e) GDPR. The target per-category retention windows are:
| Data category | Target retention window |
|---|---|
| Raw visitor events (pseudonymous session id + coarse behavioral signals) | 90 days, then aggregate-only (raw rows purged; population-level metrics retained) |
| Aggregate metrics | Life of the account (computed live; non-identifying once raw events purged) |
| LLM call telemetry (token counts + duration only; no prompt/response content) | 90 days |
| Decision / iteration audit records | Life of the account; deleted on tenant deletion |
| Security / access logs | 30 days |
| Notifications | 30 days (age-based purge) |
| Account / tenant data | Immediate and complete deletion on request (no grace tail) |
| Statutory billing data | 8 years (held in the external accounting system, outside the Service schema) |
Finalform reviews this retention policy on a regular cadence and names an owner for deletion execution.
13. Audit and information (Art 28(3)(h))
Finalform makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
In the first instance, Finalform may satisfy an audit request by providing this DPA, the TOMs (Annex 2), the Sub-processor List, and any available third-party certifications or audit reports. Where these do not resolve the Customer’s reasonable audit need, the parties agree the scope, timing, and conduct of any further audit in advance. On-site inspections take place during business hours, no more than once per twelve-month period (save where a supervisory authority requires otherwise or following a personal data breach), with reasonable prior notice, in a way that does not unreasonably disrupt operations, and subject to confidentiality. Each party bears its own costs; Finalform may charge its reasonable cost for audit support that materially exceeds the standard information response.
14. International transfers (Chapter V)
The customer-side snippet transmits visitor data only to the first-party Autopage API and calls no third party directly; every third-party transfer of visitor data happens server-side from the engine. Where the provision of Autopage involves the transfer of personal data to a third country, Finalform ensures an appropriate Article 44ff. transfer mechanism is in place for each Sub-processor, as set out in the Sub-processor List.
Where a Sub-processor is certified under the EU-US Data Privacy Framework (DPF), transfers rely on the European Commission’s adequacy decision for that framework. Where a Sub-processor is not DPF-certified, transfers are made under the European Commission’s Standard Contractual Clauses (SCCs), supported by a transfer-impact assessment evaluating the legal regime and the supplementary measures in place. On request, Finalform discloses, in advance, the third country and the specific Article 44ff. mechanism for each Sub-processor and makes a copy of the relevant safeguards available.
Per-recipient position:
- Railway Corporation (US): third-country transfer; DPF adequacy if certified, otherwise SCCs + a transfer-impact assessment.
- Anthropic, PBC (US): third-country transfer; DPF or SCCs + TIA. Mitigated by the data-minimisation posture (no per-visitor data, identifiers stripped, no content logged, no-training tier).
- Cloudflare, Inc. (US): third-country transfer; DPF or SCCs + TIA. Lowest-exposure recipient (only a public URL leaves).
- Stripe: if the contracting entity is Stripe Payments Europe, Ltd. (Ireland), the EU leg is intra-EEA with no Chapter V transfer, and onward US processing relies on Stripe’s own DPF/SCC safeguards; if the contracting entity is Stripe, Inc. (US), it is a third-country transfer (DPF / SCCs + TIA). The entity choice drives the label.
- Resend (Plus Five Five, Inc., US): third-country transfer; DPF or SCCs + TIA.
15. Consent allocation
The Customer is responsible for obtaining any visitor consent required under Section 25 TDDDG for storing or reading information on a visitor’s device, and for establishing a lawful basis under the GDPR, before behavioral data is collected through the snippet. The Customer is responsible for configuring its consent platform so that the Autopage snippet is gated and does not collect behavioral data or write to a visitor’s device until a valid consent signal is present.
Finalform provides the technical means for the snippet to respect a consent signal (default deny until consent; the snippet defaults to a strict mode in which nothing is read or written before consent), but Finalform does not determine, obtain, or verify visitor consent on the Customer’s pages, and is not the controller for that purpose. The Customer instructs Finalform to process visitor data only where the Customer has secured the necessary consent and lawful basis.
The Customer indemnifies Finalform against claims, losses, and regulatory measures arising from the Customer’s failure to obtain or document valid visitor consent or a lawful basis, aligned with the liability provisions of the Terms and the Acceptable Use Policy.
16. Liability and order of precedence
The liability of the parties under or in connection with this DPA is governed by the liability provisions of the main agreement (Terms of Service), including its limitation and cap, except where mandatory law provides otherwise.
In the event of a conflict between this DPA and the main agreement on the subject matter of data processing, this DPA prevails to the extent of the conflict. On all other matters, the main agreement prevails. The Sub-processor List and the TOMs (Annex 2) form part of this DPA; in a conflict between this DPA and those annexes, this DPA prevails unless the annex is expressly stated to govern.
17. Form and acceptance
This DPA is concluded in electronic form, which satisfies the form requirement of Article 28(9) GDPR. It is accepted in one of two ways:
- Click acceptance at signup, as part of accepting the Terms of Service; or
- Signature as a PDF, for enterprise buyers who require a signed copy.
Both methods produce a binding DPA on the same terms. The comped design-partner pilot signs this DPA (with the TOMs and Sub-processor List attached) before the snippet goes live and before any visitor personal data flows through the Service. The acceptance ledger records the DPA version and timestamp alongside the Terms acceptance.
Annex 1: Details of processing
| Field | Detail |
|---|---|
| Controller | The Customer |
| Processor | Finalform GmbH, Theodor-Heuss-Str. 106, 26129 Oldenburg, Germany; Amtsgericht Oldenburg HRB 222780; USt-IdNr. DE457693089 |
| Subject matter | Processing of visitor personal data through the Autopage snippet to provide Autopage to the Customer |
| Duration | Coextensive with the main agreement; for as long as Finalform processes personal data on the Customer’s behalf, subject to the deletion and return obligations |
| Nature of processing | Automated collection, storage, and population-level analysis of visitor interaction data; generation and serving of page variants; A/B testing; AI-assisted rewriting of the copy on the Customer’s connected pages |
| Purpose | A/B testing and AI-assisted optimization of the Customer’s connected pages |
| Types of personal data | Pseudonymous visitor session identifier (a random first-party identifier, not a fingerprint, with a 30-day cookie lifetime); coarse, bucketed behavioral signals (device class, traffic-source category, scroll depth, time on page). No IP address, full user-agent, precise geolocation, device fingerprint, raw referrer, raw UTM, or form input is collected or persisted. A visitor IP exists only transiently (~60s) in memory as a rate-limiting key and is never stored, logged, truncated, or hashed by Autopage application code |
| Data sent to the LLM | Tenant brief + baseline page copy + population-level aggregate metrics only; direct identifiers stripped; no per-visitor data; no prompt/response content logged |
| Categories of data subjects | The Customer’s website visitors |
| Special categories (Art 9) | None intended. The Customer must not configure the Service to process special categories of data or instruct processing of such data |
| Sub-processors | As listed in the published Sub-processor List, which operates under the general written authorization in Section 8 and is an annex to this DPA by reference |
Sub-processors (summary; the authoritative list, with effective date and version, is the published Sub-processor List):
| # | Sub-processor (legal entity) | Service / role | Personal data received | Hosting region | Transfer mechanism |
|---|---|---|---|---|---|
| 1 | Railway Corporation (Delaware, US) | Application hosting + compute (engine API, web dashboard) and managed PostgreSQL primary database | All processed and persisted personal data: visitor pseudonymous session id + behavioral events, customer account data, billing metadata. The visitor IP is processed transiently in memory for rate-limiting only; it is not persisted or written to any log line by Autopage application code | US default; EU residency set per service | DPF adequacy if certified, else SCCs + TIA |
| 2 | Anthropic, PBC (Delaware, US) | LLM; generates/rewrites landing-page copy | No per-visitor personal data. Tenant brief + baseline page copy + population-level aggregate metrics only; identifiers stripped; no prompt/response content logged | US | DPF adequacy if certified, else SCCs + TIA; no-training / zero-retention tier |
| 3 | Cloudflare, Inc. (Delaware, US) | Browser Rendering API; renders the customer’s SPA landing page during baseline scrape | Only the customer’s public landing-page URL; returns rendered HTML. No visitor PII, no account data | US | DPF adequacy if certified, else SCCs + TIA |
| 4 | Stripe (Stripe Payments Europe, Ltd. (Ireland) vs Stripe, Inc. (US)) | Payments; Checkout, Customer Portal, subscription management, webhooks | Customer billing email + name, org-id metadata, subscription/transaction data. Card data goes directly to Stripe-hosted pages; Finalform stores no card data | EU + US per account | Intra-EEA (no Chapter V transfer) if Stripe Payments Europe Ltd (IE); else DPF / SCCs + TIA |
| 5 | Resend (Plus Five Five, Inc., US) | Transactional email; verification, magic-link, password reset, invitations, notifications | Recipient customer email address + email content (subject/HTML), name in templates | US | DPF adequacy if certified, else SCCs + TIA |
Annex 2: Technical and Organizational Measures (TOMs)
The technical and organizational measures Finalform applies under Section 7 and Article 32 GDPR are set out in the Technical and Organizational Measures document, which forms part of this DPA as Annex 2. The TOMs document carries its own effective date and version and is published alongside this DPA.