Data processing agreement & subprocessors
Last updated: October 7, 2026Deutsche Fassung
This is an English translation for convenience. Only the German version is legally binding.
Draft for the closed beta. It will be reviewed by a lawyer before the public launch.
This agreement under Art. 28 GDPR applies between you as the operator of your websites (“controller”) and Studio Treo – Tobias Affüpper, Feldstraße 12, 40721 Hilden, Germany (“processor”). You enter into it by accepting the terms of service.
1. Subject matter
- Nature and purpose: delivering CSS and JavaScript files to the browsers of your websites’ visitors through the Koppel CDN.
- Data: visitors’ IP address, user agent, requested URL and referrer, used only technically for delivery. Koppel sets no cookies and stores no visitor profiles.
- Data subjects: visitors of your websites.
- Duration: as long as you use Koppel. Technical logs are deleted at our service providers after at most 7 days.
2. Obligations of the processor
- Processing only on your documented instructions; the instructions are your project’s configuration.
- Confidentiality of everyone with access.
- Technical and organizational measures under Art. 32 GDPR (see section 4).
- Assistance with data subject requests and with notifications under Art. 33 and 34 GDPR.
- Notification of personal data breaches to you without undue delay, at the latest within 48 hours.
- Deletion or return after use ends: deleting a project or account removes all of its files.
- Evidence and audits to a reasonable extent, with prior notice.
3. Subprocessors
You consent to the following subprocessors. We announce new ones at least 30 days in advance by email; you can object.
| Provider | Service | Location / basis |
|---|---|---|
| Cloudflare Inc. | CDN, server functions, code storage (R2) | Worldwide; storage in the EU; EU-US Data Privacy Framework |
| Vercel Inc. | Dashboard hosting | USA / worldwide; EU-US Data Privacy Framework |
| Supabase Inc. | Database, sign-in | Frankfurt (EU); EU-US Data Privacy Framework |
| Sendinblue SAS (Brevo) | Email delivery | EU |
| GitHub Inc. | Encrypted database backup | USA; EU-US Data Privacy Framework |
Only Cloudflare is involved in delivering files to visitors.
4. Technical and organizational measures
- Encrypted transport (TLS, HSTS) on all endpoints.
- Tenant isolation in the database with row level security; every API request checks account, role and project.
- Separate, cookieless domain for delivery; only CSS and JavaScript, never HTML.
- Editor access with short-lived, rotating tokens that can never change production; changes to production only after a fresh sign-in, with an email notification.
- Immutable releases that can be rolled back in seconds; emergency switch-off per project.
- Daily encrypted backups, kept for 30 days.
- Two-factor authentication on all service provider accounts.