Data processing agreement & subprocessors

Last updated: October 7, 2026Deutsche Fassung

This is an English translation for convenience. Only the German version is legally binding.

Draft for the closed beta. It will be reviewed by a lawyer before the public launch.

This agreement under Art. 28 GDPR applies between you as the operator of your websites (“controller”) and Studio Treo – Tobias Affüpper, Feldstraße 12, 40721 Hilden, Germany (“processor”). You enter into it by accepting the terms of service.

1. Subject matter

  • Nature and purpose: delivering CSS and JavaScript files to the browsers of your websites’ visitors through the Koppel CDN.
  • Data: visitors’ IP address, user agent, requested URL and referrer, used only technically for delivery. Koppel sets no cookies and stores no visitor profiles.
  • Data subjects: visitors of your websites.
  • Duration: as long as you use Koppel. Technical logs are deleted at our service providers after at most 7 days.

2. Obligations of the processor

  • Processing only on your documented instructions; the instructions are your project’s configuration.
  • Confidentiality of everyone with access.
  • Technical and organizational measures under Art. 32 GDPR (see section 4).
  • Assistance with data subject requests and with notifications under Art. 33 and 34 GDPR.
  • Notification of personal data breaches to you without undue delay, at the latest within 48 hours.
  • Deletion or return after use ends: deleting a project or account removes all of its files.
  • Evidence and audits to a reasonable extent, with prior notice.

3. Subprocessors

You consent to the following subprocessors. We announce new ones at least 30 days in advance by email; you can object.

ProviderServiceLocation / basis
Cloudflare Inc.CDN, server functions, code storage (R2)Worldwide; storage in the EU; EU-US Data Privacy Framework
Vercel Inc.Dashboard hostingUSA / worldwide; EU-US Data Privacy Framework
Supabase Inc.Database, sign-inFrankfurt (EU); EU-US Data Privacy Framework
Sendinblue SAS (Brevo)Email deliveryEU
GitHub Inc.Encrypted database backupUSA; EU-US Data Privacy Framework

Only Cloudflare is involved in delivering files to visitors.

4. Technical and organizational measures

  • Encrypted transport (TLS, HSTS) on all endpoints.
  • Tenant isolation in the database with row level security; every API request checks account, role and project.
  • Separate, cookieless domain for delivery; only CSS and JavaScript, never HTML.
  • Editor access with short-lived, rotating tokens that can never change production; changes to production only after a fresh sign-in, with an email notification.
  • Immutable releases that can be rolled back in seconds; emergency switch-off per project.
  • Daily encrypted backups, kept for 30 days.
  • Two-factor authentication on all service provider accounts.