This English version is a translation provided for information. The German version is the legally binding one.

    Data Processing Agreement (DPA)

    pursuant to Art. 28 GDPR · As of: September 2026

    Contracting Parties

    Controller (Controller)

    The company that uses the platform draftgo.io on the basis of the Terms (“Controller”).

    Processor

    draftgo.io is operated jointly by the following companies. For the purposes of this agreement, both act jointly as processor (“Processor”):

    Mai Ventures GmbH
    Heinrich-Bettinger-Str. 14, 78333 Stockach
    Represented by: Simon Mai
    Amtsgericht Freiburg i. Br., HRB 727282

    pacutec UG (haftungsbeschränkt)
    Heinrich-Bettingerstr. 11, 78333 Stockach
    Represented by: Pascal von Briel
    Amtsgericht Freiburg i. Br., HRB 735059

    Central point of contact: service@draftgo.io

    Section 1 Subject Matter, Duration and Conclusion of Contract

    The subject matter of this agreement is the processing of personal data by the processor within the scope of the provision of the proofing and approval platform draftgo.io in accordance with the Terms and Conditions (“Main Contract”). The processing shall take place exclusively for this purpose.

    The term of this agreement corresponds to the term of the Main Contract. It ends automatically upon its termination; the provisions in Section 9 shall continue to apply thereafter.

    This agreement automatically becomes an integral part of the Main Contract upon registration on draftgo.io. A separate signature is not required. In the event of conflicts between this agreement and the Terms, the provisions of this agreement shall take precedence in matters of data protection.

    § 2 Nature, Scope and Purpose of the Processing

    Nature and purpose of the processing: Storing, displaying, modifying, transmitting and deleting personal data in connection with projects, files, comments and approval processes, the dispatch of invitations and notifications, as well as the evaluation of content by AI features, to the extent that the controller uses them.

    Types of personal data:

    • Master data (name, email address, company, role, profile picture) of users and invited guests
    • Usage data (login times, actions, approvals, activity log)
    • Communication data (comments, mentions, notifications)
    • Content uploaded by the controller (files, images, videos, PDFs) and personal data contained therein
    • Technical data (IP address, browser, timestamp, device information)

    Categories of data subjects:

    • Employees and team members of the controller
    • External guests and reviewers whom the controller invites to the platform
    • Other natural persons whose data are contained in uploaded content

    The processing of special categories of personal data (Art. 9 GDPR) is not the subject matter of this agreement. If the controller nevertheless uploads such data, it shall ensure that this is permissible.

    The processing of contract, payment and invoice data of the controller is not the subject matter of this agreement; in this respect, the processor is itself the controller. Further details are governed by the Privacy Policy.

    § 3 Rights and obligations of the controller

    The controller is the controller within the meaning of Art. 4(7) GDPR. It is solely responsible for the lawfulness of the processing, in particular for the permissibility of uploading content and inviting guests, as well as for safeguarding the rights of data subjects.

    The controller shall inform the processor without undue delay if it detects errors or irregularities in the processing.

    § 4 Instructions

    The processor processes personal data exclusively on documented instructions from the controller, unless it is required by law to carry out other processing. In this case, it shall inform the controller of this obligation in advance, unless the law prohibits such notification.

    The controller generally issues instructions through the use of the functions of the platform. It shall issue supplementary instructions in text form. Instructions that go beyond the agreed scope of services shall be treated as a request for a change in services.

    If the processor is of the opinion that an instruction breaches data protection provisions, it shall inform the controller without undue delay. It may suspend the execution of the instruction until the controller confirms or amends it.

    Section 5 Obligations of the processor

    • It only engages persons who are committed to confidentiality or are subject to a statutory obligation of confidentiality (Art. 28(3)(b) GDPR).
    • It implements the technical and organisational measures described in Section 7 and Annex 2.
    • It assists the controller with appropriate measures in fulfilling the rights of data subjects (Art. 12 to 23 GDPR) and in complying with the obligations pursuant to Art. 32 to 36 GDPR. It forwards requests from data subjects that are received directly by the processor to the controller without undue delay.
    • It notifies the controller of personal data breaches without undue delay, at the latest within 72 hours of becoming aware of them. The notification contains, in so far as available, the information pursuant to Art. 33(3) GDPR.
    • It demonstrates compliance with its obligations under Art. 28 GDPR to the controller upon request (Section 8).

    The processor may demand reasonable remuneration for support services that go beyond the standard functions of the platform and are not based on a breach by the processor.

    Section 6 Sub-processors

    The controller grants general authorisation for the engagement of sub-processors. The sub-processors engaged at the time of conclusion of the contract are listed in Annex 1 and are deemed approved.

    The processor shall inform the controller of any intended addition or replacement of a sub-processor at least four weeks in advance in text form, for example by email or via the platform. The controller may object within this period for good cause under data protection law. If the parties do not reach an agreement, either party may terminate the main contract extraordinarily at the time of the change.

    The processor shall contractually impose on each sub-processor data protection obligations that correspond to those of this contract. Transfers to third countries outside the EU and the EEA shall only take place if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision (e.g. EU-US Data Privacy Framework) or the EU Standard Contractual Clauses.

    § 7 Technical and organisational measures

    The processor shall implement appropriate technical and organisational measures pursuant to Art. 32 GDPR to ensure a level of protection appropriate to the risk. The measures are described in Annex 2. The processor may adapt them to technical progress, provided that the level of protection is not thereby reduced.

    § 8 Evidence and Audits

    The processor shall demonstrate compliance with its obligations primarily by means of suitable documentation, such as current certificates, audit reports or audit results, including those of sub-processors.

    If this is not sufficient in an individual case, the controller may conduct an inspection or have one conducted by an auditor bound by confidentiality who is not in competition with the processor. Inspections shall take place following notification with a notice period of generally four weeks, at most once per calendar year, during normal business hours and without avoidable disruption to operations. Ad hoc audits following a personal data breach or by order of a supervisory authority shall remain unaffected. The processor may demand reasonable remuneration for the effort incurred for inspections.

    § 9 Deletion and Return

    Following termination of the main contract, the processor shall delete all personal data of the controller within a reasonable period, at the latest after 90 days, unless precluded by a statutory retention obligation. Data in backup copies shall be deleted within the scope of the regular backup cycles.

    Upon request by the controller prior to the end of the contract, the processor shall return the data prior to deletion in a structured, commonly used and machine-readable format, insofar as they cannot be exported via the functions of the platform itself.

    § 10 Liability

    Art. 82 GDPR applies to liability towards data subjects. In their internal relationship, the parties are liable in proportion to their respective share of responsibility for the damage incurred. In all other respects, the liability provisions of the Terms and Conditions apply.

    § 11 Final Provisions

    Amendments to this agreement shall be made in accordance with the procedure set out in the Terms and Conditions or in text form. Should individual provisions be invalid, the validity of the remaining provisions shall remain unaffected. The law of the Federal Republic of Germany shall apply, to the exclusion of the UN Convention on Contracts for the International Sale of Goods (CISG). If the controller is a merchant, a legal person under public law, or a special fund under public law, the place of jurisdiction shall be Stockach.

    Annex 1 – Sub-processors

    Sub-processorServiceLocation of processing
    Lovable Labs Incorporated (USA)Lovable Cloud: Provision of the application, Edge FunctionsUSA
    Supabase Inc. (USA)Database, authentication, file storageEU (Frankfurt)
    Amazon Web Services EMEA SARL (Luxembourg)underlying cloud infrastructureEU (Frankfurt)
    Cloudflare, Inc. (USA)runtime environment and delivery of the applicationworldwide (global data centre network)
    Resend Labs, Inc. (USA)dispatch of transactional emails, e.g. invitations and notificationsUSA
    Browserless (USA)automated creation of website preview imagesUSA
    Lovable Labs Incorporated (USA)Lovable AI Gateway: AI functions (AI review, assistant “GO”) with language models from Google (Gemini)USA, model providers worldwide

    Annex 2 – Technical and Organisational Measures

    Confidentiality

    • Physical access control: Operation exclusively in the data centres of the cloud providers deployed
    • System and data access control: role-based permissions, JWT-based authentication, row-level security at database level
    • Separation control: Multi-tenant separation via row-level security policies per company and project
    • Encryption of data at rest (AES-256 at storage level)

    Integrity

    • Transmission control: Encryption of all transmissions (HTTPS, TLS 1.2 or higher)
    • Input control: Audit log for security-relevant actions

    Availability and resilience

    • Redundant cloud infrastructure and automated backups
    • Rapid recoverability through a disaster recovery process

    Instruction control

    • Obligation of employees to maintain confidentiality
    • Documented instructions
    • Contracts with all sub-processors

    Review and incident management

    • Regular testing, assessment and evaluation of measures (data protection reviews, security scans, updating of dependencies)
    • Defined process for reporting and handling data protection incidents, including notification of the controller within 72 hours

    For the processor

    Simon Mai, Managing Director, Mai Ventures GmbH
    Pascal von Briel, Managing Director, pacutec UG (haftungsbeschränkt)

    Stockach, September 2026