Data Processing Addendum

Version 2026-07-10 · provider: Minerics UG (haftungsbeschränkt), HRB 768686

Data Processing Addendum — scope and roles

This Data Processing Addendum (DPA) is incorporated into the Customer Terms. Customer is the tenant controller and minerics UG is processor only to the extent minerics UG processes personal data on Customer's behalf to provide gated hosting, access workflows, tenant analytics, and Customer-instructed delivery. minerics UG remains an independent controller for its own account administration, billing/legal duties, service security and abuse response where it determines those purposes and means. The DPA does not mechanically apply to activity for which no controller–processor relationship exists.

1. Documented instructions and law

minerics UG processes personal data only on Customer's documented instructions, including for a third-country transfer, unless Union or Member State law requires processing. Where legally permitted, minerics UG will tell Customer before that required processing. Product configuration, the agreement, and authenticated support instructions are documented instructions. minerics UG will promptly tell Customer if it believes an instruction is an unlawful instruction and may pause the affected processing while the parties resolve it.

2. Confidentiality and personnel

minerics UG ensures that personnel authorised to process Customer personal data have committed themselves to confidentiality or are under an appropriate statutory duty, receive access only as needed for their role, and are instructed on the applicable security and data-protection controls.

3. Security

minerics UG implements the technical and organisational measures in Annex II, taking account of the state of the art, implementation cost, processing nature and risks. Customer is responsible for using available gates, notices, credentials, destination controls, and deletion functions consistently with its own risk assessment.

4. Sub-processors

Customer gives general written authorisation for the current sub-processors published by Sendhey. minerics UG will impose in substance equivalent Article 28 obligations on a sub-processor and remains responsible for its performance as required by Article 28(4). minerics UG will email the Customer account owner at least 30 days before a new or replacement sub-processor begins the affected processing. Customer may object on reasonable data-protection grounds at support@sendhey.app during that period. The parties will seek a reasonable alternative; if none is available, Customer may stop the affected optional function or terminate the affected service before the change takes effect.

5. International transfers

Transfers subject to GDPR Chapter V occur only on documented instructions or a legal requirement and with the mechanism appropriate to the actual recipient and processing. An applicable Article 45 adequacy decision, including a scope-matched active EU–US Data Privacy Framework certification, may be used where its conditions are met. Otherwise the parties select the correct safeguards, SCC module, transfer assessment, and supplementary measures. Decision 2021/914 is not boilerplate for every relationship and a vendor's SCCs do not cover unrelated processing. Commission Decision 2021/915 Article 28 clauses are an optional Assured contract form where Customer requests them; they are not Chapter V transfer clauses.

6. Data subject rights assistance

Taking account of the nature of processing, minerics UG will assist Customer by appropriate technical and organisational measures, insofar as possible, with requests for data subject rights. If minerics UG receives a request concerning Customer-controlled data, it will direct the requester to Customer where appropriate and will not independently answer on Customer's behalf unless instructed or legally required.

7. Breach, DPIA, and consultation assistance

minerics UG will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer-controlled data and provide information reasonably available for Customer's assessment and notification duties. Taking account of the processing and information available, minerics UG will reasonably assist with security obligations, data protection impact assessment work, and prior consultation with a supervisory authority.

8. Delete or return

At termination and at Customer's choice, minerics UG will delete or return Customer-controlled personal data through the documented rights workflow, then delete remaining tenant data through the purpose-based retention and tombstone workflow. Copies are deleted when provider backup/version periods expire unless Union or Member State law requires restricted retention. Suppression and minimum legal evidence are retained only for their documented purpose and period.

9. Information and audit

minerics UG will make available information reasonably necessary to demonstrate compliance with this DPA and permit and contribute to audits required by Article 28. The Lean mechanism begins with the public DPA, TOMs, sub-processor/transfer records, test evidence, and reasonable written questions. Where that is insufficient, the parties will arrange a scoped audit during normal business hours, protecting other customers, security, confidentiality, and privileged material. Customer bears avoidable third-party audit cost unless a material breach by minerics UG is found.

10. Duration and priority

This DPA starts when the Customer agreement is accepted and continues while minerics UG processes Customer personal data as processor. Mandatory processor obligations survive for retained data. If this DPA conflicts with the Customer Terms about processing on Customer's behalf, this DPA prevails.

Annex I — parties and processing details

Controller: the Customer legal person or individual identified by the Sendhey workspace and accepting account, with its current account contact. Processor: minerics UG, HRB 768686, Schellingstraße 18, 70794 Filderstadt, Germany; support@sendhey.app. Subject matter: gated hosting, access control, tenant-requested analytics and delivery. Duration: the agreement term plus the purpose-based retention and deletion periods. Nature and purpose: receive, store, organise, retrieve, transmit on instruction, secure, support, return and delete data to provide the service. Categories of data subjects: Customer users, invited workspace users, and visitors to Customer links. Categories of personal data: account identifiers and email, authentication and access records, Customer content that may contain personal data, visitor email and Customer-defined gate fields, access decisions, event/activity data, and tenant-configured delivery metadata. Special-category and criminal-offence data are not intended for Lean processing and require a separately reviewed written arrangement. Customer retains all controller rights and obligations and may issue lawful documented instructions.

Annex II — technical and organisational measures (TOMs)

Measures include tenant-scoped D1 queries and branded ownership boundaries; tenant-prefixed R2 objects; hashed API/OAuth credentials; salted password derivation; HMAC-pseudonymous rate-limit and consent subjects; TLS in transit and provider encryption at rest; least-privilege secrets and deployment credentials; separate app/content origins; restrictive CSP for tenant HTML; bounded sessions, tokens, logs and delivery attempts; disabled automatic invocation logs and traces; append-only legal/consent evidence; purpose-based cron deletion; tombstone-first tenant erasure after restore; additive reviewed migrations; automated type, unit, integration, coverage, deployment and production-smoke gates; incident, rights and provider review procedures. Availability and recovery use Cloudflare's service controls and D1 Time Travel, with deletion reapplication after restore. TOMs evolve without materially reducing the protection required by this DPA.

Annex III — authorised sub-processors and transfer information

The versioned human-readable and machine-readable Sendhey sub-processor list and transfer map recorded with Customer's acceptance are incorporated by reference. They identify role, purpose, minimum data, location/transfer status, enablement condition, and contract review record. Later list changes use the general-authorisation notice and objection process in section 4 without rewriting Customer's historical acceptance. Tenant-appointed signal destinations are listed separately as Customer instructions rather than silently classified as minerics UG sub-processors.


Contact support@sendhey.app. This operational baseline is not a legal-compliance certification.

About · Privacy · Legal notice · Report illegal content · Terms · DSA