Legal
Data processing.
Last updated · September 15, 2026
This is a convenience translation of the German original. The German version is the legally binding one; where the two differ, the German text prevails.
This Data Processing Agreement (“DPA”) forms Appendix 1 to the general terms and conditions of REVERCE GmbH for verstag (the “Terms”) and applies as an integral part of them. It governs the processing of personal data that we process on your behalf. Terms defined in the Terms have the same meaning here unless expressly defined otherwise.
Where this DPA refers to the processing of personal data, this always means exclusively the processing by us on your behalf and exclusively in the context of providing the Service under the Terms.
1. Subject matter and duration
We provide you with verstag under the Terms. This may involve the processing of personal data. The subject matter of this DPA is the processing of personal data that you or the users you authorise bring into your workspace or create there.
This DPA runs for as long as the contract for the use of verstag and ends with it. It continues to apply beyond termination for as long as we still hold personal data from your workspace.
2. Definitions
Authorised users are persons to whom you grant access to your workspace.
Service means the service provided under the Terms, in particular the provision of the verstag platform.
Service documentation means the entirety of the official descriptions of the Service: the documentation, the guidance and workflows visible within the Service itself, and the privacy notice.
The terms personal data, processing, controller, processor, data subject and personal data breach have the meaning given to them by Art. 4 GDPR.
3. Roles of the parties
For the processing covered by this DPA you are the controller and we are the processor. Covered is the content of your workspace: uploaded image and video files including the persons depicted in them, the metadata of those files, the derivatives created from them, the membership, role and invitation data of the workspace, and its verification and audit records.
For a delimited set of data we are ourselves the controller, and that set is not the subject of this DPA. It covers the master data of your account and of the authorised users, to the extent we process it to establish, perform and invoice the contractual relationship and to secure access, as well as the connection metadata of our technical operations. The purposes and legal bases of that processing are set out in the privacy notice.
For data in respect of which we are the controller we cannot be bound by instruction; the delimitation in paragraph 2 therefore records what your right to instruct under clause 4 extends to and what it does not.
4. Instructions
We process the personal data only on your documented instructions, including the enforcement of the conditions of the underlying agreement. This does not apply where we are required to process the data otherwise by Union or Member State law; in that case we will inform you of that requirement before processing, unless that law prohibits the information on important grounds of public interest. Being bound by instructions also applies to any transfer to a third country.
You hereby instruct us to process the data in accordance with the service documentation and in accordance with the use of the Service by the authorised users. Operations performed by authorised users within the Service are instructions within the meaning of this paragraph.
We do not owe services beyond the agreed scope unless the instruction is necessary to implement statutory requirements. You may instruct us at any time to stop the processing under this DPA; to the extent this makes it impossible for us to provide the Service and your instruction is the cause, the failure to provide it does not constitute a breach of contract.
You will issue instructions only in accordance with data protection law. If we consider an instruction to be unlawful under data protection law we will inform you without undue delay; pending your confirmation we may suspend the execution of that instruction.
Instructions going beyond paragraph 2 require text form; you will confirm instructions given orally in text form without undue delay.
5. Confidentiality and security of processing
We ensure that the persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they are instructed in the handling of personal data. That obligation continues after their activity ends.
We implement the technical and organisational measures required by Art. 32 GDPR. The measures currently in force are set out in Schedule 2. You check whether those measures are sufficient in your view for the type of data you bring in. We may adapt the measures to the state of the art as long as the overall level of security is not reduced.
6. Rights of data subjects
We support you by appropriate technical and organisational measures in responding to requests from data subjects under Chapter III GDPR. To the extent the Service provides functions for this purpose — information about the stored content, rectification, export and erasure — we fulfil this obligation by providing them.
If a data subject contacts us directly, we will not answer the request ourselves but forward it to you without undue delay.
7. Sub-processors
We engage further processors (“sub-processors”) only with your approval. The approved sub-processors are listed in Schedule 3.
You hereby grant us general approval for engaging further sub-processors. We will inform you of any intended change by updating Schedule 3. That update is made before the new sub-processor begins processing, and the list carries its own effective date for this purpose. You may object to the engagement of a new sub-processor on concrete data protection grounds within 14 days of that effective date.
In the event of an objection we will make commercially reasonable efforts to offer a solution without the sub-processor concerned. If no agreement is reached, we may engage the sub-processor; you may then terminate the contract for the use of the Service for cause.
We impose on the sub-processor data protection obligations corresponding to those under this DPA (Art. 28(4) GDPR). We select sub-processors carefully and are responsible for their acts and omissions as for our own.
Ancillary services of third parties that do not, as intended, receive access to the data of your workspace — such as telecommunications or maintenance services — do not constitute sub-processing.
8. Support and audits
On request we support you to a reasonable extent in your obligations under Art. 32 to 36 GDPR and in documenting and reviewing compliance with data protection law, to the extent the processing under this DPA is concerned. This includes in particular informing you of personal data breaches that have come to our knowledge, and support with a data protection impact assessment and with any necessary consultation of the supervisory authority. As a rule we fulfil this obligation by providing the documents generally available for the Service.
To implement paragraph 1 you may carry out audits at our premises, or have them carried out by a third party bound to secrecy, to the extent reasonably necessary. Such audits take place primarily through the review of documents. Where an on-site audit takes place, you will have due regard to our operational concerns and those of the sub-processors affected; the audit is limited to the necessary extent, takes place except in urgent cases after reasonable notice — as a rule at least four weeks — and during normal business hours, and the confidentiality of the data held by us and by our sub-processors is maintained.
You will exercise the aforementioned rights proportionately.
9. Personal data breaches
We will inform you without undue delay after becoming aware of a personal data breach within the meaning of Art. 4(12) GDPR affecting data processed under this DPA.
The notification contains the information you need for your own notification under Art. 33(3) GDPR, in particular: whether data processed on your behalf is affected, the categories of data concerned, where possible the categories and approximate number of data subjects and records concerned, the nature of the access to the data, the likely consequences of the breach as far as we can assess them, and the remedial measures we have taken and propose. Information not available at the time of the initial notification will be provided later.
Notification of the supervisory authority under Art. 33 GDPR and communication to data subjects under Art. 34 GDPR are your responsibility as controller. We take the containment measures that can reasonably be expected of us and document the incident.
10. Return and erasure
After the end of the processing we will, on request, make the personal data processed on your behalf available to you for export in a common format.
We will then delete the data including existing copies within the periods stated in the service documentation, to the extent no statutory retention obligation prevents this. Where a workspace falls back to a plan with a narrower retention ceiling, that period is 30 days from the downgrade; after it the originals and derivatives concerned are permanently deleted and cannot be restored.
Notwithstanding paragraph 2, we continue to keep the provenance and audit records of your workspace as evidence after the associated binaries are deleted: the continuing audit history is part of the agreed service (clause 7 of the Terms), and you hereby instruct us within the meaning of clause 4 to keep it accordingly. For the period after the end of the contract you may revoke that instruction; in that case we delete or anonymise those records as well, unless a statutory retention obligation prevents it.
If you do not request provision in good time — at the latest by the end of the applicable period under paragraph 2 — we are not obliged to hold the data any longer.
11. Transfers to third countries
The processing takes place in the European Union or the European Economic Area unless Schedule 3 states otherwise.
Where a sub-processor named in Schedule 3 processes personal data in a third country without an adequacy decision, we base the transfer on appropriate safeguards under Art. 46 GDPR, in particular the European Commission’s standard contractual clauses, and take the necessary supplementary measures. Schedule 3 states, for each sub-processor, what the transfer is based on.
12. Remuneration
Performance of the obligations under this DPA is covered by the fee for the Service. If implementing this DPA causes unusually high effort due to your particular situation, we may charge that effort at reasonable rates to the extent legally permissible. We will announce such effort in advance.
13. Liability
The liability provisions of the Terms apply. Art. 82 GDPR remains unaffected.
14. Effectiveness and relationship to the Terms
This DPA is Appendix 1 to the Terms and is agreed together with their incorporation. The written form required by Art. 28(9) GDPR may also be satisfied in an electronic format.
On your request we will additionally conclude this DPA separately in text form and provide you with a copy signed by us. Please contact hello@verstag.io.
For the processing covered by this DPA, it prevails over the Terms where the two conflict. In all other respects the Terms apply, including their provisions on governing law and place of jurisdiction. Schedule 3 is updated in accordance with clause 7; in all other respects amendments to this DPA follow the Terms.
Schedule 1 — Subject matter, nature and scope of processing
Purpose
Provision of the verstag platform: storing and managing uploaded image and video files, verifying embedded C2PA provenance information, deriving and signing channel-specific versions, maintaining a verification and audit record, and delivering the associated transactional e-mail.
Nature of the processing
Collection, storage, retrieval, alteration (cropping, format, labelling), creation of derived files, signing, provision to the authorised users, logging and erasure. The processing is fully automated.
Duration
For the term of the contract for the use of verstag, plus the periods under clause 10. Files uploaded solely for verification and not taken into the library are deleted automatically no later than 12 hours after upload.
Categories of data subjects
- your employees and other authorised users,
- persons you invite into a workspace,
- persons depicted in or identifiable from uploaded image and video files,
- persons named in the metadata of those files, in particular creators, editors and signers from embedded C2PA manifests and from EXIF and XMP fields.
Categories of personal data
- Membership data of the authorised users within the workspace: e-mail address, display name, role and membership status.
- Invitation data: e-mail address of the invited person, status and expiry of the invitation.
- Content data: the uploaded image and video files themselves, including the persons depicted in them, and the derivatives created from them.
- File and provenance metadata: file name, type, size and dimensions, and the EXIF, XMP and C2PA information embedded in the file. This may contain authorship and editing information, timestamps, signature and certificate details, source-type information about the material and — depending on the capture device — location and device data.
- Derivative and signature data: derivative specifications (crop, format, labelling options), the rendered output files and the C2PA signature metadata attached to them.
- Audit records of verification and activity: who triggered which signing, verification, change or download and when, each with the policy state in force.
- Other customer input: free-text entries in the workspace, such as folder names and labels.
Special categories of personal data
The processing of special categories of personal data within the meaning of Art. 9 GDPR is not the subject of this agreement. Image material may nevertheless reveal such data in fact. What therefore applies is what the Service actually does: we perform no facial recognition, no biometric identification and no analysis of the content of the image or video material. The processing is limited to technical operations — provenance verification, derivation, signing. Inspection by our staff does not take place in normal operation, and no automated decision-making within the meaning of Art. 22 GDPR takes place.
To the extent you bring in material whose processing requires special conditions under Art. 9 GDPR, you are responsible for their existence.
Schedule 2 — Technical and organisational measures
The following measures are those currently implemented. We may adapt them under clause 5 paragraph 2 as long as the overall level of security is not reduced.
Encryption and key custody
- Access to the Service is exclusively transport-encrypted via TLS; HTTP Strict Transport Security is set, including subdomains.
- The private signing key is held non-extractably in a hardware security module and never leaves it. Only a hash value is passed for signing, never the file content. The same applies to the time-stamping service.
- Access secrets are not stored in plain text; authentication is handled by the service designated for it in Schedule 3.
Confidentiality and access control
- Tenant separation at the database level. Each workspace is separated by row level security; access to tenant data is possible only through a path that sets the tenant context of the transaction. Cross-tenant access is confined to one deliberately designated path that can be enumerated in the source.
- Role-based permissions within the workspace govern who may bring in, derive, sign, export and delete content.
- Two-factor authentication. Whoever has enrolled a second factor must redeem it; a workspace can require a second factor of all its members. Both are enforced server-side at the level of the individual action, not in the interface.
- Database roles follow the principle of least privilege; privileges are granted per table.
- Rate limiting on every surface that sends messages or checks credentials, keyed by caller and target.
- Error reports are scrubbed before transmission. Access secrets, session cookies, invitation and password-reset tokens and signed storage URLs are redacted before a report reaches the monitoring service.
Integrity
- Append-only audit record. Signing, verification, change and download events are recorded; the privilege to alter or delete those entries afterwards is withdrawn at the database level.
- Results of external processing steps are accepted only after schema validation; a response that fails validation is discarded rather than stored.
- Security response headers across the whole surface, among them Content Security Policy, framing protection and referrer policy.
Availability, resilience and restorability
- Daily backup of the database by the database service, retained for seven days.
- Backup of originals and signed derivatives to a separate destination. Procedure, responsibility and restoration are described in a runbook.
- Separation of production and development environments.
Procedures for regular review
- Every change passes an automated gate before it is merged: type checking, test run, static analysis, and vulnerability scanning of dependencies and of the release images.
- Retention and erasure sweeps run automatically and are logged traceably.
Control of processing and physical access
- Sub-processors are selected under clause 7 and bound under Art. 28(4) GDPR.
- Operations take place in the data centres of the providers named in Schedule 3. Physical security and access control are their responsibility under their own certifications.
- The measures for subscription management, payment and invoicing are implemented independently, and at a correspondingly raised level of security, by the provider designated for them in Schedule 3; under clause 3 paragraph 2 that processing lies in our own area of responsibility and is named here for completeness.
Schedule 3 — Approved sub-processors
The following sub-processors are approved under clause 7. The last two receive hash values only; they are listed for completeness, because a reader who wants to know where their file goes is owed the whole path and not only the legally required subset.
Place of processing and third-country safeguard answer two different questions: where the data rests and who can reach it. Several of the providers named below process within the European Union but belong to a company established in a third country that may access the data in the course of operating and supporting its service. For those cases the safeguard is stated even though the place of processing is in the Union.
- Supabase — Authentication and the application database. Registered office: Supabase, Inc., San Francisco, USA. Place of processing: Germany (eu-central-1 region, Frankfurt). Third-country safeguard: European Commission standard contractual clauses.
- Hetzner — Server hosting and object storage for uploaded files and derivatives. Registered office: Hetzner Online GmbH, Gunzenhausen, Deutschland. Place of processing: Germany and Finland (Falkenstein, Nuremberg and Helsinki data centres).
- Cloudfleet — Managed Kubernetes control plane operating the servers. Registered office: Cloudfleet GmbH, Berlin, Deutschland. Place of processing: Germany (control plane in the EU region, Frankfurt). Third-country safeguard: European Commission standard contractual clauses.
- Resend — Delivery of transactional e-mail, without open or click tracking. Registered office: Resend, Inc., Delaware, USA. Place of processing: Ireland (eu-west-1 region). Third-country safeguard: European Commission standard contractual clauses.
- Stripe — Payment processing, subscription management and invoicing. Registered office: Stripe Payments Europe, Limited, Dublin, Irland. Place of processing: European Union, with onward transfer to Stripe, Inc. (United States). Third-country safeguard: European Commission standard contractual clauses. Acts in the area where we are ourselves the controller (clause 3 paragraph 2 of the DPA); listed for completeness.
- Bugsink — Error reporting and operational monitoring. Registered office: Bugsink B.V., Utrecht, Niederlande. Place of processing: European Union (infrastructure: Hetzner).
- Google Cloud KMS — Custody of the signing key in a hardware security module. Registered office: Google Cloud EMEA Limited, Dublin, Irland. Place of processing: Germany (europe-west3 region, Frankfurt). Third-country safeguard: European Commission standard contractual clauses. Receives hash values only, never file content.
- SSL.com — Qualified time-stamping service under RFC 3161. Registered office: SSL Corp, Houston, Texas, USA. Place of processing: United States. Third-country safeguard: European Commission standard contractual clauses. Receives hash values only, never file content.
List as of: September 16, 2026.