Legal · Last updated September 30, 2026
Data processing agreement (Art. 28 GDPR)
This agreement is concluded between you as the controller and Neithra Technologies – Fabian Lorenz, Neithra Technologies – Fabian Lorenz, Thaler Weg 2a, 51647 Gummersbach, Germany as the processor, and forms part of the contract for the use of InstallCue. It replaces the earlier arrangement under which a processing agreement was provided only on request.
1. Subject matter and duration
The processor processes personal data on behalf of the controller solely to provide InstallCue: site-readiness requests, customer answers, measurements, optional photos, reminders and release decisions. The agreement applies throughout the main contract and until the complete return or deletion of the data processed on behalf of the controller.
2. Nature and purpose of the processing
Collection, storage, structuring, transmission by secure customer link, display in the workspace, reminder dispatch, generation of install packs, deletion after the retention period. No processing for the processor's own purposes, no profiling, no training of AI models with customer data.
3. Type of personal data
Contact data of site contacts (name, company, e-mail address, telephone number where entered), installation address, answers and measurements about the site, optional photographs of the installation location, technical connection data (IP address, timestamps) and audit records of sending, opening, submitting and releasing.
4. Categories of data subjects
The controller's customers and their staff or site contacts, and the controller's own employees who use the workspace.
5. Instructions
The processor processes data only on documented instructions from the controller. The configuration of the workspace — templates, thresholds, retention period, customer declaration and recipients — is the standing instruction. The processor informs the controller without delay if it considers an instruction to infringe data protection law. Instructions, including those concerning international transfers, may be given in text form to the contact in the legal notice. Where Union or Member State law requires other processing, we inform the customer beforehand unless that law prohibits this on important grounds of public interest.
6. Confidentiality
The processor commits every person authorised to process the data to confidentiality, or such persons are under an appropriate statutory obligation of confidentiality. Access is limited to what is needed to operate and support the service.
7. Technical and organisational measures (Art. 32)
Tenant separation enforced in the database by row-level security and composite foreign keys; customer links use 256-bit tokens of which only SHA-256 hashes are stored; private object storage reachable only through short-lived signed URLs; HTTP-only session cookies; password hashing; rate limiting on public endpoints; a human release step before a site counts as ready; an append-only audit log of every send, open, submission, confirmation and release; encryption in transit (TLS); hourly encrypted database backups (age) to Cloudflare R2. The measures are described in more detail on the security page.
8. Sub-processors
The controller grants general written authorisation for the sub-processors listed below. The processor informs the controller of any intended change in good time and the controller may object on reasonable data-protection grounds. Each sub-processor is bound by the same obligations by contract. Changes are announced by email at least 30 days before the intended engagement. The customer may object on reasonable data-protection grounds before engagement. We consider a reasonable alternative; if no agreement is possible, the affected contract may end before engagement without an additional termination fee. Each sub-processor is bound in writing to equivalent data-protection duties; we remain responsible to the customer for their performance.
9. Third-country transfers
Where a sub-processor processes data outside the EU/EEA, the transfer is based on an adequacy decision (EU-US Data Privacy Framework) or on the EU standard contractual clauses together with supplementary measures. Copies are available on request.
10. Assistance
The processor assists the controller, taking into account the nature of the processing, in responding to requests from data subjects, and in complying with Art. 32 to 36 GDPR — security of processing, notification of personal data breaches, data protection impact assessment and prior consultation. The processor notifies the controller of a personal data breach without undue delay after becoming aware of it. The initial notification is sent at the latest within 48 hours after awareness and includes the available information under Art. 33(3) GDPR; further information follows without undue delay.
11. Deletion and return
Photos and job data are deleted automatically once the retention period configured in the workspace has passed. On termination of the contract the controller can export the data; the processor then deletes the remaining data within 30 days of a request, unless storage is required by Union or Member State law.
12. Evidence and audits
The processor makes available all information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the controller or an auditor mandated by it. Audits take place during business hours, with reasonable notice, and must not disproportionately disrupt operations. Reasonable notice, business hours and cost arrangements must not prevent or delay audits required by law or justified by a concrete suspicion, personal data breach or supervisory-authority request. The processor allows and contributes to these audits, including inspections at short notice; statutory audit rights are not conditional on advance payment.
13. Liability and form
Liability follows Art. 82 GDPR and the terms. Amendments require text form. Questions: support@installcue.com.
Authorised sub-processors
- netcup GmbH, Germany — hosting of the application and its database on a dedicated server in the Nuremberg data centre
- Cloudflare, Inc., USA — network and connection protection (tunnel, DNS; Turnstile only where enabled) and R2 object storage for photos and encrypted backups
- Resend (Plus Five Five Inc.), USA — transactional e-mail delivery
- Stripe Inc. / Stripe Payments Europe Ltd. — payment processing and invoices for plans ordered online
- Expo (650 Industries Inc.), USA — push notifications, only where enabled