Trust Center

Data Processing Agreement

Our Art. 28 GDPR DPA template, including the EU Standard Contractual Clauses (Module 2) and annexes. Request a signed copy at legal@scalable.so.

Last updated
30 May 2026
Jurisdiction
Germany

under Article 28 of Regulation (EU) 2016/679 (GDPR)

This Data Processing Agreement ("DPA") forms part of and is governed by the agreement for the provision of the Scalable services (the "Principal Agreement") between:

(1) [Customer legal entity], [registered address] (the "Customer" or "Controller"); and

(2) Machete Marketing Germany GmbH, trading as Scalable, Kirchstraße 31, 77815 Bühl, Germany (the "Processor" or "Scalable").

The Customer and Scalable are each a "Party" and together the "Parties".

Effective Date: 30 May 2026, or the date this DPA is accepted or countersigned, whichever is later.


Recitals

(A) The Customer wishes to use the services provided by Scalable under the Principal Agreement (the "Services").

(B) In providing the Services, Scalable processes personal data on behalf of the Customer. The Customer acts as controller and Scalable acts as processor in respect of that personal data, within the meaning of Article 4 GDPR.

(C) This DPA sets out the terms on which Scalable processes personal data on behalf of the Customer and gives effect to the requirements of Article 28 GDPR.

(D) Where Scalable engages third parties (including AI model and infrastructure providers) to process personal data on the Customer's behalf, those parties act as sub-processors.

(E) This DPA prevails over any conflicting data-protection terms in the Principal Agreement to the extent set out in Section 16 (Order of Precedence).


1. Definitions and Roles

1.1 Capitalised terms not defined in this DPA have the meaning given in the Principal Agreement or, where applicable, in the GDPR.

1.2 In this DPA:

  • "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
  • "BDSG" means the German Federal Data Protection Act (Bundesdatenschutzgesetz).
  • "Data Protection Law" means the GDPR, the BDSG, and any other applicable data-protection law to which a Party is subject.
  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given in Article 4 and Article 33 GDPR.
  • "Customer Personal Data" means the personal data described in Annex 1 that Scalable processes on behalf of the Customer under the Principal Agreement.
  • "Sub-processor" means any processor engaged by Scalable to process Customer Personal Data on the Customer's behalf.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

1.3 Roles. With respect to Customer Personal Data:

(a) the Customer is the Controller (or, where the Customer itself acts as a processor for a third-party controller, the Customer acts as that controller's processor and Scalable as a sub-processor; in that case the Customer warrants it has the authority to instruct Scalable on the relevant controller's behalf);

(b) Scalable is the Processor; and

(c) any third party engaged by Scalable under Section 6 is a Sub-processor.


2. Subject-Matter and Details of Processing

2.1 The subject-matter, duration, nature and purpose of the processing, the types of Customer Personal Data, and the categories of Data Subjects are set out in Annex 1.

2.2 Duration. Scalable processes Customer Personal Data for the term of the Principal Agreement and for so long thereafter as is necessary to comply with Section 9 (Deletion or Return).


3. Processing on Documented Instructions

3.1 Scalable processes Customer Personal Data only on documented instructions from the Customer, including with regard to transfers of Customer Personal Data to a third country, unless required to do so by Union or Member State law to which Scalable is subject. In that case, Scalable informs the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

3.2 The Customer's documented instructions are set out in this DPA and the Principal Agreement, including the Customer's configuration and use of the Services. The Customer may issue further written instructions consistent with the nature of the Services. Scalable is not obliged to perform instructions that fall outside the scope of the Services; any agreed change in processing scope may be subject to adjustment of fees.

3.3 Scalable does not use Customer Personal Data for its own purposes. In particular, Scalable does not use Customer Personal Data, including prompts and generated content, to train, fine-tune, or otherwise develop machine-learning models, except on the Customer's documented instruction.

3.4 Scalable informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR, the BDSG, or other applicable Data Protection Law. Scalable may suspend performance of the affected instruction until the Customer confirms or withdraws it.


4. Confidentiality

4.1 Scalable ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.2 Confidentiality obligations under Section 4.1 survive the termination of the relevant person's engagement with Scalable.

4.3 Scalable limits access to Customer Personal Data to personnel who require access to perform the Principal Agreement and ensures those personnel are subject to appropriate training on their data-protection responsibilities.


5. Security of Processing (Article 32)

5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Scalable implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.

5.2 The technical and organisational measures in force as at the Effective Date are described in Annex 2 ("TOMs").

5.3 Scalable may update the TOMs from time to time to reflect technical and organisational developments, provided that any update does not materially reduce the overall level of security of the processing of Customer Personal Data.

5.4 The Parties acknowledge that the Services operate under a shared-responsibility model. Scalable is responsible for the application-layer and operational measures within its control. Certain infrastructure-layer measures are provided by Scalable's Sub-processors, as described in Annex 2. The Customer remains responsible for the security of its own systems, credentials, and end-user access, and for the lawfulness and appropriateness of the data it submits to the Services.


6. Sub-processors

6.1 General authorisation. The Customer grants Scalable general written authorisation to engage Sub-processors to process Customer Personal Data for the purpose of providing the Services. The Sub-processors engaged as at the Effective Date are identified in Annex 3.

6.2 Flow-down of obligations. Where Scalable engages a Sub-processor, Scalable imposes on that Sub-processor, by way of a written contract, data-protection obligations that are no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in accordance with Article 28(4) GDPR.

6.3 Processor liability. Scalable remains fully liable to the Customer for the performance of each Sub-processor's data-protection obligations.

6.4 Change notice. Scalable maintains an up-to-date list of Sub-processors as described in Annex 3. Scalable gives the Customer at least thirty (30) days' prior notice of the intended addition or replacement of a Sub-processor, by updating that list and offering a mechanism to subscribe to change notifications.

6.5 Right to object. The Customer may object to the addition or replacement of a Sub-processor on reasonable grounds relating to data protection by giving written notice to Scalable within the 30-day notice period. The Parties will work together in good faith to resolve the objection. If the Parties cannot reach a resolution within a reasonable period, the Customer may terminate the affected part of the Services, or the Principal Agreement, without penalty, by written notice. Objections must be limited to genuine data-protection grounds and not to competitive or commercial preference.

6.6 If the Customer does not object within the notice period, the addition or replacement of the Sub-processor is deemed accepted. Silence does not constitute consent to processing that would otherwise require it; this Section 6.6 governs only the Sub-processor change mechanism.


7. Assistance to the Controller

7.1 Data-subject requests (Articles 12–23). Taking into account the nature of the processing, Scalable assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights under Chapter III GDPR (including rights of access, rectification, erasure, restriction, portability, and objection).

7.2 Scalable promptly notifies the Customer if it receives a request directly from a Data Subject in respect of Customer Personal Data, and does not respond to that request itself except on the Customer's documented instruction or as required by law.

7.3 Assistance with Articles 32–36. Taking into account the nature of processing and the information available to Scalable, Scalable assists the Customer in ensuring compliance with the Customer's obligations under:

(a) Article 32 (security of processing);

(b) Articles 33 and 34 (notification of Personal Data Breaches to the Supervisory Authority and to Data Subjects);

(c) Article 35 (data protection impact assessments); and

(d) Article 36 (prior consultation with the Supervisory Authority).

7.4 Scalable may charge a reasonable fee for assistance under this Section 7 that exceeds the standard functionality of the Services, having first notified the Customer of the basis for the charge.


8. Personal Data Breach Notification

8.1 Scalable notifies the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

8.2 The notification under Section 8.1 includes, to the extent then known and insofar as available to Scalable: the nature of the Personal Data Breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.

8.3 Where Scalable cannot provide all such information at once, it may provide it in phases without further undue delay.

8.4 Scalable supports the Customer in meeting the Customer's own notification obligations, including the 72-hour notification deadline to the competent Supervisory Authority under Article 33 GDPR and any obligation to communicate the breach to Data Subjects under Article 34 GDPR.

8.5 Scalable does not notify a Supervisory Authority or any Data Subject of a Personal Data Breach affecting Customer Personal Data on the Customer's behalf except on the Customer's documented instruction or as required by law.


9. Deletion or Return of Data

9.1 At the Customer's choice, Scalable deletes or returns all Customer Personal Data to the Customer after the end of the provision of the Services, and deletes existing copies, unless Union or Member State law requires storage of the personal data.

9.2 The Customer may export Customer Personal Data through the functionality of the Services during the term and for a defined wind-down period following termination, as described in the Principal Agreement.

9.3 Deletion under Section 9.1 extends to production systems and to backups, subject to the backup rotation cycle described in Annex 2, after which residual copies are overwritten in the ordinary course.

9.4 Where Scalable retains Customer Personal Data on the basis of a legal-retention requirement under Section 9.1, it processes that data only for the purpose and duration required by that law and continues to protect it under this DPA.

9.5 On the Customer's written request, Scalable provides written confirmation of deletion.


10. Audit and Information Rights

10.1 Scalable makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA.

10.2 Scalable allows for and contributes to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer, in accordance with the conditions in this Section 10.

10.3 The Customer may exercise its rights under Sections 10.1 and 10.2 by any of the following means, which Scalable offers in the following order of preference:

(a) Scalable providing relevant documentation, including third-party audit reports, certifications, and a description of the TOMs;

(b) Scalable completing a reasonable security or data-protection questionnaire; or

(c) where the means in (a) and (b) are insufficient to address a specific, substantiated concern, an on-site or remote audit.

10.4 Any audit under Section 10.3(c) is subject to: reasonable prior written notice of at least thirty (30) days (except where a Personal Data Breach or regulatory requirement makes shorter notice reasonable); conduct during normal business hours; a frequency of no more than once per twelve-month period (unless a Personal Data Breach or Supervisory Authority requirement justifies more); appropriate confidentiality undertakings by the Customer and its auditor; minimal disruption to Scalable's operations; and no access to the data or systems of other customers. The auditor must not be a competitor of Scalable.

10.5 The Customer bears its own costs of an audit and reimburses Scalable's reasonable costs of supporting an audit under Section 10.3(c).


11. International Transfers

11.1 Scalable does not transfer Customer Personal Data to a country outside the European Economic Area ("EEA") that does not benefit from an adequacy decision under Article 45 GDPR, except where appropriate safeguards under Article 46 GDPR are in place.

11.2 SCCs incorporated by reference. Where Scalable, or a Sub-processor, processes Customer Personal Data in a third country that is not the subject of an adequacy decision and no other valid transfer mechanism applies, the Parties agree that the Standard Contractual Clauses (Module Two: Controller to Processor) of Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference and apply to that transfer, with:

(a) the Customer as "data exporter" and Scalable as "data importer";

(b) the optional docking clause (Clause 7) applying;

(c) Option 2 (general written authorisation) selected for Clause 9(a), with the notice period set at thirty (30) days as per Section 6.4;

(d) for Clause 11, the optional independent-dispute-resolution body not selected;

(e) for Clause 17, the governing law being the law of the Federal Republic of Germany;

(f) for Clause 18(b), the competent courts being the courts of Germany; and

(g) Annexes I, II, and III to the SCCs being populated by Annex 1, Annex 2, and Annex 3 of this DPA respectively.

11.3 The SCCs incorporated under Section 11.2 serve both as the safeguard required under Article 46 GDPR and, to the extent applicable, as terms satisfying Article 28(3) and (4) GDPR for the relevant transfer.

11.4 Where a Sub-processor is certified under the EU-US Data Privacy Framework or another valid transfer mechanism, that mechanism may apply to transfers to that Sub-processor in place of or in addition to the SCCs. The transfer mechanism applicable to each Sub-processor is identified in, or made available with, the Sub-processor list referenced in Annex 3.

11.5 In the event of a conflict between the SCCs incorporated under Section 11.2 and the other terms of this DPA or the Principal Agreement, the SCCs prevail in respect of the relevant transfer.


12. Liability

12.1 Each Party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement.

12.2 Section 12.1 does not limit liability that cannot be limited or excluded under applicable Data Protection Law, including liability to Data Subjects under Article 82 GDPR.

12.3 The allocation of liability between the Parties under this DPA does not affect either Party's responsibilities under Data Protection Law towards Data Subjects or Supervisory Authorities.


13. Term

13.1 This DPA takes effect on the Effective Date and remains in force for the term of the Principal Agreement.

13.2 The provisions of this DPA that by their nature should survive termination, including Sections 4 (Confidentiality), 9 (Deletion or Return), 10 (Audit), 12 (Liability), and 14 (Governing Law), survive termination of the Principal Agreement.


14. Governing Law and Jurisdiction

14.1 This DPA is governed by the law of the Federal Republic of Germany, excluding its conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods.

14.2 The competent courts for any dispute arising out of or in connection with this DPA are the courts of [seat of Scalable / Bühl, Germany], to the extent permitted by mandatory law.


15. Miscellaneous

15.1 If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions remain in full force, and the invalid provision is replaced by a valid provision that most closely reflects the original intent.

15.2 This DPA may be executed in electronic form, including by clickwrap acceptance or electronic signature, which the Parties agree satisfies the written-form requirement of Article 28(9) GDPR.

15.3 Amendments to this DPA must be in writing (including electronic form).


16. Order of Precedence

16.1 In the event of a conflict between the documents governing the relationship between the Parties, the following order of precedence applies (highest first):

  1. the Standard Contractual Clauses incorporated under Section 11.2, in respect of the relevant international transfer;
  2. this DPA;
  3. the Principal Agreement.

16.2 Except as expressly modified by this DPA, the Principal Agreement remains in full force and effect.


Signatures

This DPA is accepted and agreed by the Parties.

ControllerProcessor
Entity[Customer legal entity]Machete Marketing Germany GmbH (Scalable)
Name[Name][Name]
Title[Title][Title]
Signature________________________________________________
Date[Date][Date]

Address for notices to the Processor: Machete Marketing Germany GmbH, Kirchstraße 31, 77815 Bühl, Germany. Data-protection contact: legal@scalable.so.

Address for notices to the Controller: [Customer notice address].


Annex 1 — Description of Processing

ItemDescription
Subject-matterThe processing of Customer Personal Data by Scalable to the extent necessary to provide the Services (an AI-assisted image generation and editing platform) to the Customer under the Principal Agreement.
DurationThe term of the Principal Agreement, plus the period necessary to comply with Section 9 (Deletion or Return).
Nature and purposeHosting, storage, processing, generation, editing, and delivery of images and related content; provision of user accounts and authentication; provision of AI generation features through Sub-processor model providers; analytics, error monitoring, and support, in each case solely to provide and maintain the Services on the Customer's documented instructions.
Types of Personal DataAccount data (e.g. name, email address, authentication identifiers, role); product data (e.g. project, workspace, and configuration data containing personal data the Customer chooses to include); image data (uploaded and generated images that may contain personal data, including depictions of individuals); prompt data (text and reference inputs submitted to generation features that may contain personal data); usage data (e.g. log, session, and activity data, including masked or truncated identifiers used for security and operation of the Services).
Special categories of dataThe Services are not intended for the processing of special categories of personal data (Article 9 GDPR). The Customer is responsible for not submitting such data unless it has confirmed an appropriate lawful basis and configuration.
Categories of Data SubjectsThe Customer's authorised users (e.g. employees, contractors, and administrators); and any individuals whose personal data appears in content uploaded to, or generated by, the Services.
Frequency of transferContinuous, for the duration of the Services.

Annex 2 — Technical and Organisational Measures (Article 32)

These measures describe the level of security in force as at the Effective Date. They operate under a shared-responsibility model: Scalable is responsible for application-layer and operational measures; certain infrastructure-layer measures are provided and maintained by Scalable's Sub-processors (hosting, database, storage, payments). The Customer is responsible for the security of its own systems, credentials, and end-user access. Measures may be updated under Section 5.3.

1. Encryption (Article 32(1)(a))

  • In transit: all external connections to the Services use HTTPS with TLS 1.2 or higher. Connections between application and database layers use encrypted transport.
  • At rest: Customer Personal Data, including stored images and backups, is encrypted at rest using AES-256 or equivalent, as provided by the underlying infrastructure Sub-processors.
  • Secrets: application secrets and sensitive configuration are stored using protected secret-management facilities and are not retrievable in plaintext after creation.

2. Tenant isolation (confidentiality and integrity)

  • Logical multi-tenant isolation enforced at the database layer through Row-Level Security (RLS) policies scoped to each tenant.
  • Storage objects are segregated by tenant-scoped access controls and paths.
  • Privileged keys that bypass tenant isolation are restricted to controlled server-side operations and are never exposed to client applications.

3. Access control and authentication

  • Authenticated access to the Services using short-lived session tokens and refresh tokens.
  • Internal access governed by least-privilege role-based access control; multi-factor authentication required for administrative access to production infrastructure.
  • Named individual accounts; onboarding and offboarding procedures; periodic access reviews.
  • Time-boxed, audited just-in-time access for support and operations where required.

4. Logging and monitoring (with masking)

  • Security and operational logging of access and system events.
  • Personal identifiers in logs are masked, hashed, or truncated (including truncation of IP addresses) to minimise exposure.
  • Monitoring and error-tracking configured to minimise capture of personal data.

5. Backups and recovery

  • Regular encrypted backups of production data.
  • Point-in-time recovery enabled for production databases.
  • Backups retained for a defined rotation period and stored within the EEA (or under an appropriate transfer mechanism where applicable).
  • Periodic restore testing.

6. Incident response

  • Documented incident-response process covering detection, assessment, containment, eradication, recovery, and notification, with named responsible roles.
  • Reliance on Sub-processor breach-notification commitments, which require Sub-processors to notify Scalable without undue delay.
  • Post-incident review feeding back into improvement of these measures.

7. Secure software development lifecycle

  • Version control, peer code review, and staged environments separating development, staging, and production.
  • Dependency and vulnerability scanning.
  • Security review of changes affecting tenant isolation and access control.

8. Sub-processor management

  • Written data-processing agreements (including, where relevant, Standard Contractual Clauses) in place with all Sub-processors.
  • Review of Sub-processor security posture, certifications, and sub-processor lists prior to onboarding.
  • Maintenance of an up-to-date Sub-processor list and customer notification and objection process under Section 6.

9. Availability and resilience

  • Hosting on infrastructure providing redundancy, denial-of-service mitigation, and rate limiting.
  • Service-level commitments inherited from infrastructure Sub-processors.
  • Application-level resilience measures including graceful degradation and retries.

Inherited assurance note. Scalable's infrastructure Sub-processors maintain their own independent third-party attestations and certifications for their environments. These attestations apply to the relevant Sub-processor's environment and do not transfer to Scalable; Scalable governs the configuration, access, and operation of the Services on top of that infrastructure. Details are available under Annex 3 and through Scalable's Trust Center.


Annex 3 — Approved Sub-processors

3.1 Scalable engages Sub-processors in the following categories to provide the Services: cloud hosting and edge delivery; managed database, authentication, and object storage; AI model inference and image generation; payment processing; and observability (error monitoring and product analytics).

3.2 The current, named list of approved Sub-processors, including for each Sub-processor its name, the processing activity, the location of processing, and the applicable international-transfer mechanism, is maintained in the separate document "Scalable — Sub-Processor List" (v1.0, 30 May 2026), made available through Scalable's Trust Center and provided to the Customer on request.

3.3 The Sub-processor List is updated in accordance with the change-notice and objection process in Section 6.

3.4 For the purpose of Annex III to the Standard Contractual Clauses incorporated under Section 11.2, the Sub-processor List referenced in this Annex 3 constitutes the agreed list of authorised sub-processors.


End of Data Processing Agreement.