This DPA forms part of the contract under our Terms of Service and applies automatically when you process personal data through the Service. A signed copy and a German version (AVV) are available on request via support@bigapi.dev.
Download as PDFContracting Parties: This Data Processing Agreement is entered into between the customer using the Service under the Terms of Service ("Controller") and Artoption GmbH, Am Wiesenrain 14, 71720 Oberstenfeld, Germany ("Processor"), together the "Parties".
1.1 The Processor provides file-processing operations via the API at api.bigapi.dev (the "Service"), as described in the Terms of Service. In doing so, the Processor may process personal data contained in files the Controller submits, on behalf of the Controller.
1.2 This DPA applies for as long as the Controller uses the Service and forms part of the contract under the Terms of Service. It is concluded by the Controller's use of the Service for the processing of personal data; a signed copy is available on request.
2.1 Nature and purpose: technical, automated processing of files submitted by the Controller (e.g. rendering to PDF/PNG, PDF manipulation, OCR, format conversion, image processing) for the sole purpose of returning the requested result to the Controller. The Processor has no knowledge of, and does not evaluate, the content of files.
2.2 Types of personal data: any personal data the Controller chooses to include in submitted files (e.g. names, contact details, contract or invoice data, identifiers). The Processor does not require or request any specific data. Special categories of data (Art. 9 GDPR) may be contained in files at the Controller's discretion; the Controller is responsible for the lawfulness of such processing.
2.3 Categories of data subjects: persons whose data is contained in the Controller's files (e.g. the Controller's customers, employees, business contacts).
2.4 Not covered by this DPA: account and billing data of the Controller itself (API key hashes, email address, balance, usage metadata) – processed by the Processor as an independent controller under the Privacy Policy; and payment data processed by Stripe as merchant of record under Stripe's own terms.
The Processor shall:
The Processor shall notify the Controller without undue delay, and no later than 48 hours after becoming aware, of a personal data breach affecting the Controller's data, with the information required by Art. 33(3) GDPR to the extent available. Notification is made to the email address associated with the Controller's account.
5.1 The Controller authorises the sub-processors listed in Annex 1.
5.2 The Processor will inform the Controller of any intended addition or replacement of sub-processors by publishing an updated Annex 1 at the Service website with at least 30 days' notice. The Controller may object on reasonable data-protection grounds within that period; if no solution is found, the Controller may terminate the use of the Service. Continued use after the notice period constitutes acceptance.
5.3 The Processor imposes on each sub-processor data-protection obligations that are essentially equivalent to those in this DPA.
The Controller may verify compliance with this DPA once per year, or after a personal data breach, by requesting the information described in Annex 2 and, where reasonably required, by an on-site or remote inspection at the Controller's expense, with reasonable notice and without disrupting the Service. The Processor may satisfy audit requests by providing current documentation and, where available, third-party certifications of its sub-processors.
Processing of files takes place exclusively on servers in Germany (Hetzner Online GmbH, Falkenstein). Account metadata is stored in the EU (Supabase, region Frankfurt). Payment processing by Stripe, Inc. as merchant of record may involve transfers to the USA on the basis of the EU-US Data Privacy Framework and/or Standard Contractual Clauses; these transfers concern the Controller's payment data, not files.
Because files are deleted immediately after delivery of each result (Annex 2), no return or deletion at the end of the contract is required for file contents. Usage and billing records are retained as required by tax and commercial law (§ 147 AO, § 257 HGB).
Liability follows the Terms of Service. German law applies; if the Controller is a merchant, the exclusive place of jurisdiction is Stuttgart, Germany. Should provisions of this DPA conflict with the Terms of Service, this DPA prevails with respect to the processing of personal data on behalf of the Controller.
| Sub-processor | Purpose | Location | Basis |
|---|---|---|---|
| Hetzner Online GmbH, Gunzenhausen (DE) | Hosting of processing servers (API gateway and processing engine) | Falkenstein, Germany | DPA with Hetzner (Art. 28) |
| Supabase, Inc. | Database for account metadata (key hashes, balances, usage metadata) – no file contents | EU (Frankfurt) | DPA with Supabase; SCCs where applicable |
| Stripe, Inc. / Stripe Payments Europe Ltd. | Payment processing and invoicing as merchant of record – acts as independent controller for payment data | EU / USA | Stripe terms; EU-US DPF / SCCs |