BiGapi Data Processing Agreement

Data Processing Agreement (DPA)

pursuant to Art. 28 GDPR · BiGapi File Processing API (api.bigapi.dev) · Artoption GmbH · August 2026

This DPA forms part of the contract under our Terms of Service and applies automatically when you process personal data through the Service. A signed copy and a German version (AVV) are available on request via support@bigapi.dev.

Download as PDF

Contracting Parties: This Data Processing Agreement is entered into between the customer using the Service under the Terms of Service ("Controller") and Artoption GmbH, Am Wiesenrain 14, 71720 Oberstenfeld, Germany ("Processor"), together the "Parties".

1. Subject matter and duration

1.1 The Processor provides file-processing operations via the API at api.bigapi.dev (the "Service"), as described in the Terms of Service. In doing so, the Processor may process personal data contained in files the Controller submits, on behalf of the Controller.

1.2 This DPA applies for as long as the Controller uses the Service and forms part of the contract under the Terms of Service. It is concluded by the Controller's use of the Service for the processing of personal data; a signed copy is available on request.

2. Nature and purpose of processing, data and data subjects

2.1 Nature and purpose: technical, automated processing of files submitted by the Controller (e.g. rendering to PDF/PNG, PDF manipulation, OCR, format conversion, image processing) for the sole purpose of returning the requested result to the Controller. The Processor has no knowledge of, and does not evaluate, the content of files.

2.2 Types of personal data: any personal data the Controller chooses to include in submitted files (e.g. names, contact details, contract or invoice data, identifiers). The Processor does not require or request any specific data. Special categories of data (Art. 9 GDPR) may be contained in files at the Controller's discretion; the Controller is responsible for the lawfulness of such processing.

2.3 Categories of data subjects: persons whose data is contained in the Controller's files (e.g. the Controller's customers, employees, business contacts).

2.4 Not covered by this DPA: account and billing data of the Controller itself (API key hashes, email address, balance, usage metadata) – processed by the Processor as an independent controller under the Privacy Policy; and payment data processed by Stripe as merchant of record under Stripe's own terms.

3. Obligations of the Processor (Art. 28(3) GDPR)

The Processor shall:

4. Personal data breach

The Processor shall notify the Controller without undue delay, and no later than 48 hours after becoming aware, of a personal data breach affecting the Controller's data, with the information required by Art. 33(3) GDPR to the extent available. Notification is made to the email address associated with the Controller's account.

5. Sub-processors

5.1 The Controller authorises the sub-processors listed in Annex 1.

5.2 The Processor will inform the Controller of any intended addition or replacement of sub-processors by publishing an updated Annex 1 at the Service website with at least 30 days' notice. The Controller may object on reasonable data-protection grounds within that period; if no solution is found, the Controller may terminate the use of the Service. Continued use after the notice period constitutes acceptance.

5.3 The Processor imposes on each sub-processor data-protection obligations that are essentially equivalent to those in this DPA.

6. Audits

The Controller may verify compliance with this DPA once per year, or after a personal data breach, by requesting the information described in Annex 2 and, where reasonably required, by an on-site or remote inspection at the Controller's expense, with reasonable notice and without disrupting the Service. The Processor may satisfy audit requests by providing current documentation and, where available, third-party certifications of its sub-processors.

7. International transfers

Processing of files takes place exclusively on servers in Germany (Hetzner Online GmbH, Falkenstein). Account metadata is stored in the EU (Supabase, region Frankfurt). Payment processing by Stripe, Inc. as merchant of record may involve transfers to the USA on the basis of the EU-US Data Privacy Framework and/or Standard Contractual Clauses; these transfers concern the Controller's payment data, not files.

8. Deletion and return

Because files are deleted immediately after delivery of each result (Annex 2), no return or deletion at the end of the contract is required for file contents. Usage and billing records are retained as required by tax and commercial law (§ 147 AO, § 257 HGB).

9. Liability and final provisions

Liability follows the Terms of Service. German law applies; if the Controller is a merchant, the exclusive place of jurisdiction is Stuttgart, Germany. Should provisions of this DPA conflict with the Terms of Service, this DPA prevails with respect to the processing of personal data on behalf of the Controller.

Annex 1 – Sub-processors

Sub-processorPurposeLocationBasis
Hetzner Online GmbH, Gunzenhausen (DE) Hosting of processing servers (API gateway and processing engine) Falkenstein, Germany DPA with Hetzner (Art. 28)
Supabase, Inc. Database for account metadata (key hashes, balances, usage metadata) – no file contents EU (Frankfurt) DPA with Supabase; SCCs where applicable
Stripe, Inc. / Stripe Payments Europe Ltd. Payment processing and invoicing as merchant of record – acts as independent controller for payment data EU / USA Stripe terms; EU-US DPF / SCCs

Annex 2 – Technical and organisational measures (Art. 32 GDPR)

A. Data minimisation by design

B. Logging and retention

C. Access control and credentials

D. Transport and infrastructure security

E. Availability and monitoring

F. Organisational measures