Data processing agreement
Last updated: October 6, 2026
This data processing agreement (DPA) under Art. 28 GDPR applies between you as a Gramli customer (controller) and Baduno GmbH (processor) as soon as you use features with which we process personal data on your behalf – in particular a published website with a contact, sign-up or order form, a shop or an email mailbox. It forms part of the contract of use and is concluded electronically (Art. 28(9) GDPR).
1. Subject matter and duration
The subject matter is hosting your website, receiving and forwarding form messages, storing order requests and operating email mailboxes. The DPA applies for as long as we process such data for you.
2. Nature, purpose, types of data and data subjects
Nature and purpose: storing, delivering, forwarding, backing up and deleting data so that your website, shop and mailboxes work.
Types of data: connection data (IP address, time, browser identifier), contact data (name, email address, phone number), message content, order and delivery data (address, items, amounts, payment method), emails with attachments and data you publish on your website yourself.
Data subjects: visitors to your website, your prospects, customers and subscribers, and senders and recipients of emails.
3. Instructions
We only process the data on your documented instructions – given through the settings in the dashboard and in writing or by email – unless we are legally required to process it; in that case we will inform you beforehand where the law permits. If we consider an instruction unlawful, we will tell you.
4. Confidentiality
Everyone at Gramli with access to the data is bound to confidentiality. Administrators only see technical metadata of customer mailboxes; access to other people’s mailboxes is logged.
5. Technical and organisational measures (Art. 32 GDPR)
Transmission only encrypted (HTTPS); the server only accepts connections through Cloudflare. Servers in a data centre in Germany with access control by the host.
Encrypted storage of email content, support messages and customer data in order requests. Passwords only as hashes. Email attachments scanned for malware before release.
Role and permission concept, separate database roles with minimal rights for the individual domains, request limits against abuse, logging of administrative access, regular backups and updates.
6. Subprocessors
You grant general authorisation to engage the providers named in the list of subprocessors. We will inform you of intended changes by email at least 30 days in advance; you may object for an important data protection reason. If the objection cannot be resolved, you can end the affected feature or terminate the contract. We contractually bind subprocessors to the same level of protection.
7. Assistance
We assist you with appropriate measures in responding to data subject requests (Art. 12 to 23 GDPR), with security, with notifying personal data breaches and with data protection impact assessments (Art. 32 to 36 GDPR). If data subjects contact us directly, we forward the request to you.
8. Personal data breaches
We notify you of a personal data breach without undue delay after becoming aware of it, with the information under Art. 33(3) GDPR as far as available.
9. Deletion and return
After processing ends, we delete or return the data unless there is a statutory obligation to store it. You can export mailboxes before the end; after a package ends they remain usable for 30 days, are then locked for 60 days and afterwards deleted. We do not store contact form messages but only forward them to you by email.
10. Evidence and audits
On request we provide all information necessary to demonstrate compliance with these obligations and allow audits by you or an auditor you appoint who is bound to confidentiality, after reasonable notice.
11. Gramli’s own responsibility
For our own purposes – billing, security of the service, abuse prevention and handling notices under the Digital Services Act – we process data as an independent controller; this is not covered by this DPA.