# Compliance & contracts

> DPA, TOMs, subprocessors, and processing locations for Application Platform — written for privacy, procurement, and security reviews.

> Source: https://www.application-platform.com/en/platform-compliance/

**Application Platform** by doppelt.digital GmbH is a B2B SaaS service for modern software teams. This page explains how we process personal data when operating the platform, which subprocessors we engage for platform operations, and which contractual documents you can generate inside the product.

It supplements the [privacy policy]({{< relref "privacy" >}}) and [terms of use]({{< relref "terms" >}}) and is intended for controllers, data protection officers, and procurement or security teams.

## What this covers

When operating Application Platform, we process personal data on behalf of our customers — for example organization member master data, authentication data, project and operations metadata, and billing information. This processing is based on the applicable B2B main agreement and a Data Processing Agreement (DPA) pursuant to Article 28 GDPR.

The primary place of processing is Germany or the EU/EEA. Where individual platform services involve third-country transfers (for example payment processing), we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and the respective provider DPAs.

## Service scope under the DPA

Under the same agreement and DPA, the following are covered in particular:

- Operation of Application Platform (control plane, customer frontend, platform APIs)
- GitLab on platform infrastructure (repositories, CI/CD, issue tracking, container registry)
- Deployments and runtime on managed Hetzner servers
- Server administration, monitoring, and incident response
- Support and admin access by authorized doppelt.digital GmbH staff for contract performance

Optional connections activated by the customer (for example SMTP/Mailtrap, Sentry, Firebase, Cloudflare, or IONOS credentials) are additional processing activities. They appear in the platform on a project basis and remain the customer’s responsibility to assess and document.

## Processing locations

- **Primary hosting:** Germany (Hetzner) — control plane, managed servers, GitLab, secrets, and backups
- **Support and operations:** Cologne, Germany — customer support, incident response, and administration

## Platform subprocessors

The table below lists the main subprocessors engaged by doppelt.digital GmbH to operate Application Platform itself. They process platform and account data — not automatically the project-specific data of your customer applications.

| Service | Purpose | Location | Safeguards |
|---------|---------|----------|------------|
| [Hetzner Online GmbH](https://docs.hetzner.com/general/others/data-protection/) | Server hosting, networking, and storage | Germany | DPA under Art. 28 GDPR; Hetzner TOMs |
| [GitLab](https://about.gitlab.com/privacy/) (self-hosted) | Source code, CI/CD, issues, registry | Germany (managed servers) | Operated under the same DPA as the platform |
| [Stripe Payments Europe, Ltd.](https://stripe.com/privacy) | Payment processing and subscriptions | EU / USA | Stripe DPA and SCCs |

The full versioned list — including optional project-related connections — is available to organization admins in Application Platform under **Compliance & contracts**.

## Documents you can generate yourself

In the signed-in Application Platform, you can generate personalized compliance PDFs for your organization. The documents use your stored company details and are available for download:

- **Data Processing Agreement (DPA)** — contractual terms for processing on your behalf
- **Technical and organizational measures (TOMs)** — description of safeguards under Article 32 GDPR
- **Service scope and DPA coverage** — which platform services fall under the same agreement
- **SaaS privacy information** — complementary information on processing in the SaaS context

This lets you share DPA, TOMs, and related evidence directly with privacy, procurement, or security reviews — without a separate email request.

## Contact

Questions about compliance, the DPA, or data protection:

**doppelt.digital GmbH**  
Im Mediapark 5  
50670 Köln  
Germany  

Email: [kontakt@doppelt-digital.de](mailto:kontakt@doppelt-digital.de)

