Data Processing Agreement

pursuant to Art. 28 GDPR

Version: 4 October 2026

between

Harald Eric Beringer, sole proprietor (jixmo), Marlene-Dietrich-Straße 5, 89231 Neu-Ulm, Germany, support (at) jixmo (dot) io, hereinafter the “Processor”,

and

the customer who uses the jixmo application (venue, club or organizer), hereinafter the “Controller”.

Contents

  1. 1 Introduction, scope, definitions
  2. 2 Subject matter and duration
  3. 3 Nature and purpose, types of data, data subjects
  4. 4 Obligations of the Processor
  5. 5 Technical and organizational measures
  6. 6 Rectification, erasure and blocking
  7. 7 Sub-processing
  8. 8 Rights and obligations of the Controller
  9. 9 Notification obligations
  10. 10 Instructions
  11. 11 Termination
  12. 12 Remuneration
  13. 13 Liability
  14. 14 Extraordinary termination
  15. 15 Miscellaneous
  16. 16 Acceptance

1 Introduction, scope, definitions

(1) This Agreement governs the rights and obligations of the Controller and the Processor (the “Parties”) in the processing of personal data on behalf of the Controller under Art. 28 GDPR.

(2) It applies to all activities in which the Processor, or sub-processors engaged by it, process personal data of the Controller.

(3) Terms used in this Agreement have the meaning given in the GDPR. Where “written” form is required, text form with adequate proof (including electronic acceptance) is sufficient, unless mandatory law requires otherwise.

2 Subject matter and duration

2.1 Subject matter

The Processor provides the jixmo platform. On behalf of the Controller, the Processor in particular:

Processing is based on the existing contract between the Parties for the use of the jixmo platform (the “Main Contract”).

2.2 Duration

Processing begins with the conclusion of the Main Contract and continues for an indefinite period until this Agreement or the Main Contract is terminated by a Party.

3 Nature and purpose, types of data, data subjects

3.1 Nature and purpose

Collection, storage, adaptation or alteration, use, disclosure or other provision, erasure or destruction of data, for the purposes described in Section 2.1.

3.2 Types of data

Not covered by this Agreement: the Controller's own contact, billing and payment data, which the Processor processes as a controller under its privacy policy.

3.3 Categories of data subjects

3.4 Voice data

Spoken audio is processed only to read out the name and/or code a player says, so that the player can be matched to a player record. No voice profile or other biometric template is created, and voice is not used to recognize a person by their voice characteristics. Audio is processed transiently and is not stored. The audio and the transcript are transmitted to the sub-processors named in Annex 2 for transcription and extraction.

3.5 Rankings across customers

Ratings and rankings are calculated from the match results of all customers of the platform. The ranking of an individual Controller is a filtered view of this combined calculation. Results of a Controller may therefore influence the rankings shown to other customers. A player's name appears in a ranking only if the player has created their own account, has an active Player License and has accepted the applicable privacy terms. Processing of that account data takes place under the Processor's own responsibility and is not covered by this Agreement.

4 Obligations of the Processor

(1) The Processor processes personal data only as contractually agreed or as instructed by the Controller, unless required by law to process otherwise. In that case the Processor informs the Controller before processing, unless the law prohibits this. The Processor does not use the data for other purposes, in particular not for its own purposes, except as described in Section 3.5.

(2) The Processor confirms that it knows the applicable data protection rules and observes the principles of proper data processing.

(3) The Processor keeps the data strictly confidential.

(4) Persons who may gain knowledge of the data must be bound to confidentiality in writing, unless already subject to a statutory duty of secrecy.

(5) The Processor ensures that persons involved in processing are familiar with data protection requirements and this Agreement and are guided and supervised accordingly.

(6) The Processor assists the Controller in maintaining the record of processing activities and in carrying out data protection impact assessments, and provides the necessary information on request.

(7) If the Controller is subject to an inspection by a supervisory authority, or data subjects assert rights against the Controller, the Processor assists to the extent necessary.

(8) The Processor gives information to third parties or data subjects only with the Controller's prior consent and forwards requests directed to it without undue delay.

(9) Processing takes place in the EU or EEA, except for the sub-processors in third countries listed in Annex 2. Any transfer to a third country requires the conditions of Chapter V GDPR (in particular the EU standard contractual clauses under Decision (EU) 2021/914 and/or certification under the EU-US Data Privacy Framework).

5 Technical and organizational measures

(1) The Processor takes the technical and organizational measures required under Art. 32 GDPR, taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, to ensure a level of protection appropriate to the risk.

(2) The Processor keeps the data processed on behalf of the Controller strictly separate from other data.

(3) The Processor may change the measures during the term, provided they continue to meet the legal requirements.

(4) A current description of the measures is attached as Annex 1.

6 Rectification, erasure and blocking

(1) The Processor rectifies, erases or blocks data only in line with the contract or on the Controller's instruction.

(2) The Processor follows such instructions at any time, including after termination of this Agreement.

(3) Statutory retention obligations remain unaffected.

7 Sub-processing

(1) The Controller gives the Processor general authorization to engage further processors. The sub-processors engaged at the time of conclusion are listed in Annex 2. Service providers for testing or maintenance of processing systems or other ancillary services are not subject to authorization, as long as the Processor makes appropriate arrangements to protect confidentiality.

(2) The Processor informs the Controller of intended changes regarding the engagement or replacement of sub-processors. The Controller may object for an important reason, to be shown to the Processor. The right to object expires if the Controller does not object within 14 days of notification. If the Controller objects, the Processor may terminate the Main Contract and this Agreement with a notice period of 3 months.

(3) The contract with the sub-processor must impose the same obligations as this Agreement, or at least the obligations of Art. 28(3) GDPR.

(4) Where a sub-processor is located in a third country, Section 4(9) applies. The Controller authorizes the Processor to conclude, on the Controller's behalf, the EU standard contractual clauses with that sub-processor where required, and to cooperate to the extent necessary.

8 Rights and obligations of the Controller

(1) The Controller alone is responsible for assessing the lawfulness of the processing and for safeguarding data subjects' rights, including a legal basis for entering the data of players.

(2) The Controller issues all orders, partial orders and instructions in documented form. Oral instructions in urgent cases are to be confirmed in documented form without undue delay.

(3) The Controller informs the Processor without undue delay if it finds errors or irregularities.

(4) The Controller may check compliance with data protection rules and this Agreement at the Processor, itself or through third parties, in particular by requesting information and by reviewing documentation. On-site checks are possible by arrangement.

(5) Checks are made without avoidable disruption of business operations, after reasonable notice, during business hours, and not more often than every 12 months, unless urgent reasons require otherwise. If the Processor provides proof of compliance, a check is limited to samples.

9 Notification obligations

(1) The Processor notifies the Controller of personal data breaches without undue delay, at the latest within 72 hours of becoming aware, at an address named by the Controller, including justified suspected cases. The notification contains at least: (a) the nature of the breach, with categories and approximate number of data subjects and records concerned; (b) the contact point for further information; (c) the likely consequences; (d) the measures taken or proposed.

(2) Significant disruptions and violations of data protection rules or of this Agreement are also to be reported without undue delay.

(3) The Processor informs the Controller without undue delay of inspections or measures by supervisory authorities or third parties relating to this processing.

(4) The Processor assists the Controller with its obligations under Art. 33 and 34 GDPR.

10 Instructions

(1) The Controller retains a comprehensive right to issue instructions regarding the processing.

(2) The Processor informs the Controller without undue delay if it believes an instruction violates legal provisions, and may suspend execution until the instruction is confirmed or changed.

11 Termination

(1) On termination of the contract, or at any time on request, the Processor deletes the processed data or returns it, at the Controller's choice, together with all copies, so that restoration is not possible with reasonable effort. Backups are deleted in the regular backup cycle (daily backups for 7 days, weekly for 4 weeks, monthly and yearly for 1 year). Until they expire, backups are blocked from active use and are used only for disaster recovery.

(2) The Processor ensures return or deletion at its sub-processors.

(3) The Processor provides proof of proper deletion without undue delay.

(4) Documentation serving as proof of proper processing is retained by the Processor according to the applicable retention periods.

12 Remuneration

Remuneration is governed exclusively by the Main Contract. No separate remuneration or reimbursement is due under this Agreement.

13 Liability

(1) The exclusions and limitations of liability of the Main Contract apply. If third parties assert claims against the Processor that result from a culpable breach by the Controller of this Agreement or of its duties as controller, the Controller indemnifies the Processor on first demand.

(2) The Controller indemnifies the Processor on first demand from fines imposed on the Processor to the extent the Controller bears a share of responsibility for the sanctioned violation.

14 Extraordinary termination

(1) The Controller may terminate the Main Contract and this Agreement at any time without notice in case of a serious violation by the Processor of data protection rules or of this Agreement.

(2) A serious violation exists in particular if the Processor materially fails to meet the agreed technical and organizational measures.

(3) In case of minor violations the Controller sets a reasonable period for remedy; if it is not met, extraordinary termination is possible.

15 Miscellaneous

(1) Both Parties keep business secrets and data security measures of the other Party confidential, also after termination.

(2) If the Controller's property at the Processor is endangered by third-party measures (for example seizure) or insolvency proceedings, the Processor informs the Controller without undue delay.

(3) Side agreements require text form.

(4) A right of retention under § 273 German Civil Code is excluded with regard to the data and data carriers.

(5) If individual provisions are invalid, the remainder stays effective.

(6) Governing Law and Jurisdiction: This Agreement is governed by the laws of the Federal Republic of Germany. Place of jurisdiction for all disputes arising from or in connection with this Agreement is Neu-Ulm, Germany, to the extent legally permissible.

16 Acceptance

This Agreement is concluded by electronic acceptance by the Controller.

Place, date — Processor (Harald Eric Beringer)

Place, date — Controller (name, signature)

Annex 1 — Technical and organizational measures

The Processor operates the platform alone. The measures below describe the actual setup.

  1. Physical access. Servers and backups are operated in the data center of the hosting provider IONOS SE, located within Germany and/or the EU/EEA. The Processor has no own server room.
  2. Access to systems. Administrative access to the application instance is restricted to the Processor. Access is secured via SSH using keys/certificates; password login is disabled, firewalls are active, and system updates are applied regularly.
  3. Application access and roles. Users sign in with name and password; passwords are stored only as secure hashes. Access within the application is controlled by roles (owner, admin, manager, viewer) per organization, following the principle of least privilege.
  4. Secrets and tokens. Device API tokens, player access codes and claim tokens are stored only as hashes.
  5. Transmission. All connections use HTTPS with current industry-standard TLS encryption (TLS 1.2 or higher). Connections to sub-processors use encrypted APIs.
  6. Separation. Data of different customers is separated logically by organization. Development and production environments are strictly separate.
  7. Voice data. Audio is processed transiently and is not stored. Transcripts are not written to application logs.
  8. Availability and backup. Automated backups are created daily, weekly, monthly and yearly and are stored securely with IONOS. Retention periods: daily backups for 7 days, weekly for 4 weeks, monthly and yearly for 1 year. Software security updates are applied continuously.
  9. Retention and deletion. Device logs are deleted automatically after 365 days. Audio files without a database record are removed immediately by a scheduled job. Customer data is deleted on instruction of the Controller and upon contract termination under Section 11. Deleted data naturally expires from backups according to the defined backup retention cycle. Until expiry, backups are blocked from active use and are used only for disaster recovery.
  10. Order control. Data is processed exclusively according to the Controller's documented instructions. Persons involved are bound to confidentiality. Sub-processors are bound by compliant data processing agreements.

Annex 2 — Authorized sub-processors

Company, addressType of processingPurposeDataData subjectsLocation
IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany (HRB 24498, Amtsgericht Montabaur)Hosting, storage, backupsOperation of the platformAll data under Section 3.2Section 3.3Germany / EU / EEA
OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (contracting entity for EEA customers; parent OpenAI, USA)AI text processingExtract names from imported participant lists; extract the spoken name/code from voice transcriptsNames from pasted participant lists; text of what a player saidPlayers, participantsProcessing in the USA is possible; transfer secured under the EU-US Data Privacy Framework and standard contractual clauses (SCCs)
Eleven Labs Inc., 169 Madison Ave #2484, New York, NY 10016, USASpeech-to-text and text-to-speechTranscribe spoken identification; synthesize name announcementsVoice audio; player names as textPlayersUnited States; transfer secured under the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs), as applicable.

Annex 3 — Persons authorized to give instructions

Processor

Harald Eric Beringer

Name

Owner

Role

support (at) jixmo (dot) io

E-mail

Controller

 

Name

 

Role

 

E-mail