Skip to content
BitHive
Products
  • Reporting DeskCRA vulnerability reporting for manufacturers
  • Our products
PricingDocsSecurityServicesAbout
DEStart free trial
Menu
  • Reporting Desk
  • Products
  • Pricing
  • Docs
  • Security
  • Services
  • About
  • Request trial access
Start free trial

Version 3.0 · September 2026

Data Processing Agreement pursuant to Article 28 GDPR

between the Customer (the "Controller") and BitHive UG (haftungsbeschränkt), Heisenbergstraße 3, 10587 Berlin, Germany (the "Processor"), for the BitHive Reporting Desk (the "Service").

Version 3.0 · September 2026 · Replaces version 2.0 (changes: hosting provider STACKIT, processing in the European Union)

1. Subject matter, duration and specification of processing

1.1 The Processor processes personal data on behalf of the Controller for the purpose of providing the Service under the Terms of Service (the "Main Contract"). This Agreement applies to all such processing.

1.2 The term of this Agreement corresponds to the term of the Main Contract. Obligations that by their nature continue beyond it (in particular Sections 8 and 9) remain in force.

1.3 Nature and purpose of processing, types of personal data and categories of data subjects are set out in Annex 1.

1.4 Place of processing. The Service is hosted exclusively in data centres in Germany by a hosting provider established in Germany. All data stored in the Service, in particular SBOMs, vulnerability cases, report texts and the audit log, remains in Germany. E-mails sent by the Service (login links and notifications) are delivered by the e-mail sub-processor listed in Annex 3, a company established in Germany whose servers are located in the European Union. That sub-processor uses service providers, some of them US companies, and group companies in the USA and India for hosting, content delivery, support and maintenance. Only the data required for delivery (recipient address, name, content of the e-mail) can be affected, and such processing takes place only in accordance with Articles 44 to 49 GDPR, on the basis of the standard contractual clauses of the European Commission pursuant to Article 46 (2) (c) GDPR and, where applicable, the EU-U.S. Data Privacy Framework pursuant to Article 45 GDPR. Any other transfer to a third country requires the prior consent of the Controller in text form.

2. Instructions

2.1 The Processor processes personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law; in such a case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information. The Main Contract, this Agreement and the Controller's use of the Service's functions constitute the Controller's instructions.

2.2 Further instructions are given in text form. The Processor informs the Controller without undue delay if it considers that an instruction infringes data protection law. It may suspend the execution of that instruction until the Controller confirms or changes it.

3. Obligations of the Processor

3.1 The Processor ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

3.2 The Processor takes all measures required under Article 32 GDPR. The technical and organisational measures are described in Annex 2. The Processor may adapt them to technical progress, provided the level of protection is not reduced.

3.3 Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organisational measures in fulfilling its obligations to respond to requests from data subjects (Articles 12 to 23 GDPR). If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay.

3.4 The Processor assists the Controller in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to it.

3.5 The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's data. The notification contains, as far as available, the information set out in Article 33 (3) GDPR. Information that is not yet available is provided without undue delay as it becomes available.

3.6 If a public authority of a third country requests the disclosure of the Controller's personal data, the Processor will inform the Controller without undue delay, unless prohibited by law, will challenge the request where there are reasonable grounds to do so, and will disclose only the minimum necessary. The Processor will pass on any such request received by a sub-processor.

3.7 The Processor has designated a contact person for data protection: contact@bithive-it.com. The Processor is not obliged to appoint a data protection officer as long as the statutory requirements for this are not met.

4. Sub-processors

4.1 The Controller grants general authorisation to engage the sub-processors listed in Annex 3.

4.2 The Processor informs the Controller in text form at least four weeks in advance of any intended addition or replacement of a sub-processor. The Controller may object to the change within this period for important data protection reasons. If the Processor does not refrain from the change, the Controller may terminate the Main Contract with effect from the date of the change.

4.3 The Processor imposes on each sub-processor, by contract, the same data protection obligations as set out in this Agreement, in particular sufficient guarantees for appropriate technical and organisational measures, and ensures that the standard contractual clauses are in place where a sub-processor or one of its own sub-processors processes data in or from a third country. The Processor remains liable to the Controller for the performance of the sub-processor's obligations.

4.4 Services that the Processor uses as ancillary services, such as telecommunications or postal services, are not sub-processing within the meaning of this Section.

5. Rights and obligations of the Controller

5.1 The Controller is responsible for the lawfulness of the processing, including the lawfulness of the disclosure of personal data to the Processor, and for safeguarding the rights of data subjects.

5.2 The Controller informs the Processor without undue delay if it detects errors or irregularities in the processing results.

6. Audits

6.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR, in particular this Agreement, the description of technical and organisational measures and, where available, certificates or audit reports, including those of its sub-processors.

6.2 The Controller or an auditor mandated by it and bound to confidentiality may carry out inspections, as a rule after notice of at least four weeks, during normal business hours and without disrupting operations, and no more than once per calendar year unless there are specific indications of a breach. Inspections of sub-processors take place by means of the sub-processor's certificates and audit reports.

6.3 The Processor may charge reasonable compensation for its effort in supporting inspections that go beyond Section 6.1, unless the inspection reveals a breach by the Processor.

7. Deletion and return

7.1 After the end of the provision of services, the Processor deletes all personal data processed on behalf of the Controller in accordance with Section 8.5 of the Main Contract, unless Union or Member State law requires storage. Until then, the Controller can export its data.

7.2 Backups are overwritten in the regular backup cycle, at the latest 35 days after deletion from the production system.

8. Liability

Liability is governed by Article 82 GDPR. In the internal relationship between the parties, the liability provisions of the Main Contract apply, unless mandatory law provides otherwise.

9. Final provisions

9.1 In the event of contradictions, this Agreement takes precedence over the Main Contract with regard to data protection.

9.2 Changes and additions to this Agreement require text form.

9.3 The law of the Federal Republic of Germany applies. The place of jurisdiction is determined by the Main Contract.

9.4 This Agreement exists in a German and an English version. In the event of discrepancies, the German version prevails.

Annex 1: Specification of processing

Item Description
Nature and purpose Hosting and operation of the Service: user administration and login, storage and analysis of SBOMs, comparison with vulnerability information, sending notifications, deadline tracking, preparation of report texts, audit log, support.
Types of personal data User master data (name, business e-mail address, role, team); authentication data (login links, hashed API tokens); usage and log data (time stamps, IP addresses, actions in the Service); contents entered by users (comments, report texts, which may contain names of contact persons); contact data of notification recipients; where the Controller uses a vulnerability-intake function: name and contact details of reporting persons and the content of their reports.
Categories of data subjects Employees and agents of the Controller who use the Service or receive notifications; contact persons named in reports; persons who report vulnerabilities to the Controller through the Service.
Special categories (Art. 9 GDPR) Not intended. The Controller shall not enter such data into the Service.

Annex 2: Technical and organisational measures (Article 32 GDPR)

Confidentiality

  • Physical access: the Service runs exclusively in data centres in Germany of the hosting provider listed in Annex 3, which operates access control, video surveillance and security staff and is certified to ISO/IEC 27001 among other standards. The Processor operates no own server rooms.
  • System access: administrative access only via personal accounts with multi-factor authentication; no shared accounts; access keys stored encrypted; principle of least privilege.
  • Data access: strict separation of customers (tenants): every customer data record carries a tenant identifier, and the database enforces isolation through row-level security in addition to the application; users log in without passwords via one-time links; API tokens are stored only as cryptographic hashes and can be restricted and revoked.
  • Separation: production, test and development environments are separate; no customer data in test or development.

Integrity

  • Transmission: all connections encrypted with TLS 1.2 or higher; e-mail notifications contain no vulnerability details beyond what is necessary and link to the Service.
  • Input control: append-only audit log of relevant actions per tenant, with time stamp and user.
  • Software integrity: every change is reviewed and passes automated tests, static analysis and a dependency vulnerability scan before deployment; container images are built reproducibly.

Availability and resilience

  • Managed database with automatic backups and point-in-time recovery; restore procedures are tested at least monthly.
  • Encryption of stored data at rest.
  • External availability monitoring with alerting; documented incident-response procedure.

Procedures for regular review

  • Review of access rights at least quarterly; review of these measures at least annually and after significant changes.
  • Automated weekly checks for updates of used software components.
  • Data protection by default: only data necessary for the Service is collected; no tracking, no advertising, no use of customer data for other purposes, in particular not for training AI models.

Annex 3: Approved sub-processors

Sub-processor Service Location of processing Third-country safeguards
Schwarz Digits Cloud GmbH & Co. KG (STACKIT), Am Campus 1, 74177 Bad Friedrichshall, Germany Cloud hosting: servers, managed database, storage Germany Not applicable (no third-country processing)
Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany (Brevo group) Delivery of transactional e-mails (login links, notifications) European Union (servers in France and Belgium) Standard contractual clauses and, where applicable, the EU-U.S. Data Privacy Framework for Brevo's service providers and group companies outside the European Union (USA, India: hosting, content delivery, support, maintenance), limited to the data required for e-mail delivery (Section 1.4)

The details above reflect each sub-processor's data processing agreement as of September 2026.

All legal documents

Products

  • Reporting Desk
  • Why a reporting desk
  • Pricing
  • Request trial access

Company

  • About
  • Services
  • Contact
  • LinkedIn

Resources

  • Docs
  • API reference
  • Security of the Reporting Desk
  • Security and trust
  • security.txt

Legal

  • Legal documents
  • Legal notice
  • Privacy

© 2026 BitHive UG (haftungsbeschränkt), Heisenbergstraße 3, 10587 Berlin. All rights reserved.

Calls are held in English. Written support in English and German.

Deutsch