Legal
Data Processing Agreement
Data processing agreement pursuant to Art. 28 GDPR for business customers.
This is a translation for your convenience. Only the German version is legally binding: Vertrag zur Auftragsverarbeitung.
This agreement applies between the customer as a business (“Controller”) and Highlight PC, owner Günter Geisler (“Processor”), and forms part of the contract for the use of Mailsecurity24.
1. Subject matter and duration
- The Processor processes personal data contained in DMARC reports on the Controller’s domains, as well as the data of users whom the Controller creates in its organisation.
- The duration corresponds to the term of the usage contract including the deletion period under section 8.
2. Nature, purpose and scope
| Item | Content |
|---|---|
| Purpose | Receipt, analysis and storage of DMARC aggregate reports and SMTP TLS reports; checks of DNS records, of mail server encryption and of MTA-STS policies; alerts; provision via portal and API |
| Types of data | IP addresses of sending mail servers, domain names, counts and check results of emails, name and contact address of reporting organisations; for TLS reports additionally names of receiving mail servers and the number and type of failed encrypted deliveries; technical check results of mail servers (TLS version, certificate details); name, email address and role of users |
| Data subjects | Operators and users of mail servers that send on behalf of the Controller’s domains or deliver to them; contacts of reporting organisations; users of the Controller |
| Location | Servers of 1blu GmbH in Germany |
3. Instructions
- The Processor processes the data only on documented instructions from the Controller. The instructions are given by this agreement, the settings in the portal and requests via the API.
- The Controller gives further instructions in text form. If the Processor considers an instruction to be unlawful, it informs the Controller without delay.
4. Obligations of the Processor
- It commits all persons with access to the data to confidentiality.
- It implements the technical and organisational measures set out in Annex 1 and adapts them to the state of the art without lowering the level of protection.
- It supports the Controller with data subject requests, the notification of personal data breaches and data protection impact assessments within reason.
- It notifies personal data breaches without undue delay, where possible within 48 hours of becoming aware of them, with the information required under Art. 33 (3) GDPR to the extent known.
- Support access to the Controller’s data is read-only, time-limited, justified and logged.
5. Sub-processors
- The Controller approves the sub-processors listed in Annex 2.
- The Processor announces new or replaced sub-processors at least four weeks in advance in text form. The Controller may object for an important data protection reason; if no agreement is reached, the Controller may terminate the usage contract with effect from the date of the change.
- The Processor contractually binds sub-processors to the same level of protection.
6. Transfers to third countries
To classify and check senders, IP addresses and domain names are sent by DNS lookup to the services listed in Annex 2, including parties in the USA, the Netherlands and Switzerland. The lookup only contains the respective IP address or domain, with no reference to the Controller.
The Processor handles support requests in the ticket system of Atera Networks Ltd. in Israel, for which the European Commission has adopted an adequacy decision (2011/61/EU). Atera stores data in data centres in the EU and the USA; transfers to the USA are safeguarded by adequacy decisions or EU standard contractual clauses. Report data only reaches Atera insofar as users of the Controller write it into a request themselves.
7. Audit rights
The Controller may check compliance with this agreement by obtaining information and evidence and, after notice with a reasonable period, during business hours and without disrupting operations, carry out on-site inspections or have them carried out by an auditor bound to confidentiality.
8. Deletion and return
- The Processor deletes reports on an ongoing basis after the retention period of the booked plan.
- After the end of the contract, the Controller can retrieve its data via portal and API for 30 days. The Processor then deletes all of the Controller’s data, including copies in backups at the latest after a further 30 days, unless a statutory retention obligation applies.
9. Liability and final provisions
Liability is governed by Art. 82 GDPR and the rules of the usage contract. Amendments require text form. In case of conflict, this agreement takes precedence over the terms and conditions insofar as the protection of personal data is concerned.
Annex 1 – Technical and organisational measures
| Area | Measures |
|---|---|
| Physical access | Data centre of 1blu GmbH, Berlin |
| System access | Passwords stored only as hashes; two-factor sign-in available; sign-in via one-time code; server access only for administrators via secured, personal accounts |
| Data access | Roles per organisation (owner, administrator, analyst, viewer); optional restriction to individual domains; API keys with individual permissions and expiry date; rate limiting |
| Separation | Every record is assigned to one organisation; queries are restricted to the organisation; test and production systems are separate |
| Transfer | Transmission exclusively encrypted (HTTPS/TLS); strict browser security rules (Content Security Policy) |
| Input control | Log of security-relevant actions with user and time; support access read-only, time-limited and logged |
| Availability | Backup before every software update; monitoring of the background service |
| Data minimisation | Automatic deletion of reports after the plan’s retention period; no processing of forensic reports containing email content; mail server checks without transmitting messages; mailbox credentials stored encrypted |
Annex 2 – Sub-processors and recipients of lookups
| Party | Location | Activity |
|---|---|---|
| 1blu GmbH, Berlin | Germany | Server operation, storage of all data |
| 1blu GmbH (DNS resolution) | Germany | DNS resolution |
| Team Cymru | USA | Mapping IP addresses to network operator and country (DNS lookup) |
| SpamCop (Cisco) | USA | IP blocklist (DNS lookup) |
| PSBL, UCEPROTECT | Netherlands, Switzerland | IP blocklists (DNS lookup) |
| SURBL, URIBL | Netherlands | Domain blocklists (DNS lookup) |
| Atera Networks Ltd., Tel Aviv | Israel (storage in the EU and the USA) | Ticket system for support requests; only receives data insofar as users of the Controller write it into a request |
Stripe and Lexware Office are not sub-processors under this agreement: they only process contract and billing data for which the Provider is itself responsible.
Last updated: 26 September 2026
