Data Processing Agreement (DPA / AVV)
Last updated: August 2026
This Data Processing Agreement (Auftragsverarbeitungsvertrag, "DPA") pursuant to Art. 28 GDPR applies where Picsure GmbH ("Processor", operating the brand Fahrzeugschein24) processes personal data contained in documents on behalf of the customer ("Controller"). It is available online and becomes part of the service agreement on its conclusion; a separately signed copy is available on request.
1. Subject & duration
The Processor extracts structured data from vehicle registration documents uploaded by the Controller and, optionally, checks them for manipulation. Processing lasts for the duration of the service agreement.
2. Nature, purpose & data
Nature/purpose: automated reading of uploaded documents and return of structured fields. Categories of data: the data contained in the uploaded documents (which may include personal data such as names, addresses and identifiers). Data subjects: persons referenced in those documents.
3. Controller instructions
The Processor processes personal data only on the documented instructions of the Controller, including the Controller's choices in the product, unless required otherwise by law. Instructions are normally given through these settings; any further individual instruction requires text form. If the Processor considers an instruction unlawful, it informs the Controller without undue delay.
4. Confidentiality & security
Persons authorised to process data are bound to confidentiality. The Processor implements appropriate technical and organisational measures pursuant to Art. 32 GDPR, in particular: encrypted transfer (TLS), processing of uploaded images in memory only without writing them to disk, least-privilege access control and — where duplicate detection is enabled — only salted one-way hash values (SHA-256) instead of the documents themselves. Documents are hosted in Germany and processed within the EU.
5. Sub-processors
The Processor engages sub-processors under written agreements imposing equivalent data protection obligations. For the commissioned processing these are currently: Hetzner Online GmbH (Germany) — server hosting; Google Cloud via its EU regional endpoint (EU processing location, US parent company) — text recognition on uploaded documents. The commissioned data (uploaded documents) is processed exclusively within the EU; no transfer to a third country takes place. The Controller is informed of intended changes to this list in advance and may object to them.
6. Assistance, breach notification & data subject rights
Taking into account the nature of processing, the Processor assists the Controller in responding to data subject requests and in meeting obligations under Art. 32–36 GDPR. It notifies the Controller of any personal data breach without undue delay after becoming aware of it.
7. Deletion & return
On termination, the Processor deletes or returns personal data at the Controller's choice, unless storage is required by law. Uploaded document images are not stored at any point, so no separate deletion is required for them.
8. Audits
The Processor makes available information necessary to demonstrate compliance and supports audits as required by Art. 28(3)(h) GDPR.
9. Place of processing
The commissioned data is processed within the European Union; the Processor's servers are operated in Germany. The sub-processors listed in section 5 likewise process the commissioned data only at processing locations inside the EU. Data processed under this AVV is not transferred to a third country or to an international organisation; such a transfer would require a documented instruction from the Controller and a legal basis pursuant to Art. 44 et seq. GDPR. Relocating the place of processing outside the European Union is not envisaged; it would amount to a change within the meaning of the provision on sub-processors, of which the Processor informs the Controller in advance and to which the Controller may object.
10. Authorised persons & points of contact
Individual instructions going beyond the settings in the product are issued by the Controller in text form to support@fahrzeugschein24.de. Authorised to issue instructions are the person who holds the Controller's account and any further person the Controller designates to the Processor in text form; the Controller keeps this group up to date and notifies changes without undue delay. The designation of additional authorised persons takes effect once the Processor confirms it; the withdrawal of an authorisation takes effect as soon as the notice is received. The point of contact for data protection matters is the Processor's data protection officer, reachable at datenschutz@fahrzeugschein24.de. Oral instructions are confirmed by the Controller in text form without undue delay; the Processor documents the instructions it receives.
11. Rights & obligations of the Controller
The Controller is responsible for the lawfulness of the processing, in particular for holding a legal basis for uploading and reading the documents and for informing data subjects pursuant to Art. 13 and 14 GDPR. It decides which documents it uploads and ensures that its instructions are accurate and complete. Extraction results are an aid: the Controller reviews them before relying on them for a decision and remains responsible for the accuracy of the data it goes on to process; the Terms of Service apply in addition. Requests from data subjects are answered by the Controller. If a data subject approaches the Processor directly, the Processor forwards the request to the Controller without undue delay and does not answer it itself.
12. Conducting audits
On request, the Processor provides information in text form about the technical and organisational measures in place and makes available the documentation required as evidence. Audits going beyond this are carried out by the Controller or by an auditor mandated by it and bound to secrecy, as a rule remotely — after reasonable notice, during usual business hours and without disrupting operations. On-site audits are possible by prior agreement; they are subject to the protection of trade and business secrets and of the confidentiality owed to other customers. The cost of the audit is borne by the Controller; the Processor bears its own reasonable effort. Audits prompted by a specific incident remain unaffected.
13. Term, amendments & liability
This DPA, referred to in German as the Auftragsverarbeitungsvertrag (AVV), runs for the term of the service agreement and ends with it; the obligations of deletion, return and confidentiality continue to apply until deletion is complete. The AVV cannot be terminated on its own for as long as processing is carried out on the Controller's behalf. Amendments and additions require text form, as does any waiver of this form requirement. Adjustments to changed legal requirements are notified by the Processor in text form; the Controller may object to them. In matters of data protection, this AVV prevails over conflicting provisions of the service agreement. Liability follows the liability provisions of the Terms of Service; the statutory allocation of liability between Controller and Processor under Art. 82 GDPR remains unaffected. Should any provision of this AVV be invalid, the validity of the remaining provisions is unaffected.
14. Parties
Processor: Picsure GmbH, Heidenkampsweg 58, 20097 Hamburg, Germany, Amtsgericht Hamburg HRB 190861. Contact: support@fahrzeugschein24.de.