Data Processing Agreement
Version 1.0 · As of 30 September 2026
This Data Processing Agreement (“DPA”) forms part of the contract under our Terms of Service and is concluded when the Customer accepts the Terms. The English version is binding; the German version is a convenience translation.
1. Parties and scope
1.1 This DPA is concluded between the business that uses The Setting Lab (“Controller” or “Customer”) and Benjamin Luis Alessandro Rüger, trading as SAYNT, Selma-Lagerlöf-Straße 22, 81829 Munich, Germany (“Processor”, “we”).
1.2 It applies to all processing of personal data that the Processor carries out on behalf of the Controller in providing the Service under the Terms (“Customer Personal Data”). It does not apply to data the Processor processes as its own controller, in particular account and billing data of the Customer and its staff and technical security data under section 11 of our Privacy Policy.
1.3 Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning given in Regulation (EU) 2016/679 (GDPR). References to the GDPR include, where applicable, the UK GDPR and the UK Data Protection Act 2018.
1.4 In the event of conflict, this DPA takes precedence over the Terms with regard to data protection. The Standard Contractual Clauses, where concluded under section 7, take precedence over this DPA.
2. Subject matter, duration, nature and purpose
2.1 The subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex 1.
2.2 The DPA runs for as long as the Processor processes Customer Personal Data, i.e. for the term of the contract and the subsequent data retrieval and deletion period under section 17 of the Terms.
3. Instructions
3.1 The Processor processes Customer Personal Data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor informs the Controller of that legal requirement before processing, unless the law prohibits this.
3.2 The Controller’s instructions are conclusively documented in the Terms, this DPA and the settings the Controller makes in the Backend (for example catalog, request form, end customer accounts, lead export, deletion). Further instructions must be given in text form and must be compatible with the Service; instructions that go beyond the agreed scope of services may be billed at reasonable rates after prior notice.
3.3 The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions. It may suspend the execution of the instruction until the Controller confirms or changes it.
4. Obligations of the Processor
4.1 Confidentiality. The Processor ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation continues after the end of their activity.
4.2 Security. The Processor implements the technical and organisational measures described in Annex 2 (Art. 32 GDPR). It may adapt the measures to technical progress, provided that the level of protection is not reduced. Material changes are documented.
4.3 Assistance. Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organisational measures in responding to requests from data subjects (Art. 12–22 GDPR), in particular through the export and deletion functions of the Backend. If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay and does not respond itself unless instructed. The Processor also assists the Controller, taking into account the information available to it, in complying with Art. 32 to 36 GDPR (security, breach notification, data protection impact assessment, prior consultation).
4.4 Personal data breaches. The Processor notifies the Controller without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification contains, as far as available, the information set out in Art. 33 (3) GDPR; information not yet available is provided in phases. The Processor takes the necessary measures to secure the data and mitigate possible adverse consequences and documents the breach. Notifying supervisory authorities and data subjects is the responsibility of the Controller.
4.5 Records. The Processor maintains a record of processing activities carried out on behalf of controllers (Art. 30 (2) GDPR).
4.6 No other use. The Processor does not use Customer Personal Data for its own purposes, does not sell it and does not combine it with data of other customers. The creation of aggregated, anonymised statistics under section 9.5 of the Terms is permitted as part of the instructed processing.
4.7 Location. The Processor itself processes Customer Personal Data in the EU/EEA. Processing by subprocessors in third countries is subject to section 7.
5. Subprocessors
5.1 The Controller grants the Processor general written authorisation to engage subprocessors. The subprocessors engaged at the time of conclusion are listed on our subprocessor page, which forms Annex 3.
5.2 The Processor informs the Controller of any intended addition or replacement of a subprocessor at least 30 days in advance by e-mail to the address stored in the account and by updating the subprocessor page. The Controller may object in text form within 14 days of the notification for reasonable data protection grounds. If the parties cannot resolve the objection, the Controller may terminate the affected part of the contract with effect from the date the change is to take effect; prepaid fees for the remaining period are refunded. In urgent cases (for example the sudden failure of a provider), the period may be shortened; the Controller’s right to object and terminate remains.
5.3 The Processor imposes on each subprocessor by contract data protection obligations that offer at least the level of protection of this DPA (Art. 28 (4) GDPR) and remains responsible to the Controller for the subprocessor’s compliance.
5.4 Services that the Processor uses as ancillary services (for example telecommunications, postal services, the payment provider for its own billing) are not subprocessors within the meaning of this section, provided they do not have access to Customer Personal Data.
6. Obligations of the Controller
6.1 The Controller is responsible for the lawfulness of the processing, including the legal basis, the information of data subjects (Art. 13, 14 GDPR) – for which the Processor provides a template text – and, where required, obtaining consent.
6.2 The Controller does not transfer special categories of personal data (Art. 9 GDPR), in particular dental scans or health information, to the Service.
6.3 The Controller informs the Processor without undue delay if it finds errors or irregularities in the processing results.
7. International transfers
7.1 Transfers of Customer Personal Data to a third country outside the EU/EEA take place only where the conditions of Art. 44 to 49 GDPR are met, in particular on the basis of an adequacy decision (for example the EU-U.S. Data Privacy Framework for certified recipients, or the decision for the United Kingdom) or of the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, “SCC”).
7.2 For subprocessors in third countries without an adequacy decision, the Processor concludes Module 3 (processor to processor) of the SCC with the subprocessor, supplemented where necessary by additional measures.
7.3 If the Controller is established in a third country without an adequacy decision and the Processor transfers Customer Personal Data back to it, Module 4 (processor to controller) of the SCC applies and is hereby incorporated by reference; the Processor is the data exporter and the Controller the data importer. For such SCC, Clause 17 (governing law) is German law and Clause 18 (choice of forum) refers to the courts of Munich.
7.4 For transfers subject to the UK GDPR, the International Data Transfer Addendum to the SCC issued by the UK Information Commissioner applies accordingly.
8. Evidence and audits
8.1 The Processor provides the Controller on request with the information necessary to demonstrate compliance with Art. 28 GDPR, in particular this DPA, the current TOMs and the subprocessor list, and where available certifications or audit reports of its subprocessors.
8.2 If this information is not sufficient in an individual case, the Controller may carry out an audit, itself or through an independent auditor bound to confidentiality who is not a competitor of the Processor, after notice of at least 30 days, during normal business hours, without disrupting operations, and generally not more than once per calendar year. An audit on shorter notice is permitted following a personal data breach. Audits of the premises of subprocessors are carried out by means of their audit reports and certifications. Each party bears its own costs; if an audit requires more than one working day of the Processor’s time, the Processor may charge reasonable fees unless the audit reveals material breaches.
9. Deletion and return
9.1 At the end of the provision of services, the Processor makes Customer Personal Data available for export in accordance with section 17 of the Terms for at least 30 days and then deletes it, unless Union or Member State law requires storage. Backups are overwritten in the ordinary backup cycle, at the latest after a further 35 days. The Processor confirms deletion in text form on request.
9.2 During the term, the Controller can delete individual data records in the Backend or instruct the Processor to delete them.
10. Additional provisions for US state privacy laws
Where the Controller is subject to US state privacy laws (such as the California Consumer Privacy Act as amended by the CPRA), the Processor acts as “service provider” or “processor” within the meaning of those laws and: (a) does not sell or share Customer Personal Data; (b) does not retain, use or disclose it for any purpose other than providing the Service, or outside the direct business relationship with the Controller; (c) does not combine it with personal data from other sources except as permitted by those laws; (d) complies with applicable obligations and provides the same level of protection as required of the Controller; and (e) notifies the Controller if it can no longer meet its obligations. The Controller may take reasonable steps to stop and remediate unauthorised use.
11. Liability and final provisions
11.1 Liability of the parties towards data subjects is governed by Art. 82 GDPR. In the relationship between the parties, the liability provisions of the Terms apply, to the extent permitted by law.
11.2 Changes and additions to this DPA require text form. Section 19 of the Terms applies to changes of this DPA accordingly; changes required by law or by supervisory authorities may be made with 30 days’ notice.
11.3 German law applies; the place of jurisdiction follows section 24 of the Terms. If individual provisions are invalid, the remaining provisions remain unaffected.
Annex 1 – Description of the processing
| Subject matter | Provision of a white-label 3D configurator for grillz and jewellery, embedded in the Controller’s website, and of a backend for managing it. |
|---|---|
| Nature of processing | Collection, recording, storage, organisation, retrieval, transmission (to the Controller’s shop page, by e-mail notification, export or webhook), rendering of images/videos, aggregation, erasure. |
| Purposes | Display of the configurator and prices; saving and sharing designs; transmitting configurations to the Controller’s cart; receiving and forwarding enquiries; end customer accounts; photoreal renders and video export; lead management and export; usage statistics for the Controller; security and abuse prevention of the embedded service. |
| Categories of data subjects | End customers and prospective customers of the Controller who use the configurator; persons who send an enquiry via the configurator; holders of end customer accounts (where offered). |
| Types of personal data | Configuration data (selected teeth, styles, metals, stones, prices shown, configuration ID, share link); enquiry data (name, e-mail address, phone number or social media handle if provided, message, preferred contact); end customer account data (e-mail address, password hash, saved designs); renders and videos of configurations; usage data (events in the configurator, timestamps, pseudonymous session identifier, device type, referring page); technical connection data (IP address, user agent) for delivery and security. |
| Special categories | None. The Controller must not transfer such data (section 6.2). |
| Frequency | Continuous for the term of the contract. |
| Retention | As set by the Controller in the Backend; at the latest until deletion after the end of the contract (section 9). Technical connection data: max. 30 days. |
Annex 2 – Technical and organisational measures (Art. 32 GDPR)
1. Confidentiality
- Physical access control: the Service runs exclusively in data centres of certified cloud providers (Cloudflare, Google Cloud; ISO/IEC 27001, SOC 2). The Processor operates no servers of its own. Work devices are kept in locked premises.
- System access control: Backend access only with personal accounts via Firebase Authentication; accounts are created only after a paid order (no open registration); strong passwords; two-factor authentication on all administrative accounts of the Processor (cloud consoles, domain management, e-mail, payment provider); automatic screen lock and full-disk encryption on work devices; operating systems and browsers kept up to date.
- Data access control and tenant separation: each Customer is a separate tenant. Access to data in Cloud Firestore and Cloud Storage is enforced server-side by security rules that check the tenant claim in the signed identity token of the logged-in user – never by filters in the browser. A Customer can only read and write its own records. Administrative access by the Processor uses a separate role and is limited to support, operation and legal obligations. Secret keys are stored only as encrypted environment variables of the hosting platform, never in source code or in the browser.
- Separation: development, test and production environments are separated; test data does not contain real end customer data.
- Pseudonymisation and minimisation: configuration IDs and session identifiers are random; usage statistics are evaluated in aggregated form; share links contain only design parameters and no personal data; IP addresses are not stored in the database.
2. Integrity
- Transfer control: all connections are encrypted with TLS 1.2 or higher (HSTS); data at rest is encrypted by the cloud providers (AES-256).
- Protected delivery: 3D files are delivered only via short-lived links signed with HMAC-SHA256, bound to tenant and expiry time (max. 15 minutes); file names are not guessable, directory listings are disabled, and requests are rate-limited.
- License and domain check: before loading, the configurator checks server-side whether the calling domain is registered for an active license.
- Input control: prices and catalog rules are validated server-side; messages between the embedded frame and the shop page are accepted only from the expected origin; relevant administrative changes are logged.
3. Availability and resilience
- Delivery via Cloudflare’s global network with DDoS protection; managed, redundant database and storage services.
- Daily backups (export) of the database, kept for [30] days in a separate storage location; restore procedure tested at least [every six months].
- Monitoring of availability and error rates; documented procedure for incidents.
4. Procedures for regular testing and evaluation
- Security rules are tested automatically (emulator tests for tenant separation) before every deployment.
- Regular updates of dependencies and review of security advisories.
- Review of these measures at least once a year and after significant changes to the Service.
- Incident response: detection, containment, assessment, notification of the Controller (section 4.4), documentation.
5. Order control
- Subprocessors are selected with care and bound by data processing agreements including, where necessary, SCC; their certifications are reviewed.
- Processing only on the basis of the Controller’s documented instructions (section 3).
Annex 3 – Subprocessors
The current list of subprocessors, including their location, purpose and transfer mechanism, is available at settinglab.com/subprocessors.html.