Data Processing Agreement

PublishedSeptember 22nd, 2026

Last updated: September 22, 2026

Note: The German version of this Data Processing Agreement is legally binding. This English version is provided for information purposes only (see Section 14).

1. Scope and Parties

This Data Processing Agreement ("DPA") forms part of the contract for the use of the SaaS service viral.app (the "Main Contract") between FMD Labs GmbH, Ernst-Haeckel-Platz 5/6, 07745 Jena, Germany (the "Processor" or "Provider") and the respective customer (the "Controller" or "Customer"). It sets out the parties' data protection obligations to the extent the Provider processes personal data on behalf of the Customer. This DPA is concluded in electronic form upon conclusion of the Main Contract (Art. 28 (9) GDPR). Customers who need a countersigned copy can request one at hello@viral.app.

2. Subject Matter and Duration

The subject matter of the processing is the provision of the viral.app platform in accordance with the Main Contract. The term of this DPA corresponds to the term of the Main Contract; it ends when the Main Contract ends, without prejudice to the obligations under Section 12.

3. Nature and Purpose of Processing, Types of Data, Data Subjects

Nature and purpose: Collection, storage, analysis, and preparation of performance data on social media content and accounts that the Customer selects for tracking; management of creator profiles and campaigns created by the Customer; calculation of payout proposals; on the Customer's instruction, transmission of approved payout proposals to the payout service provider chosen by the Customer; automated analysis of video content based on criteria configured by the Customer; integration of third-party sources authorized by the Customer (for example, ad account, revenue, and app store data) using credentials stored in encrypted form; support and operation of the platform.

Types of data: Public profile and content data of tracked accounts (for example, username, content, reach and engagement metrics); creator master data entered by the Customer (for example, name, handle, contact details); compensation and payout data; data from third-party sources connected by the Customer; usage and access data of the Customer's employees.

Data subjects: Creators and owners of tracked accounts; employees and contact persons of the Customer; other persons whose data the Customer enters into the platform.

The transmission of approved payout proposals to the payout service provider chosen by the Customer takes place on the Customer's instruction to a service provider with which the Customer has concluded its own contract; it does not constitute sub-processing within the meaning of Section 8.

4. Customer's Right to Issue Instructions

The Provider processes personal data only on documented instructions from the Customer, unless required to do so by Union or Member State law; in such a case, the Provider informs the Customer before processing, unless that law prohibits this. The Main Contract, this DPA, and the Customer's use of the platform's features (including the approval of payout proposals) constitute instructions. Further individual instructions must be given in text form. The Provider will carry out instructions that go beyond the contractually agreed scope of services and cause more than insignificant additional effort after prior agreement and against reasonable compensation. If the Provider considers an instruction to be unlawful, it informs the Customer without undue delay and may suspend its execution until confirmed.

5. Confidentiality

The Provider only engages persons who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28 (3)(b) GDPR). These obligations continue after the end of their activity.

6. Records and Contact Point

The Provider maintains a record of all categories of processing activities carried out on behalf of the Customer (Art. 30 (2) GDPR). The contact point for the Customer's data protection inquiries is hello@viral.app.

7. Technical and Organizational Measures

The Provider implements the technical and organizational measures described in Annex 2 in accordance with Art. 32 GDPR and develops them further in line with the state of the art. Measures may be replaced by equivalent or better ones; material changes are documented.

8. Sub-processors

The Customer grants general authorization for the use of the sub-processors listed in Annex 3. The Provider informs the Customer in text form of any intended changes (addition or replacement) at least 30 days in advance; the Customer may object for good cause under data protection law. If no reasonable solution can be found following a justified objection, either party may terminate the affected services; prepaid fees will be refunded pro rata. The Provider imposes on each sub-processor by contract the same data protection obligations as set out in this DPA and remains liable to the Customer for the performance of the sub-processor's data protection obligations (Art. 28 (4) GDPR).

9. Processing in Third Countries

Processing outside the EU or EEA only takes place if the requirements of Chapter V GDPR are met, in particular on the basis of an adequacy decision or the EU Standard Contractual Clauses, supplemented by any necessary additional measures. The mechanisms used are specified for each sub-processor in Annex 3.

10. Provider's Assistance Obligations

  • Data subject rights: The Provider assists the Customer with appropriate technical and organizational measures in fulfilling the rights of data subjects (Art. 12 to 23 GDPR). The Provider forwards requests from data subjects that it receives to the Customer without undue delay, without responding to them on the merits itself.
  • Security and notification obligations: The Provider notifies the Customer of personal data breaches without undue delay after becoming aware of them and assists the Customer with its obligations under Art. 32 to 36 GDPR (security, notification of the supervisory authority and data subjects, data protection impact assessment, prior consultation), taking into account the nature of the processing and the information available to it. A notification does not constitute an acknowledgment of fault or of a breach of duty.

The Provider provides assistance beyond the self-service features it offers and beyond the scope required by law against reasonable compensation after prior agreement.

11. Customer's Obligations and Representations

As controller, the Customer is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects. It issues instructions in good time and documents them.

The Customer warrants that there is a valid legal basis for the personal data it enters, in particular creator profiles and compensation data, and that the data subjects are informed in accordance with Art. 13 and 14 GDPR; the Customer provides evidence of this upon request.

The Customer indemnifies the Provider against third-party claims and fines arising from an instruction of the Customer or data entered by the Customer violating data protection law, unless the Customer is not responsible for the violation. Further recourse claims under Art. 82 (5) GDPR remain unaffected.

12. Deletion and Return After the End of Processing

At the Customer's choice, the Provider returns or deletes the personal data processed on the Customer's behalf after the end of the Main Contract (Art. 28 (3)(g) GDPR). Data is returned via the export function provided for in the Main Contract; if the Customer does not state a different choice within the period provided there, the Provider deletes the data after the period has expired. Where statutory retention obligations exist, processing is restricted instead. Data in backup copies is deleted in the course of the usual backup cycles; until then, processing is limited to storage. Upon request, the Provider confirms the deletion in text form.

13. Evidence and Audit Rights

The Provider makes available to the Customer all information necessary to demonstrate compliance with this DPA, primarily through meaningful documentation (for example, descriptions of technical and organizational measures, audit reports, certificates). In addition, after reasonable prior notice (at least 30 days), the Customer may carry out an inspection during normal business hours no more than once a year, as well as after a personal data breach at the Provider or on the justified order of a supervisory authority, or have it carried out by a third party bound to confidentiality who must not be a competitor of the Provider. Disruptions to operations must be avoided. Each party bears its own costs; the Provider may charge reasonable fees for any additional or repeated inspections.

14. Final Provisions

In the event of conflicts between this DPA and the Main Contract, this DPA takes precedence in matters of data protection. Liability is governed by the provisions of the Main Contract. The amendment clause of the Terms of Service applies accordingly to amendments of this DPA. The choice of law and place of jurisdiction of the Main Contract apply. This DPA is concluded in the German language; versions in other languages, including this English version, are provided for information purposes only, and in the event of discrepancies the German version prevails.

Annex 1: Description of Processing

The subject matter, nature and purpose of processing, types of data, and categories of data subjects are set out in Section 3.

Annex 2: Technical and Organizational Measures

Physical security: The servers are located in data centers of Hetzner Online GmbH in Germany and Finland and with the cloud providers listed in Annex 3, which ensure the physical protection of their data centers (certified to ISO/IEC 27001 in the case of Hetzner).

Access control (systems):

  • Passwordless sign-in via sign-in links or one-time codes valid for 5 minutes (one-time codes with a limited number of attempts and stored only as a hash), Google accounts, or passkeys
  • Sessions with automatic expiry
  • Rate limiting for sign-in, API, and other endpoints
  • Administrative interfaces and internal services are only reachable via a private network (Tailscale) or through zero-trust access controls (Cloudflare Access); servers are protected by firewalls

Access control (data) and separation:

  • Logical separation of customer data by organization; every request is checked server-side for membership in the organization
  • Role-based permission model (for example, owner, administrator, member, viewer)
  • API keys and access by connected AI assistants are each bound to a single organization
  • The Provider's administrative rights are limited to designated persons; support access to customer accounts is limited to one hour and logged

Transfer control:

  • Encrypted transmission (TLS) between browsers or clients and the service
  • Credentials for services connected by the Customer are stored in a dedicated, self-hosted secrets manager or encrypted at application level (AES-256-GCM)
  • Signature verification of incoming webhooks from connected services

Input control: Logging of security-relevant actions (acting person, action, time, IP address, browser identifier) for 365 days; error monitoring of the application.

Availability and resilience:

  • Regular backups of the main database and nightly backups of the analytics database to separate object storage
  • Monitoring of systems with automatic alerting

Processor control: Sub-processors are only engaged on the basis of contracts pursuant to Art. 28 GDPR; the persons engaged are bound to confidentiality.

Data minimization and deletion: Automated deletion of temporary data (for example, data exports after 7 days, internal processing events after 2 days, details in logs after 90 days).

Software supply chain: Software dependencies are checked for known malicious packages in the build and deployment pipeline.

Annex 3: Sub-processors

Sub-processorServiceProcessing locationTransfer mechanism
Hetzner Online GmbH, Gunzenhausen, GermanyServers for databases, data processing, real-time chat, and cachingGermany, Finlandnot applicable (EU)
Vercel Inc., USAHosting of the web applicationsUSA and worldwide (edge network)EU-U.S. Data Privacy Framework
Cloudflare, Inc., USAObject storage, network and access protectionEU and USAEU-U.S. Data Privacy Framework
Google Cloud EMEA Limited, Dublin, IrelandAI analysis (Gemini API): video analysis, assistant, profile matchingworldwide, including the USAEU-U.S. Data Privacy Framework (Google LLC)
Plus Five Five, Inc. (Resend), USADelivery of transactional emailsUSAEU-U.S. Data Privacy Framework
PostHog Inc., USA

Product analytics including session recording in the application (form inputs masked)

EUEU-U.S. Data Privacy Framework
Functional Software, Inc. (Sentry), USAError monitoringEU (Germany)EU-U.S. Data Privacy Framework

Service providers for retrieving public platform data (including via RapidAPI) and proxy infrastructure (DataImpulse)

Retrieval of publicly available platform data on tracked accounts and content

various, including the USA

adequacy decision or EU Standard Contractual Clauses, depending on the provider

The payout service provider chosen by the Customer (currently Talentir) is not a sub-processor of the Provider (see Section 3).