Data Processing Agreement (DPA)

Data Processing Agreement pursuant to Art. 28 GDPR

between the user of the BonusFlow service (hereinafter "Controller") and

Bonus Service BS GmbH Dorotheenstr. 5, 45130 Essen, Germany Email: datenschutz@bonusflow.de Phone: 0201-89083160

(hereinafter "Processor")


§ 1 – Subject Matter and Duration

(1) The Processor processes personal data on behalf of the Controller within the scope of the BonusFlow service (voice-powered personal assistant for managing tasks, reminders, calendar entries, life areas, and personal knowledge).

(2) The duration of processing corresponds to the term of the service agreement. Processing ends upon deletion of the user account. Personal data will be deleted within 30 days after account deletion, unless statutory retention obligations apply.

§ 2 – Nature and Purpose of Processing

The processing includes the following activities:

  • Storage of todos, reminders, calendar entries, life areas, and personal facts
  • AI processing for intent recognition from transcribed text (Intent Recognition)
  • AI processing for calculation of vector representations (embeddings) for semantic search
  • Calendar integration (ICS feed generation, optional Google Calendar synchronization)
  • User management (account creation, authentication)
  • Email delivery (account confirmation, password reset, notifications)
  • Payment processing (subscription management and invoicing)
  • Trial management (14-day free trial; after expiration without upgrade, data remains readable, voice commands and new entries are paused until plan selection — no automatic downgrade, no automatic deletion)

§ 3 – Types of Personal Data

The following data categories are processed:

  • Name and email address
  • Password (stored encrypted)
  • Todos, reminders, and calendar entries (title, description, date/time)
  • Life areas and associated entries (content, notes, dosage instructions)
  • Personal facts (allergies, contacts, preferences — only when actively stored by the user)
  • Calendar data (ICS feed tokens, optionally synced Google Calendar events)
  • Vector representations (embeddings) of the above-mentioned text content
  • Subscription and trial period data (plan, trial start/end dates)
  • Payment data (processed by Stripe, not stored by the Processor)
  • Server log data (IP address, browser, timestamp)

Note on special categories: Users may voluntarily store health-related facts (medications, supplements, allergies). These may qualify as special categories of personal data within the meaning of Art. 9 GDPR. Processing is based on the user's explicit consent (Art. 9(2)(a) GDPR).

§ 4 – Categories of Data Subjects

  • Registered users of the service

§ 5 – Obligations of the Processor

(1) The Processor shall process personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law.

(2) The Processor ensures that persons authorized to process personal data have committed themselves to confidentiality.

(3) The Processor implements all measures required under Art. 32 GDPR, including:

  • SSL/TLS encryption of all data transmissions
  • Encrypted storage of passwords (bcrypt)
  • Local speech processing — audio data never leaves the user's device
  • Access control and authorization concept
  • Regular security updates for all systems
  • Server locations exclusively in Germany and the EU

(4) The Processor assists the Controller in fulfilling the obligations referred to in Articles 32 to 36 GDPR.

(5) Upon termination of processing, the Processor shall delete all personal data, including vector data in the Qdrant database, unless statutory retention obligations exist.

(6) The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR.

§ 6 – Sub-processors

(1) The Controller agrees to the engagement of the following sub-processors:

6.1 Hetzner Online GmbH

PurposeServer hosting (application and database)
AddressIndustriestr. 25, 91710 Gunzenhausen, Germany
Server locationGermany
Data processedAll user and content data, vector data (Qdrant)
DPAData Processing Agreement pursuant to Art. 28 GDPR in place

6.2 Mistral AI SAS

PurposeAI processing: Intent Recognition (Mistral Small) and embedding calculation (Mistral Embed)
Address16 Passage Jouffroy, 75009 Paris, France
Server locationEU (France)
Data processedTranscribed text from voice commands (for intent recognition), text content of entries (for embedding calculation)
NoteAll AI processing takes place exclusively within the EU. No data transfer to third countries. No audio data is transmitted.

6.3 ALL-INKL.COM - Neue Medien Muennich

PurposeEmail delivery (account confirmation, password reset, notifications)
AddressHauptstrasse 68, 02742 Friedersdorf, Germany
Server locationGermany
Data processedEmail address, name, email content

6.4 Stripe, Inc.

PurposePayment processing (credit cards, SEPA, subscription management)
Address354 Oyster Point Blvd, South San Francisco, CA 94080, USA
Data processing locationEU (Stripe processes European payment data in the EU)
Data processedPayment information (credit card data, SEPA data). These are processed exclusively by Stripe and not stored by the Processor.
SafeguardsEU-US Data Privacy Framework, Standard Contractual Clauses (SCC)

6.5 Google Ireland Limited (optional)

PurposeAuthentication (Google OAuth 2.0) and Calendar synchronization (Google Calendar API) — only if the user actively chooses to connect
AddressGordon House, Barrow Street, Dublin 4, Ireland
Data processing locationEU (Ireland)
Data processedFor authentication: user's name and email address. For Calendar sync: calendar events (title, date/time, description)
NoteBoth Google OAuth and Google Calendar are entirely optional. Users can always sign in via email/password or magic link and use the built-in ICS feed instead of Google Calendar sync. Content data is only transmitted to Google when Calendar sync is actively enabled by the user.
SafeguardsEU-US Data Privacy Framework, Standard Contractual Clauses (SCC)

(2) The Processor will inform the Controller of any intended changes regarding the addition or replacement of sub-processors. The Controller may object to such changes.

§ 7 – Transfers to Third Countries

(1) Transfer of personal data to third countries (outside the EEA) does not take place as a general rule.

(2) Exceptions:

  • Stripe (payment processing): Stripe, Inc. is based in the USA but processes European data in the EU. The EU-US Data Privacy Framework and Standard Contractual Clauses apply.
  • Google (Google OAuth only): Google Ireland Limited processes data in the EU. Only when the user actively chooses Google login.

(3) AI processing and the storage of all content and user data (including vector data) takes place exclusively in Germany and the EU.

§ 8 – Rights of Data Subjects

The Processor assists the Controller in fulfilling the rights of data subjects pursuant to Art. 12–22 GDPR, including:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)

Users can view and delete their data at any time through their user account.

§ 9 – Notification of Data Breaches

The Processor shall notify the Controller without undue delay, and no later than within 48 hours, of any personal data breach pursuant to Art. 33 GDPR.

§ 10 – Audit Rights

(1) The Controller has the right to verify compliance with this agreement in a reasonable manner.

(2) The Processor shall make available to the Controller all necessary information and enable audits including inspections.

§ 11 – Term and Termination

This agreement applies for the duration of use of the BonusFlow service. It takes effect upon registration and ends upon deletion of the user account.

§ 12 – Final Provisions

(1) Should individual provisions of this agreement be invalid, the validity of the remaining provisions shall remain unaffected.

(2) The law of the Federal Republic of Germany shall apply.

(3) Place of jurisdiction is Essen, Germany.


Last updated: March 2026

Contact for data protection inquiries: datenschutz@bonusflow.de