Data Processing Agreement

Last updated: 2026-09-04

Where an organisation uses Jackpoll to collect personal data — the answers of survey participants, for instance — that organisation is the controller and Quavon UG (haftungsbeschränkt) is the processor. This agreement governs that relationship under Art. 28 (3) GDPR. It applies to the instance we operate at app.jackpoll.org and forms part of using it; separate signature is required only if the controller asks for it.

It does not apply to a self-hosted installation: there Quavon processes nothing and is not the processor.

1. Subject matter, duration, nature and purpose

(1) The subject matter is the provision of the hosted survey and polling application Jackpoll. (2) The nature and purpose are the collection, storage, display, analysis, export, backup and deletion of the data created by the controller and by the participants in its surveys, together with the metadata required to operate the service. (3) The duration corresponds to the period of use plus the periods set out in clause 10. (4) Processing and storage take place exclusively on servers in Germany; the only exception is the optional push services under clause 6.

2. Categories of data subjects and data

Data subjects are the participants in the controller's surveys and the people to whom it grants access to its account. The categories of data are: account and contact data of users (name, email address, role), survey content including the questions the controller itself writes, participants' answers including uploaded files, and usage and security data (sessions, IP addresses, log entries).

What a survey collects is determined by the controller alone. If it asks for special categories under Art. 9 GDPR — health or trade union data, say — that is its decision and its legal basis; Jackpoll neither compels nor prevents it.

3. Instructions

(1) We process personal data solely on the documented instructions of the controller. Using the application's features — creating a survey, setting a retention period, an export, a deletion — constitutes such an instruction. (2) Further instructions are given in text form to contact@quavon.de. (3) If we consider an instruction unlawful we will say so without delay and may suspend execution until it is confirmed.

4. Confidentiality

We place every person authorised to process the data under an obligation of confidentiality and instruct them in the duties of data protection law. The obligation survives the end of their engagement.

5. Technical and organisational measures (Art. 32 GDPR)

We implement the following measures and maintain them for the duration of use. They may be developed further as long as the level of protection is not reduced.

6. Sub-processors

(1) The controller grants general authorisation for the engagement of the following sub-processors: the provider of the server infrastructure in Germany, the SMTP provider for sending email, and Mollie B.V. (Amsterdam, Netherlands) for processing voluntary supporter payments. Identity management (Keycloak) and object storage (MinIO/S3) we run ourselves; they are not third parties.

(2) Push notifications are delivered only where the data subject enables them on their device. Delivery runs through the device vendor's browser push service or the UnifiedPush distributor the user chooses; only the Google Play build of the app may fall back to a bundled Google FCM distributor. The contents are end-to-end encrypted. A transfer to a third country arises here alone and rests on the adequacy decision for the EU-US Data Privacy Framework, or in the alternative on standard contractual clauses under Art. 46 (2)(c) GDPR.

(3) We inform the controller in text form at least 30 days before engaging an additional sub-processor or replacing an existing one. The controller may object within that period on important data protection grounds; if the objection cannot be resolved it may end its use with effect from the intended change. (4) We impose on every sub-processor obligations equivalent to those agreed here and are liable for its conduct as for our own.

7. Assistance to the controller

(1) We assist the controller in responding to requests from data subjects under Chapter III GDPR. Much of that is built into the application: export, deletion of individual responses and deletion of an account can be carried out by the controller without us. If a data subject approaches us directly we refer them to the controller and inform it without delay. (2) We assist with the obligations under Art. 32 to 36 GDPR, in particular with a data protection impact assessment. (3) We answer requests within ten working days, urgent ones without delay.

8. Notification of personal data breaches

(1) We inform the controller without delay, and at the latest within 24 hours of becoming aware, of any personal data breach affecting its data. (2) The notification describes the nature and extent of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken; information not immediately available is supplied subsequently. (3) Notifications and queries are handled via contact@quavon.de.

9. Evidence and audits

(1) We make available all information necessary to demonstrate compliance with Art. 28 GDPR and answer one processing questionnaire per calendar year. (2) Further verification is carried out primarily on the basis of documentation and written information; an on-site audit requires specific cause, 30 days' notice and confidentiality undertakings from the auditing persons. The auditor must not be a competitor.

(3) We hold no certification under ISO 27001, SOC 2 or a comparable standard and have not undergone an external security audit. This statement forms part of the information provided. The source code is open and can be inspected, which makes an audit easier but does not replace one.

10. Deletion and return

(1) The controller can download its data in full through the export function at any time, including after use ends, for as long as its account exists. (2) If it deletes its account we delete the associated data; backups are retained for no longer than 30 days and expire thereafter. (3) Excepted is data subject to a statutory retention obligation — in particular invoices under § 147 (3) AO and § 14b (1) UStG; such data is blocked for other purposes and deleted once the period expires. On request we confirm deletion in text form.

11. Contact and final provisions

(1) Contact for data protection matters: contact@quavon.de. No data protection officer has been appointed; the conditions of § 38 (1) BDSG and Art. 37 (1) GDPR are not met. Competent supervisory authority: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach. (2) Where this agreement and the other terms conflict in respect of the processing of personal data, this agreement prevails. (3) Liability follows Art. 82 GDPR. (4) German law applies. Amendments require text form.