# GTC (Standard)

> Canonical: https://legal.sweap.io/en

Status: 08.07.2026

These terms and conditions have been translated automatically. Please check the German version for a legally secure version.

## Components

### GTC

MATE Development GmbH, Rankestraße 9, 10789 Berlin, registered at the Charlottenburg Local Court under HRB 174234 B, represented by the managing directors Florian Kühne, Matthias Heicke and Sven Frauen (hereinafter “**Sweap**”) offers software products under the Sweap brand to entrepreneurs in the exercise of their business or independent professional activities within the meaning of Section 14 of the German Civil Code (BGB) (“**Customers**”) via the sweap.io website.

The Customers wish to use these products for the purposes of better event and organization management within their respective companies as a web-based SaaS or cloud solution in accordance with the product description, limited to the period of existence of this contract.

Any general terms and conditions of the Customer shall not apply vis-à-vis Sweap, regardless of whether Sweap has expressly objected to their application or not.

### 1. Subject matter of the contract
1. The terms and conditions of these GTC shall apply to the use of the 'Sweap' software in accordance with the current product description at https://www.sweap.io/ (“**Product Description**”) (the “**Software**” depending on the current product description).
2. The Software is operated by Sweap as a web-based SaaS or cloud solution. The Customer shall be enabled to use the Software stored and running on the servers of Sweap or a service provider commissioned by Sweap via a connection to the Internet for its own purposes during the term of the Agreement in accordance with these GTC and to store, process or use its data or content uploaded by it and to integrate elements of the Software, such as certain login pages and forms, into its own websites.

### 2. Conclusion of contract
1. The Customer can register via the sweap.io website, stating his name, company, e-mail address and VAT number, and thus submit an offer to conclude these GTC, whereby Sweap will then check the registration and send the Customer a confirmation e-mail and the agreement will be deemed to have been concluded upon receipt of the confirmation e-mail by the Customer (“**Start Date**”).
2. Sweap shall then provide the Customer with the access data for an account that can be accessed on the sweap.io website, which the Customer can then log into in order to use Sweap's services (“**Account**”).

### 3. Services provided by Sweap
1. Sweap shall make the Software available to the Customer for use in its most recent version at the router exit of the data center where the server with the Software is located (“**Transfer Point**”). The Software, the computing power required for its use and the required storage and data processing space shall be made available by Sweap. However, Sweap is not responsible for establishing and maintaining the data connection between the Customer's IT systems and the described Transfer Point.
2. To the extent that the software runs exclusively on the servers of Sweap or another contracted service provider, the customer does not require any copyright usage rights to the software and Sweap does not grant any such rights.
3. For the term of the relevant license to be paid for, Sweap grants the Customer the non-exclusive, non-transferable right, limited in time to the term of the agreement in accordance with these GTC, to load the user interface of the Software for display on the screen into the memory of the end devices used for this purpose in accordance with the agreement and to make the resulting reproductions of the user interface. The customer hereby accepts the granting of these rights.
4. The support services within the meaning of these GTC (see clause 8) include the localization of the cause of the error, error diagnosis and services aimed at rectifying the error (in particular patches and service packs). Sweap assumes no responsibility for the elimination of the error.

### 4. Availability of the Software
1. Sweap draws the Customer's attention to the fact that restrictions and/or impairments of the services provided may arise that are beyond Sweap's control, such as actions by third parties not acting on Sweap's behalf, technical conditions beyond Sweap's control and force majeure.
2. The hardware, software and technical infrastructure used by the Customer may also have an influence on Sweap's Services. Insofar as such circumstances affect the availability and/or functionality of the Services provided by Sweap, this shall not affect the conformity of the Services provided with the Agreement.
3. The Customer is obliged to notify Sweap immediately of any malfunctions, malfunctions or impairments of the Software via the integrated reporting function within the Software and to name these as precisely as possible, or if the reporting function within the Software is affected by the malfunction, the Customer must notify Sweap of the relevant malfunction by e-mail to support@sweap.io. If the Customer fails to do so, the provisions of Section 536c BGB shall apply accordingly.

### 5. Rights to data processing; data backup
1. Sweap shall act in accordance with the applicable statutory provisions on data protection. Sweap's current privacy policy, available at https://www.sweap.io/en/privacy-policy, shall apply.
2. The Customer grants Sweap the right to reproduce the data to be stored by Sweap for the Customer for the purposes of the performance of the Agreement in accordance with these GTC, insofar as this is necessary for the provision of the services owed under these GTC. Sweap is also entitled to store the data in a failure system or separate failure data center. Sweap is also entitled to make changes to the structure of the data or the data format in order to remedy malfunctions. Sweap hereby accepts this grant of rights.
3. Sweap regularly backs up the Customer's data on the server for which Sweap is responsible to a backup server. The Customer may extract this data for backup purposes at any time, insofar as technically possible, and is obliged to do so at regular intervals.

### 6. Order processing
1. If and insofar as the Client processes or uses personal data on IT systems for which Sweap is responsible, the parties shall enter into a data processing agreement.
2. Sweap shall use the Customer Data exclusively in accordance with the instructions of the Customer, as conclusively expressed in the provisions of the Data Processing Agreement. Individual instructions that deviate from the provisions of the Data Processing Agreement or impose additional requirements shall require Sweap's prior consent and shall be issued after contact by the customer by e-mail at least in text form in accordance with Section 126b of the German Civil Code. Any additional costs arising from these individual instructions shall be borne by the customer and shall be paid to Sweap after prior invoicing by Sweap in accordance with the provisions of clause 9 of these GTC.
3. Sweap and the Client undertake to enter into an amended version of such a data processing agreement should this become necessary, for example due to changes in the law.

### 7. Content of the customer
1. The customer has the option of uploading content (such as data, graphics, images, texts, diagrams, files, etc.) within his account (“**Customer Content**”).
2. The Customer shall be solely responsible for such Customer Content and undertakes not to upload or otherwise use any prohibited content within its Account in accordance with clause 13 (1) of these GTC.
3. Sweap does not claim ownership of this Customer Content.
4. To the extent that the Customer provides Sweap with this Customer Content, the Customer grants Sweap all rights technically necessary for the performance of the contractual agreement (e.g. in the event of a change to Sweap's domain). This includes in particular the right to deliver the content designated for publication by the Customer (e.g. event websites, registration forms, invitation emails) within the platform, in accordance with the Customer's configuration, to the recipients determined by the Customer and to host it in a publicly accessible manner. Sweap does not use the Customer Content beyond this. Sweap hereby accepts this grant of rights.
5. In the event that Customer Content is removed from an Account or that an Account is deleted by the Customer or by Sweap - for whatever reason - Sweap's rights to the relevant Customer Content shall lapse.

### 8. Service and support services
1. A “**Service Case**” exists if the Software does not fulfill the contractual functions in accordance with the product description, delivers incorrect results, aborts data processing in an uncontrolled manner or does not work properly in any other way, so that the use of the Software is not possible or only possible to a limited extent.
2. The Customer can report a service case to Sweap via the integrated reporting function within the Software. If for any reason the reporting function within the Software is not functional, Customer can report the service case by e-mail to support@sweap.io, whereby Sweap will be available during the service hours on weekdays (Berlin), Monday through Friday between 9 a.m. and 6 p.m. (“**Service Hours**”). The Customer is obliged to provide as detailed a description as possible of the respective functional failure, malfunction or impairment, at least in text form in accordance with § 126b BGB (e.g. by e-mail).

### 9. Remuneration
1. If Sweap offers a demo or other limited version, this shall be free of charge in accordance with the conditions described on the sweap.io website. The demo or other limited version of the Software may be used by each Customer with one demo Account only. Multiple demo Accounts require Sweap’s prior consent in text form.
2. Furthermore, the customer shall pay remuneration plus statutory VAT for the services owed by Sweap under these GTC or the granting of rights. The amount and further provisions on remuneration are set out in the price table attached to the product description at https://www.sweap.io/en/pricing.
3. Payment of the remuneration shall be made using one of the payment methods available on Sweap's website at https://www.sweap.io/en/pricing.
4. Unless otherwise agreed between the parties, payment shall be due within fourteen (14) calendar days of the Customer's receipt of a corresponding invoice from Sweap.
5. If the Customer is in default with a payment or if there is a return debit note, Sweap reserves the right to claim damages for default (e.g. collection fees, reminder fees, default interest and chargeback fees).

### 10. Obligations of the customer
1. The Customer shall support Sweap to a reasonable extent in the provision of the contractual services
2. The Customer shall be responsible for the proper and regular backup of its data. The same applies to Sweap with regard to the documents provided during the performance of the contract.
3. In order to use the Software in accordance with these GTC, the Customer must meet the system requirements set out in the product description. The Customer is responsible for this.
4. The Customer is aware that Sweap does not operate its own network and does not provide the Customer with Internet access. For this reason, Sweap accepts no responsibility for the functionality of the Internet access in question.
5. All requested data and customer content must be provided completely and correctly, insofar as the request for such data does not violate any (privacy) law(s).
6. To the extent that the Customer provides Sweap with Customer Content, the Customer warrants that it has all the necessary rights to the Customer Content provided in order to grant Sweap the relevant rights.
7. The Account (including the Admin Profile and sub-profiles created by the Admin for the Customer's employees) must be secured with a password, whereby the Customer must immediately change the password originally provided to a secure password. The Customer must take all necessary steps to ensure the confidentiality of the password and must ensure that any employees to whom the access data is made available do the same. Each Customer is obliged to notify Sweap immediately at support@sweap.io if there are indications that its Account has been compromised by third parties who are not employees of the Customer or of a company affiliated with the Customer pursuant to Sections 15 et seq. of the German Stock Corporation Act (AktG) (“Third Parties”) are misusing the Account.
8. The Customer is not authorized to grant third parties access to an Account opened in his name or to make Sweap's services available to third parties, unless the parties have expressly agreed otherwise in writing in accordance with the law.
9. In the context of sending e-mails, Sweap is obliged to comply with the “Mailjet Acceptable Use Policy” (https://www.mailjet.de/sending-policy/) vis-à-vis the e-mail service provider used. The customer also undertakes to Sweap to comply with these guidelines. If these guidelines are not observed by the customer, the use of e-mail dispatch may be restricted. In some cases, this may lead to the temporary or permanent blocking of e-mail delivery.
10. The Customer may not circumvent technical or contractual usage restrictions applicable to the demo or other limited version, in particular by creating or using additional demo Accounts with different email addresses, domains, contacts or other registration data.

### 11. Warranty
1. The statutory provisions on warranty in rental agreements apply in principle. The provisions in Section 536b BGB (knowledge of the Tenant of the defect upon conclusion of the contract or acceptance) and in Section 536c BGB (defects occurring during the rental period; notification of defects by the Tenant) shall apply. However, the application of Section 536a (2) BGB (tenant's right to rectify defects himself) is excluded. The application of Section 536a (1) BGB (landlord's liability for damages) is also excluded, insofar as the standard provides for strict liability.
2. in all other respects, the provisions of service contract law (§§ 611 ff. BGB) shall apply.

### 12. Liability
1. Sweap shall not be liable for damage caused by or in connection with the performance of obligations under this agreement. A limitation of liability shall not apply to
	- Damage resulting from injury to life, body or health;
	- damages resulting from a breach of Sweap's obligations with regard to essential contractual rights and obligations that are indispensable for the proper performance of the agreement and which jeopardize the achievement of the purpose of the agreement (cardinal obligations), in which case liability shall be limited to typical and foreseeable damages;
	- damages resulting from an intentional or grossly negligent breach of duty by Sweap;
	- liability under the Product Liability Act;
	- liability in the event of the assumption of a guarantee;
	- the basis for claims under data protection law.
2. Sweap's exclusion and limitation of liability shall also apply to Sweap's legal representatives and vicarious agents.
3. Sweap is not liable for damage due to labor disputes and/or force majeure.

### 13. Customer data and exemption
1. As a technical service provider, Sweap stores content and data for the Customer, which the Customer enters and stores when using the Software and makes available for retrieval. The Customer undertakes vis-à-vis Sweap not to upload any content and data that is criminal or otherwise illegal in absolute terms or in relation to individual third parties and not to use any programs containing viruses or other malware in connection with the Software. In particular, the customer undertakes not to use the software to offer unlawful services or goods. The customer is the controller with regard to personal data of itself and its users/employees and must therefore always check whether the processing of such data via the use of the software is supported by the corresponding permissions or, if necessary, obtain the corresponding consent of the data subjects.
2. The Customer is solely responsible for all content and processed data used by it or its Users and for the legal positions required for this. Sweap takes no cognizance of the content of the Customer or its Users/employees and does not check the content used with the Software.
3. Sweap will receive data from the Customer in the context of the provision of the services in accordance with these GTC, as described in clause 5. This may include, among other things, e-mail addresses. Sweap is generally not in a position to check whether, in accordance with the planned use of the data pursuant to these GTC by Sweap itself or on behalf of the customer, the legal requirements, such as the express consent of the data subject or compliance with the consent procedure with regard to the sending of advertising (such as double opt-in), have been met and whether consent has been withdrawn. This is the sole responsibility of the customer.
4. The Customer and Sweap make it clear that no special personal data, i.e. information about racial and ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health or sex life, will be processed in the context of the provision of Sweap's services or use of the Software. The Customer undertakes to comply with this requirement and to inform Sweap immediately in the event of misuse.
5. In this context, the Customer undertakes to indemnify Sweap and/or Sweap's representatives, employees and agents against all liability and costs (including potential and actual losses, damages, expenses, costs, lawsuits, claims, legal proceedings, disputes, actions, obligations, claims and liabilities) in the event that Sweap is held personally liable by third parties and/or employees of the Customer as a result of alleged acts or omissions of the Customer and the Customer is responsible for the infringement. Sweap shall inform the Customer of the claim and, insofar as this is legally possible, give the Customer the opportunity to defend itself against the asserted claim. At the same time, the Customer shall provide Sweap with all available information that is necessary to verify the asserted claims and to defend against them. The Customer shall provide this information promptly, truthfully and completely. Customer undertakes not to agree to any settlement of claims without Sweap's prior written consent.
6. Sweap's right to claim further damages remains unaffected.

### 14. Contract term and termination; validity of acquired licenses; export option
1. The term of this contract shall commence on the start date
2. Individual licenses purchased for the Software shall be valid until an event is created within the Sweap Software, but for no longer than 12 months from the start date. After the creation of an event, after the expiry of the 12 months from the start date or when a termination of the associated account takes effect, the licenses acquired in each case lose their validity without the need for a separate termination.
3. Term licenses are purchased for a minimum period of 12 months from the start date. The contract is automatically extended by a further 12 months unless it is terminated by one of the contracting parties with a notice period of (1) month to the end of the contract.
4. Purchased term licenses for agencies are concluded for a period of 1 to 12 months from the start date, depending on the license variant selected.
	- The Sweap Agency License (M) is purchased from the start date for a minimum duration of 1 month. The contract shall be automatically extended by (1) further month, unless terminated by one of the contracting parties subject to a notice period of 2 weeks to the end of the month.
	- The Sweap Agency License (Y) is purchased for a minimum period of (12) months from the start date. The contract shall be automatically extended by (12) further months, unless it is terminated by one of the contracting parties with a notice period of (1) month to the end of the contract.
	The provisions of §14 (2) of this contract apply to individual licenses acquired as part of a term license for agencies.
5. The right of each party to extraordinary termination for good cause remains unaffected both for this contract and for purchased licenses for the software. Sweap shall be deemed to have good cause to terminate this Agreement in particular if
	- the Customer fails to meet its obligation to pay the remuneration referred to in clause 9 of this Agreement on two (2) consecutive dates, despite a reminder and the setting of a deadline;
	- insolvency proceedings have been instituted against the assets of a Contractual Partner or if such proceedings have been rejected for lack of assets.
	- the Customer breaches clause 9(1) sentence 2 or clause 10(10) and fails to remedy the breach within a reasonable period set by Sweap after notice. In such case, Sweap shall be entitled to temporarily suspend the affected demo Accounts until the matter has been clarified.
6. Termination must be in text form (email is sufficient) to be effective.
7. After termination of the Agreement, Sweap shall return to the Customer all documents and data carriers provided by the Customer and still in Sweap's possession that are related to the Agreement in accordance with these GTC, and delete the data stored by Sweap, unless there are retention periods or rights. However, in the event of ordinary termination, the Customer shall have the right to export the data and information stored within the Contract Software within 30 days of the effective date of termination, whereby the Customer may make a copy of the data and information stored on an external data storage device, which the Customer may then use solely for internal purposes.

### 15.Confidentiality
1. The parties are obliged to keep permanently secret, not to pass on to third parties, record or otherwise exploit all information about the other party that has become known or becomes known to them in connection with this agreement, which is marked as confidential or is recognizable as business and trade secrets (“confidential information”), unless the other party has expressly consented to the disclosure or exploitation in compliance with the statutory written form or the information must be disclosed by law, court decision or an administrative decision.
2. The information is not confidential information within the meaning of the provisions of this clause 15 if it
	- was already known to the other party without the information being subject to a confidentiality obligation;
	- is generally known or becomes known without breach of the confidentiality obligation assumed;
	- is disclosed to the other party by a third party without breach of a confidentiality obligation.
3. The obligations of the provisions of this clause 15 shall survive the termination of the contract in accordance with these GTC.

### 16. Assignment and transfer to third parties
The Customer may not transfer the rights and obligations arising from the Agreement under these Terms and Conditions to third parties without Sweap's prior written consent. Sweap is entitled to entrust third parties with the performance of the obligations under this Agreement.

### 17. Completeness and amendments to the Agreement
1. This agreement, together with the annexes, each of which shall be deemed an integral part of this agreement, constitutes the entire agreement between the parties.
2. Amendments and additions to this agreement must be made in writing to be effective. This also applies to the waiver of the written form requirement. Terms and conditions of the customer or third parties shall only become part of the contract if and insofar as Sweap has expressly agreed to their validity in writing.

### 18. Miscellaneous
1. The present contract shall be governed by German law to the exclusion of the UN Convention on Contracts for the International Sale of Goods
2. In the event that the customer, like Sweap, is a merchant within the meaning of §§ 1 et seq. HGB, the parties agree that Sweap's registered office shall be the exclusive place of jurisdiction for all disputes arising from and in connection with this agreement.
3. In the event that one or more provisions of this agreement are invalid, the parties shall agree on a replacement provision that comes as close as possible to the invalid provision.
4. The invalidity of one or more provisions of this agreement shall not affect the validity of the remaining provisions.
5. in the event of contradictions between these GTC and provisions from the annexes to these GTC, the provisions from the annexes shall take precedence over those from these GTC.

### Enclosure 1: Data processing agreement

Data processing agreement on behalf (DPA) pursuant to Art. 28 GDPR and § 62 BDSG

between

Customer according to “GTC”
(“Client”) and
MATE Development GmbH, Rankestraße 9, 10789 Berlin, Germany
(“Contractor”)

### Preamble

The Client has commissioned the Contractor with the implementation of digital guest management in accordance with the “General Terms and Conditions for Software of MATE Development GmbH” (“GTC”). Reference is made to the contents of the contract. The data referred to in **Annex 1** include those that are also the subject of the contract referred to. This Agreement sets out the obligations of the contracting parties under data protection law in the context of commissioned processing.

### § 1 Subject matter and duration of the contract (Art. 28 para. 3)

1. The Contractor undertakes to process the personal data specified in **Annex 1** on behalf of the Client for the purposes set out therein. The description of the respective order with information on the subject matter of the order, scope, type and purpose of data processing, type of personal data and categories of data subjects can be found in **Annex 1**.

2. This agreement begins on the start date of the assignment and ends upon termination of the contract concluded between the client and the contractor. The notice period for ordinary termination shall be governed by the underlying GTC. The right to terminate for good cause remains unaffected.

3. The Client may terminate the agreement at any time without notice if there is a serious breach by the Contractor of the provisions of the GDPR, the Federal Data Protection Act or the State Data Protection Act and other data protection regulations or this agreement, if the Contractor is unable or unwilling to carry out an instruction from the Client or if the Contractor refuses inspections by the Client or the State Data Protection Officer in breach of contract.

### § 2 Scope, type and purpose of data processing (Art. 28 para. 3)

1. The Contractor shall process the personal data pursuant to § 1 (1) exclusively within the scope of the order pursuant to § 1 and in accordance with the Client's instructions. This shall not apply if the Contractor is obliged to process the data by the law of the EU or the Member States to which the Contractor is subject. In this case, the Contractor shall notify these legal requirements prior to processing, unless notification is prohibited by the law in question due to an important public interest. The contractor shall not use the data provided for data processing for any other purposes. Copies or duplicates shall not be made without the knowledge of the client.

2. Within this order, the contractor shall carry out all measures technically necessary to ensure the purpose of the contract as well as the security and/or processing of the data (e.g. duplication of stocks for loss protection, creation of log files, etc.), insofar as this processing does not lead to changes in the content of the data and is necessary for the fulfillment of the order.

3. The processing of the data, including by subcontractors, takes place primarily in the territory of the Federal Republic of Germany, otherwise in member states of the European Union or in another state party to the Agreement on the European Economic Area. Any subsequent transfer to a third country requires prior consent.

### § 3 Technical and organizational measures/security of processing (Art. 28 para. 1, para. 3 c, Art. 32 - 36)

1. The Contractor shall take the technical and organizational measures specified in **Annex 2** to this Agreement (pursuant to Art. 32 GDPR) for the processing of personal data within the scope of the order placed by the Client. The Contractor shall document the implementation of the technical and organizational measures set out and required prior to the award of the contract before the start of processing, in particular with regard to the specific execution of the contract, and submit them to the Client for review. The Contractor's technical and organizational measures are set out separately in Annex 2 to this agreement and form part of the contract.  The technical and organizational measures in accordance with Annex 2 to this Agreement have been reviewed by the Client and assessed as suitable to ensure an appropriate level of protection.

2. The Contractor shall ensure that a procedure is used to regularly review the effectiveness of the technical and organizational measures to ensure the security of the processing.

3. The contractor undertakes to adapt the technical and organizational measures to the state of the art, insofar as this is necessary and economically reasonable (Art. 32 GDPR). The state of the art, the implementation costs and the nature, scope and purposes of the processing as well as the different probability of occurrence and severity of the risk to the rights and freedoms of natural persons within the meaning of Art. 32 para. 1 GDPR must be taken into account. The contractor is permitted to implement alternative adequate measures. In doing so, the security level of the defined measures must not be undercut. Significant changes must be documented. The client must be informed of significant changes in advance; the changes must be recorded in writing and become part of the contract. The Contractor shall examine the Client's proposals and inform the Client of the result.

4. The contractor shall ensure the technical and organizational measures necessary for the proper execution of the work in cooperation with the subcontractors. The technical and organizational measures of the third parties commissioned by the Contractor must correspond to the state of the art.

### § 4 Rectification, restriction of processing and erasure of data, access to data (Art. 28 (1), (3g))

The Contractor shall only rectify, erase or restrict the processing of data processed on behalf of the Client on the basis of a provision in the GTC or in accordance with documented instructions from the Client. If a data subject contacts the Contractor directly for the purpose of rectification, restriction of processing or erasure of their data, the Contractor shall forward this request to the Client without delay. The same shall apply to requests for information.

### § 5 Controls and other obligations of the Contractor (Art. 28 para. 3 h, Art. 32 - 36)

1. The Contractor shall ensure compliance with the provisions of data protection law with regard to the contractual relationship. If the Contractor discovers any irregularities, it shall inform the Client without delay.

2. The Contractor undertakes to maintain confidentiality and any professional secrecy obligations (in particular those protected by § 203 StGB) when processing the Client's personal data and to provide evidence of this to the Client. It shall only use employees for the processing who are appropriately obligated and trained. In particular, it shall take due care to ensure that all persons entrusted by it with the processing or fulfillment of this contract are carefully selected, observe the statutory provisions on data protection and do not pass on to third parties or otherwise exploit the information obtained from the client's area without authorization.

3. The contractor has appointed a data protection officer. His contact details are listed below:

    Proliance GmbH / [www.proliance.ai](https://www.proliance.ai)
	Data Protection Officer
	Leopoldstr. 21
	80802 Munich
    Germany
	datenschutzbeauftragter@proliance.ai

4. The contractor undertakes to maintain a processing directory in accordance with Art. 30 para. 2 GDPR

5. The contractor undertakes to grant the state data protection officer responsible for the client and the employees employed by him access to the work premises and submits to control in accordance with the GDPR, the BDSG and the state data protection laws, if applicable, in his respective country.

6. The Contractor must immediately inform the Client of any inspections or measures taken by the supervisory authority pursuant to the GDPR, the BDSG, and the LDSG. This also applies if a competent authority is investigating the Contractor for violations.

7. If individuals whose rights are affected by the data processing carried out by the Contractor contact the Contractor, the Contractor must immediately refer these individuals to the Client. In view of the nature of the processing, the Contractor shall take appropriate technical and organizational measures to support the Client in fulfilling its obligation to respond to requests from data subjects pursuant to Articles 12 through 22 of the GDPR. The Contractor shall do everything in its power to ensure that the Client can fulfill the rights of data subjects, in particular the rights to notification, access, rectification, restriction of processing (blocking), erasure of data, the right to object, and the right to data portability, provided that the cooperation required to implement these rights is not impossible for the Contractor or the Client is already capable of implementing the data subjects’ rights on its own due to the design of the software provided.

8. The Contractor shall assist the Client in complying with the obligations regarding the security of personal data, data breach notification obligations, data protection impact assessments, and prior consultations set forth in Articles 32 through 36 of the GDPR. This includes, among other things:
	- ensuring an appropriate level of protection through technical and organizational measures that take into account the circumstances and purposes of the processing, as well as the estimated likelihood and severity of a potential breach resulting from security vulnerabilities, and that enable the immediate detection of relevant breach incidents;
	- the obligation to report personal data breaches to the Client without delay:
	- assisting the Client with its data protection impact assessment;
	- assisting the Client in the context of prior consultations with the supervisory authority.

### § 6 Subcontracting relationships (Art. 28 para. 2, para. 3 d, para. 4)

1. The Principal shall grant general authorization to engage or replace subcontractors. The Contractor shall inform the Client in writing or in text form (e.g. by e-mail) before involving or replacing subcontractors. The client may object to the change in writing or in text form (e.g. by e-mail) within 3 weeks of receiving the information from the contractor. If no objection is made within this period, the change shall be deemed approved.

2. The Contractor must contractually ensure that the provisions agreed in this contract also apply to subcontractors. The Contractor's contract with the subcontractor must be concluded in writing or in electronic format.

3. Subcontractors in third countries shall only be commissioned if the special requirements of Art. 44 et seq. GDPR are fulfilled.

4. The subcontractors listed in Annex 3 shall be deemed approved upon signing the contract

5. The contractor shall ensure that the client has the same rights of instruction and control vis-à-vis the subcontractor as vis-à-vis the contractor under this contract. If a subcontractor fails to comply with its data protection obligations, the Contractor shall be liable to the Client for compliance with the obligations of that subcontractor.

### § 7 Control rights of the Principal (Art. 28 para. 3 h)

1. The Client shall have the right to carry out inspections in consultation with the Contractor or to have them carried out by inspectors to be named in individual cases. It shall have the right to satisfy itself of the Contractor's compliance with this Agreement in its business operations by means of spot checks, which must generally be notified in good time. In doing so, the Client shall regularly verify compliance with the technical and organizational measures taken by the Contractor and the subcontractors and document the results. The client shall appoint persons responsible for this order control and name them to the contractor in advance. The Contractor must be informed immediately of any change of person.

2. The Contractor shall ensure that the Client can satisfy itself of the Contractor's compliance with its obligations under Art. 28 GDPR. To this end, the Contractor shall provide the Client with evidence of the implementation of the technical and organizational measures pursuant to Art. 32 GDPR upon request. Proof of the implementation of such measures, which do not only concern the specific order, can also be provided by submitting a current certificate or reports or report extracts from independent bodies (e.g. auditors, internal audit, data protection officer, IT security department, data protection auditors, quality auditors), by compliance with approved rules of conduct in accordance with Art. 40 GDPR or by certification in accordance with an approved certification procedure in accordance with Art. 42 GDPR.

3. If the contractor and/or the subcontractors commissioned by it have submitted to approved rules of conduct or have successfully completed an approved certification procedure, they are obliged to prove this to the client. Certificates must be updated. The Client must be informed of this.

### § 8 Notification of breaches (Art. 33 para. 2)

1. The Contractor shall notify the Client without delay of any breaches or suspected breaches of this Agreement or regulations relating to the protection of personal data. Data protection breaches shall be reported to the contact person of the controller (Section 9 (4)) in text form (by e-mail/fax). In addition, notification shall be made by telephone to ensure that the controller is aware of the breach

2. The contractor shall support the client in the investigation, damage limitation and rectification of the violations.

3. Should the personal data processed under this agreement at the Contractor be jeopardized by seizure or confiscation, by insolvency or composition proceedings or by other events or measures of third parties, the Contractor shall inform the Client thereof without delay. The Contractor shall also immediately inform all relevant bodies in this context that the Client is in control of the data.

4. Insofar as audits are carried out by the data protection supervisory authorities, the Contractor undertakes to inform the Client of the result insofar as it concerns the processing of personal data under this contract. The Contractor shall immediately remedy any deficiencies identified in the audit report and inform the Client thereof.

5. This § 8 shall apply accordingly to incidents in processes carried out by subcontractors.

### § 9 Authority of the Principal to issue instructions (Art. 28 para. 3g, p. 3)

1. The Contractor shall process the personal data only within the scope of the instructions issued by the Client. This does not apply if the Contractor is obliged to process the data by the law of the EU or the Member States to which the Contractor is subject. In this case, the contractor shall notify these legal requirements prior to processing, unless notification is prohibited by the law in question on grounds of important public interest (Art. 28 para. 3 sentence 2 lit. a GDPR).

2. If the contractor is of the opinion that an instruction of the client infringes the GDPR or other data protection provisions of the Union or the Member States, he must inform the client immediately. It shall be entitled to suspend the implementation of the corresponding instruction until it is confirmed or amended by the controller of the client.

3. The client's instructions shall generally be issued in text form. Verbal instructions shall be documented in writing. Irrespective of the form in which they are issued, both the Contractor and the Client shall document every instruction issued by the Client in text form. The instructions shall be kept for the period of validity of this contract and for three years thereafter.

4. The persons listed in Annex 4 shall be authorized to issue instructions on behalf of the Client. At the Contractor, Florian Kühne or Sven Frauen are responsible for accepting instructions. In the event of a change of contact person or a longer-term absence, the contractual partner must be informed immediately in writing of the successor or representative.

5. If the contractor identifies disruptions that necessitate a significant change in the procedure, the corresponding procedural change must be agreed with the client before it is implemented. It may not be carried out without the client's consent in text form.

6. If the client issues individual instructions regarding the handling of personal data that go beyond the contractually agreed scope of services in accordance with the GTC, e.g. changes to the technical and organizational measures, they shall be treated as an application for a change in services, whereby the contractor does not have to agree to these and the client may have to bear any separate costs incurred if these measures are implemented.

7. In the event of a change of contact person or a longer-term absence, the contractual partner must be informed immediately and in principle in writing or electronically of the successors or representatives. The instructions shall be retained for the period of validity and subsequently for three full calendar years.

### § 10 Deletion of data and return of data carriers (Art. 28 para. 3 g)

1. Immediately after completion of the contractual work or earlier at the request of the Client, but at the latest upon termination of the cooperation, the Contractor shall hand over to the Client all documents containing personal data, processing results and data files related to the contractual relationship that have come into its possession or, with the prior consent of the Client, destroy them in accordance with data protection regulations, generally within 30 days. This does not apply to backup copies, which are also automatically destroyed in accordance with data protection regulations 30 days after deletion of the data. Within these 30 days, the contractor must ensure that the data is stored in a manner that ensures confidentiality. The log of the deletion must be presented on request. A right of retention is excluded.

2. Documentation that serves as proof of proper data processing in accordance with the order shall be retained by the Contractor beyond the end of the contract in accordance with the retention periods applicable to the service concerned. It may hand these over to the Client at the end of the contract for its discharge.

### § 11 Final provisions

1. Should individual provisions of this agreement be or become invalid or contain a loophole, the remaining provisions shall remain unaffected. The parties undertake to replace the invalid provision with a legally permissible provision that comes closest to the economic purpose of the invalid provision or fills the gap.

2. Amendments and supplements must be made in writing. This also applies to the amendment of this written form clause.

3. Both parties undertake to maintain secrecy about all knowledge gained within the framework of the contractual relationship, in particular about the data that has become known, in compliance with trade and business secrecy. This obligation shall continue to apply after the end of the contractual relationship.

4. The defense of the right of retention within the meaning of § 273 BGB is excluded with regard to the data processed for the person responsible and the associated data carriers.

5. Should the personal data processed under this agreement at the contractor be jeopardized by seizure or confiscation, by insolvency or composition proceedings or by other events or measures of third parties, the contractor must inform the client immediately. The Contractor shall also immediately inform all relevant bodies in this context that the Client is in control of the data.

### § 12 Relationship to GTC

1. Insofar as no special provisions are contained in this contract, the provisions of the GTC shall apply.
2. In the event of contradictions between this contract and provisions from other agreements, in particular from the GTC, the provisions from this contract shall take precedence.

### Annex 1: Description of the processing activity

### 1. Object of the order:
Performance of the contractual relationship in accordance with the GTC

### 2. Scope, type (Art. 4 No. 2 GDPR) and purpose of data processing:

Implementation of digital guest management with the possibility of e-mail communication between the organizer and guests, to record online feedback via corresponding websites and to accredit guests at the event location in order to record their attendance. The data will also be processed for further evaluations to measure the success of guest management.

The data is also processed for the following purposes

- Transmission of the data of the data subjects by the client to the contractor
- Integration into the contractor's system/structure
- Evaluation by the contractor
- If applicable, integration into sub-websites of the Contractor

### 3. Type of data:

| No. | Name of the data |
|:--|:--|
| 1 | Surname, first name |
| 2 | E-mail address |
| 3 | Company |
| 4 | Position |
| 5 | Salutation (gender) |
| 6 | Title |
| 7 | Telephone number |
| 8 | Other data, the nature of which is determined by the client and which is loaded into the contractor's system by the client. |

No special personal data, i.e. data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health or sex life shall be collected, processed or used.

### 4. Circle of data subjects

| No. | Name of the data |
|:--|:--|
| 1 | Employees, trainees, freelancers and other employees of the client |
| 2 | Interested parties and customers of the client |
| 3 | Employees and/or customers of the client's business partners in the event of complaints by the business partners to the client |
| 4 | Other visitors/guests/contact persons of the client |

### Annex 2: Technical and organizational measures

In the context of order processing, MATE Development GmbH (hereinafter referred to as Sweap) undertakes to implement the technical and organizational measures in accordance with Art. 32 GDPR to the necessary and appropriate extent and in accordance with the generally recognized state of the art in its area of responsibility and in relation to the subject matter of the contract. The measures to be implemented by Sweap based on the purpose of the contract are essentially at least the following:

### 1. Access control

Measures that are suitable for preventing unauthorized persons from gaining access to data processing systems with which personal data is processed or used.

- Secured entrances
- Documentation and regulation of key allocation (allocation of security keys only to permanent employees)
- Door security with security locks
- Outsourced server: documentation of the hoster's security regulations, VPN connection between server and company network

### 2. Access and permission control

Measures that are suitable for preventing unauthorized persons from using data processing systems and for ensuring that authorized persons only work on the data processing system within the scope of their authorization.

- Creation of user profiles
- Authentication with individual user name and individual password
- Documentation of authorizations
- Password policy (16 characters consisting of upper and lower case letters, numbers and special characters for all systems with high security requirements, e.g. access to customer data or sweap infrastructure)
- Automatic screen lock after 5 minutes of inactivity
- Visitors are only admitted by employees and may only enter the offices when accompanied by an employee
- Authorization concept (authorizations according to the “need-to-know” and “need-to-do” principle)
- SSL encryption
- Anti-virus program
- firewall
- Encryption of data carriers (hard disks) in laptops
- Use of two-factor authentication for other systems (where possible)

### 3. Input control

Measures that ensure that it can be subsequently verified and established whether and by whom personal data has been entered into, modified or removed from data processing systems.

- Logging of the input, modification and deletion of data
- Logging of user activities
- Logging of IT systems (anti-virus, software firewall)
- Regular checking of the logs
- Deletion of the logs once the purpose has been achieved

### 4. Order control

Measures to ensure that personal data processed on behalf of the client can only be processed in accordance with the client's instructions.

- Conclusion of legally compliant order processing contracts in accordance with Art. 28 GDPR with clients and contractors
- Contractually defined responsibilities (authorized person and recipient of instructions)
- Ensuring that the client's personal data is only processed on behalf of the client in accordance with the instructions
- Ensuring the destruction of data after completion of the order
- Regular monitoring of the TOM of the processor

### 5. Data separation control

Measures to ensure that data collected for different purposes can be processed separately.

- At least logical, ideally physical separation according to the purpose of the order
- Separation of the production and test systems by using separate servers and/or server clusters in the ISP's data center
- No use of live systems for test purposes
- Compliance with deletion deadlines

### 6. Disclosure control

Measures to ensure that personal data cannot be read, copied, altered or removed without authorization during electronic transmission or during its transport or storage on data carriers, and that it is possible to check and determine to which bodies personal data is intended to be transmitted by data transmission devices.

- WLAN access secured with WPA2
- Encryption on mobile devices via AES-256+SHA2 with a 64-byte encryption key
- Use of VPN with password
- Proper document destruction (use of document shredders with security level P-4 or service providers)
- Proper data carrier destruction (use of shredders with security level H-4 or service providers; deletion of data: Overwrite the entire data carrier; for SSDs: encrypt from the start and overwrite as for other data carriers)

### 7. Data protection through technology design and data protection-friendly default settings

Privacy by design means “data protection through technology design”. The aim is to ensure that suitable technical measures are already implemented during the development of processing operations in order to ensure that the planned processing operations comply with data protection regulations.

- Sweap's guest management platform requires as little data as possible for an event (variable attributes)
- Events can also be held completely anonymously
- Software includes data protection-friendly default settings (e.g. no tracking of the opening rate for emails, no tracking software for guest data registrations)

### 8. Availability and resilience (Art. 32 para. 1 lit. b GDPR)

Measures to ensure that personal data is protected against accidental destruction or loss

- Regular implementation of updates of the anti-virus program
- Separate, redundant backup system secured by UPS systems
- Regular testing of data recovery from backups
- Monitoring of system utilization
- Regular random success checks by restoring the data

### 9. Organizational control

These are measures that ensure that employees are informed about and made aware of data protection requirements and that they are obliged to comply with data protection. In addition, organizational control includes overarching concepts in which the company management defines how it intends to handle data protection in the company.

- Verifiable commitment of all employees to confidentiality (data secrecy) and, where applicable, to telecommunications secrecy and the protection of professional secrets
- Corporate concepts for data protection and data security
- Employee training on data protection and data security
- IT emergency plan, the functionality of which is regularly tested and documented.
- Home office policy
- Regulation on the use of business e-mail and Internet access in the employment contract
- Documentation of the IT systems used and their system configuration
- Permanent and practiced reminder for all employees on how to deal with data protection-critical content

### 10. Effectiveness check

All actions that lead to proof that the measures used are regularly checked and actually work.

- Regular monitoring of the technical and organizational measures implemented
- Regular monitoring of the authorizations granted to employees
- Regular monitoring of the functionality of anti-virus systems and firewalls

### Annex 3: Subcontractors

The contractually agreed services or the partial services described below will be carried out with the involvement of the following subcontractors:

### Hosting
1. **IBM Deutschland GmbH (Platform-as-a-Service Provider/Hosting):**
	- IBM-Allee 1, 71139 Ehningen, Germany
	- Data centre locations: Frankfurt (Germany)

2. **Hetzner Online GmbH (DNS and domain hosting):**
	- Industriestr. 25, 91710 Gunzenhausen, Germany
	- Data centre locations: Nuremberg, Falkenstein (Germany)

3. **hosting.de GmbH (DNS and domain hosting):**
	- Franzstr. 51, 52064 Aachen, Germany
	- Data centre locations: Aachen, Cologne, Nuremberg (Germany)

### Cloud solution

1. **Mailjet GmbH (e-mail service provider):**
	- Alt-Moabit 2, 10557 Berlin, Germany
	- Data centre locations: Frankfurt (Germany), Saint-Ghislain (Belgium)

### Annex 4: Authorised persons of the client

| No. | Name of person authorised to issue instructions |
| :--- | :--- |
| 1 | Management |
| 2 | The data protection officer(s) appointed by the client |

