Data Processing Agreement (DPA)

Language notice. This is an English translation of the MeterGate Data Processing Agreement provided for convenience. The German version is the sole legally authoritative text. In case of any discrepancy between the two versions, the German version prevails. The German version is available at /avv.

This page contains two data processing agreements: Part A — MeterGate ⇄ Customer (Buyer) and Part B — MeterGate ⇄ Provider (Seller). Authoritative language: German.

Part A — Data Processing Agreement (DPA): MeterGate ⇄ Customer (Buyer)

Version v2 · authoritative language: German

Preamble. This agreement governs the processing of personal data which the Customer causes to be routed through the MeterGate gateway to the Providers subscribed by it. It forms part of the usage relationship between MeterGate (Jan Ebert, sole proprietorship, Hamburg — hereinafter “MeterGate”) and the Customer and is concluded electronically upon the first Subscription. The Customer is an entrepreneur (B2B). The acceptance is recorded as a data record (subprocessor_authorization, Version v2).

§ 1 Roles and scope. MeterGate has two separate roles. (1) For account, billing and usage metadata (e-mail address, company, VAT identification number, means of payment, invoices, call counters), MeterGate is its own controller; this is governed by the privacy policy and is not the subject matter of this agreement. (2) For the request data sent by the Customer which the gateway routes to the Provider selected by the Customer (query parameters, request body, headers of an API call, as well as the response returned), MeterGate is the processor, the Customer the controller and the respective Provider a sub-processor. This agreement governs only this routing (Durchleitung).

§ 2 Subject matter, nature, purpose, duration (Art. 28 (3) sentence 1 GDPR). The subject matter is the receipt and technical routing (“proxying”) of the request data to the subscribed API and the return of the response. Nature of the processing: collection, brief processing in main memory, forwarding. The content of the request and response data is not stored permanently. Only metadata per call are persisted (price in cents, point in time, HTTP status code, latency, allocation of Buyer/Provider/key) for billing, credit limit and evidence — no payload content. The purpose is the performance of the contract concluded between the Customer and MeterGate on the use of the API service, which MeterGate distributes in its own name for the account of the Provider. Duration: for the term of the usage relationship. The nature of the data and the categories of data subjects are determined solely by the Customer; it ensures that it sends only data for whose transmission to the selected Provider it has a legal basis.

§ 3 Bound by instructions (Art. 28 (3) (a), Art. 29). MeterGate processes the request data exclusively on documented instructions from the Customer. The instruction is technically determined: the active Subscription and the individual call directed at the callUrl are the instruction to route exactly these data to exactly this Provider. MeterGate processes the request data for no purpose of its own and passes them on to no one other than the Provider selected by the Customer, subject to statutory obligations of which MeterGate informs the Customer insofar as legally permissible. If MeterGate considers an instruction to be unlawful, it informs the Customer.

§ 4 Confidentiality (Art. 28 (3) (b), Art. 29). MeterGate is operated as a sole proprietorship; access to the systems is held solely by the operator, who is obliged to maintain confidentiality. If further persons or service providers with access are engaged in future, they will be obliged in writing to maintain confidentiality and to comply with instructions before access is granted.

§ 5 Technical and organisational measures (Art. 28 (3) (c), Art. 32). The measures set out in Annex 1 apply. MeterGate may develop them further as long as the level of protection is not fallen short of.

§ 6 Sub-processors — the Providers (Art. 28 (2) and (4)). Every Provider subscribed by the Customer receives the routed request data and is a sub-processor to that extent. MeterGate contractually obliges every Provider to the same data protection obligations as in this agreement (back-to-back, Art. 28 (4); see Part B) and admits as Providers only undertakings that give assurances as to their own technical and organisational measures; the Provider's use of the request data is limited to the performance of the call retrieved, and processing for its own purposes is prohibited to it. The Customer authorises the engagement of the respective Provider as a sub-processor upon conclusion of the Subscription (Art. 28 (2) sentence 1); the list of authorised sub-processors, current at any time, is the set of its active Subscriptions, viewable in the customer account. Upon request, MeterGate makes available to the Customer information on the entire chain of sub-processors (identity, purpose and data residency, including those of the further processors engaged by the respective Provider), so that the Customer can review their suitability and control the safeguards for any onward transfers (European Data Protection Board, Opinion 22/2024). Two routes of authorisation, both with prior control by the Customer:

If a Provider fails to comply with its data protection obligations, MeterGate is liable to the Customer for compliance with those obligations as for its own conduct (Art. 28 (4) sentence 2).

§ 7 Support of the Customer (Art. 28 (3) (e) and (f)). MeterGate supports the Customer within the scope of what is technically possible: in the case of data subject rights (Art. 12–23) to a limited extent, since MeterGate does not permanently store any request content — access and erasure of the payload content lie with the Customer and with the respective Provider; in the case of notification obligations (Art. 33/34) by giving notice of relevant security incidents of its own without undue delay; in the case of data protection impact assessments (Art. 35/36) by providing the necessary information (this agreement, the measures set out in Annex 1, the description of the routing model).

§ 8 Erasure and retention (Art. 28 (3) (g)). Since MeterGate does not permanently store the contents of the request/response data, there is no return or erasure in that respect. The metadata are erased as soon as their purpose ceases to apply; metadata relevant to billing and taxation are retained for the duration of the statutory retention periods — accounting documents including invoices for eight years (§ 147 (1) no. 4 AO (German Fiscal Code), in the version applicable since 2025 pursuant to the Fourth Bureaucracy Relief Act (Viertes Bürokratieentlastungsgesetz); correspondingly § 14b UStG (German Value Added Tax Act)), commercial books and financial statements for ten years — and are erased thereafter.

§ 9 Evidence and audits (Art. 28 (3) (h)). MeterGate makes available to the Customer the information necessary to demonstrate compliance (this agreement, Annex 1, description of the model) and allows for audits after prior notice of at least 30 days, during business hours, at most once a year without particular cause; the costs are borne by the Customer unless the audit establishes a material breach on the part of MeterGate. The rights of other customers and of third parties remain safeguarded. Audits for cause in the event of specific suspicion remain unaffected.

§ 10 International transfers (Chapter V GDPR). MeterGate operates its infrastructure in the EU. The Customer selects the Provider and thereby determines the recipient of the request data. If a selected Provider or one of its sub-sub-processors is established outside the EU/the EEA, the transfer takes place only on a basis under Chapter V, as a rule the EU standard contractual clauses together with a transfer impact assessment. MeterGate states the data residency per Provider in the catalogue and provides the Customer with an EU-only filter with which it can exclude third-country transfers.

§ 11 Version. This version is v2. Changes are made by issuing a new version and take effect like amendments to the Terms (§ 14 of the Terms): on the first day of a calendar quarter, after notification in text form at least 30 days in advance; if the Customer does not object by the day on which the change takes effect, consent is deemed given, and until then the Customer may object or terminate. For the engagement or replacement of a sub-processor, the notification is at the same time the information under Art. 28(2) sentence 2 GDPR and the objection is at the same time the objection under that provision; it has the consequence of § 14 (3) of the Terms. Existing acceptances retain their version and document what the Customer has accepted; deemed consent also suffices for the continued use of the automatic authorisation.

§ 12 Applicable law, place of jurisdiction, precedence. German law applies. The place of jurisdiction is, insofar as legally permissible, Hamburg. In the event of contradictions between this agreement and the other terms of use, the provisions of this agreement take precedence for the processing of personal data.

Annex 1 — Technical and organisational measures (Art. 32). Transport/transmission security: TLS for all connections; outgoing calls via an SSRF-hardened proxy (single DNS resolution, IP pinning, blocking of private, loopback, link-local, CGNAT and multicast ranges for IPv4 and IPv6, renewed check on redirects, timeout, size limit, content-type blocklist). System access and data access control: passwords with bcrypt; session hardening (httpOnly, sameSite, secure in production, server-side session store, rotation of the session ID upon login and registration); API keys stored only as a bcrypt hash, plaintext displayed only once; ownership checks throughout; separate administration role. Application security: Content Security Policy with a per-request nonce; CSRF protection on all forms; security headers; rate limits on authentication and gateway endpoints; body size limit; generic error handler without stack trace disclosure; enforced, sufficiently long session secret. Data minimisation and purpose limitation: no permanent storage of request/response contents, only billing metadata; no content logging in the routing path. Availability and recoverability: health/readiness endpoints; reconciliation and clean-up jobs for consistent billing; regular database backups. Separation control: tenant separation via the ownership relation per data record; Providers receive only the request data addressed to them.

Annex 2 — Sub-processors. For the routed request data: the Providers subscribed by the Customer (dynamic; current list = the Customer's active Subscriptions) as well as the hosting service provider Hetzner Online GmbH, Gunzenhausen, Germany (operation of the gateway in the EU). Not the subject matter of this agreement (account/billing sphere, MeterGate = controller, see privacy policy): the payment service provider Stripe and the e-mail service mailbox.org.

Part B — Data Processing Agreement (DPA): MeterGate ⇄ Provider (Seller), back-to-back

Version v5 · authoritative language: German · legal basis: Art. 28 (4) GDPR

Preamble. This agreement imposes on every Provider, as a sub-processor, the same data protection obligations as Part A does between MeterGate and the Customer. The chain reads: Customer = controller → MeterGate = processor → Provider = sub-processor. The agreement is concluded electronically upon the Provider onboarding; creating and editing products — including their public activation — requires acceptance of the current version (§ 12; recorded as seller_terms, Version v5).

§ 1 Scope. The subject matter is exclusively the Customer's request data which MeterGate routes to the Provider, as well as the response data. Not the subject matter are the Provider's master, account and billing data vis-à-vis MeterGate, nor data from the Provider's own business relationships outside MeterGate. This agreement governs data protection alone and does not prejudge any classification under tax or supervisory law. The Provider is an entrepreneur (access only for BUSINESS accounts).

§ 2 Subject matter, nature, purpose, duration (Art. 28 (3) sentence 1). The subject matter is the receipt of the request data routed via MeterGate, their processing in order to generate the API response, and the return. Nature of the processing, depending on the Provider's service: receiving, evaluating, computing or generating the response, as well as — insofar as technically necessary for the provision of the service — short-term or time-limited storage. Unlike MeterGate, the Provider is able to store the contents of the request data; it is therefore subject to the content-related obligations of §§ 7 and 8 in full. The purpose is exclusively the performance of the specific call retrieved. Duration: for the term of the respective Subscription, subject to the erasure obligations. The nature of the data and the categories of data subjects are determined solely by the Customer.

§ 3 Bound by instructions and purpose limitation (Art. 28 (3) (a), (10); Art. 29). The Provider processes the routed data exclusively in order to perform the specific call; the instruction is the call passed through via MeterGate. The Provider is prohibited from processing for its own purposes, in particular: the training, fine-tuning or improvement of its own or third-party models (AI/ML) with the request or response data; profiling, analysis, enrichment or aggregation beyond the individual call; disclosure, sale or transfer to third parties outside the contractually bound sub-sub-processors engaged for the performance of the call; and any combination with other data holdings of the Provider for its own purposes. If the Provider processes the data in breach of this for its own, self-determined purposes, it is to that extent deemed to be a controller (Art. 28 (10)) and is directly liable for this itself. If the Provider considers an instruction to be unlawful, it notifies MeterGate without undue delay. If the Provider renders its service by means of an AI system, it is the provider or deployer of that system within the meaning of Regulation (EU) 2024/1689 (AI Act) and bears the obligations set out therein itself, including the transparency obligations under Art. 50 applicable from 2 August 2026; MeterGate is not the provider of the AI system.

§ 4 Confidentiality (Art. 28 (3) (b), Art. 29). The Provider ensures that all persons authorised to process the data are committed to confidentiality or are under an appropriate statutory obligation of confidentiality and process the data only in accordance with instructions.

§ 5 Technical and organisational measures (Art. 28 (3) (c), Art. 32). The Provider takes the measures necessary for security pursuant to Art. 32 and gives assurances as to compliance with them; the minimum catalogue follows from Annex 1. It keeps the measures up to date with the state of the art.

§ 6 Further sub-processors of the Provider (Art. 28 (2) and (4)). If the Provider engages further processors of its own (e.g. cloud, hosting or AI infrastructure), it names them in Annex 2 and keeps that annex up to date. MeterGate grants general authorisation for them, provided that the Provider binds them by contract to the same data protection obligations as this agreement imposes on it (Art. 28 (4)) and provided that they are established in the EU/the EEA or a basis under Chapter V exists (§ 10). The Provider remains responsible to MeterGate for their compliance as for its own conduct and notifies intended changes in advance.

§ 7 Support of the Customer (Art. 28 (3) (e) and (f)). Because the Provider is able to process and store the contents, these obligations apply to it in full. It supports the Customer — via MeterGate — with appropriate measures in the case of data subject rights (Art. 12–23), insofar as they concern the request/response content processed at the Provider; it reports a personal data breach affecting the routed data to MeterGate without undue delay, with the information referred to in Art. 33 (3); it provides the information necessary for a data protection impact assessment (Art. 35/36).

§ 8 Erasure and return (Art. 28 (3) (g)). Upon completion of the provision of the service, at the latest upon termination of the respective Customer's Subscription, the Provider erases the routed request and response data or returns them at the Customer's option, including any copies in existence, unless a statutory retention obligation stands in the way. If the Provider processes the data only transiently without storage, this fulfils the obligation; it gives verifiable assurances of erasure upon request.

§ 9 Evidence and audits (Art. 28 (3) (h)). The Provider makes available to MeterGate — for onward transmission to the Customer — the information necessary to demonstrate compliance (description of measures, list of sub-sub-processors, data residency) and allows for audits after reasonable prior notice, insofar as they do not disproportionately impair operations and safeguard the rights of third parties. Audits for cause in the event of specific suspicion remain unaffected.

§ 10 International transfers (Chapter V GDPR). The Provider states its data residency and that of its sub-sub-processors truthfully; MeterGate states it in the catalogue. If the Provider or one of its sub-sub-processors is established outside the EU/the EEA, it processes the routed data only on a basis under Chapter V (as a rule EU standard contractual clauses together with a transfer impact assessment). The Provider supports the Customer's EU-only option by making accurate residency statements and reporting changes without undue delay.

§ 11 Liability and indemnification (Art. 28 (4) sentence 2, Art. 82). In relation to the Customer, MeterGate remains responsible for compliance by the Provider; in the internal relationship, the Provider is liable to MeterGate for compliance with this agreement. If the Provider breaches its obligations and MeterGate is held liable on that account by a customer, a data subject or a supervisory authority (including claims under Art. 82 and administrative fines under Art. 83), the Provider indemnifies MeterGate to the extent of its share of causation and fault (Art. 82 (4) and (5)). The mandatory liability under Art. 28/82 cannot be contracted out.

§ 12 Version. This version is v5; it applies from its publication. It is maintained together with the platform framework agreement, in which the Providers' obligations appear in § 7 and § 9a; it therefore does not run in sync with Part A — Part A carries a version number of its own (§ 11 of Part A) and is maintained independently. A new version takes effect under § 14 of the platform framework agreement: on the first day of a calendar quarter, after notification in text form at least 30 days in advance; if the Provider does not object by the day on which it takes effect, consent is deemed given; if the Provider objects, § 14 (3) of the framework agreement applies. Where an amendment takes effect only with express consent (§ 14 (4) of the framework agreement), the version last accepted by the Provider continues to apply between the parties until then; products already publicly activated remain public. Creating and editing products and linking the payout account require acceptance of the current version; deemed consent suffices. The continued application of the version last accepted concerns this Part B alone; amendments to the platform framework agreement are governed by its § 14.

§ 13 Applicable law, place of jurisdiction, precedence. German law applies. The place of jurisdiction is, insofar as legally permissible, Hamburg. In the event of contradictions between this agreement and the other provider terms, the provisions of this agreement take precedence for the processing of personal data.

Annex 1 — Minimum measures of the Provider (Art. 32). TLS for all connections over which routed data flow; access only for authorised persons committed to confidentiality, on a need-to-know basis; technical and organisational assurance of purpose limitation (§ 3), in particular no inclusion of the data in training or analysis pipelines; either no permanent storage of the contents or a documented, time-bound erasure routine that satisfies § 8, with verifiable erasure upon request; appropriate measures against unauthorised alteration and loss, as well as logging of security-relevant access to the extent necessary; a defined process for reporting personal data breaches to MeterGate without undue delay.

Annex 2 — Sub-sub-processors of the Provider. To be named by the Provider (name, purpose, data residency). As long as none are named, the Provider gives assurances that it engages no further processors for the routed data.