GDPR Art. 28 · Standard contract

Data Processing Agreement

Version: 2026-06-25 · Print / Save as PDF
In short: If you use Now2Wallet to issue wallet passes for tickets of your customers (the ticket holders), GDPR Art. 28 requires a Data Processing Agreement between you (the controller) and us (the processor). This page is our standard agreement. It takes effect when you accept it during sign-up; a signed PDF copy is available on request at info@now2wallet.com.

§ 1 Subject and duration

(1) The subject of this agreement is the processing of personal data by the processor (Odenwald IT Service UG, hereinafter “Processor”) on behalf of the controller (the merchant using Now2Wallet, hereinafter “Controller”) within the Now2Wallet service.

(2) The term of this agreement corresponds to the term of the main contract (Now2Wallet subscription). It ends automatically when the main contract ends.

§ 2 Nature and purpose of the processing

(1) The Processor processes personal data on behalf of the Controller solely for the purpose of providing the Now2Wallet service:

(2) Processing for any other purpose (e.g. profiling, advertising, sale to third parties) does not take place.

§ 3 Type of personal data and categories of data subjects

(1) The following categories of data are processed:

(2) Not processed are: the full contents of the Controller’s WooCommerce database (articles, payment data, customer passwords), or FTP / SSH / database credentials. Communication takes place exclusively via the Now2Wallet plugin over a signed HTTPS API.

(3) Categories of data subjects: the Controller and its staff (account users) as well as the ticket holders whose passes are generated.

§ 4 Obligations of the Processor

The Processor undertakes to:

§ 5 Sub-processors

(1) The Processor is entitled to engage the following sub-processors:

ProviderPurposeLocation
Mittwald CM Service GmbH & Co. KGHosting of the Now2Wallet platformEspelkamp, Germany
Apple Inc.Apple Wallet pass deliveryUSA (EU SCC)
Google Ireland Ltd.Google Wallet pass deliveryIreland, EU
PayPal (Europe) S.à r.l. et Cie, S.C.A.Payment processing (billing)Luxembourg

(2) The Controller consents to the engagement of these sub-processors. Changes are announced at least 30 days in advance; the Controller has a right to object.

§ 6 Rights of data subjects

(1) Insofar as the Controller is legally obliged to do so, the Processor supports the Controller in fulfilling data-subject rights (access, rectification, erasure, portability, objection).

(2) The Processor forwards any such requests received directly to the Controller without undue delay.

§ 7 Technical and organisational measures (TOMs)

The Processor implements the following measures pursuant to Art. 32 GDPR:

Confidentiality

Integrity

Availability & resilience

§ 8 Deletion and return

After the end of the engagement, the Processor deletes or returns all personal data processed on behalf of the Controller, unless statutory retention obligations require further storage.

Draft note: This standard agreement is provided as a template and should be reviewed by your legal counsel before commercial use. A countersigned PDF version is available on request.