Data processing agreement
Last updated: 7 Oct 2026
This agreement governs how we process personal data on behalf of business customers (Art. 28 GDPR). It is between the business customer as controller ("customer") and Glockner Holding UG (haftungsbeschränkt), Julius-Hatry-Straße 1, 68163 Mannheim, Germany, as processor ("we").
1. Scope
- This agreement applies where we process personal data on behalf of a customer who uses Fiveover for their business under our terms. It becomes part of the contract of use once the customer switches on "Business use" in the app and accepts it, or indicates at checkout that they are buying as a business. We'll send a signed copy on request.
- Where this agreement and the terms conflict on data protection, this agreement prevails.
2. Subject matter and duration
The subject matter is providing Fiveover: writing reports with AI from what is said, typed and photographed, signing them electronically, sealing them as a PDF, delivering them to the people involved, keeping them and making them verifiable. The agreement runs for as long as the customer uses Fiveover for their business, and after that until we have deleted or returned the data under section 11.
3. Nature and purpose of processing
We store and organise the data, have speech turned into text, have the AI write the report's text and facts from it and from what is typed, read photos and list what's missing, keep what was said until 48 hours after the report is finished, transmit the report to the other side when the customer gives it to them to sign, create and seal the PDF, send emails, keep the data and delete it. The purpose is to provide these services to the customer and, as far as section 13 allows, to learn from reports.
4. Types of personal data
Names, email addresses (the other side's only if given) and roles of the people involved; details of what the report is about, such as the address of a flat, a job, number plates, serial numbers and meter readings; the text of the sections and the facts in their fields, such as hours worked or, after an accident, the insurer and policy number; what was said and typed, as text with voice labels; photos, which may show people; the other side's remark; the customer's own forms with their fixed text and, if the customer uploads a form that's already filled in, what it contains (the file goes to the AI provider to be read and isn't stored); signatures (drawn or typed), whether and when an email address was confirmed, and the history of who wrote, changed and signed what and when. Special categories of personal data (Art. 9 GDPR) are not intended, except injuries an accident report may describe; the customer only records them where entitled to.
5. Data subjects
The customer's staff and agents; the other side of a report, such as the customer's tenants, owners or clients; people named in a report, such as witnesses; people speaking nearby while someone talks to write a report; people shown in photos.
6. Instructions
- We process the data only on documented instructions from the customer, including for transfers to a third country, unless EU or member state law requires us to; we then tell the customer about that requirement beforehand unless the law prohibits it (Art. 28(3)(a) GDPR).
- The customer's instructions are this agreement, the terms and the use of Fiveover's features. The customer gives further instructions in text form to privacy@fiveover.app.
- If we think an instruction infringes data protection law, we tell the customer without delay and may suspend it until the customer confirms or changes it.
7. Confidentiality
Everyone at our company with access to the data is bound to confidentiality or under a statutory duty of confidentiality.
8. Security
We take the technical and organisational measures in Annex 1 (Art. 32 GDPR). We may improve them as long as the level of protection doesn't drop.
9. Sub-processors
- The customer gives general authorisation for the sub-processors listed in Annex 2.
- Before a new sub-processor receives the customer's data or one is replaced, we tell the customer at least 30 days in advance by email and on the page in Annex 2. Within that period, the customer may object for good cause relating to data protection. If we can't find a solution, the customer may terminate the contract of use before the change.
- We bind every sub-processor by contract to the obligations of this agreement (Art. 28(4) GDPR) and are liable for them as for ourselves.
10. Assisting the customer
- Data subjects' rights: the customer sees the data of their reports in the app. We carry out access, copies, rectification, restriction and erasure beyond that on the customer's request. If data subjects contact us about something that clearly concerns the customer, we forward it to the customer.
- Personal data breaches: we notify the customer without undue delay and at the latest 48 hours after becoming aware of one, with the information under Art. 33(3) GDPR as far as we have it, and add to it as we learn more.
- Other obligations: we assist the customer with security, notifications, data protection impact assessments and prior consultation (Art. 32 to 36 GDPR) with the information available to us.
11. Return and deletion
- When business use ends, we give the customer their data on request, as described under "Data export and switching" in the terms (JSON and PDF, provided within 30 days and available for at least 30 days). We then delete it unless EU or member state law requires us to keep it. Database backups are overwritten after 35 days.
- Without a request, we delete the data after the periods in our privacy policy, sealed records 3 years after sealing.
- A sealed record belongs to both sides. If the other side of a report uses Fiveover with their own access, they keep that access to the shared record under their own contract with us until the end of the retention period; a deletion instruction from the customer doesn't extend to it.
12. Evidence and audits
- We give the customer the information needed to demonstrate compliance with this agreement and answer questions about it in text form.
- If that isn't enough, the customer or an auditor they appoint who is bound to confidentiality may audit us, with at least 30 days' notice, during business hours, without disrupting operations, and at most once a year unless a personal data breach or a supervisory authority gives reason. The customer bears the cost of an audit unless it reveals a material breach by us.
- For our sub-processors, their current audit reports and certificates are sufficient.
13. Learning from reports
- The customer allows us to use its reports, after removing what identifies people, to improve Fiveover, train AI models and develop new forms, as our privacy policy describes. We are responsible for this ourselves.
- This applies to reports started after this version was accepted, while "Let Fiveover learn from my reports" is on.
- We don't publish or sell this data. The customer informs the people in its reports about it; it can refer to our privacy policy.
- Otherwise, we don't use the customer's data for our own purposes. We process data about the account itself, purchases, the security of Fiveover and usage statistics without content as a controller in our own right under our privacy policy.
14. Processing outside the EU
We store the data in the EU (Frankfurt, Germany). Sub-processors only process data outside the EU and EEA where there is an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework, or the European Commission's standard contractual clauses apply (module 3, Art. 46(2)(c) GDPR). If the customer is established outside the EU and EEA, the standard contractual clauses in module 4 apply to transfers to the customer where required.
15. Liability and final provisions
- Liability is governed by the terms; Art. 82 GDPR remains unaffected.
- This agreement ends when business use ends; the obligations under section 11 continue until they are fulfilled.
- The law and courts in the terms apply. Changes must be made in text form. If a provision is invalid, the rest of the agreement remains valid.
Annex 1: Technical and organisational measures
Confidentiality
- We run no servers of our own. Our sub-processors provide the data centres and their physical security under their certifications (such as ISO/IEC 27001 or SOC 2).
- Fiveover has no passwords: people sign in with a one-time code sent to their email address, and Cloudflare Turnstile keeps bots out.
- Row level security in the database limits every account to the reports it takes part in; only the person writing a report reads what was said. Only the server changes payments, signatures, status and checksums.
- Only the managing director has access to the production systems.
- Invite links, sign-in codes and verification codes are stored only as a checksum (SHA-256).
- The app removes location and other metadata from photos before uploading them.
- Customers' data is logically separated; row level security separates access.
Integrity
- Data is only transmitted encrypted (TLS, HSTS) and stored encrypted.
- Every change to a report goes into a history that can't be altered unnoticed; signatures and evidence are only ever added.
- A sealed PDF (PDF/A-2b) carries a checksum of the confirmed content and an RFC 3161 timestamp; any later change shows when it is verified.
Availability and resilience
- Database backups, deleted after 35 days; restoring them is documented.
- The app keeps what was typed, photos and speech recorded without a signal on the device until the server has accepted them.
- Caps and counters against abuse and overload.
Data protection by design
- Reports contain no IP addresses or device identifiers; error reports are stored without IP addresses.
- AI: on our instruction, OpenAI stores nothing for us and doesn't train on the data; OpenAI keeps requests for up to 30 days to detect abuse. OpenAI may keep the unchanged beginning of requests about one report in memory for a few minutes to reuse it (prompt caching, default retention, not extended). The AI doesn't overwrite text a person changed without asking; the PDF's metadata says in machine-readable form what came from AI.
- Speech: speech goes to AssemblyAI in the EU only to be turned into text, while a person has the microphone on; AssemblyAI deletes recordings and text once converted, and we don't store the recordings. What was said is deleted 48 hours after the report is sealed or cancelled, otherwise with the report; it isn't in the PDF.
- Deletion after fixed periods, automatically every night.
Review
- Automated tests check access rights and the database's rules with every change; we keep dependencies up to date.
- We report personal data breaches following a set procedure (section 10).
Annex 2: Sub-processors
The authorised sub-processors and where they process data are listed on our sub-processors page.
Annex 3: Australia
Where the Privacy Act 1988 (Cth) applies to the customer, we handle the personal information we hold for the customer in line with the Australian Privacy Principles, in particular APP 11 (security of personal information), and help the customer meet APP 8 for information held outside Australia (Annex 2). We tell the customer without delay about any data breach that may be an eligible data breach under Part IIIC of the Act, so the customer can assess and notify it.