1. Parties, scope and structure
1.1This Data Processing Agreement (“DPA”) is concluded between the customer identified in section 13 (the “Controller”) and Synergetic GmbH, Dr.-Helle-Straße 8, 59558 Lippstadt, Germany (the “Processor”), operator of Simplified Webhooks.
1.2It forms part of the agreement under which the Controller uses Simplified Webhooks (the “Service Agreement”) and implements Art. 28(3) of Regulation (EU) 2016/679 (“GDPR”).
1.3Annexes 1 to 3 form an integral part of this DPA. Annex 3 is maintained at simplified-webhooks.com/dpa and may be updated in accordance with section 6.
1.4The Controller acts as controller and the Processor as processor with respect to the personal data described in Annex 1. Each party is independently responsible for complying with the data protection law applicable to it.
2. Definitions
2.1“Personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR.
2.2“Customer Data” means the personal data that the Processor processes on behalf of the Controller under the Service Agreement, as described in Annex 1.
3. Subject matter and instructions
3.1Subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
3.2The Processor processes Customer Data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which it is subject; in that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
3.3This DPA, the Service Agreement, and the configuration the Controller makes in the Service — in particular the Airtable bases and tables connected, the events subscribed to, and the destination URLs configured — constitute the Controller’s complete instructions. Further instructions must be given in text form to contact@simplified-webhooks.com.
3.4The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. The Processor may suspend execution of that instruction until it is confirmed or amended.
3.5The Controller is responsible for the lawfulness of the processing it instructs, for having a legal basis for the transfer of Customer Data to the Processor, and for the content it routes through the Service.
4. Confidentiality
4.1The Processor ensures that persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that this obligation survives the end of their engagement.
4.2Access to Customer Data is limited to personnel who need it to provide, secure or support the Service.
5. Security of processing
5.1The Processor implements the technical and organisational measures set out in Annex 2 pursuant to Art. 32 GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing as well as the risk to the rights and freedoms of natural persons.
5.2The measures in Annex 2 are subject to technical progress. The Processor may change them provided the level of protection is not reduced. Material changes are reflected in Annex 2 and on the security page.
6. Sub-processors
6.1The Controller grants the Processor general written authorisation to engage sub-processors. The sub-processors engaged at the effective date of this DPA are listed in Annex 3.
6.2The Processor informs the Controller of any intended addition or replacement of a sub-processor at least 14 days in advance by updating Annex 3, which carries an effective date and a change log. Controllers who wish to be notified by email can subscribe at contact@simplified-webhooks.com; the Processor then also notifies them by email. Where a sub-processor must be engaged or replaced at shorter notice to maintain the security or continuity of the Service, the Processor informs without undue delay instead.
6.3The Controller may object to such a change on reasonable data protection grounds before it takes effect. If the parties cannot agree on a solution, the Controller may terminate the Service Agreement with respect to the affected services without penalty, effective on the date the change takes effect.
6.4The Processor imposes on each sub-processor, by contract, data protection obligations that are no less protective than those set out in this DPA, and remains fully liable to the Controller for the performance of the sub-processor’s obligations.
6.5Airtable is not a sub-processor under this DPA. It is the Controller’s own source system, which the Processor accesses on the Controller’s instruction using credentials the Controller provides. The relationship between the Controller and Airtable is governed separately.
7. International transfers
7.1Customer Data is stored and processed within the European Union on the infrastructure listed in Annex 3.
7.2Where a sub-processor is established outside the European Economic Area and may access Customer Data from there, the Processor has concluded the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with that sub-processor, or relies on another transfer mechanism permitted under Chapter V GDPR, and has assessed the transfer accordingly.
7.3The Processor does not transfer Customer Data to a third country on its own initiative beyond what is described in Annex 3.
8. Assistance with data subject rights
8.1Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller’s obligation to respond to requests for exercising the data subject’s rights under Chapter III GDPR.
8.2The Service gives the Controller direct access to the Customer Data held on its behalf, including the ability to inspect, export and delete it. Where the Controller can act itself through the Service, that is the primary route.
8.3If a data subject contacts the Processor directly regarding Customer Data, the Processor forwards the request to the Controller without undue delay and does not respond on the merits itself.
9. Personal data breaches and further assistance
9.1The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data. The notification describes the nature of the breach, the likely consequences, the measures taken or proposed, and a point of contact. Notification is sent to the email address associated with the Controller’s account.
9.2The Processor assists the Controller in ensuring compliance with the obligations pursuant to Art. 32 to 36 GDPR, taking into account the nature of the processing and the information available to it — in particular with data protection impact assessments and prior consultation of a supervisory authority.
9.3The Processor documents personal data breaches affecting Customer Data and makes that documentation available to the Controller on request.
10. Information and audits
10.1The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR: this DPA including Annexes 1 to 3, the security page, and — once per calendar year — answers to a reasonable written security questionnaire.
10.2The parties agree that providing this information ordinarily satisfies the Controller’s audit and inspection rights under Art. 28(3)(h) GDPR.
10.3An on-site inspection may be carried out only where (a) a supervisory authority requires it, (b) mandatory law obliges the Controller to carry it out, or (c) a personal data breach has affected the Controller’s Customer Data. Such an inspection takes place at most once per calendar year, requires at least 30 days’ written notice, is limited to the systems used to process Customer Data, takes place during regular business hours, must not disrupt operations disproportionately, and is subject to confidentiality. The auditor must not be a competitor of the Processor.
10.4Information under 10.1 is provided free of charge. For an inspection under 10.3, the Controller bears its own costs and reimburses the Processor’s reasonable expenses, unless the inspection establishes a material breach of this DPA by the Processor.
11. Deletion and return of data
11.1The content of webhook events — the Airtable payload received and the payload forwarded — is deleted automatically 30 days after the event. What remains is delivery metadata (timestamps, delivery status, HTTP status codes, error messages) containing no record content.
11.2The Controller may delete individual webhooks, its stored Airtable credentials, or its entire account at any time through the Service, which deletes the associated Customer Data.
11.3After the end of the provision of services, the Processor deletes all remaining Customer Data within 30 days, unless Union or Member State law requires storage of the personal data. Backups are overwritten in the ordinary backup cycle.
11.4At the Controller’s choice, the Processor returns Customer Data instead of deleting it, provided the request is made before termination takes effect.
12. Term, precedence, liability, governing law
12.1This DPA forms part of the Terms of Service and takes effect when the Controller accepts those terms or begins using the Service, whichever is earlier. A signature is not required for it to be binding; section 13 exists for controllers whose internal process needs a signed copy. It remains in force for as long as the Processor processes Customer Data on the Controller’s behalf.
12.2In case of conflict between this DPA and the Service Agreement, this DPA prevails in matters of data protection.
12.3Liability under this DPA is governed by the limitations of liability set out in the Terms of Service, which apply to this DPA accordingly. Where the Service is provided free of charge, the Processor is liable only for intent and gross negligence. Liability for intent and gross negligence, for injury to life, body or health, under a guarantee given, under the German Product Liability Act, and under Art. 82 GDPR remains unaffected.
12.4This DPA is governed by German law. The place of jurisdiction is Lippstadt, Germany, where the Controller is a merchant, legal person under public law, or special fund under public law.
12.5The Processor may amend this DPA where necessary to reflect changes in applicable law, in the Service, or in the sub-processors engaged. The Processor publishes the new version at simplified-webhooks.com/dpa and notifies the Controller by email at least 30 days before it takes effect. If the Controller objects on reasonable data protection grounds within 14 days, the parties seek a solution in good faith; if none is found, either party may terminate the Service Agreement effective on the date the amendment takes effect. Amendments required by mandatory law take effect on the date the law requires.
12.6Should individual provisions be invalid, the validity of the remaining provisions remains unaffected.
13. How to conclude this DPA
Complete the Controller block below, then print or save this page as a PDF, sign it, and send it to contact@simplified-webhooks.com. A signature in electronic form is sufficient (Art. 28(9) GDPR). The Processor’s signature is provided below; no countersignature is required.
Processor
Signed electronically for and on behalf of Synergetic GmbH on 25 August 2026, version 1.0 of this DPA.
Controller
For Annex 1 we need one thing only you can provide: the categories of data subjects whose data your connected Airtable bases contain. Add them to the table in Annex 1 or name them in your email.
Annex 1 — Description of the processing
| Item | Description |
|---|---|
| Subject matter | Receiving change events from the Controller’s Airtable bases, transforming them, and forwarding them to endpoints the Controller configures; optionally recording per-table record counts. |
| Duration | For the term of the Service Agreement, plus the deletion periods in section 11. |
| Nature and purpose | Automated receipt, storage, transformation and transmission of event data for the purpose of providing the Service; storage of account and connection data to operate it. |
| Types of personal data | Account data Email address, name, plan, authentication data, API key hashes. Connection data Encrypted Airtable access token or OAuth tokens, base/table identifiers, destination URLs. Event content The Airtable payload of each change event and the payload forwarded, whose content is determined entirely by the Controller. Includes the identity of the Airtable user who triggered the change where Airtable supplies it. Deleted 30 days after the event. Delivery metadata Timestamps, delivery status, HTTP status codes, error messages, retry state. Usage data Per-table record counts for bases the Controller chooses to track. |
| Categories of data subjects | Users of the Controller’s account and collaborators in its Airtable bases. In addition, the data subjects whose records the Controller stores in the connected Airtable bases — to be specified by the Controller, for example: customers, prospects, employees, applicants, suppliers. Specified by the Controller: |
| Special categories of data | None are required by the Service. If the Controller routes special categories of data (Art. 9 GDPR) through it, the Controller is responsible for the lawfulness of doing so and must inform the Processor. |
| Place of processing | European Union — see Annex 3. |
Annex 2 — Technical and organisational measures
Measures pursuant to Art. 32 GDPR, current as of 25 August 2026. The security page describes the same measures in non-contractual language.
| Area | Measures |
|---|---|
| Confidentiality — access control | Authentication for every API request via signed JWT or personal API key; API keys stored only as SHA-256 hashes; row-level security in the database, scoping every row to its owner; administrative access limited to an explicit allowlist and protected by two-factor authentication; least-privilege service accounts authenticated with signed OIDC tokens for scheduled jobs. |
| Confidentiality — encryption | TLS for all data in transit, including inbound events and outbound delivery; Airtable access tokens and OAuth tokens additionally encrypted at application level with AES-256-GCM; encryption keys held in Google Secret Manager, separate from the database; storage-level encryption at rest by the hosting providers. |
| Integrity — input and transmission control | Inbound Airtable notifications verified against Airtable’s HMAC signature before processing; deduplication of events at database level; administrative actions written to an audit log; changes deployed from version-controlled sources. |
| Availability and resilience | Managed, redundant cloud infrastructure; automated daily database backups; automatic retry of failed deliveries with exponential backoff; durable delivery queue; scheduled refresh of Airtable webhook subscriptions; continuous monitoring with automated alerting. |
| Data minimisation and storage limitation | Event content automatically deleted 30 days after the event, retaining only content-free delivery metadata; record-count tracking stores counts, never record content; deletion of webhooks, credentials or the entire account available to the Controller at any time. |
| Separation and purpose limitation | Customer Data logically separated per account and enforced by row-level security; production access restricted to operating, securing and supporting the Service; no use of Customer Data for the Processor’s own purposes and no use for training machine learning models. |
| Organisational measures | Personnel bound to confidentiality; documented procedure for personal data breaches; sub-processors contractually bound under Art. 28 GDPR; regular review of these measures. |
Annex 3 — Sub-processors
Sub-processors engaged as of 25 August 2026:
| Sub-processor | Purpose | Place of processing |
|---|---|---|
| Google CloudGoogle Cloud EMEA Limited, Ireland | API hosting, job scheduling, delivery queues, secret management | EU — europe-west1 (Belgium) |
| SupabaseSupabase, Inc., United States | Managed PostgreSQL database and user authentication | EU — Frankfurt (eu-central-1)Entity outside the EEA — Standard Contractual Clauses in place |
| VercelVercel Inc., United States | Hosting of the marketing site and the customer dashboard | EU — Frankfurt (fra1)Entity outside the EEA — Standard Contractual Clauses in place |
| PostHogPostHog, Inc., United States | Product analytics and error tracking | EU Cloud — FrankfurtEntity outside the EEA — Standard Contractual Clauses in place |
Announced in advance — not engaged
The following are announced under section 6.2 but do not process Customer Data today. Listing them here serves as the advance notice required by that section: when one of them is put into use, it moves to the table above and the change log records the date. Until then, no data reaches them.
| Provider | Intended purpose | Status |
|---|---|---|
| Vercel AI GatewayVercel Inc., United States | Routing requests for planned AI-assisted features to language model providers | Not in use. Before this is activated, the model providers it routes to will be named here, the routing will be pinned to those providers, and no-training and retention terms will be agreed with them. |
Airtable is not listed: it is the Controller’s own source system, accessed on the Controller’s instruction with credentials the Controller provides (section 6.5).
This annex lists only providers that process Customer Data on the Processor’s behalf. Tools the Processor uses for its own purposes — such as accounting, invoicing or website analytics — are not sub-processors under this DPA; they are described in the privacy policy.
Change log
| Date | Change |
|---|---|
| 25 August 2026 | Initial list published. |
Version history
| Version | Date | Change |
|---|---|---|
| 1.0 | 25 August 2026 | First published version. |