pursuant to Art. 28 of the EU General Data Protection Regulation (GDPR)
Parties
between the customer of the PanelWave platform (the creator or their team) — hereinafter the “Controller” —
and
PanelWave, Jens Hoppe
c/o RUFFINI Creative Hub
Sendlinger Straße 1
80331 München
Deutschland
Email: privacy@panelwave.org
— hereinafter the “Processor” —
Preamble
The Controller uses the software-as-a-service platform PanelWave (authoring, management, publishing, and distribution of interactive graphic novels, including reader analytics and optional reader monetization). In doing so, the Processor processes personal data on behalf of the Controller — in particular data of readers of the Controller's published works. This Agreement specifies the data protection obligations of the parties pursuant to Art. 28 GDPR.
This Agreement is concluded electronically: it becomes an effective part of the service contract upon the Controller's registration on the platform or acceptance of the Terms of Service. No separate signature is required (Art. 28(9) GDPR — electronic format is sufficient).
For the personal data of the Controller's registered users themselves (account and profile data of creators and team members), PanelWave is the controller; this is governed by the Privacy Policy, not by this Agreement.
§ 1 Subject Matter and Duration of Processing
- The subject matter of the processing is the provision of the SaaS services described in the Preamble in accordance with the service contract.
- The duration of the processing corresponds to the term of the service contract. Upon termination, § 12 applies.
§ 2 Nature, Purpose, and Location of Processing
- The nature and purpose of the processing, the categories of data, and the categories of data subjects are set out in Annex 1.
- Processing takes place in data centers within the European Union — including databases, object storage, and backups.
- Transfers to third countries occur only via the sub-processors listed in Annex 3 and only where appropriate safeguards pursuant to Chapter V GDPR are in place (adequacy decision, EU-U.S. Data Privacy Framework, or EU Standard Contractual Clauses).
§ 3 Responsibility and Obligations of the Controller
- Within the scope of this Agreement, the Controller is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects (Art. 4 No. 7, Art. 24 GDPR).
- The Controller shall in particular ensure that readers are informed pursuant to Art. 13/14 GDPR, that any required consents are obtained (for example for reading analytics, where consent is the chosen legal basis — the PanelWave Player provides a consent mechanism for this purpose), and that content uploaded to the platform does not contain personal data of third parties without a legal basis.
- Instructions from the Controller are generally issued through use of the platform's functions (configuration, input, deletion, export); instructions beyond this must be in text form.
§ 4 Obligations of the Processor
The Processor shall:
- process personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information (Art. 28(3)(a) GDPR);
- inform the Controller immediately if, in its opinion, an instruction infringes the GDPR or other data protection provisions;
- ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR);
- take all measures required pursuant to Art. 32 GDPR (Annex 2);
- assist the Controller by appropriate technical and organizational measures in fulfilling requests of data subjects (Art. 12–23 GDPR) — in particular through the export, correction, and deletion functions integrated into the platform;
- assist the Controller in ensuring compliance with the obligations pursuant to Art. 32–36 GDPR (security of processing, notification of breaches, data protection impact assessment, prior consultation), taking into account the nature of the processing and the information available to the Processor;
- notify the Controller without undue delay after becoming aware of a personal data breach affecting the data processed on behalf of the Controller, and provide the information required for a notification pursuant to Art. 33 GDPR insofar as available;
- make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR (§ 10);
- maintain a record of processing activities pursuant to Art. 30(2) GDPR;
- not process the data entrusted to it for its own purposes. Excepted are aggregated, anonymized evaluations without personal reference (for example system metrics and platform usage statistics).
§ 5 Confidentiality
The Processor binds all persons involved in the processing (including support staff with account access) to confidentiality. Support access to customer accounts (“impersonation”) occurs only for the purpose of service provision, requires a documented reason, is time-limited, is fully logged, and is disclosed to the affected account holder by email.
§ 6 Technical and Organizational Measures (TOMs)
- The Processor implements the technical and organizational measures pursuant to Art. 32 GDPR described in Annex 2.
- The measures are subject to technical progress. The Processor may further develop them, provided the level of protection is not reduced.
§ 7 Sub-Processors
- The Controller grants general authorization for the engagement of the sub-processors listed in Annex 3 (Art. 28(2) GDPR).
- The Processor shall inform the Controller of intended changes (addition or replacement of sub-processors) at least 30 days in advance in text form (for example by email or an in-app notice) and shall publish the current sub-processor list on this page.
- The Controller may object to a change for important data protection reasons within 30 days. If no amicable solution is reached, both parties have an extraordinary right to terminate the service contract.
- The Processor shall impose on each sub-processor the same data protection obligations as set out in this Agreement (Art. 28(4) GDPR) and remains liable to the Controller for the performance of the sub-processor's obligations.
§ 8 Assistance with Data Subject Rights
- If a data subject contacts the Processor directly, the Processor shall forward the request to the Controller without undue delay, insofar as attribution is possible.
- The platform provides the Controller with self-service tools, in particular: export of works and data in a structured, commonly used, machine-readable format (Art. 15, 20 GDPR), correction of content (Art. 16 GDPR), and deletion of individual data and of the entire account (Art. 17 GDPR), subject to statutory retention obligations.
§ 9 Notifications
Notifications pursuant to § 4 No. 7 (personal data breaches) and other incidents with data protection relevance for the Controller are sent by the Processor to the email address stored in the Controller's account.
§ 10 Evidence and Audit Rights
- The Processor shall demonstrate compliance with its obligations by appropriate means, in particular: current documentation of the TOMs, certifications and audit reports of its data center and cloud providers (for example ISO 27001), and information in text form.
- In addition, the Controller may — at most once per year, and additionally where there are concrete indications of non-compliance — after reasonable advance notice and during normal business hours, conduct audits itself or have them conducted by an auditor bound to confidentiality and not in competition with the Processor. The Processor's operations and the data of other customers must not be impaired. The Processor may charge a reasonable fee for on-site audits, unless the audit was occasioned by an established breach of obligations.
§ 11 Liability
The liability of the parties is governed by Art. 82 GDPR. In the internal relationship between the parties, the liability provisions of the service contract apply in addition.
§ 12 Deletion and Return After Termination
- After termination of the service contract, the Processor shall delete all personal data processed on behalf of the Controller after a grace period of 30 days, unless the Controller requests deletion earlier. Within the grace period, the Controller can retrieve the data via the export functions in a structured, commonly used, machine-readable format.
- Exempt from deletion is data subject to statutory retention obligations — in particular invoicing and accounting data (up to 10 years under German GoBD/AO). Such data is blocked, retained solely for the retention purpose, and deleted automatically after the period expires.
- Backups are overwritten on a rolling basis; data contained in backups is deleted no later than with the regular backup cycle and is not restored before then, except where restoration is necessary to recover system operation.
§ 13 Final Provisions
- The law of the Federal Republic of Germany applies.
- In the event of contradictions between this Agreement and the service contract, the provisions of this Agreement prevail with respect to data protection.
- Should individual provisions be invalid, the validity of the remaining provisions remains unaffected.
- Amendments and supplements to this Agreement must be in text form. The Processor may adapt this Agreement with effect for the future insofar as this is necessary due to legal or technical developments; the Controller will be informed in good time.
Annex 1 — Subject Matter of Processing, Data Categories, Data Subjects
Purposes of processing
- hosting, management, and publishing of the Controller's interactive graphic novels (works, chapters, panels, assets)
- delivery of published works to readers via the PanelWave Player and a content delivery network
- collection and aggregation of reading analytics (sessions, panel views, dwell times, choices, completion, funnels) for the Controller's dashboards
- measurement of bonus content (“extras”) views and share interactions
- optional reader monetization: paywalls, purchase entitlements, and access restoration (payment processing itself is performed by the payment provider; the Controller is merchant of record)
- optional AI-assisted processing of content provided by the Controller (script import, page splitting, translation, text-to-speech, image upscaling)
Categories of data subjects
- readers and prospective readers of the Controller's published works
- purchasers of access to the Controller's works (where monetization is enabled)
- persons whose personal data is contained in content uploaded by the Controller (for example persons depicted in artwork or named in scripts)
Categories of personal data
- Reading analytics events: pseudonymous, per-visit random session ID; work, chapter, and panel references; event type (for example panel view, dwell time, choice, hotspot click, like, bookmark, share, completion); device type; interface language; timestamps. No IP address and no user agent are stored with these events; the IP address is used transiently for rate limiting only.
- Extras views and shares: IP address, user agent, timestamp, and the content reference, for reach measurement and abuse prevention.
- Entitlement data (where monetization is enabled): checkout email address in hashed (pseudonymized) form, payment provider references (for example customer and transaction IDs), product reference, entitlement status. No credit card or bank details.
- Content data: personal data contained in works, scripts, artwork, audio, or other files uploaded by the Controller (content-defined; determined by the Controller).
- Client-side story state: story variables (for example reader choices and progress) stored in the reader's browser local storage; this data remains on the reader's device and is not transmitted to the Processor.
Special categories of personal data (Art. 9 GDPR) are not the subject of this engagement; they may be contained indirectly in free-form content uploaded by the Controller.
Annex 2 — Technical and Organizational Measures (Art. 32 GDPR)
1. Confidentiality
- Physical and data center security: operation exclusively in ISO 27001-certified EU data centers with the operator's physical security measures.
- System access control: access to production systems only via secured administrative access with key-based authentication; internal services (database, queues, object storage) are reachable only on the private network.
- Application access control: role-based permissions at team level (owner, editor, viewer) and separate platform roles for administrative staff (superadmin, support, analyst); optional two-factor authentication (TOTP) for customers; rate limiting against brute-force attacks on authentication endpoints.
- Tenant separation: strict separation of customer data by tenant scoping at the application and database level.
- Encryption and hashing: transport encryption (TLS) on all public connections; passwords stored exclusively as salted bcrypt/PBKDF2 hashes; refresh tokens, password reset tokens, invitation and recovery codes stored as SHA-256 hashes; purchase email addresses stored only as hashes.
- Data minimization by design: the reading analytics pipeline stores no IP addresses or user agents; session IDs are random, in-memory, and per visit; the Player sets no cookies.
2. Integrity
- Input control: append-only audit log of administrative and security-relevant actions (actor, action, before/after state, reason, timestamp, IP address); complete logging of support access to customer accounts, including email notification to the account holder.
- Transfer control: short-lived signed URLs for file access; signature-verified payment webhooks; tokenized preview links for unpublished works; session registry with individually revocable sessions.
3. Availability and resilience
- regular database backups with point-in-time recovery; backups remain in EU data centers.
- queue-based background processing with retry mechanisms; monitoring and alerting.
- rate limiting and kill switches on public ingestion endpoints.
4. Procedures for regular review
- regular review and further development of the measures (state of the art).
- privacy-friendly defaults (Art. 25 GDPR): reading analytics are consent-gated by default, event types are restricted to a whitelist, no advertising or cross-site tracking.
- automated deletion routines: account deletion after the grace period, expiry-based cleanup of sessions and tokens, aggregation and deletion of raw analytics events.
Annex 3 — Approved Sub-Processors
| Sub-processor | Address | Service | Location / Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Industriestraße 25, 91710 Gunzenhausen, Germany | Hosting of the platform, databases, object storage, backups | Germany / EU |
| Brevo (Sendinblue GmbH) | Köpenicker Straße 126, 10179 Berlin, Germany | Dispatch of transactional emails | EU |
| OpenAI Ireland Ltd. / OpenAI, L.L.C. | Dublin, Ireland / San Francisco, USA | AI features (script structure analysis, page-split panel detection on uploaded page images) — only when used by the Controller; no model training on submitted content | EU/USA; EU Standard Contractual Clauses |
| DeepL SE | Maarweg 165, 50825 Cologne, Germany | Machine translation of work content — only when used by the Controller | EU |
| ElevenLabs, Inc. | New York, USA | Text-to-speech generation from script text — only when used by the Controller | USA; EU Standard Contractual Clauses |
| Freepik Company S.L. | Málaga, Spain | AI image upscaling (Magnific) of images submitted by the Controller — only when used by the Controller | EU |
| Stripe Payments Europe, Ltd. | 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland | Payment processing for reader purchases (Stripe Connect; the Controller is merchant of record) — only where monetization is enabled | EU; transfers to Stripe, Inc. (USA) under the EU-U.S. Data Privacy Framework / EU Standard Contractual Clauses |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | 22-24 Boulevard Royal, 2449 Luxembourg | Payment processing for reader purchases — only where monetization is enabled | EU; EU Standard Contractual Clauses for intra-group transfers |
The current list is published on this page; changes are announced in accordance with § 7 of this Agreement.