Legal & Compliance
Data Processors & Subcontractors
Note: This translation is for informational purposes only. The German version shall be solely legally binding. Deutsch →
Transparency regarding which service providers process personal data on behalf of Baduno GmbH is the foundation of any GDPR-compliant collaboration. This page lists our data processors, their role, location, and the legal basis for data transfer – both for the website and for the provision of services to clients.
This page provides general information about our practices and the legal situation. It does not constitute legal advice; only the contract documents and the German version of these pages are binding.
Principles of Our Service Provider Selection
We select service providers based on three criteria: processing preferably within the EU, a contract pursuant to Art. 28 GDPR with documented technical and organizational measures, and data minimization – each service only receives the data required for its task. Confidential customer content is pseudonymized or removed before transmission to AI services, unless otherwise agreed contractually.
Hosting & Infrastructure
Hetzner Online GmbH, Gunzenhausen (Germany): Operation of servers for the website and customer portal in German data centers; a data processing agreement pursuant to Art. 28 GDPR is in place. Cloudflare Inc. (USA/EU): DNS, TLS termination and protection against overload attacks; transfer based on the EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework, to the extent that data leaves the EU.
Payment Service Providers
Stripe Payments Europe Ltd. (Ireland), PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg) and Mollie B.V. (Netherlands) process payment data under their own data protection responsibility; we do not receive or store full card details. The choice of payment method is yours during the ordering process.
AI Tools in Service Delivery
For machine translation, we use DeepSeek as a tool; for image generation, Magnific/Freepik. Only the content to be translated or illustrated is transmitted – without master customer data, without access data and, in confidential projects, after pseudonymization of sensitive passages. Results always undergo human review before reaching customers.
Analysis & Advertising (consent only)
Google Ireland Ltd. for Google Analytics 4 and Google Ads measurement – exclusively upon your consent via the cookie dialog; details in the cookie policy. For sending login links to the customer area by email, we use our own server infrastructure.
Changes to this list
If a service provider is added or removed, we update this page. Customers with a data processing agreement will be informed of material changes in advance and granted the contractually agreed objection rights.
Step-by-step practical example
Imagine you commission us to translate your corporate website. First, we prepare the content: we extract the texts from your content management system and remove confidential customer master data such as names or direct contact information that are not part of the translation scope. The text segments to be translated are pseudonymized by replacing company names with placeholders, unless contractually agreed otherwise.
Then we transfer the prepared content to DeepSeek, our processor for machine translation. DeepSeek receives only the plain text files – without metadata from your user account, without login credentials, and without payment information. After machine translation, a human editor checks the result for accuracy and consistency. Only after this quality assurance is the translation delivered to you.
In parallel, Magnific or Freepik may be used for images. Here too: only the image motifs are transferred, no personal data. The entire chain is secured by data processing agreements and technical-organizational measures. If you make a payment, Stripe, PayPal or Mollie process the transaction under their own responsibility – we do not store complete card data.
Common Misunderstandings
A common misunderstanding concerns the role of Cloudflare: Many assume that Cloudflare is a processor – but it is only for infrastructure services such as DNS and TLS. In fact, Cloudflare as a fulfillment service provider in the context of content delivery does not process personal data beyond the technical connection setup. We have concluded standard contractual clauses with Cloudflare, and data processing is limited to IP addresses and browser identifiers to ensure website availability.
Another misunderstanding: that analysis tools like Google Analytics 4 are automatically active. The opposite is true: they are only loaded after your explicit consent via the cookie dialog. Without consent, no data is transferred to Google Ireland Ltd. for analysis or advertising purposes. The payment service providers also act independently – we do not pass on customer profiles, only the data necessary for the transaction.
Finally, it is often assumed that AI tools have access to the entire customer project. In fact, they only receive the specific content to be processed – and in pseudonymized form if contractual confidentiality agreements exist. A full disclosure of project contents does not take place.
Interaction with our other policies
The list of processors and subprocessors is a central piece of our data protection concept, which is interlinked with other policies. Our privacy policy informs you of your rights as a data subject and how to exercise them – such as access, rectification, or deletion of your data. It also provides the contact details of our data protection officer.
Our cookie policy supplements the list of processors by detailing which services are activated on the website after your consent – in particular Google Analytics 4 and Google Ads. Consent is managed via the cookie dialog, and you can withdraw it at any time.
The Data Processing Agreement (DPA) we enter into with our clients specifies which data we may process and to what extent. The subprocessors named here are either already listed there or are mentioned as a category (e.g., "hosting provider"). In the event of material changes – such as the addition or removal of a service provider – we inform you in advance and grant you the contractually agreed right to object.
This ensures that all policies work together seamlessly and that you can always trace who processes which data for what purpose.
Step-by-step practical example
Suppose you commission us to translate your corporate website. The process begins with content preparation: we extract the texts from your content management system and remove confidential customer master data such as names or direct contact information that is not part of the translation scope. We then pseudonymize the text segments to be translated – for example, replacing company names with placeholders, unless otherwise agreed contractually. In this prepared state, we transmit the content to DeepSeek, our processor for machine translation. DeepSeek receives only the plain text files – without metadata from your user account, without login credentials, and without payment processing information. After machine translation, a human editor checks the result for accuracy and consistency. Only after this quality assurance step is the translation delivered to you. In parallel, Magnific or Freepik may be used for imagery. Here too, only the image motifs are transmitted, no personal data. The entire chain is secured by data processing agreements and technical and organizational measures. If you make a payment, Stripe, PayPal, or Mollie process the transaction under their own responsibility – we do not store complete card data. This concrete example illustrates how data minimization and our contractual obligations are implemented already in the normal project workflow.
Common misconceptions
A common misconception is the assumption that we pass on your content to third parties without protection. In fact, we always prepare the data to be transmitted so that only the bare minimum is transmitted: When using AI tools such as DeepSeek, they receive only the pure text modules, but not your access data, master customer data, or payment information. It is also important to note that payment service providers such as Stripe, PayPal, and Mollie do not act as our processors, but as independent controllers – we do not store any complete card data. Another misconception concerns storage locations: Our servers run at Hetzner in Germany, while Cloudflare is responsible for DNS and protection. If data leaves the EU, this is done on the basis of the EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. Finally, not everyone is aware that analytics and advertising services such as Google Analytics are only used after your consent via the cookie dialog. These clarifications help to strengthen trust in data processing with us.
What this means for customers in practice
This published list of our processors and subprocessors provides you as a customer with a transparent overview of which service providers process personal data on your behalf. You can trace at any time who receives your data for what purpose and on what legal basis this occurs. For customers who have concluded a data processing agreement with us, this page contains the essential information required to fulfill your own documentation obligations pursuant to Art. 28 GDPR.
In practice, this means: When you commission us with the localization of your website, you know that the required texts are transmitted to DeepSeek for machine translation – but in pseudonymized form and only after concluding a data processing agreement. You can rely on your content not being used for other purposes. Should changes occur in the list, we will inform you in a timely manner so that you can object if necessary. Your rights to information, correction, and deletion remain unaffected by the collaboration with our service providers.
Our internal process
Before engaging a new service provider as a processor, we subject them to a standardized review process. First, we assess whether the processing is truly necessary and cannot be performed more efficiently or in a more privacy-friendly manner using our own resources. We then request a detailed description of the provider's technical and organizational measures (TOMs). Based on this, we verify that data security meets the state of the art and that data is processed exclusively within the EEA or in a third country with an adequate level of protection.
After successful review, we conclude a data processing agreement pursuant to Art. 28 GDPR, which specifies the exact processing purposes, categories of personal data, duration, and the provider's obligations. All contracts are centrally documented and regularly reviewed for currency. In the event of material changes—such as a change in the provider's location—we inform our customers who have a data processing agreement in advance and grant them a right to object. The entire selection and monitoring process is carried out by our data protection department in close coordination with IT.
Key terms explained
Processor: A service provider that processes personal data on our behalf without using it for its own purposes. For example, Hetzner as a hosting provider processes your data on our servers – but only in accordance with our instructions. The legal basis is a contract pursuant to Art. 28 GDPR.
Sub-processor: A company engaged by the processor to perform parts of the data processing. In our chain, there are currently no sub-processors; all listed services are directly commissioned by us.
Standard Contractual Clauses (SCCs): Contract clauses issued by the European Commission that ensure an adequate level of data protection when transferring personal data to third countries. They are used when no adequacy decision exists.
Pseudonymization: The replacement of identifying characteristics with a pseudonym, so that a link to the data subject is only possible with additional knowledge. In practice, before transferring data to AI services, we replace names or specific company designations with placeholders to minimize the amount of data.
Technical and Organizational Measures (TOMs): Security measures such as encryption, access controls, or firewalls that are documented in data processing agreements.
Common misconceptions
In dealing with data processors and subprocessors, we frequently encounter typical misconceptions. A common misunderstanding is the assumption that every service provider involved in service delivery is automatically a data processor. In fact, the GDPR distinguishes between data processors (who process data on behalf of the controller) and independent controllers (such as payment service providers who use data for their own purposes). Therefore, we explicitly indicate in our list when a service provider acts under its own responsibility. Another misconception concerns the geographical boundary of data processing. Many customers assume that processing outside the EU is generally impermissible. The correct view is that transfers to third countries may only take place under certain guarantees, such as standard contractual clauses or adequacy decisions. We transparently document these bases for each service provider. The role of artificial intelligence is also often misjudged. Some customers fear that AI tools like DeepSeek automatically gain access to all customer data. In fact, we strictly limit the transmission to the minimum necessary for the service and pseudonymize sensitive content beforehand. Finally, there is uncertainty about the duration of data processing agreements: they are not unlimited but end with the termination of the main contract or are updated regularly. We clarify these points at the time of contract conclusion and in the event of material changes.
What this means for customers in practice
The transparent presentation of our data processors and subprocessors has several practical implications for you as a customer. First, you can always see which service providers are involved in which role in the provision of our services. This facilitates your fulfillment of your own data protection obligations, especially if you need to inform your end customers about the processing of personal data. Second, you are legally protected by the existing data processing agreements: should a data breach occur at one of our service providers, we as the controller are liable – not you. Third, you benefit from reduced data exposure: by passing on data only pseudonymized or limited to what is necessary to subprocessors, we minimize the risk to your confidential information. Fourth, choosing service providers established in the EU or with equivalent data protection standards means no additional bureaucratic effort for you, such as the need for your own supplementary agreements. Fifth, at the time of contract conclusion, you can express individual wishes: if you wish to exclude certain subprocessors, we will examine the technical and economic feasibility – within the framework of the existing contractual provisions. Should a service provider you do not wish to include be absolutely necessary, we will discuss alternative solutions. Overall, we thus create a reliable foundation for your data protection compliance.
Our internal process
The integration of a new processor or subcontractor at Baduno GmbH follows a defined internal process. First, the compliance team reviews the potential service provider based on our selection criteria: establishment in the EU or a third country with an adequate level of data protection, evidence of technical and organizational measures (TOMs), and willingness to conclude a data processing agreement pursuant to Art. 28 GDPR. Subsequently, a data protection impact assessment (DPIA) is carried out if the processing is likely to result in a high risk to the rights and freedoms of natural persons – for example, in the case of large-scale processing of special categories of data. After a positive review, the data processing agreement is concluded, which governs, among other things, the obligation to follow instructions, the duty of confidentiality, and the deletion periods. In parallel, our IT department adjusts the technical interfaces to ensure data-minimized transmission. Prior to productive use, we test the implementation in an isolated environment. If the service provider is relevant for the provision of services to customers, we inform affected customers with existing data processing agreements in advance about the planned integration and, if necessary, grant a right to object. Ongoing monitoring is carried out through regular audits and checks of the TOMs, at least annually or on an ad-hoc basis. Changes to the list of service providers are documented immediately on our website. This process ensures that each subcontractor meets the same high data protection standards that we also apply internally.
Status of this information: July 2026 – we update upon changes in the legal situation or our procedures.