Data Processing Agreement (DPA)
pursuant to Art. 28 GDPR
Download the DPA pre-filled with your company details
You can download the DPA pre-filled with your company details in the logged-in area under Settings → Company details download it.
This data processing agreement is concluded electronically during the registration or setup process. Herz-Kilometer records the time of conclusion, the user ID of the accepting person, the assigned organisation and the accepted version of this agreement.
between
[Name of the organisation or controller]
[Address]
represented by [name and position]
– hereinafter the "Controller" –
and
Herz-Kilometer UG (haftungsbeschränkt)
Grüne Trift 123
12557 Berlin
Germany
– hereinafter the "Processor" –
– together the "Parties" –
1 Subject matter, scope and duration
1.1 Subject matter
The Processor provides the Controller with the "Herz-Kilometer" platform, including the website, administration area, challenge pages, mobile apps, interfaces, activity tracking, analytics and reporting functions.
In particular, the platform enables the setup and operation of running, walking, hiking and comparable movement challenges in which the kilometres covered are recorded, assigned to a challenge and linked to a social project or another impact goal.
1.2 Possible controllers
A controller within the meaning of this agreement may in particular be:
- a company or other commercially active organisation,
- an association or federation,
- a school, university or other educational institution,
- a foundation, non-profit organisation or social institution,
- an initiative, neighbourhood, community or other organised group of people,
- a natural person, insofar as they do not use the platform exclusively for personal or household activities and decide on the purposes and means of processing other people’s personal data.
1.3 Scope of the processing on behalf of the Controller
This agreement applies only insofar as the Processor processes personal data on behalf of the Controller.
This concerns in particular cases in which the Controller:
- creates or administers an internal or public challenge of its own,
- invites participants or enables them to join,
- provides join codes, invitation links or comparable access routes,
- assigns roles and permissions within a challenge or organisation,
- determines the challenge period, kilometre goal, activity types or conditions of participation,
- selects a social project or donation recipient,
- receives personal or aggregated challenge analytics,
- decides on publication settings, leaderboards or participant displays.
1.4 Cases not covered by this agreement
This agreement does not apply merely because a company or another organisation supports a third-party challenge as a supporter.
A supporter who in particular:
- selects a supporter package,
- pays a service fee to Herz-Kilometer,
- pledges an impact budget towards a project, betterplace.org or an NGO,
- provides its logo or a sponsor statement,
- receives exclusively aggregated closing information,
does not thereby become, as a matter of principle, a controller for the personal data of the challenge participants.
The respective supporter terms, the privacy policy and, where applicable, separate agreements apply to such supporters. This DPA applies to a supporter only if that supporter additionally organises a challenge of its own or demonstrably instructs Herz-Kilometer to process personal data on its behalf.
1.5 Herz-Kilometer acting as its own controller
Insofar as Herz-Kilometer processes personal data for its own purposes and on the basis of its own statutory or contractual obligations, Herz-Kilometer does not act as a processor but as a controller in its own right.
This may concern in particular:
- the conclusion and administration of the contract with the Controller,
- the billing of service or usage fees,
- the administration of its own contact and customer data,
- compliance with statutory retention obligations,
- the establishment, exercise or defence of legal claims,
- measures for general IT and platform security,
- the prevention of misuse, fraud or unlawful use.
Such processing is governed by the Herz-Kilometer privacy policy.
1.6 Main contract
Depending on the use, the main contract is in particular:
- a paid subscription,
- a contract for a company or organisation challenge,
- an agreement on the use of a community challenge,
- a free-of-charge usage agreement,
- the terms and conditions applicable to the Controller,
- an individually concluded service agreement.
1.7 Duration
The duration of this agreement corresponds to the duration of the main contract or of the use of the respective organisation or challenge functions.
It also applies to agreed transition, export, backup and deletion periods pursuant to Section 10.
2 Nature and purpose of the processing
2.1 Nature of the processing
Depending on how the platform is used, the processing may in particular comprise the following operations:
- collection,
- recording,
- organisation,
- structuring,
- storage,
- adaptation and alteration,
- retrieval,
- querying,
- use,
- calculation,
- aggregation,
- combination,
- display,
- transmission,
- restriction,
- export,
- erasure and destruction.
2.2 Purposes of the processing
The processing takes place in particular for the following purposes:
- provision and operation of the Herz-Kilometer platform,
- setup and administration of organisation accounts,
- setup, operation and administration of internal or public challenges,
- administration of administrators, controllers, team leads and other roles,
- administration of memberships, participations, join codes, invitations and access,
- recording, import and assignment of activity and kilometre data,
- manual or automatic recording of activities,
- import of activities from connected third-party services,
- calculation of individual, team and overall progress,
- display of progress, kilometre totals and challenge results,
- provision of leaderboards, where activated by the Controller,
- display of participant names, display names or profile information in accordance with the selected settings,
- linking a challenge to a social project, an NGO or a fundraising campaign,
- assignment and display of supporters or sponsors,
- administration of impact pledges and supporter packages,
- receipt and administration of proof of payments or donations made,
- creation of interim, final, impact, CSR or ESG reports,
- creation of exports, key figures and communication materials,
- sending of system, invitation, status and report emails,
- provision of support,
- ensuring security, stability and prevention of misuse,
- technical logging, error analysis, maintenance and recovery.
2.3 Public challenge content
In the case of public challenges, certain information may be displayed publicly in accordance with the settings and instructions of the Controller.
This may concern in particular:
- name and description of the challenge,
- name or logo of the organiser,
- social project or beneficiary organisation,
- kilometre goal and challenge period,
- overall progress,
- number of participants,
- aggregated activity data,
- supporters, logos and sponsor statements,
- confirmed impact or proof of donation,
- public leaderboards or participant displays, where activated.
The Controller determines which optional content is displayed publicly. The Processor provides the corresponding technical settings.
2.4 Purpose limitation
The Processor processes the data subject to this agreement exclusively:
- to perform the main contract,
- on documented instructions from the Controller,
- or insofar as processing is required by Union law or the law of a Member State.
Personal data processed on behalf of the Controller is not used for the Processor’s own advertising, profiling or marketing purposes unless a separate legal basis exists for this.
3 Data subjects and categories of data
3.1 Data subjects
Depending on the type of organisation and challenge, the following groups of people may in particular be affected:
- employees,
- members of associations or federations,
- members and supporters of communities or initiatives,
- pupils,
- students,
- teachers and other staff of educational institutions,
- volunteers,
- participants in challenges,
- invited or joining users,
- team members and team leads,
- administrators,
- contact persons and authorised representatives of the Controller,
- contact persons of social projects, NGOs or supporters,
- further user groups added or admitted by the Controller.
3.2 Master data and organisation data
Depending on the use, the following data may in particular be processed:
- first and last name,
- display name or username,
- email address,
- user ID,
- organisation, association, school, university, community or team assignment,
- role and permission level,
- joining and membership status,
- details of the authorised representative or administering person,
- organisation name and organisation data.
3.3 Account and authentication data
- login and authentication information,
- technically necessary tokens,
- verification status,
- password hashes,
- session and security information,
- information about connected accounts or services.
Passwords are not stored in plain text.
3.4 Activity and movement data
Depending on the use and the connected service, the following may in particular be processed:
- kilometres or distances covered,
- type of activity,
- date and time of an activity,
- duration of the activity,
- assignment to a challenge,
- manually entered activities,
- activities imported from third-party services,
- status of an activity,
- where applicable, further activity metadata required for challenge analytics.
Precise GPS routes or location histories are processed only where this is offered as a specific function, is necessary and has been configured accordingly. Insofar as only distance and activity values are required for the challenge, complete route histories should not be processed.
3.5 Challenge, participation and result data
- challenge membership,
- date of joining,
- join code or invitation assignment,
- individual, team and overall kilometres,
- rank or position on a leaderboard,
- progress and goal achievement,
- participation rate,
- activity mix,
- aggregated key figures,
- result and report data,
- certificates or completion records issued.
3.6 Supporter, project and impact data
Insofar as this data is processed on behalf of the Controller:
- name and logo of a supporter,
- contact persons and business contact details,
- selected supporter package,
- number and scope of pledged impact kilometres,
- sponsor or supporter statement,
- name of and information about the supported project,
- details of betterplace.org, an NGO or another recipient,
- uploaded payment, donation or fulfilment records,
- status of review or confirmation,
- details for final reports and communication materials.
3.7 Usage, device and log data
- time and extent of use,
- interactions with the app and website,
- technical events,
- IP address,
- device and browser information,
- operating system,
- log, error and crash data,
- security-relevant events,
- timestamps of changes and administrative actions.
3.8 Communication data
- support requests,
- messages to the Controller or the Processor,
- system notifications,
- contents of queries or error descriptions,
- attachments transmitted, where applicable.
3.9 Special categories of personal data
Depending on content, level of detail, context and intended use, activity and movement data may allow conclusions to be drawn about a person’s health or physical fitness and may, where applicable, qualify as health data within the meaning of Art. 9 GDPR.
Insofar as special categories of personal data are processed:
- the processing takes place exclusively on the documented instructions of the Controller,
- enhanced protective measures pursuant to Annex 1 are applied,
- the Processor limits the scope to the data required for the challenge,
- the Controller ensures that a legal basis under Art. 6 and Art. 9 GDPR exists.
4 Right to issue instructions and responsibility of the Controller
4.1 Instructions
The Processor processes personal data exclusively on documented instructions from the Controller, unless there is a statutory obligation to process.
In such a case, the Processor informs the Controller of the statutory obligation before processing, insofar as this is legally permissible.
4.2 Form of instructions
Instructions may be given in particular by:
- settings within the platform,
- selection or configuration of functions,
- definition of challenge settings,
- activation or deactivation of public displays,
- email,
- support request,
- other notification in text form.
The processing operations agreed under the main contract and provided for by the platform are deemed to be documented instructions.
4.3 Unlawful instructions
If the Processor considers an instruction to infringe data protection law, it informs the Controller without undue delay.
The Processor may suspend execution of the instruction until the Controller confirms, amends or withdraws it.
Manifestly unlawful instructions do not have to be carried out.
4.4 Obligations of the Controller
The Controller remains responsible in particular for:
- the lawfulness of the processing,
- the selection of appropriate legal bases,
- compliance with information obligations towards data subjects,
- the proper involvement of employees, members, pupils, students or other participants,
- the lawfulness of invitations and participant lists,
- the decision on public displays,
- the lawfulness of leaderboards,
- obtaining any necessary consent,
- compliance with special requirements concerning minors,
- the lawfulness of processing special categories of personal data,
- handling and legally assessing data subject requests,
- the admissibility of logos, images, texts and sponsor statements transmitted.
5 Obligations of the Processor
5.1 Confidentiality
The Processor ensures that all persons authorised to process personal data:
- have committed themselves to confidentiality,
- access data only to the extent necessary,
- have been appropriately instructed in data protection and information security.
5.2 Technical and organisational measures
The Processor takes and maintains appropriate technical and organisational measures pursuant to Art. 32 GDPR.
The measures in force at the time this agreement is concluded are described in Annex 1.
5.3 Support for the Controller
Taking into account the nature of the processing and the information available to it, the Processor supports the Controller in particular with:
- fulfilling data subject rights,
- ensuring data security,
- notifying personal data breaches,
- data protection impact assessments,
- prior consultations with supervisory authorities,
- providing information on sub-processors,
- the return, export and deletion of data.
5.4 Record of processing activities
The Processor maintains a record of the categories of processing activities pursuant to Art. 30(2) GDPR insofar as this is required by law.
5.5 Data protection by design
In developing and operating the platform, the Processor takes into account the principles of data protection by design and by default.
These include in particular:
- data minimisation,
- restrictive default permissions,
- separation of organisations and challenges,
- role-based access,
- appropriate deletion and retention rules,
- limitation of public displays to configured content.
6 Sub-processors
6.1 General authorisation
The Controller grants the Processor general authorisation to engage sub-processors.
The sub-processors engaged at the time this agreement is concluded are listed in Annex 2.
6.2 Changes
The Processor informs the Controller at least 14 days before the intended addition or replacement of a sub-processor.
This information may be provided in particular:
- by email,
- via the administration area,
- via a publicly accessible and versioned list of sub-processors.
The Controller may object to the change for important data protection reasons.
If the Processor cannot reasonably provide the agreed service without the sub-processor concerned, the Parties may extraordinarily terminate the affected part of the service or the main contract.
6.3 Contractual obligation
The Processor contractually binds sub-processors to data protection obligations that meet the requirements of Art. 28 GDPR.
6.4 Third-party services connected by participants
Services such as Strava, Garmin, Polar, Suunto, Apple Health, Samsung Health or comparable providers may be connected by participants on their own initiative.
With regard to their own services, these providers regularly act as controllers in their own right and are not sub-processors merely because of the connection with Herz-Kilometer.
The Processor processes the data received from these services and required for the challenge in accordance with this agreement.
6.5 Project, donation and payment providers
betterplace.org, NGOs, project sponsors, payment service providers and other recipients may act as controllers in their own right with regard to their respective services.
The data protection role is determined by the specific processing and not solely by the technical integration into the platform.
7 Data subject rights
7.1 Support
The Processor supports the Controller with appropriate technical and organisational measures in handling data subject requests for:
- access,
- rectification,
- erasure,
- restriction of processing,
- data portability,
- objection,
- withdrawal of consent,
- not being subject to solely automated decisions, where applicable.
7.2 Forwarding of requests
If the Processor receives a request that evidently concerns processing carried out on behalf of the Controller, it will:
- forward the request to the Controller, or
- advise the data subject to contact the Controller.
The Processor answers such requests only on the instructions of the Controller or insofar as this is legally required or permitted.
7.3 Responsibility
The Controller remains responsible for:
- verifying identity,
- the legal assessment,
- communication with the data subject,
- compliance with statutory deadlines.
8 Data protection impact assessment and prior consultation
The Processor supports the Controller to a reasonable extent with:
- assessing whether a data protection impact assessment is required,
- carrying out a data protection impact assessment pursuant to Art. 35 GDPR,
- a prior consultation pursuant to Art. 36 GDPR.
This support includes in particular the provision of available information on:
- processing operations,
- categories of data,
- technical and organisational measures,
- sub-processors,
- storage locations,
- deletion and security concepts.
9 Personal data breaches
9.1 Notification
The Processor informs the Controller without undue delay after becoming aware of a personal data breach, insofar as the breach concerns data processed on behalf of the Controller.
9.2 Content of the notification
The notification contains, insofar as available at that time:
- a description of the nature of the breach,
- the categories of data affected,
- the groups of people affected,
- an approximate number of data subjects and records affected,
- the likely consequences,
- measures already taken or recommended,
- a contact point for further enquiries.
Missing information may be provided in stages.
9.3 Further support
The Processor supports the Controller to the necessary and reasonable extent in fulfilling its obligations under Art. 33 and 34 GDPR.
The decision on notifying the supervisory authority or informing data subjects rests with the Controller.
10 Return, export and deletion
10.1 Processing after the end of the contract
After the main contract ends, the Processor processes the data processed on behalf of the Controller only insofar as this is necessary for:
- winding up the contract,
- an agreed data export,
- the return or deletion,
- maintaining technically necessary backups,
- compliance with statutory obligations.
10.2 Export period
The Controller may request an export of the data processed on its behalf for up to 30 days after the end of the contract, insofar as a corresponding export function is not already provided within the platform.
10.3 Format
The Processor provides the data in a structured, commonly used and machine-readable format, insofar as this is technically possible and proportionate.
There is no obligation to transfer proprietary software, algorithms, analytics logic or internal security information.
10.4 Deletion
After the export period has expired or the export has been completed, the Processor deletes the data processed on behalf of the Controller insofar as:
- there is no statutory retention obligation,
- there is no other legal basis,
- the data is not required for the establishment, exercise or defence of legal claims.
10.5 Backups
Data in backup copies is deleted or overwritten as part of the regular backup and overwrite cycles.
Until it is finally overwritten, it is protected against further productive processing.
10.6 Data processed by Herz-Kilometer as controller
Data that Herz-Kilometer processes as a controller in its own right, in particular contract, billing, security or evidence data, is not subject to the Controller’s right of election regarding deletion under this section.
10.7 Evidence
The Processor confirms the deletion to a reasonable extent upon justified request.
11 Evidence and audits
11.1 Evidence
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR.
This may include in particular:
- a description of the technical and organisational measures,
- the list of sub-processors,
- security and data protection concepts,
- audit reports or certificates, where available,
- standardised questionnaires and self-assessments.
11.2 Audits
The Controller may verify compliance with this agreement itself or through an auditor bound to confidentiality.
Audits are to be:
- carried out first by way of a documentation review as a matter of principle,
- announced with reasonable prior notice,
- carried out during normal business hours,
- limited to the necessary scope,
- carried out while protecting operational, business and security secrets.
11.3 On-site audits
On-site audits are permissible only if:
- there is a specific legitimate reason,
- a documentation review is not sufficient,
- the audit does not disproportionately interfere with business operations.
11.4 Costs
The Controller bears the reasonable costs of an audit unless the audit became necessary due to a demonstrated material breach of duty by the Processor.
12 Technical and organisational measures
The Parties agree on the technical and organisational measures described in Annex 1.
The Processor may develop the measures further in line with technical developments and replace them with equivalent or better measures.
The agreed level of security must not be materially reduced as a result.
Material changes that significantly reduce the level of security are communicated to the Controller in advance.
13 International data transfers
13.1 Principle
Personal data is processed within the European Economic Area as a matter of principle, insofar as this is supported by the services used.
13.2 Transfers to third countries
Insofar as personal data is transferred to a third country, the Processor ensures that the statutory requirements of Art. 44 et seq. GDPR are met.
Appropriate safeguards may in particular be:
- an adequacy decision,
- EU standard contractual clauses,
- additional technical and organisational protective measures,
- other legally recognised transfer instruments.
13.3 Information
Information on possible third-country processing can be found in Annex 2 and in the applicable provider information.
14 Liability
14.1 General rule
The liability provisions of the main contract or the terms and conditions apply.
As between the Parties, the Processor is liable for breaches of this agreement in accordance with statutory provisions and the effectively agreed liability rules.
14.2 Art. 82 GDPR
The statutory liability rules under Art. 82 GDPR remain unaffected.
14.3 Responsibility for content and instructions
As between the Parties, the Controller is liable for damages and expenses based on:
- unlawful instructions,
- inadmissible participant lists,
- missing legal bases,
- inadmissible public displays,
- unlawfully used logos, images or texts,
- information obligations that have not been fulfilled,
insofar as the Processor is not responsible for the cause.
15 Final provisions
15.1 Precedence
In the event of contradictions between this agreement and the main contract, this agreement takes precedence with regard to the processing of personal data on behalf of the Controller.
15.2 Amendments
Amendments and additions to this agreement must be made in text form.
This also applies to changes made by way of a new version accepted electronically.
15.3 Invalid provisions
Should individual provisions of this agreement be or become invalid in whole or in part, the validity of the remaining provisions remains unaffected.
The statutory provision replaces the invalid provision.
15.4 Governing law and place of jurisdiction
German law applies.
The place of jurisdiction is, insofar as legally permissible, the registered office of the Processor.
15.5 Electronic conclusion
This agreement is concluded in text form.
Electronic acceptance is documented in particular by:
- organisation ID,
- user ID of the accepting person,
- name and email address of the accepting person,
- time of acceptance,
- accepted DPA version,
- assignment to the main contract or the organisation.
The accepting person confirms that they are authorised to conclude this agreement on behalf of the Controller.
Electronic acceptance
Controller
- Organisation:
- [Name of the organisation]
- Address:
- [Address]
- Represented by:
- [Name and position]
- Date and time of acceptance:
- [Timestamp]
- Version:
- 1.2
Processor
Herz-Kilometer UG (haftungsbeschränkt)
Grüne Trift 123
12557 Berlin
Germany
Annex 1 – Technical and organisational measures
1. Physical access control
- protection of premises and workstations against unauthorised entry,
- access to development and operating environments only by authorised persons,
- screen locks and device protection,
- encryption of suitable work devices,
- secure management of keys and access media.
2. System access control
- individual user accounts,
- role-based permissions,
- password requirements,
- technically supported multi-factor authentication, where available,
- session and token management,
- blocking or withdrawal of access that is no longer required,
- logging of security-relevant events.
3. Data access control
- least-privilege principle,
- role-based access restriction,
- tenant and organisation separation,
- database policies such as row-level security, where technically deployed,
- separate service and administration keys,
- limitation of support access to necessary cases,
- regular review of administrative permissions.
4. Separation control
- logical separation of different organisations and challenges,
- assignment via organisation, tenant or challenge IDs,
- role-based separation of administrators and participants,
- separation of development, test and production environments, where possible,
- no use of productive personal data for testing purposes, insofar as not necessary and legally permissible.
5. Transfer control
- TLS encryption during data transmission,
- secured API connections,
- standardised authorisation procedures such as OAuth,
- secure storage of API keys and secrets,
- access restrictions for exports,
- documented transmission to sub-processors and recipients.
6. Input control and traceability
- technical timestamps,
- logging of material administrative operations, where provided for by the product,
- version control for software changes,
- documented release and change processes,
- storage of the DPA version and time of acceptance,
- assignment of administrative changes to authorised accounts, where technically possible.
7. Assignment control
- contracts with sub-processors,
- review of the data protection suitability of the providers used,
- documented process for changes to sub-processors,
- instruction and support processes,
- commitment of authorised persons to confidentiality.
8. Availability control
- backup and restore procedures,
- monitoring and error surveillance,
- technical alerting for critical events,
- protection against overload and abusive access,
- rate limits and comparable protective measures, where deployed,
- restoration and emergency processes,
- use of the availability measures of the hosting and database providers.
9. Resilience and recovery
- appropriate system architecture,
- regular software and security updates,
- procedures for error analysis,
- restoration of data and services after technical incidents,
- review of critical dependencies.
10. Privacy-friendly default settings
- limitation to necessary data,
- restrictive roles and permissions,
- public display only in accordance with the configuration,
- processing of aggregated data where individual data is not required,
- limitation of the data used for reports and public challenge pages.
11. Encryption and protection of secrets
- transport encryption via TLS,
- encryption of data at rest according to the capabilities of the infrastructure and database provider used,
- storage of passwords exclusively in hashed form,
- no storage of passwords or secrets in plain text,
- secure management of technical secrets.
12. Deletion and retention
- documented deletion processes,
- deletion or anonymisation once the purpose of processing no longer applies,
- regulated end-of-contract and export periods,
- overwriting of backups within regular backup cycles,
- separation of contract data subject to statutory retention from challenge data.
13. Special protective measures for activity data
- processing only of the activity values required for the challenge,
- no processing of complete GPS routes where these are not necessary for the function,
- restrictive access to individual activity data,
- preferred use of aggregated data in reports,
- protection against unauthorised cross-organisation access,
- limited public display in accordance with the Controller’s settings.
Annex 2 – Sub-processors and other recipients
A. Sub-processors
Supabase
Service: database, authentication, storage and edge functions
Purpose: operation of the platform and storage of platform data
Location: Frankfurt am Main, Germany or European Economic Area
Mailjet / Sinch Mailjet
Service: email delivery
Purpose: sending of system, invitation, transactional and report emails
Location: European Union, in particular France
Supabase Auth
Service: authentication-related system communication
Purpose: registration, login, verification and account recovery
Location: European Economic Area, depending on the configuration used
Sentry
Service: error analysis and performance monitoring
Purpose: detection and analysis of technical errors, crashes and performance problems
Location: Frankfurt am Main, Germany or European Economic Area, where configured accordingly
Protection: pseudonymisation and data minimisation, where technically possible
Google Firebase Cloud Messaging
Service: push notifications
Purpose: technical delivery of push messages to mobile devices
Location: third-country processing, in particular in the USA, possible
Safeguards: adequacy decision, EU standard contractual clauses or other appropriate safeguards
B. Only subject to consent or configuration
Google Analytics 4
Service: web analytics
Purpose: analysis of the use of the public website
Use: only with the consent of the respective website visitor
Location: third-country processing, in particular in the USA, possible
Safeguards: adequacy decision, EU standard contractual clauses or other appropriate safeguards
With regard to the public website, Google Analytics is not necessarily used as processing on behalf of the controller of the challenge. Such processing is additionally governed by the Herz-Kilometer privacy policy.
C. Other recipients or controllers in their own right
Depending on the specific use, the following providers or bodies may act as controllers in their own right:
- Strava,
- Garmin,
- Polar,
- Suunto,
- Apple Health,
- Samsung Health,
- other activity providers connected by the participant,
- betterplace.org,
- social projects and NGOs,
- PayPal or other payment service providers,
- Qonto or other financial service providers,
- Microsoft Teams or target systems configured by the Controller.
These bodies are not automatically sub-processors of Herz-Kilometer. Their data protection role depends on the respective service, configuration and contractual relationship.
Data protection contact
Herz-Kilometer UG (haftungsbeschränkt)
Grüne Trift 123
12557 Berlin
Germany
datenschutz@herz-kilometer.de