Data Processing Agreement (DPA)
Version 1.0 · Last updated 30 July 2026
Agreement under Article 28 GDPR for processing personal tournament data on behalf of customers.
1. Parties and incorporation
The controller is the respective Turnierplan.eu customer. The processor is Markus Müller, trading as Pixel33 Software, An den Gleisen 5, 92224 Amberg, Germany. This DPA supplements the main contract once accepted electronically or otherwise validly incorporated and prevails for commissioned processing.
2. Allocation of roles
The Customer controls personal data entered, uploaded, published or processed for tournaments; Pixel33 Software processes it on instructions. Account administration, billing, payments, own security, contractual communications and own server/access logs are processed under Pixel33 Software’s own responsibility as described in the Privacy Policy.
3. Subject, purpose and duration
Turnierplan.eu is provided for planning, running and publishing tournaments. Operations include collection, storage, display, editing, transmission, backup, export and deletion. Processing lasts for the main contract and until contractual deletion or return.
4. Data and persons
Data may include names, emails, user IDs, roles, team and participant data, images, logos, results, communications and technical usage data. Persons may include users, organisers, participants, minors, coaches, referees, contacts and others entered by the Customer.
5. Instructions and confidentiality
Processing occurs only on documented instructions unless law requires otherwise. The main contract, DPA, settings and authorised user actions constitute instructions. Unlawful instructions are challenged and suspended. Authorised personnel are bound to confidentiality.
6. Security
Measures under Article 32 include HTTPS/TLS, password hashing, role/object access controls, parameterised database queries, security logging, tenant separation, backups, recovery, updates and deletion procedures. Equivalent or better measures may replace them.
7. Sub-processors
STRATO GmbH, Germany, is generally authorised for hosting, servers, databases, storage, backups, technical logs and system email. Sub-processors are bound under Article 28 and material changes are announced in time; the Customer may object for important data-protection reasons.
8. Assistance and breaches
The Processor reasonably assists with data-subject rights, impact assessments, consultations and evidence. Requests are forwarded where the Customer is responsible. Personal-data breaches affecting commissioned data are reported without undue delay with available required information.
9. Audits
Required compliance information is provided. Reviews primarily use documents and certificates. On-site audits are possible with reasonable notice during business hours where documents are insufficient, while protecting other customers, security and trade secrets.
10. Deletion and final terms
After termination, commissioned data is deleted or exported at the Customer’s choice unless law requires retention. Exports should be used before termination. Backups remain restricted until scheduled overwrite. The Processor’s own contract, invoice and payment data is excluded. German law applies without limiting mandatory GDPR rights.
Markus Müller · An den Gleisen 5 · 92224 Amberg · Deutschland
info@turnierplan.eu

