Data processing agreement
Agreement under Article 28 GDPR · Version: 7 September 2026
Scope notice: This agreement is intended for the B2B case where a customer has admin-tools.de process diagnostic data of its employees, customers or other end users. Use of the public website or demo does not automatically create a processor relationship.
Windows and Linux diagnostics
Processing may include diagnostic data from Windows and Linux systems. Depending on the selection and target, the Linux path may process the hostname, Linux version, kernel, username, process names, network, DNS, routing, neighbour and Wi-Fi data. The customer determines the scope through checks and targets and must ensure authorisation for the examination and information of data subjects.
Subject matter of processing
The subject matter is the initial technical diagnosis of supported Windows and Linux systems, network connections and Wi-Fi environments. Customer-selected checks and targets are run, logs are transferred, processed, displayed, made available for download and deleted within the application. The customer determines the specific scope through the selected checks and targets.
Duration of processing
Processing begins when a diagnostic log is submitted and ends when the associated data is deleted on the customer’s instruction, when the configured retention period expires or when the engagement ends, unless a statutory retention obligation applies. For registered users, the application currently provides for 90 days by default and allows settings from 1 to a maximum of 300 days. Uploadeded demo diagnostic data has a retention period of 7 days from upload; deletion takes place during the next server-side cleanup run after expiry. The public example result uses static, fictitious sample data and is not subject to this upload deletion period.
Nature and purpose of processing
Processing serves the initial technical diagnosis and documentation of Windows and Linux systems, network connections and Wi-Fi environments. The application creates operating-system-specific diagnostic tools, accepts logs manually or automatically, structures selected values and makes them available to the authorised account. It is not intended for general monitoring, a complete security assessment or automatic repair.
Categories of personal data
Depending on the selection and log content, the following may be processed in particular: computer name, logged-in user, operating-system and hardware data, processes and process users, drivers and modules, network shares, IP and MAC addresses, DHCP, DNS, routing, connection and neighbour data, target and remote addresses, ping and traceroute data, Wi-Fi information, Wi-Fi profile names, proxy status, and technical errors and raw log data. Linux logs may additionally contain the Linux version, kernel, CPU, memory, PCI information and NetworkManager profile names. User-entered targets may contain internal hostnames and IP addresses.
Categories of data subjects
Data subjects may include employees and other users of examined Windows or Linux systems, customers or other end users of the customer, and persons appearing in process, network, DNS, Wi-Fi or other log content. The customer determines the specific categories through diagnostic targets and selected checks.
Instructions
admin-tools.de generally processes diagnostic data on the basis of the customer’s documented instructions. The customer controls the selected checks, targets, upload mode and retention period through the application. Statutory processing obligations remain unaffected; where legally permitted, the customer is informed before processing.
Confidentiality
Persons handling diagnostic data on behalf of admin-tools.de may process it only to the extent necessary and for the agreed purposes.
Technical and organisational measures
Based on the currently visible implementation, application-level measures include HTTPS/TLS for automatic uploads, individual 64-character upload tokens, server-side token checks against stored SHA-256 hashes (upload tokens are also contained in the generated batch and stored raw log), HttpOnly, SameSite and Secure cookies when HTTPS is used, CSRF protection for session-based forms and token checks at the automatic upload endpoint, password-based login with password hashing, ownership and access controls for user results, upload size limits, validation of genuine uploads, server-generated or protected filenames, storage of diagnostic files outside the publicly accessible web root, path and access protection, and cascading deletion of related data. Regular administrative access to the production environment is performed by the operator. Technical access by the hosting provider is generally possible as part of hosting operations. Administrative accounts are password-protected; MFA or 2FA protection is not promised. To the current knowledge, there is no further regular group of persons with administrative access. Administrative access is limited to what is required for administration and operation.
Application security updates are reviewed and implemented on an occasion-related basis. The technical and organisational measures of the applicable Hostinger DPA apply to the hosting infrastructure. Hostinger creates daily backups in France and currently retains them for seven days. Backup protection is governed by the applicable Hostinger DPA; the application does not control the backup infrastructure itself. A complete restore from a backup has not yet been tested systematically. No specific RTO, RPO or guaranteed recovery time is therefore promised. HTTPS/TLS protects data in transit. Specific encryption of application data at rest or of backups has not been verified and is not claimed. There is currently no systematic regular effectiveness review of all TOMs. Security-relevant application safeguards are reviewed manually in part and on an occasion-related basis when changes are made, in particular access control, token validation, CSRF protection, upload validation and deletion logic. The audit and security measures of the Hostinger DPA apply to the hosting infrastructure.
Sub-processors
Hostinger acts as processor for the shared hosting of the application and the mail environment provided with it. The application uses a MariaDB/MySQL connection, local storage paths and the mail delivery available on the server. Hostinger may use further subprocessors in connection with its services under the applicable Data Processing Addendum. The application does not name or control these subprocessors individually.
Email communication
The application sends system emails using the PHP mail() function and the mail environment provided by the hosting provider. The emails may include account activation information, account deletion confirmation links, usernames, email addresses and, for upload notifications, technical metadata such as IP address, user agent, filename, file size, batch ID, timestamp, an indication of whether the upload was authenticated and a result link. Diagnostic files and their contents are not transmitted by email. The application does not itself control the specific technical mail transport within the hosting and mail infrastructure. Where Hostinger or subprocessors engaged by Hostinger process personal data for this purpose, the relevant provisions of the applicable Hostinger DPA apply.
Assistance with data subject rights
Within its available technical capabilities, admin-tools.de supports the customer by displaying, downloading and manually deleting individual diagnostic records. Where existing diagnostic data can be located, provided or deleted, admin-tools.de supports the customer in handling data-subject requests. A general export, search or data-subject-rights management function is not implemented. The customer remains responsible for communication with data subjects, examining requests and deciding whether they are justified.
Assistance with personal data breaches
If admin-tools becomes aware of an incident affecting the controller’s personal data, admin-tools informs the controller without undue delay after becoming aware of it through the agreed contact method or the contact method recorded in the relevant agreement. The central contact address of admin-tools for data-protection and security incidents is info@admin-tools.de. The information available at the time of notification is provided as appropriate. Within its available technical capabilities, admin-tools supports the controller in assessing the incident and fulfilling its data-protection obligations. No 24/7 availability or blanket commitment to conduct its own forensic investigation is owed. The controller remains responsible for its own statutory notification and information duties. If the controller becomes aware of a relevant incident in connection with admin-tools, the controller also informs admin-tools without undue delay through the central contact address.
Deletion or return of data
The customer can delete individual results through the application. The customer may also request deletion of their user account in their profile. As a safeguard, a time-limited confirmation link is sent to the registered email address. Only explicit final confirmation on the linked page triggers account deletion. Upon successful completion, the account, its saved settings and diagnostic configurations, and all assigned diagnostic data, including batch records without uploads, stored diagnostic files, raw logs and structured result data, are deleted from the production database and associated file storage of the application. Restoration within the application is not provided. The customer must access or download any required data through the available functions before this confirmation. Statutory obligations remain unaffected. The database record is removed only after the associated file has been deleted or confirmed absent; related result data is deleted through the intended foreign-key relationships. Errors are logged and affected records remain available for follow-up. File and database deletion are not atomic; after successful file deletion, database data may remain in the event of a database error until a successful retry. The cleanup script deletes diagnostic data due under the configured retention periods; its regular execution depends on server operations. Before the data-processing relationship ends, the customer may access or download existing diagnostic data through the available functions. After the data-processing relationship ends, remaining diagnostic data is deleted according to the retention period agreed for the relevant customer, unless statutory retention obligations prevent this. A separate complete export of all data is not currently provided. The deletion functions of the application do not remove copies already downloaded to user devices, previously sent emails or technical server and mail logs; their retention is governed by the respective operations and applicable obligations. Hostinger creates daily backups in France and currently retains them for seven days. The application cannot control the deletion of individual data from existing Hostinger backups; immediate removal from all backups is not promised. The applicable Hostinger DPA governs processing after termination.
Audit and inspection rights
The controller may review compliance with the data-protection obligations of admin-tools to a reasonable extent. Available information, documentation and evidence are used first. Audits are conducted with reasonable prior notice during usual business hours, unless a specific risk or special circumstance justifies shorter notice. Audits must not unreasonably impair ongoing operations or infrastructure security. Security and business secrets and data of other customers must be protected. A permanent audit portal is not promised. On-site audits or audits involving significant additional effort must be agreed in advance. Reasonable, verifiable additional costs of exceptionally extensive audits may be charged to the controller.
Use of further processors
The controller grants general authorisation for the engagement of further processors. A further processor may be engaged only if the data-protection requirements are complied with. The controller is informed of the intended addition or replacement of a further processor and may object with reasons within a reasonable period on important data-protection grounds. If no reasoned objection is made within that period, the change is deemed approved. admin-tools remains responsible to the controller for compliance with data-protection obligations by engaged further processors.
International transfers
According to the known infrastructure information, the application host is located in Frankfurt am Main, Germany. Daily backups are located in France and are currently retained for seven days. Further processing by Hostinger or subprocessors engaged by Hostinger is governed by the applicable Hostinger DPA. Where third-country transfers take place under that DPA, the safeguards provided there apply, in particular Standard Contractual Clauses where applicable. The application code does not establish that a specific third-country transfer currently takes place for admin-tools.de.
Term
This data processing agreement applies for the duration of processing diagnostic data on behalf of the customer. It begins when processing on behalf of the customer starts within the relevant business relationship and ends when that processing has been fully terminated, subject to statutory retention obligations.
The parties, contract start date, underlying agreement, notice periods and contact persons are specified in the relevant contractual relationship when the agreement is concluded. The central contact address of admin-tools.de for organisational, data-protection and security matters is info@admin-tools.de.
Responsibilities of customer and admin-tools.de
The customer determines the purposes and means of processing, selects checks and targets, ensures authorisation for the diagnosis, informs end users, issues instructions and verifies the lawfulness of processing. admin-tools.de provides the technical service according to instructions, limits processing to the agreed purpose, protects access according to the available security standard and deletes data under the agreed or technically configured periods. Both parties must promptly report detected errors and personal data breaches through the agreed contact.
Related legal information
Legal notice · Privacy policy · Terms of use · Software and diagnostic licence