PROWERB processes recipient data for commissioned mailings, prize dispatch and customer correspondence. Purpose, data paths and roles are reviewed before transfer. Where processing on behalf of a controller applies, an Article 28 GDPR DPA defines instructions, safeguards and deletion.
Read on →
Since 1979 · negative corporate CO₂ balance · ISO 9001 & 14001 · EcoVadis Silver
Before data transfer, the mandate’s purpose, roles and data paths are defined. Whether PROWERB, carriers or other parties act as processors or independent controllers depends on their actual tasks. The responsible privacy specialists review the classification and required agreements.

In lettershop and data-handling mandates, data protection is not an add-on service. It's the condition under which all other services take place.
PROWERB CORE, the in-house developed ERP and warehouse management system, runs orders, items and inventory with gapless real-time booking. Recipient lists for campaigns and mailings are imported via the online tool or the MEP platform and assigned to the order. Direct mail dispatch to recipients runs through the Operations Cockpit — documented in the process, traceable for the client. Because the stack is developed in-house, the paths are short: a disclosure or deletion request doesn't wait on a third-party vendor. The external data protection officer oversees the processing, and the whistleblower portal is open at prowerb.hinweisgeberportal.de.
PROWERB operates a shop in a membership context for a nationwide statutory health insurer. Bitburger’s 2025 summer campaign combined prize dispatch with telephone and email service. Since 2021, event ticketing and hospitality have been part of the Coca-Cola mandate. These different tasks each require an agreed data and role assessment.
The process is the same for every data-sensitive mandate, whether a mailing campaign, sweepstakes dispatch, or ongoing shop operations.
Data processing agreement before the first record: purposes, instructions, sub-processors and deletion rules are set.
Recipient data arrives via the agreed path — SFTP, online tool, MEP platform or interface — and is assigned to the order.
Kitting & assembly, personalization, dispatch: exclusively for the commissioned purpose, tracked in the system.
Every step exists as a tracked process — with track-and-trace and reporting for the client, retrievable around the clock.
Deletion or return of the data on instruction. The processing itself stays provable — the data doesn't stay in the system longer than necessary.
A DPA alone doesn't send a mailing — it makes possible the mandates in which recipient data is processed.
Yes, where the mandate includes processing on behalf of a controller. The responsible privacy specialists clarify roles, contract, instructions and deletion periods before transfer.
An external one: Daseco GmbH, attorney Michael Bock LL.M., Willich. Named, reachable and referenceable in the DPA.
Via agreed channels: SFTP transfer, import via online tool or MEP platform, direct import via interface — for the Bitburger summer campaign, for instance, directly from the sweepstakes app.
It is deleted or returned on the client's instruction. The processing itself stays documented as a process, the data itself doesn't stay in the system longer than necessary.
Providers, tasks and data paths are identified for the mandate. Their status as subprocessors or independent controllers is reviewed by specialists; request the required documents through the Trust Center.
Yes. For a nationwide statutory health insurer, PROWERB runs the web shop in the member context — the healthcare industry, vetted and run accordingly.
Request the DPA, technical and organisational measures and information about subprocessors for your intended scope through the Trust Center. Specify data types, purpose, recipients and retention needs; the responsible contacts then coordinate review and approval.