If you use an external service provider (like Famulor), they are a data processor according to the GDPR. A data processing agreement (DPA) must be concluded, which, among other things, regulates what data is processed and how, that it is not misused for other purposes, and what security measures apply.