Data processing agreement
This is a translation for convenience. The German version is legally binding.
Data Processing Agreement (DPA)
Between the customer who uses ERPM with an online account
(hereinafter the controller),
and GMI GmbH, Theodor-Rehbock-Straße 3, 76131 Karlsruhe, Germany
(hereinafter the processor).
This agreement is tailored to ERPM and names the procedures actually
in use; it does not replace legal advice in the individual case.
1. Subject matter, roles and scope
(1) The processor provides the controller with the ERPM software as a
service: a server account (backend), the operator and customer portal,
and the synchronisation of the ERPM app with that account.
(2) The controller alone decides on the purposes and means of the
processing of its data. The processor processes personal data
exclusively on the controller's behalf and on its instructions.
(3) This agreement applies only to use with an online account. If
ERPM is operated purely locally (without signing in to a server
account), no personal data leaves the controller's device; no
processing on behalf then takes place.
(4) Not covered by this agreement is the processing of the
controller's data for the establishment and performance of the parties'
own contractual relationship (company name, address, contact person,
invoicing and payment data, licence and scope of use). In that respect
the processor is itself the controller; its privacy policy applies.
2. Duration
The agreement begins upon acceptance and runs for as long as a server
account of the controller exists. It ends with the deletion of the
tenant; clause 11 remains unaffected.
3. Nature and purpose of the processing
(1) The purpose is the operation of the functions offered by ERPM for
the controller — nothing beyond that. The data are not used for the
processor's own purposes, in particular not for the development or
training of models.
(2) The processing operations are: collection via the app and the
portals, storage in the server database and the file store, retrieval
and transmission to the controller's devices during synchronisation,
alteration, erasure, and the generation of documents, reports and
export files.
(3) Transmission to third parties takes place only to the further
processors named in Annex 2, and only in so far as the controller uses
the respective function.
4. Type of data and categories of data subjects
| Type of data | Examples |
|---|---|
| Master data of business partners | Company, contact person, address, e-mail, telephone, VAT ID |
| Transaction and business data | Quotes, orders, invoices, deliveries, payments, notes |
| Employee data | Name, function, working and project times, leave, shifts, pay types |
| User accounts | E-mail, password hash, two-factor secret, roles, sessions |
| Documents and files | Uploaded PDFs, images, attachments |
| Communication data | Mailbox contents, sent messages, recipients |
| Log data | Time, user, operation, IP address at sign-in |
| Location-related data | Delivery and tour addresses, coordinates, in so far as used |
Categories of data subjects: customers, prospects, suppliers and their
contact persons, employees and applicants of the controller, users of
the accounts it has created.
Special categories (Art. 9 GDPR) are not the subject of the
service. Free-text fields (e.g. notes, sickness periods in time
recording) may in individual cases contain health data; the controller
decides whether to record such entries and bears the legal basis for
doing so.
5. Instructions (Art. 28(3)(a))
(1) The processor processes the data only on documented instructions.
This agreement, the settings the controller makes in the application,
and instructions in text form to info@gmitso.de count as instructions.
(2) If the processor considers an instruction to be unlawful, it shall
notify this without delay and may suspend its execution until
confirmed.
(3) Where it is obliged to process by Union or national law, it shall
notify this before the processing, unless that law prohibits such
notification on important grounds of public interest.
6. Confidentiality (point (b))
Persons engaged in the processing are bound to confidentiality and have
been informed of the data protection requirements. The obligation
continues beyond the end of their activity.
7. Technical and organisational measures (point (c), Art. 32)
(1) The measures are described in Annex 1. They correspond to the
state of the art and are updated; the level of protection may not be
reduced in the process.
(2) The processor may update Annex 1 without amending this agreement.
It shall notify material changes.
8. Further processors (point (d))
(1) The controller grants general authorisation for the engagement
of further processors. Those engaged at the time of conclusion are
listed in Annex 2 with name, service and place of processing.
(2) Before engaging a further processor or replacing an existing one,
the processor shall give notice in text form at least four weeks in
advance. Within that period the controller may object on important
data protection grounds. If it objects, either party may terminate the
agreement with effect from the beginning of the change.
(3) The same obligations as apply here are agreed with every further
processor.
(4) Functions that pass data to third parties (Annex 2, Section B) are
used only at the controller's instigation. If the controller
deposits its own credentials for that purpose, the third party acts on
the controller's behalf; the processor merely forwards the data.
9. Assistance with data subject rights (point (e))
(1) The service provides the controller with the means to answer
requests from data subjects itself:
- Access and portability (Art. 15, 20): complete export as Excel,
CSV and ZIP file in the app and in the portal — even without a valid
licence;
- Rectification (Art. 16): all master data can be edited;
- Erasure (Art. 17): individual records can be deleted, and the
deletion is propagated to all of the controller's devices; deleting
the tenant removes the server data completely;
- Restriction and objection (Art. 18, 21): accounts can be
deactivated and records locked.
(2) If a data subject approaches the processor directly, the processor
forwards the request without delay and does not answer it itself.
Further assistance is provided to a reasonable extent.
10. Assistance with the controller's obligations (point (f))
(1) The processor assists with the obligations under Art. 32 to 36
GDPR.
(2) Personal data breaches (Art. 33 GDPR) are reported without
delay, at the latest 48 hours after becoming aware, in text form to
the address deposited by the controller. The report contains what is
known at that time: the nature of the incident, the types of data
affected and the approximate number of data subjects, the likely
consequences and the measures taken. Missing details are supplied
later. The deadline is shorter than the controller's own notification
deadline under Art. 33(1) GDPR (72 hours), so that it retains time for
its own notification.
(3) It maintains a record of all categories of processing under
Art. 30(2) and makes it available on request.
11. Erasure and return (point (g))
(1) After the end of the agreement the processor erases the data or
returns them — the controller chooses. Before erasure the controller
secures its data itself using the export functions; the processor gives
notice of this before the tenant is deleted.
(2) Deleting the tenant removes the data from the server database and
the file store. Backup copies drop out of the stock on a rolling
basis: the database backups and the file backups are deleted
automatically after seven days. Because the clean-up runs daily,
the oldest copy may be up to eight days old. Until then the data remain
contained in those copies and are not processed further.
(3) Statutory retention obligations remain unaffected. The processor
points out that retention obligations apply to the controller (in
particular §§ 147 AO, 257 HGB, GoBD; for cash register data § 146a AO)
— it must secure its data before erasure.
(4) Data that the processor itself must retain (invoices for its own
services, log data for the defence against attacks) are kept separately
and only for that purpose.
12. Evidence and review (point (h))
(1) The processor demonstrates compliance by means of the description
in Annex 1, a self-assessment and, where available, reports or
certificates of its service providers.
(2) If that is not sufficient, the controller may, upon four weeks'
notice, during business hours, at most once per calendar year and
without disrupting operations, carry out or have carried out an
inspection. The inspector may not be a competitor and is bound to
secrecy. Where there is specific cause (an order by an authority, a
reported breach), the notice period and the frequency limit do not
apply.
(3) Effort beyond the first day of inspection may be invoiced.
13. Place of processing
(1) The processing takes place within the European Union. The
server location is named in Annex 2.
(2) A transfer to a third country takes place only if the controller
uses a function whose provider processes there (Annex 2, Section B).
The basis is then an adequacy decision or standard contractual clauses
pursuant to Art. 46(2)(c) GDPR; the services concerned are marked in
Annex 2.
14. Liability and final provisions
(1) Art. 82 GDPR applies to liability vis-à-vis third parties.
(2) Amendments require text form. In the event of conflicts this
agreement takes precedence over the other agreements in so far as the
processing of personal data is concerned.
(3) If a provision is invalid, the remainder of the agreement remains
valid.
(4) German law applies. The place of jurisdiction is, in so far as
permissible, the registered seat of the processor.
(5) This agreement is concluded in the German language; the German
version is authoritative.
Annex 1 — Technical and organisational measures
As at: 5 October 2026
Confidentiality
Physical access. The server is operated in the data centre of the
provider named in Annex 2; access control, video surveillance and
visitor rules lie with that provider and are evidenced by it.
System access. Sign-in with e-mail and password; passwords are
stored exclusively as an argon2id hash. Optional two-factor sign-in
(TOTP). Access tokens are short-lived (15 minutes); refresh tokens
rotate and reuse is detected, whereupon the entire session chain is
invalidated. Accounts lock for 15 minutes after five failed attempts.
New accounts must confirm their e-mail address before sign-in is
possible. Interface keys are held only as a hash. Administrator access
to the server is exclusively via SSH key; password sign-in is switched
off, and a firewall and fail2ban are active.
Data access. Separation of tenants at database level with
server-side checking of every request. Roles online
(OWNER/ADMIN/MEMBER/VIEWER) and locally (admin/employee/read-only) with
hard write locks; accounting data are writable only for OWNER and
ADMIN. The operator's accesses to tenant data are logged.
Separation. Production and test environments are separate. Every
tenant has its own records and its own file area.
Integrity
Transfer. Transport exclusively via TLS. Sensitive fields (contact
data, notes, credentials for mailboxes and services) are held in the
database encrypted with AES-256-GCM; uploaded files are stored
encrypted. On the controller's device the local database is held with
SQLCipher (AES-256), the key in the operating system's key store.
Input. Logging of business operations (sign-ins, write accesses
during synchronisation, file uploads and downloads, mail dispatch,
licence changes) with user, time and operation. Cash register
operations are additionally recorded in an unalterable manner pursuant
to § 146a AO.
Availability and resilience
Daily backup of the database and of the uploaded files, retention
seven days (clean-up daily, hence the oldest copy may be up to eight
days old), restoration tested. Before every deployment of a new version
an additional backup is taken and the last three versions are kept, so
that a return is possible. Monitoring of the service with a health
check. Limiting of requests per address (rate limiting), security
headers and a strict Content Security Policy.
Procedures for review and evaluation
Automated checks before every release; dependencies are checked for
known vulnerabilities. Permission and tenant separation are secured by
dedicated test cases. Data protection by default: the application runs
entirely locally without an online account, and synchronisation is a
deliberate decision of the controller.
Annex 2 — Further processors
As at: 5 October 2026
The details in Section A were read off the running system: the host
name of the server and the IP assignment for the data centre, and the
stored server configuration for mail dispatch. If the processor changes
one of these service providers, clause 8(2) applies — notice four weeks
in advance.
A. Always engaged
| Service provider | Service | Place of processing |
|---|---|---|
| Contabo GmbH, Munich | Server and data centre (ERPM backend, database, file store, backups) | EU — data centre Lauterbourg, France |
| Hostinger International Ltd. | Dispatch of account and system messages (confirmations, invitations, invoices, replies to enquiries) | EU |
B. Only when the respective function is used
| Service provider | Function | Data | Place |
|---|---|---|---|
| Apple Inc. (APNs) | Push messages to iOS devices | Device identifier, notification text | USA — adequacy decision / standard contractual clauses |
| Google LLC (FCM) | Push messages to Android devices | Device identifier, notification text | USA — adequacy decision / standard contractual clauses |
| Google Maps Platform (Routes API) | Tour planning, route optimisation | Addresses and coordinates of the intermediate stops | USA — only if the operator engages this provider; alternatively a self-hosted routing engine without transfer to third parties |
| Twilio Inc. | SMS and WhatsApp dispatch | Telephone number and content of the message | USA — only when used; with the controller's own account Twilio acts on the controller's behalf |
| Provider of the AI assistant (OpenAI or a service named by the controller with the same interface) | Assistance functions | The content of the respective request | depending on the provider — only if the controller deposits its own access key; without a key no transfer takes place |
| Microsoft Corporation (Entra ID) | Enterprise sign-in (SSO) | Sign-in data, identifier | only if the controller sets up SSO |
Not a processor under this agreement: Stripe Payments Europe Ltd.
handles the payments for the controller's licence. That processing
concerns the parties' own contractual relationship (clause 1(4)), not
the data that the controller maintains in ERPM.
Mailbox function: If the controller connects its own mailbox
(IMAP/SMTP), its mail provider remains its own service provider. ERPM
stores the credentials encrypted and retrieves the messages on the
controller's behalf.