ERPM

Data processing agreement

This is a translation for convenience. The German version is legally binding.

Data Processing Agreement (DPA)

Between the customer who uses ERPM with an online account

(hereinafter the controller),

and GMI GmbH, Theodor-Rehbock-Straße 3, 76131 Karlsruhe, Germany

(hereinafter the processor).

This agreement is tailored to ERPM and names the procedures actually
in use; it does not replace legal advice in the individual case.

1. Subject matter, roles and scope

(1) The processor provides the controller with the ERPM software as a

service: a server account (backend), the operator and customer portal,

and the synchronisation of the ERPM app with that account.

(2) The controller alone decides on the purposes and means of the

processing of its data. The processor processes personal data

exclusively on the controller's behalf and on its instructions.

(3) This agreement applies only to use with an online account. If

ERPM is operated purely locally (without signing in to a server

account), no personal data leaves the controller's device; no

processing on behalf then takes place.

(4) Not covered by this agreement is the processing of the

controller's data for the establishment and performance of the parties'

own contractual relationship (company name, address, contact person,

invoicing and payment data, licence and scope of use). In that respect

the processor is itself the controller; its privacy policy applies.

2. Duration

The agreement begins upon acceptance and runs for as long as a server

account of the controller exists. It ends with the deletion of the

tenant; clause 11 remains unaffected.

3. Nature and purpose of the processing

(1) The purpose is the operation of the functions offered by ERPM for

the controller — nothing beyond that. The data are not used for the

processor's own purposes, in particular not for the development or

training of models.

(2) The processing operations are: collection via the app and the

portals, storage in the server database and the file store, retrieval

and transmission to the controller's devices during synchronisation,

alteration, erasure, and the generation of documents, reports and

export files.

(3) Transmission to third parties takes place only to the further

processors named in Annex 2, and only in so far as the controller uses

the respective function.

4. Type of data and categories of data subjects

Type of dataExamples
Master data of business partnersCompany, contact person, address, e-mail, telephone, VAT ID
Transaction and business dataQuotes, orders, invoices, deliveries, payments, notes
Employee dataName, function, working and project times, leave, shifts, pay types
User accountsE-mail, password hash, two-factor secret, roles, sessions
Documents and filesUploaded PDFs, images, attachments
Communication dataMailbox contents, sent messages, recipients
Log dataTime, user, operation, IP address at sign-in
Location-related dataDelivery and tour addresses, coordinates, in so far as used

Categories of data subjects: customers, prospects, suppliers and their

contact persons, employees and applicants of the controller, users of

the accounts it has created.

Special categories (Art. 9 GDPR) are not the subject of the

service. Free-text fields (e.g. notes, sickness periods in time

recording) may in individual cases contain health data; the controller

decides whether to record such entries and bears the legal basis for

doing so.

5. Instructions (Art. 28(3)(a))

(1) The processor processes the data only on documented instructions.

This agreement, the settings the controller makes in the application,

and instructions in text form to info@gmitso.de count as instructions.

(2) If the processor considers an instruction to be unlawful, it shall

notify this without delay and may suspend its execution until

confirmed.

(3) Where it is obliged to process by Union or national law, it shall

notify this before the processing, unless that law prohibits such

notification on important grounds of public interest.

6. Confidentiality (point (b))

Persons engaged in the processing are bound to confidentiality and have

been informed of the data protection requirements. The obligation

continues beyond the end of their activity.

7. Technical and organisational measures (point (c), Art. 32)

(1) The measures are described in Annex 1. They correspond to the

state of the art and are updated; the level of protection may not be

reduced in the process.

(2) The processor may update Annex 1 without amending this agreement.

It shall notify material changes.

8. Further processors (point (d))

(1) The controller grants general authorisation for the engagement

of further processors. Those engaged at the time of conclusion are

listed in Annex 2 with name, service and place of processing.

(2) Before engaging a further processor or replacing an existing one,

the processor shall give notice in text form at least four weeks in

advance. Within that period the controller may object on important

data protection grounds. If it objects, either party may terminate the

agreement with effect from the beginning of the change.

(3) The same obligations as apply here are agreed with every further

processor.

(4) Functions that pass data to third parties (Annex 2, Section B) are

used only at the controller's instigation. If the controller

deposits its own credentials for that purpose, the third party acts on

the controller's behalf; the processor merely forwards the data.

9. Assistance with data subject rights (point (e))

(1) The service provides the controller with the means to answer

requests from data subjects itself:

CSV and ZIP file in the app and in the portal — even without a valid

licence;

deletion is propagated to all of the controller's devices; deleting

the tenant removes the server data completely;

deactivated and records locked.

(2) If a data subject approaches the processor directly, the processor

forwards the request without delay and does not answer it itself.

Further assistance is provided to a reasonable extent.

10. Assistance with the controller's obligations (point (f))

(1) The processor assists with the obligations under Art. 32 to 36

GDPR.

(2) Personal data breaches (Art. 33 GDPR) are reported without

delay, at the latest 48 hours after becoming aware, in text form to

the address deposited by the controller. The report contains what is

known at that time: the nature of the incident, the types of data

affected and the approximate number of data subjects, the likely

consequences and the measures taken. Missing details are supplied

later. The deadline is shorter than the controller's own notification

deadline under Art. 33(1) GDPR (72 hours), so that it retains time for

its own notification.

(3) It maintains a record of all categories of processing under

Art. 30(2) and makes it available on request.

11. Erasure and return (point (g))

(1) After the end of the agreement the processor erases the data or

returns them — the controller chooses. Before erasure the controller

secures its data itself using the export functions; the processor gives

notice of this before the tenant is deleted.

(2) Deleting the tenant removes the data from the server database and

the file store. Backup copies drop out of the stock on a rolling

basis: the database backups and the file backups are deleted

automatically after seven days. Because the clean-up runs daily,

the oldest copy may be up to eight days old. Until then the data remain

contained in those copies and are not processed further.

(3) Statutory retention obligations remain unaffected. The processor

points out that retention obligations apply to the controller (in

particular §§ 147 AO, 257 HGB, GoBD; for cash register data § 146a AO)

— it must secure its data before erasure.

(4) Data that the processor itself must retain (invoices for its own

services, log data for the defence against attacks) are kept separately

and only for that purpose.

12. Evidence and review (point (h))

(1) The processor demonstrates compliance by means of the description

in Annex 1, a self-assessment and, where available, reports or

certificates of its service providers.

(2) If that is not sufficient, the controller may, upon four weeks'

notice, during business hours, at most once per calendar year and

without disrupting operations, carry out or have carried out an

inspection. The inspector may not be a competitor and is bound to

secrecy. Where there is specific cause (an order by an authority, a

reported breach), the notice period and the frequency limit do not

apply.

(3) Effort beyond the first day of inspection may be invoiced.

13. Place of processing

(1) The processing takes place within the European Union. The

server location is named in Annex 2.

(2) A transfer to a third country takes place only if the controller

uses a function whose provider processes there (Annex 2, Section B).

The basis is then an adequacy decision or standard contractual clauses

pursuant to Art. 46(2)(c) GDPR; the services concerned are marked in

Annex 2.

14. Liability and final provisions

(1) Art. 82 GDPR applies to liability vis-à-vis third parties.

(2) Amendments require text form. In the event of conflicts this

agreement takes precedence over the other agreements in so far as the

processing of personal data is concerned.

(3) If a provision is invalid, the remainder of the agreement remains

valid.

(4) German law applies. The place of jurisdiction is, in so far as

permissible, the registered seat of the processor.

(5) This agreement is concluded in the German language; the German

version is authoritative.


Annex 1 — Technical and organisational measures

As at: 5 October 2026

Confidentiality

Physical access. The server is operated in the data centre of the

provider named in Annex 2; access control, video surveillance and

visitor rules lie with that provider and are evidenced by it.

System access. Sign-in with e-mail and password; passwords are

stored exclusively as an argon2id hash. Optional two-factor sign-in

(TOTP). Access tokens are short-lived (15 minutes); refresh tokens

rotate and reuse is detected, whereupon the entire session chain is

invalidated. Accounts lock for 15 minutes after five failed attempts.

New accounts must confirm their e-mail address before sign-in is

possible. Interface keys are held only as a hash. Administrator access

to the server is exclusively via SSH key; password sign-in is switched

off, and a firewall and fail2ban are active.

Data access. Separation of tenants at database level with

server-side checking of every request. Roles online

(OWNER/ADMIN/MEMBER/VIEWER) and locally (admin/employee/read-only) with

hard write locks; accounting data are writable only for OWNER and

ADMIN. The operator's accesses to tenant data are logged.

Separation. Production and test environments are separate. Every

tenant has its own records and its own file area.

Integrity

Transfer. Transport exclusively via TLS. Sensitive fields (contact

data, notes, credentials for mailboxes and services) are held in the

database encrypted with AES-256-GCM; uploaded files are stored

encrypted. On the controller's device the local database is held with

SQLCipher (AES-256), the key in the operating system's key store.

Input. Logging of business operations (sign-ins, write accesses

during synchronisation, file uploads and downloads, mail dispatch,

licence changes) with user, time and operation. Cash register

operations are additionally recorded in an unalterable manner pursuant

to § 146a AO.

Availability and resilience

Daily backup of the database and of the uploaded files, retention

seven days (clean-up daily, hence the oldest copy may be up to eight

days old), restoration tested. Before every deployment of a new version

an additional backup is taken and the last three versions are kept, so

that a return is possible. Monitoring of the service with a health

check. Limiting of requests per address (rate limiting), security

headers and a strict Content Security Policy.

Procedures for review and evaluation

Automated checks before every release; dependencies are checked for

known vulnerabilities. Permission and tenant separation are secured by

dedicated test cases. Data protection by default: the application runs

entirely locally without an online account, and synchronisation is a

deliberate decision of the controller.


Annex 2 — Further processors

As at: 5 October 2026

The details in Section A were read off the running system: the host

name of the server and the IP assignment for the data centre, and the

stored server configuration for mail dispatch. If the processor changes

one of these service providers, clause 8(2) applies — notice four weeks

in advance.

A. Always engaged

Service providerServicePlace of processing
Contabo GmbH, MunichServer and data centre (ERPM backend, database, file store, backups)EU — data centre Lauterbourg, France
Hostinger International Ltd.Dispatch of account and system messages (confirmations, invitations, invoices, replies to enquiries)EU

B. Only when the respective function is used

Service providerFunctionDataPlace
Apple Inc. (APNs)Push messages to iOS devicesDevice identifier, notification textUSA — adequacy decision / standard contractual clauses
Google LLC (FCM)Push messages to Android devicesDevice identifier, notification textUSA — adequacy decision / standard contractual clauses
Google Maps Platform (Routes API)Tour planning, route optimisationAddresses and coordinates of the intermediate stopsUSA — only if the operator engages this provider; alternatively a self-hosted routing engine without transfer to third parties
Twilio Inc.SMS and WhatsApp dispatchTelephone number and content of the messageUSA — only when used; with the controller's own account Twilio acts on the controller's behalf
Provider of the AI assistant (OpenAI or a service named by the controller with the same interface)Assistance functionsThe content of the respective requestdepending on the provider — only if the controller deposits its own access key; without a key no transfer takes place
Microsoft Corporation (Entra ID)Enterprise sign-in (SSO)Sign-in data, identifieronly if the controller sets up SSO

Not a processor under this agreement: Stripe Payments Europe Ltd.

handles the payments for the controller's licence. That processing

concerns the parties' own contractual relationship (clause 1(4)), not

the data that the controller maintains in ERPM.

Mailbox function: If the controller connects its own mailbox

(IMAP/SMTP), its mail provider remains its own service provider. ERPM

stores the credentials encrypted and retrieves the messages on the

controller's behalf.