Data Processing Agreement
Agreement on processing on behalf of a controller pursuant to Art. 28 GDPR
1. Parties
Processor:
smiit GmbH, Reiherweg 96, 89584 Ehingen, Germany
Email: kontakt@smiit.de
Phone: +49 160 4073198
Data protection officer: Noah Neßlauer
Controller: the customer using smiit Analytics under the Terms of Service (the “Controller”).
This agreement specifies the data protection obligations of the parties for the processing of personal data in connection with the provision and operation of smiit Analytics.
2. Subject matter and duration of processing
The subject matter of the processing is the provision of the services described in the Terms of Service and the applicable individual agreement — in particular connecting the Controller's data sources, building and operating the data model, and providing dashboards, reports and AI-assisted analytics features.
The duration of the processing corresponds to the term of the underlying main agreement. It ends upon termination of that agreement, unless statutory retention obligations require longer storage.
3. Nature and purpose of processing
Processing is carried out solely for the purpose of delivering the contractually agreed services. The Processor does not process the data for its own purposes.
The processing comprises in particular the following activities:
- Collection, recording and retrieval of data from the source systems released by the Controller
- Storage, organisation and structuring of the data within the data model
- Analysis, aggregation and visualisation of the data in dashboards and reports
- Processing through AI-assisted analytics and assistance features, where enabled by the Controller
- Erasure and destruction of data on instruction or after the end of the contract
4. Types of personal data
Depending on the source systems connected by the Controller, the following types of data may be processed:
- Master data (e.g. name, company affiliation, customer and supplier numbers)
- Contact data (e.g. address, email address, phone number)
- Contract and billing data (e.g. quotes, orders, invoices, payment information)
- Service and time-tracking data, where present in the source system
- Usage and log data of the analytics platform (e.g. sign-in times, reports accessed)
5. Categories of data subjects
- Customers and prospects of the Controller
- Suppliers and service providers of the Controller
- Employees and contact persons of the Controller
- Users of the analytics platform
6. Rights and obligations of the Controller
The Controller is solely responsible for the lawfulness of the processing and for safeguarding the rights of data subjects.
The Controller issues all instructions in text form as a matter of principle. Verbal instructions must be confirmed in text form without undue delay.
The Controller shall inform the Processor without undue delay if it detects errors or irregularities when reviewing the processing results.
7. Obligations of the Processor
a) Processing on instructions
The Processor processes personal data solely on documented instructions from the Controller, unless required to process by Union or Member State law. In that case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
If the Processor considers that an instruction infringes data protection law, it shall inform the Controller without undue delay. The Processor is entitled to suspend the execution of the instruction until it is confirmed or amended.
b) Confidentiality
The Processor ensures that all persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation survives the termination of the contractual relationship.
c) Security of processing
The Processor implements all technical and organisational measures required under Art. 32 GDPR (see section 9) and maintains them throughout the term of the contract. Measures may be further developed provided the agreed level of protection is not reduced.
d) Assistance to the Controller
The Processor assists the Controller with appropriate technical and organisational measures in responding to requests from data subjects (Art. 12 to 23 GDPR) and in complying with the obligations under Art. 32 to 36 GDPR, in particular data protection impact assessments.
If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay.
e) Notification of personal data breaches
The Processor notifies the Controller of any personal data breach without undue delay, and no later than 24 hours after becoming aware of it, and assists the Controller in complying with its notification obligations under Art. 33 and 34 GDPR.
f) Evidence and audits
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for and contributes to audits, including inspections.
Audits must be announced with reasonable notice of at least 14 days, carried out during regular business hours and must not disproportionately disrupt operations. Evidence may also be provided by way of current certifications, attestations or audit reports from independent bodies.
8. Sub-processors
The Controller grants the Processor general authorisation to engage further processors. The Processor informs the Controller of any intended changes concerning the addition or replacement of sub-processors; the Controller may object on important grounds within 14 days.
The Processor contractually obliges every sub-processor to a level of data protection equivalent to this agreement and is liable for their conduct as for its own.
At the time this agreement is concluded, the following sub-processors are engaged in particular:
- Microsoft Ireland Operations Ltd., Ireland — hosting and operation of the data platform (Microsoft Azure, Microsoft Fabric, Power BI)
- GitHub Inc., USA — hosting of this website
- EmailJS Pte. Ltd., Singapore — technical delivery of contact form messages
- Calendly LLC, USA — appointment scheduling
9. Technical and organisational measures
The Processor has implemented the following measures pursuant to Art. 32 GDPR:
- Physical access control: processing in certified data centres of the cloud providers used, with physical access safeguards
- System access control: individual user accounts, multi-factor authentication, password policies, automatic locking of inactive sessions
- Data access control: role-based authorisation concept following the principle of least privilege, separation of administrative and end-user roles
- Transfer control: transport encryption (TLS 1.2 or higher) for all transmissions, encryption of data at rest
- Input control: logging of sign-ins, administrative changes and access to reports
- Availability control: regular backups, redundant storage, documented recovery procedures
- Separation control: tenant-separated storage and processing of data per Controller
- Procedures for regularly testing, assessing and evaluating the effectiveness of the measures
10. Processing in third countries
Personal data is processed in a third country only where the specific requirements of Art. 44 et seq. GDPR are met — in particular on the basis of an adequacy decision or the European Commission's standard contractual clauses together with supplementary safeguards.
The data platform is operated by default in data centres within the European Union.
11. Erasure and return of data
After the end of the provision of processing services, the Processor erases all personal data or returns it at the Controller's choice, unless there is a statutory obligation to store it.
The return is made in a common, machine-readable format. Backup copies are deleted as part of the regular backup cycles.
Erasure is confirmed to the Controller in text form upon request.
12. Liability
Art. 82 GDPR applies to the liability of the parties. In all other respects, the liability provisions of the main agreement apply.
13. Final provisions
Amendments and additions to this agreement must be made in text form. This also applies to any waiver of this form requirement.
Should individual provisions of this agreement be or become invalid, the validity of the remaining provisions shall remain unaffected.
In the event of contradictions between this agreement and the main agreement, the provisions of this agreement shall prevail insofar as the processing of personal data is concerned.
The law of the Federal Republic of Germany applies.
Last updated: August 2026
