Between
Weisscam GmbH
Osterwaldstr. 53, 80805 Munich, Germany
("Processor")
and
the Customer (as defined in the Terms of Use)
("Controller")
Effective as of: date of acceptance / contract conclusion
1. Subject Matter and Scope of Processing
1.1 This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the use of the Weisscam Safe AI Workspace (“Service”).
1.2 The subject matter, duration, nature, and purpose of processing, as well as categories of data and data subjects, are specified in Annex 1.
1.3 This DPA supplements the Terms of Use and the Privacy Policy. In case of conflict, this DPA prevails regarding data processing obligations.
2. Roles and Instructions
2.1 The Controller determines the purposes and means of processing.
2.2 The Processor processes personal data solely on documented instructions of the Controller unless required by EU or Member State law.
2.3 Instructions are primarily defined by:
- This DPA,
- The Terms of Use,
- Configurations within the Service (e.g., admin settings, roles, permissions).
2.4 The Processor shall inform the Controller if an instruction infringes GDPR.
3. Confidentiality
3.1 The Processor ensures that persons authorized to process personal data:
- Are bound to confidentiality obligations, and
- Receive appropriate data protection training.
3.2 Confidentiality obligations survive termination of this DPA.
4. Security of Processing (Art. 32 GDPR)
4.1 The Processor implements appropriate technical and organizational measures (“TOMs”) to ensure a level of security appropriate to the risk.
4.2 Measures are described in Annex 3 and include in particular:
- Access control, authentication (incl. 2FA support),
- Encryption and secure transmission,
- Logging and monitoring,
- Backup and recovery,
- Role-based access control (RBAC).
4.3 The Processor may update TOMs, provided the security level is not reduced.
5. Subprocessors (Art. 28(2) GDPR)
5.1 The Controller grants general authorization for the use of subprocessors.
5.2 Current subprocessors are listed in Annex 2, including:
- IONOS SE (Germany) – hosting (Berlin data center),
- Nebius B.V. (Netherlands) – AI inference processing.
5.3 The Processor shall:
- Inform the Controller of changes to subprocessors, and
- Allow reasonable objection rights.
5.4 The Processor ensures that subprocessors are bound by equivalent data protection obligations.
5.5 No transfers to third countries currently occur.
6. Data Processing Locations
6.1 Data is processed exclusively within the European Union:
- Germany → hosting (IONOS)
- Netherlands → AI processing (Nebius)
6.2 No third-country transfers (Art. 44 GDPR) take place.
7. AI Processing Specific Provisions
7.1 AI processing is limited to generating outputs based on user inputs.
7.2 Zero Data Retention (where enabled):
- No persistent storage of inputs/outputs
- Processing occurs ephemerally
7.3 No training of AI models:
- User inputs are not used for training
- Only open-source models are used (e.g., gpt-oss-120b)
7.4 The Controller remains responsible for assessing the legality of data input into AI systems.
8. Assistance Obligations
8.1 The Processor assists the Controller in fulfilling:
- Data subject rights (Art. 12–23 GDPR),
- Security obligations (Art. 32 GDPR),
- Breach notifications (Art. 33–34 GDPR),
- Data protection impact assessments (Art. 35 GDPR).
8.2 Assistance is provided within reasonable limits and based on available information.
9. Data Subject Requests
9.1 The Controller is responsible for handling requests.
9.2 The Processor shall:
- Not respond directly unless instructed,
- Support the Controller where technically feasible.
10. Personal Data Breaches
10.1 The Processor shall notify the Controller without undue delay after becoming aware of a breach.
10.2 Notification includes:
- Nature of breach,
- Affected data,
- Mitigation measures,
- Recommended actions.
11. Deletion and Return of Data
11.1 Upon termination, the Processor shall:
- Delete or return personal data,
- Unless legal obligations require retention.
11.2 Details are aligned with the Terms of Use (export window, deletion cycles).
11.3 Backup data is deleted in accordance with standard retention cycles.
12. Audit and Inspection Rights
12.1 The Controller has the right to audit compliance.
12.2 Audits shall:
- Be conducted with reasonable notice,
- Not disrupt operations,
- Be limited to necessary scope.
12.3 The Processor may provide:
- Certifications,
- Security documentation,
- Audit reports
as an alternative to on-site audits.
13. Liability
13.1 Liability is governed by the Terms of Use.
13.2 Mandatory GDPR liability provisions remain unaffected.
14. Term and Termination
14.1 This DPA is valid for the duration of the main contract.
14.2 Termination follows the underlying agreement.
15. Final Provisions
15.1 German law applies.
15.2 Place of jurisdiction: Munich (for business customers).
15.3 Amendments must be made in text form.
Annex 1 – Description of Processing
Subject matter:
Provision of a secure AI-based workspace platform.
Duration:
For the duration of the contract.
Nature and purpose:
- Account management
- Collaboration and storage
- AI-supported processing
- Communication and support
Categories of data:
- Account data (name, email)
- Content data (files, messages, inputs)
- Usage/log data
Data subjects:
- Employees
- Customers
- Partners
- End users
Annex 2 – Subprocessors
| Provider | Location | Service |
|---|---|---|
| IONOS SE | Germany | Hosting (Berlin) |
| Nebius B.V. | Netherlands | AI inference (zero retention) |
Annex 3 – Technical and Organizational Measures (TOMs)
Access Control:
- RBAC system
- Strong authentication
- Optional/enforceable 2FA
System Security:
- Patch management
- Monitoring & logging
- Intrusion detection
Data Protection:
- Encryption in transit
- Controlled access
- Isolation of tenants
Availability:
- Backups
- Disaster recovery
Organizational Measures:
- Confidentiality agreements
- Least privilege principle
- Internal policies
Annex 4 – Instructions and Contact Points
Controller contact:
(as defined by Customer)
Processor contact:
Weisscam GmbH
datenschutz@weisscam.com
Instructions:
- Defined via Service configuration
- Supplemented by written instructions
Support for requests:
- Via support channels or admin console
