Skip to content
Weisscam
ProductBenefitsUse casesWho it is forSecurityPricing
DEENLog inStart free
ProductBenefitsUse casesWho it is forSecurityPricing
DEENLog inStart free

Legal

Data Processing Agreement (DPA)

pursuant to Art. 28 GDPR

Between
Weisscam GmbH
Osterwaldstr. 53, 80805 Munich, Germany
("Processor")

and

the Customer (as defined in the Terms of Use)
("Controller")

Effective as of: date of acceptance / contract conclusion

1. Subject Matter and Scope of Processing

1.1 This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the use of the Weisscam Safe AI Workspace (“Service”).

1.2 The subject matter, duration, nature, and purpose of processing, as well as categories of data and data subjects, are specified in Annex 1.

1.3 This DPA supplements the Terms of Use and the Privacy Policy. In case of conflict, this DPA prevails regarding data processing obligations.

2. Roles and Instructions

2.1 The Controller determines the purposes and means of processing.

2.2 The Processor processes personal data solely on documented instructions of the Controller unless required by EU or Member State law.

2.3 Instructions are primarily defined by:

  • This DPA,
  • The Terms of Use,
  • Configurations within the Service (e.g., admin settings, roles, permissions).

2.4 The Processor shall inform the Controller if an instruction infringes GDPR.

3. Confidentiality

3.1 The Processor ensures that persons authorized to process personal data:

  • Are bound to confidentiality obligations, and
  • Receive appropriate data protection training.

3.2 Confidentiality obligations survive termination of this DPA.

4. Security of Processing (Art. 32 GDPR)

4.1 The Processor implements appropriate technical and organizational measures (“TOMs”) to ensure a level of security appropriate to the risk.

4.2 Measures are described in Annex 3 and include in particular:

  • Access control, authentication (incl. 2FA support),
  • Encryption and secure transmission,
  • Logging and monitoring,
  • Backup and recovery,
  • Role-based access control (RBAC).

4.3 The Processor may update TOMs, provided the security level is not reduced.

5. Subprocessors (Art. 28(2) GDPR)

5.1 The Controller grants general authorization for the use of subprocessors.

5.2 Current subprocessors are listed in Annex 2, including:

  • IONOS SE (Germany) – hosting (Berlin data center),
  • Nebius B.V. (Netherlands) – AI inference processing.

5.3 The Processor shall:

  • Inform the Controller of changes to subprocessors, and
  • Allow reasonable objection rights.

5.4 The Processor ensures that subprocessors are bound by equivalent data protection obligations.

5.5 No transfers to third countries currently occur.

6. Data Processing Locations

6.1 Data is processed exclusively within the European Union:

  • Germany → hosting (IONOS)
  • Netherlands → AI processing (Nebius)

6.2 No third-country transfers (Art. 44 GDPR) take place.

7. AI Processing Specific Provisions

7.1 AI processing is limited to generating outputs based on user inputs.

7.2 Zero Data Retention (where enabled):

  • No persistent storage of inputs/outputs
  • Processing occurs ephemerally

7.3 No training of AI models:

  • User inputs are not used for training
  • Only open-source models are used (e.g., gpt-oss-120b)

7.4 The Controller remains responsible for assessing the legality of data input into AI systems.

8. Assistance Obligations

8.1 The Processor assists the Controller in fulfilling:

  • Data subject rights (Art. 12–23 GDPR),
  • Security obligations (Art. 32 GDPR),
  • Breach notifications (Art. 33–34 GDPR),
  • Data protection impact assessments (Art. 35 GDPR).

8.2 Assistance is provided within reasonable limits and based on available information.

9. Data Subject Requests

9.1 The Controller is responsible for handling requests.

9.2 The Processor shall:

  • Not respond directly unless instructed,
  • Support the Controller where technically feasible.

10. Personal Data Breaches

10.1 The Processor shall notify the Controller without undue delay after becoming aware of a breach.

10.2 Notification includes:

  • Nature of breach,
  • Affected data,
  • Mitigation measures,
  • Recommended actions.

11. Deletion and Return of Data

11.1 Upon termination, the Processor shall:

  • Delete or return personal data,
  • Unless legal obligations require retention.

11.2 Details are aligned with the Terms of Use (export window, deletion cycles).

11.3 Backup data is deleted in accordance with standard retention cycles.

12. Audit and Inspection Rights

12.1 The Controller has the right to audit compliance.

12.2 Audits shall:

  • Be conducted with reasonable notice,
  • Not disrupt operations,
  • Be limited to necessary scope.

12.3 The Processor may provide:

  • Certifications,
  • Security documentation,
  • Audit reports

as an alternative to on-site audits.

13. Liability

13.1 Liability is governed by the Terms of Use.

13.2 Mandatory GDPR liability provisions remain unaffected.

14. Term and Termination

14.1 This DPA is valid for the duration of the main contract.

14.2 Termination follows the underlying agreement.

15. Final Provisions

15.1 German law applies.

15.2 Place of jurisdiction: Munich (for business customers).

15.3 Amendments must be made in text form.

Annex 1 – Description of Processing

Subject matter:
Provision of a secure AI-based workspace platform.

Duration:
For the duration of the contract.

Nature and purpose:

  • Account management
  • Collaboration and storage
  • AI-supported processing
  • Communication and support

Categories of data:

  • Account data (name, email)
  • Content data (files, messages, inputs)
  • Usage/log data

Data subjects:

  • Employees
  • Customers
  • Partners
  • End users

Annex 2 – Subprocessors

ProviderLocationService
IONOS SEGermanyHosting (Berlin)
Nebius B.V.NetherlandsAI inference (zero retention)

Annex 3 – Technical and Organizational Measures (TOMs)

Access Control:

  • RBAC system
  • Strong authentication
  • Optional/enforceable 2FA

System Security:

  • Patch management
  • Monitoring & logging
  • Intrusion detection

Data Protection:

  • Encryption in transit
  • Controlled access
  • Isolation of tenants

Availability:

  • Backups
  • Disaster recovery

Organizational Measures:

  • Confidentiality agreements
  • Least privilege principle
  • Internal policies

Annex 4 – Instructions and Contact Points

Controller contact:
(as defined by Customer)

Processor contact:
Weisscam GmbH
datenschutz@weisscam.com

Instructions:

  • Defined via Service configuration
  • Supplemented by written instructions

Support for requests:

  • Via support channels or admin console

Newsletter

News from Weisscam.

Product updates and perspectives on digital independence.

Subscribe
Weisscam

Sovereign business software for people and agents.

Product

Weisscam workspaceUpload & ResearchNotesSpreadsheetsAnalyticsKanbanWhiteboardContactsAI AgentsCustom appsOpen Source

Use cases

Knowledgemanagement & CollaborationData analysisCompliance managementProject managementCRM & contactsPersonal Workspace

Company

BenefitsWho it is forSecurityPricingWeisscam PrinciplesAbout WeisscamBlogContact

Legal

Legal noticeTerms of usePrivacy policyDPA
© 2026 Weisscam GmbH7 apps · 1 data layer · People & agents