Compliance

Data processing agreement
under GDPR Article 28.

Whenever personal data is processed on a customer's behalf, a data processing agreement is concluded. SIMO GmbH provides a template for it that is customized per customer: counterparty, processing purposes, choice of sub-processors.

What the agreement covers

The template follows the structure Article 28(3) prescribes and adds the annexes without which a processing agreement cannot realistically be audited.

  • Subject matter, duration, nature and purpose of the processing under Article 28(3)(a).
  • Types of personal data and categories of data subjects.
  • Obligations and rights of the controller.
  • Technical and organizational measures as Annex 2.
  • List of approved sub-processors as Annex 3.
  • EU standard contractual clauses 2021/914 as Annex 4 wherever a third-country transfer applies.
  • Provisions on inspection, audit and information rights.

How to obtain it: what we need from you

The customized template is provided as a PDF on request. So that we can draft it without a round trip, please include the following straight away:

A directly downloadable, unsigned version will be added in one of the coming waves. Until then the route runs through the compliance address.

  1. Counterparty: company, legal form, address and authorized signatory.
  2. Intended processing scope: which parts of the platform, which categories of data.
  3. Sub-processor opt-ins: Tavily, Microsoft Graph, Stripe.