Data Processing Agreement (DPA)

pursuant to Art. 28 GDPR

This Data Processing Agreement becomes effective upon purchase. Your company name and acceptance date will be recorded at checkout and visible in your account settings after signup.

Data Processing Agreement (DPA)

pursuant to Art. 28 GDPR

Personalrampe Digital

between

[Customer Company Name]
[Customer Address]
(hereinafter "Controller")

and

Luis Moretto, operating as "Personalrampe Digital"
An der Windecke 9, 58300 Wetter
Email: privacy@personalrampe.de
(hereinafter "Processor")

§ 0 Language

The Data Processing Agreement is available in German and English. In case of discrepancies or disputes regarding interpretation, the German version shall prevail.

§ 1 Subject Matter and Duration

  1. Subject matter: The Processor processes personal data on behalf of the Controller for the purpose of providing the services under the main contract.
  2. Duration: This DPA commences upon conclusion of the main contract and ends upon its termination.

§ 2 Nature and Purpose of Processing

Purpose of processing:

  • Digitisation of personnel files (upload, OCR, text extraction),
  • Structuring of extracted content,
  • AI-supported generation of summaries and insights,
  • Provision of an AI assistant for HR queries,
  • Operation of the Platform.

§ 3 Categories of Data Subjects

  • Employees of the Controller,
  • Former employees of the Controller,
  • HR administrators and personnel managers of the Controller as Platform users,
  • Other users authorised by the Controller.

§ 4 Categories of Personal Data

  • Master and contact data,
  • Employment and contract data,
  • Remuneration and benefits data,
  • Performance and behaviour data,
  • Attendance and absence data,
  • System and usage data,
  • Audit log data,
  • Special categories of personal data (Art. 9 GDPR) if contained in documents.

§ 5 Obligations of the Processor

The Processor undertakes:

  1. to process personal data only on documented instructions of the Controller,
  2. to ensure confidentiality,
  3. to implement technical and organisational measures (Annex 1),
  4. to comply with sub-processor obligations,
  5. to assist the Controller with data subjects' rights and obligations under Art. 32-36 GDPR,
  6. to return or delete data upon termination,
  7. to demonstrate compliance through audits.

§ 6 Sub-Processors

The following sub-processors are approved: Vercel Inc. (EU Hosting), Supabase Inc. (EU Database), Mailgun (EU Email). For billing data only (no employee data): Dodo Payments Limited, 3rd Floor Crown House, 151 High Road, Loughton IG10 4LG, United Kingdom, VAT: 495 1783 48.

§ 7-11 Misc.

(Sections 7-11 remain valid as per standard DPA terms).

Annex 1: Technical and Organisational Measures (TOMs)

(As per standard TOMs).