Data Processing Agreement

pursuant to Art. 28 GDPR

Last updated: July 20, 2026

between

the respective company or organization using the CustCom SaaS platform,
– hereinafter the "Controller" –

and

CustCom UG
Sandstr. 17, 49080 Osnabrück, Deutschland
– hereinafter the "Processor" –

The Controller and the Processor are jointly referred to as the "Parties".

This Data Processing Agreement (DPA) applies to the use of the CustCom SaaS platform (custcom.io / app.custcom.io) by B2B customers. Publication at custcom.io/legal/dsgvo represents the current version and does not replace individual legal review.

1. Subject matter and duration of processing

  1. The Processor processes personal data on behalf of the Controller within the meaning of Art. 28 of the General Data Protection Regulation ("GDPR").
  2. The subject matter of the processing is the provision, operation, maintenance, and support of the CustCom SaaS platform, including related technical and organizational services. CustCom is a web-based business software platform for task management, time tracking, invoicing, reporting, and customer communication workflows.
  3. Processing takes place exclusively on the basis of this Agreement, the main contract for the use of the CustCom SaaS platform, and documented instructions from the Controller.
  4. The duration of processing is governed by the term of the main contract. This Agreement ends automatically upon complete termination of the processing of personal data by the Processor, unless statutory retention obligations apply.

2. Nature and purpose of processing

  1. Processing serves the Controller's use of the CustCom SaaS platform, in particular for managing tasks, projects, time tracking, invoicing, reporting, customer communication, and comparable business processes.
  2. The Processor processes personal data in particular by:
    • storage
    • organization
    • structuring
    • alteration
    • retrieval
    • consultation
    • use
    • transmission within platform functions
    • restriction
    • erasure or destruction
  3. The Processor does not process data for its own purposes unless expressly permitted by this Agreement or the main contract.

3. Categories of data subjects

Depending on the Controller's use of the CustCom SaaS platform, the following categories of data subjects may be affected:

  1. Employees and contractors of the Controller
  2. Customers, prospects, and business partners of the Controller
  3. Contact persons at companies
  4. Project and task participants
  5. Users of the CustCom SaaS platform
  6. Other persons whose data the Controller processes in the platform

4. Categories of personal data

Depending on use by the Controller, the following categories of personal data may be processed:

  1. Master data, e.g. name, company, address
  2. Contact data, e.g. email address, phone number
  3. User and access data, e.g. username, roles, permissions
  4. Task and project data
  5. Time and performance data
  6. Invoice and billing data
  7. Communication, documentation, and note data
  8. AI assistant data, where the Controller uses this feature
  9. Technical usage data, e.g. log data, IP address, timestamps
  10. Support and communication content provided by the Controller

Special categories of personal data pursuant to Art. 9 GDPR are not the subject of the agreed processing unless the Controller independently enters them into the platform. In that case, the Controller remains responsible for the lawfulness of entry and processing.

5. Responsibility and right to issue instructions

  1. The Controller is responsible for the lawfulness of processing personal data and for safeguarding the rights of data subjects.
  2. The Processor processes personal data exclusively on documented instructions from the Controller, unless required to do so by Union or Member State law.
  3. Instructions may arise from the main contract, this Agreement, use of platform functions, or separate written instructions.
  4. Oral instructions must be confirmed in text form without undue delay.
  5. The Processor shall inform the Controller without undue delay if it considers an instruction to violate data protection law. The Processor may suspend execution of the instruction until confirmed or amended by the Controller.

6. Obligations of the Processor

The Processor undertakes in particular to:

  1. process personal data only within the scope of this Agreement and documented instructions from the Controller
  2. ensure confidentiality pursuant to Art. 28(3)(b) GDPR
  3. implement appropriate technical and organizational measures pursuant to Art. 32 GDPR
  4. assist the Controller, where possible, in fulfilling data subject rights
  5. appropriately assist the Controller with data protection impact assessments and consultations with supervisory authorities, where processing by the Processor is concerned
  6. delete or return personal data after completion of processing at the Controller's choice, unless statutory retention obligations apply
  7. provide the Controller with information necessary to verify compliance with this Agreement
  8. engage sub-processors only in accordance with this Agreement

7. Confidentiality

  1. The Processor ensures that persons authorized to process personal data are bound by confidentiality or subject to an appropriate statutory duty of confidentiality.
  2. The duty of confidentiality continues after termination of activities.
  3. The Processor restricts access to personal data to persons who need such access to perform their tasks.

8. Technical and organizational measures

  1. The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
  2. Measures take into account in particular:
    • confidentiality
    • integrity
    • availability
    • resilience of systems and services
    • restorability in the event of incidents
    • regular review and evaluation of the effectiveness of measures
  3. The specific agreed technical and organizational measures are set out in Annex 1.
  4. The Processor may further develop technical and organizational measures provided the agreed level of protection is not undermined.

9. Assistance with data subject rights

  1. The Processor assists the Controller, where possible, with appropriate technical and organizational measures in fulfilling data subject requests.
  2. This concerns in particular requests for:
    • access
    • rectification
    • erasure
    • restriction of processing
    • data portability
    • objection
  3. If a data subject request is received directly by the Processor and concerns the Controller's data, the Processor shall forward it to the Controller without undue delay, where attribution is possible.
  4. The Processor does not respond to such requests independently unless instructed by the Controller or required by law.

10. Personal data breaches and security incidents

  1. The Processor informs the Controller without undue delay upon becoming aware of a personal data breach affecting the Controller's data.
  2. The notification shall, where available, include in particular:
    • nature of the incident
    • affected data categories
    • affected groups of data subjects
    • likely consequences
    • measures taken or proposed
  3. The Processor appropriately assists the Controller in fulfilling notification obligations under Art. 33 and 34 GDPR.
  4. Measures to secure data and mitigate adverse consequences shall be initiated without undue delay.

11. Sub-processors

  1. The Controller authorizes the Processor to engage sub-processors where necessary for the provision, operation, maintenance, security, or support of the CustCom SaaS platform.
  2. The Processor ensures that agreements with sub-processors provide a level of data protection comparable to this Agreement.
  3. The Processor remains liable to the Controller for compliance by sub-processors.
  4. A list of sub-processors engaged at the time of conclusion is contained in Annex 2.
  5. The Processor informs the Controller of intended changes to sub-processors in an appropriate manner. The Controller may object on important data protection grounds.
  6. If no objection is raised within 14 calendar days of notification, the change is deemed approved.

12. Third-country transfers

  1. Transfers of personal data to countries outside the European Union or European Economic Area occur only where the requirements of Art. 44 et seq. GDPR are met.
  2. The Processor ensures appropriate safeguards exist, in particular through:
    • adequacy decision of the European Commission
    • EU Standard Contractual Clauses
    • binding corporate rules
    • other instruments permitted under the GDPR
  3. Details on possible third-country transfers are set out in Annex 2.

13. Audit and evidence obligations

  1. Upon request, the Processor provides the Controller with information necessary to demonstrate compliance with Art. 28 GDPR obligations.
  2. Evidence may be provided in particular through:
    • documentation of technical and organizational measures
    • appropriate certifications
    • audit reports
    • security concepts
    • self-assessments
  3. On-site audits are permitted only with reasonable prior notice, during normal business hours, and while preserving the Processor's trade and business secrets.
  4. Audits must not disproportionately disrupt the Processor's business operations.
  5. The Controller bears reasonable costs of an audit unless the audit is required due to substantiated suspicion of a data protection violation.

14. Deletion and return of data

  1. Upon termination of the main contract or at the Controller's instruction, the Processor deletes personal data or returns it to the Controller, unless statutory retention obligations apply.
  2. Deletion occurs after technically required backup cycles, where earlier deletion is not technically possible or economically unreasonable.
  3. During this transition period, data is no longer actively processed and is used only for recovery, security, or compliance with legal obligations.
  4. The Processor confirms deletion upon request in an appropriate form.

15. Obligations of the Controller

The Controller undertakes to:

  1. process personal data lawfully in the CustCom SaaS platform
  2. ensure that data subjects have been properly informed
  3. manage access rights within the platform independently
  4. enter only data necessary for the respective purpose
  5. not enter special categories of personal data unless expressly agreed and legally secured
  6. issue instructions clearly, comprehensibly, and in documented form
  7. inform the Processor without undue delay of data protection risks or impermissible use

16. Liability

  1. Liability of the Parties is governed by statutory provisions and the main contract.
  2. Where provisions of the main contract and this Agreement conflict, the data protection provisions of this Agreement prevail with respect to the processing of personal data.

17. Remuneration for additional effort

  1. Services of the Processor beyond the contractually owed provision of the CustCom SaaS platform may be remunerated separately.
  2. This applies in particular to extensive assistance with data subject requests, audits, data protection impact assessments, or special evaluations, where the effort is not attributable to the Processor.
  3. The Parties shall coordinate before substantial additional costs arise.

18. Priority and final provisions

  1. This Agreement supplements the main contract between the Parties for the use of the CustCom SaaS platform.
  2. In case of conflict, the provisions of this Agreement prevail where they concern data protection requirements for processing.
  3. Amendments and supplements require text form unless a stricter form is prescribed by law.
  4. If individual provisions are or become invalid, the validity of the remaining provisions is unaffected.
  5. The law of the Federal Republic of Germany applies. Place of jurisdiction is Osnabrück, unless mandatory law provides otherwise.

Annex 1: Technical and organizational measures

The following technical and organizational measures describe the Processor's baseline level of protection for the CustCom SaaS platform.

1. Physical access control

  • Use of secure data centers through certified hosting providers
  • Access restrictions to office premises
  • Limited physical access to development and production systems

2. System access control

  • Individual user accounts with organization-based authentication
  • Secure password policies
  • Multi-factor authentication (passkeys)
  • Role-based permissions at organization and member level
  • Automatic locking or deactivation of inactive accounts
  • Encrypted connections via TLS/HTTPS

3. Data access control

  • Role- and permission-based access concepts
  • Tenant separation within the SaaS platform (organizations)
  • Logging of administrative access
  • Regular review of permissions
  • Access restriction on a need-to-know basis

4. Transmission control

  • Transport encryption via TLS/HTTPS
  • Encrypted data transmission to connected services
  • Secure interfaces and API access
  • Contractual arrangements with sub-processors
  • Documented processes for data exports

5. Input control

  • User and timestamp logging for relevant actions
  • Logging of security-relevant events
  • Traceable user administration

6. Job control

  • Conclusion of this Data Processing Agreement
  • Documented instruction processes
  • Careful selection of sub-processors
  • Contractual obligations for sub-processors
  • Internal data protection and security policies

7. Availability control

  • Regular database backups
  • Backup and recovery concepts
  • System availability monitoring (status.custcom.io)
  • Protection against malware
  • Security updates and patch management
  • Emergency and recovery processes

8. Separation requirement

  • Logical tenant separation by organization
  • Separate data areas per customer or organization
  • Role-based access
  • Separate processing of production, test, and development data

9. Privacy-friendly defaults

  • Role-based default permissions
  • Minimization of required mandatory fields
  • Deletion and export options where technically provided
  • Restriction of administrative access
  • Privacy-conscious product development

Annex 2: Sub-processors

The Processor engages the following sub-processors as of this version. Material changes will be communicated pursuant to Section 11.

CompanyServiceLocationData categoriesThird-country transferSafeguard
Vercel Inc.Hosting and deployment of web applications (website, dashboard)USA / EUUsage, content and technical dataYesDPA, EU Standard Contractual Clauses (SCC)
Railway Corporation (railway.com)API hosting and database hosting (PostgreSQL)USA / EUCustomer data stored in the platform, API requests and responses, technical log dataYesDPA, EU Standard Contractual Clauses (SCC)
Cloudflare, Inc.CDN, DNS and edge securityEU / USARequest metadata, traffic and technical log dataYesDPA, EU Standard Contractual Clauses (SCC)
Stripe, Inc.Payment processing and subscription managementUSA / IrelandBilling data, customer and organization IDsYesDPA, EU Standard Contractual Clauses (SCC)
Amazon Web Services EMEA SARLEmail delivery (Amazon SES)EU / USAEmail addresses, names, email contentYesDPA, EU Standard Contractual Clauses (SCC)
PostHog, Inc.Product analytics and usage statisticsEU (eu.posthog.com)Technical usage data, pseudonymous identifiersNoDPA
Functional Software, Inc. (Sentry)Error monitoring and performance trackingUSATechnical log data, error informationYesDPA, EU Standard Contractual Clauses (SCC)
Trigger.dev, Inc.Background processing and scheduled tasksUSAJob payload data as requiredYesDPA, EU Standard Contractual Clauses (SCC)
Microsoft Corporation (Azure OpenAI Service)AI assistant and automated text processingEU / EEAAI assistant inputs and outputs, context dataNo (EU region)DPA, Microsoft DPA

The Processor informs the Controller of material changes to this list pursuant to Section 11 of this Agreement.

Annex 3: Description of processing

1. Purpose of processing

Provision, operation, maintenance, support, and further development of the CustCom SaaS platform for task management, time tracking, invoicing, reporting, and customer communication workflows for freelancers, agencies, and small teams.

2. Nature of processing

Storage, structuring, organization, alteration, retrieval, consultation, use, transmission within platform functions, erasure, and backup of personal data.

3. Categories of data subjects

Employees, contractors, customers, prospects, business partners, contact persons, project and task participants, and platform users.

4. Types of data

Master data, contact data, access data, task and project data, time and performance data, invoice and billing data, AI assistant data, and technical usage and log data.

5. Retention periods

Deletion occurs upon termination of the contractual relationship or at the Controller's instruction, unless statutory retention obligations apply. Backups are overwritten or deleted within regular backup cycles.

Annex 4: Instruction and contact points

Controller

The Controller designates its data protection contact as part of the contractual relationship or upon conclusion of the contract.

Processor

Data protection contact: CustCom UG

Email: support@custcom.io

Phone: 0157 33676333

Instructions from the Controller should generally be issued in text form to the Processor's designated contact point.

Turn finished work into billable work — faster.