Data Processing Agreement (DPA)
Last updated: 8 July 2026 · Version 1.1
pursuant to Art. 28 of the General Data Protection Regulation (GDPR)
This English text is a translation provided for information only. In the event of any discrepancy, the German Auftragsverarbeitungsvertrag prevails.
Preamble
This data processing agreement (“DPA”) is concluded between the Customer who uses the software “Valiro” (valiro.ai) by registering and agreeing to the terms of use (AGB) — the usage contract thereby concluded hereinafter the “main contract”, the Customer hereinafter the “controller” — and Valiro Solutions UG (haftungsbeschränkt) (hereinafter “processor” or “we”/“us”); each also referred to as a “party” or jointly as the “parties”. In the course of performing the main contract, it may be necessary for the processor to process personal data on behalf of the controller. To specify the mutual data protection rights and obligations under the General Data Protection Regulation (GDPR), the parties conclude this DPA.
Processor details
Valiro Solutions UG (haftungsbeschränkt), Eduard-Kandl-Str. 23, 82211 Herrsching am Ammersee, represented by its managing director Olga Ryannel; Munich Local Court, HRB 311011; email: info@valiro.ai, website: www.valiro.ai. Data protection contact: info@valiro.ai. No data protection officer has been appointed, as the requirements of Art. 37 GDPR / Sec. 38 BDSG are not currently met.
The details identifying the controller (company and contact data) result from its registration or the ordering process. This DPA is part of the main contract.
§ 1 Subject Matter, Nature, Purpose and Duration of Processing
The subject matter, nature and purpose of the processing, the type of personal data and the categories of data subjects result from the main contract and are set out in Annex 1. The duration of the processing corresponds to the term of the main contract. (Art. 28(3) sentence 1 GDPR)
§ 2 Bound by Instructions
2.1 The processor processes the personal data exclusively on documented instructions from the controller, including with regard to a transfer to third countries, unless it is required to process otherwise by Union or Member State law; in this case, it informs the controller of the legal requirements prior to processing, unless the law prohibits this. The use of the application in accordance with the main contract is deemed an instruction. (Art. 28(3)(a) GDPR)
2.2 The controller remains the controller within the meaning of Art. 4 no. 7 GDPR and is solely responsible for the lawfulness of the processing. It issues further or deviating instructions in text form.
2.3 If the processor considers an instruction to be unlawful, it informs the controller of this without undue delay. (Art. 28(3) sentence 3 GDPR)
§ 3 Confidentiality
The processor ensures that the persons authorized to process the data are committed to confidentiality or are subject to an appropriate statutory obligation of secrecy. (Art. 28(3)(b) GDPR)
§ 4 Technical and Organizational Measures
The processor takes the technical and organizational measures necessary to ensure an appropriate level of protection pursuant to Art. 32 GDPR. These are described in Annex 3 and may be further developed in line with the state of the art, provided that the level of protection is not undercut. (Art. 28(3)(c) GDPR)
§ 5 Sub-processors
5.1 The controller approves the use of the sub-processors named in Annex 2. (Art. 28(2) GDPR)
5.2 The processor informs the controller in advance of intended changes (text form is sufficient). The controller may object within 14 days for good cause; if no objection is made, the change is deemed approved. If the controller objects in good time and the objection cannot be resolved by mutual agreement, the controller is entitled to terminate the main contract extraordinarily; there is no claim to prohibit the processor from using the sub-processor.
5.3 The processor contractually obliges each sub-processor to the same data protection obligations as set out in this DPA, in particular to sufficient guarantees pursuant to Art. 32 GDPR. It is liable for compliance by the sub-processor. (Art. 28(4) GDPR)
§ 6 Support of the Controller
6.1 The processor supports the controller through appropriate technical and organizational measures in fulfilling data subject rights pursuant to Art. 12–23 GDPR. If a data subject contacts the processor directly, it forwards the request without undue delay. (Art. 28(3)(e) GDPR)
6.2 The processor supports the controller in complying with the obligations under Art. 32–36 GDPR (security of processing, notification of data breaches, data protection impact assessment, prior consultation), taking into account the nature of the processing and the information available to it. (Art. 28(3)(f) GDPR)
6.3 The processor notifies the controller without undue delay after becoming aware of a breach of the protection of personal data and provides the information required under Art. 33(3) GDPR, insofar as it is known to it, so that the controller can fulfill its notification and communication obligations (Art. 33, 34 GDPR).
§ 7 Deletion and Return
After the end of the provision of the processing services, the processor, at the controller’s choice, deletes all personal data or returns it and deletes existing copies, unless there is a Union or Member State retention obligation. Before deletion, the processor enables the controller to export its data in a common, structured and machine-readable format. (Art. 28(3)(g) GDPR)
§ 8 Evidence and Audits
The processor provides the controller with all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and enables and contributes to reviews — including inspections — carried out by the controller or an auditor commissioned by it. Evidence may also be provided by current attestations, certifications or comparable evidence (including that of sub-processors used). (Art. 28(3)(h) GDPR)
The controller announces on-site audits with reasonable notice (generally two weeks) and carries them out during normal business hours and, in principle, no more than once per calendar year (further audits only for specific cause, in particular after a security incident). An auditor commissioned by the controller must be obliged to confidentiality; a direct competitor of the processor may not be commissioned. The controller bears the costs arising from elaborate on-site audits at the processor.
§ 9 Third-Country Transfer
Where processing takes place outside the EU/EEA, the processor bases the transfer primarily on an adequacy decision of the EU Commission pursuant to Art. 45 GDPR (in particular the EU-US Data Privacy Framework, insofar as the recipient is certified). In addition, and in case a certification or the adequacy decision ceases to apply, the processor ensures appropriate safeguards pursuant to Art. 46 GDPR (in particular EU Standard Contractual Clauses pursuant to Implementing Decision (EU) 2021/914 together with the necessary additional measures). The sub-processors concerned and the respective transfer basis are set out in Annex 2.
§ 10 Final Provisions
10.1 The law of the Federal Republic of Germany applies. 10.2 In the event of contradictions on data protection matters, this DPA takes precedence over the main contract. 10.3 Changes require text form. 10.4 If a provision is invalid, the validity of the remaining provisions remains unaffected.
This DPA takes effect upon conclusion of the main contract. Where concluded electronically with consent to the main contract, no signature is required.
Annex 1 — Subject Matter, Nature, Purpose of Processing; Types of Data; Categories of Data Subjects
Subject matter and purpose: Provision and operation of the SaaS application “Valiro” (management of projects, work packages, tasks and resources) in accordance with the main contract, including the functions used for this purpose — in particular AI-powered search/assistance, address geocoding, sending of transactional emails and, insofar as activated, payment processing (sub-processors for this see Annex 2).
Nature of processing: Collection, recording, organization, storage, adaptation, retrieval, querying, use, transmission to sub-processors (Annex 2), restriction and deletion by automated means.
Categories of data subjects: Users of the application (employees of the controller); contact persons of the controller; third parties named in content/documents, in particular end customers/clients of the controller (including private individuals), whose contact and address data is recorded in the course of projects/orders (e.g. name, phone, email, property/residential address).
Categories of personal data:
- Master data (name, where applicable organization/place of work)
- Contact data (email, where applicable phone number, address — business or, for end customers, private)
- Access/authentication data (login identifier, password hash, where applicable 2FA secret)
- Usage/log data (IP address, timestamp, activity/log data)
- Content/input data (projects, tasks, documents, messages, comments); this also includes prompt/output data passed to the language model when using the AI features, as well as address/location data transmitted for geocoding
- Contract/billing data (only when the payment function is activated; card data is collected exclusively by Stripe, not by the processor)
Special categories under Art. 9 GDPR are not subject to processing.
Duration: For the term of the main contract; deletion/return in accordance with § 7.
Annex 2 — Approved Sub-processors
| No. | Sub-processor | Registered office / place of processing | Purpose | Transfer basis |
|---|---|---|---|---|
| 1 | Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, DE | Germany (EU) | Hosting, storage, backups (operation of the application/infrastructure) | EU/EEA — no third-country transfer |
| 2 | EDEN AI SAS (trade name DATAGENIUS), 19 Rue Louis Guérin, 69100 Villeurbanne, FR | France (EU) | AI service: orchestration/provision of the language model (chat + embeddings); processing of prompt/content data | EU/EEA; model provider see no. 3 |
| 3 | Google (Gemini) as sub-sub-processor via EdenAI — Google Ireland Ltd.; model processing via Google Vertex AI (EU multi-region) | EU (Vertex AI EU multi-region) | AI model processing of user inputs transmitted via EdenAI’s EU endpoint (api.eu.edenai.run); routing exclusively via EU-capable providers | EU/EEA — no third-country transfer |
| 4 | Google Maps Platform / Places — Google Ireland Ltd. / Google LLC (USA) | USA | Resolution/geocoding of address/location information (work package locations) | Third country USA: EU-US DPF, supplemented by EU Standard Contractual Clauses + TIA |
| 5 | Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, IE | Ireland (EU) | Payment/subscription processing (seat-based) | EU contractual partner; Stripe, Inc. (USA) as sub-processor: EU-US DPF, supplemented by SCC |
| 6 | Brevo GmbH (formerly Sendinblue), Köpenicker Str. 126, 10179 Berlin, DE | Germany (EU) | Sending of transactional emails | EU/EEA |
| 7 | Cloudflare Germany GmbH, Rosenheimer Str. 143C, 81671 Munich, DE (parent company Cloudflare, Inc., USA) | Germany (EU); global (CDN) | DNS for the domain as well as delivery/protection of the public landing page (website); the application itself runs directly on Hetzner (no Cloudflare proxy) | Where there is US group affiliation: EU-US DPF, supplemented by EU Standard Contractual Clauses + TIA |
Notes:
- Google is used in two functions: as the model provider behind the AI service (no. 3, only when using the AI features) and for address geocoding (no. 4).
- Web analytics is carried out with self-operated software (Umami) on the processor’s infrastructure (Hetzner); no data transfer to third parties takes place.
- A data processing agreement pursuant to Art. 28(4) GDPR is in place with each listed sub-processor.
Annex 3 — Technical and Organizational Measures (Art. 32 GDPR)
1. Confidentiality
- Physical access control: Operation in a certified data center (Hetzner, ISO 27001); physical access protection is the responsibility of the operator. No own server operation.
- System access control: Login with username/password; passwords exclusively as secure hashes (bcrypt); optional two-factor authentication (TOTP, secret AES-256-GCM-encrypted); lockout after repeated failed attempts; session management.
- Data access control: Role-based permission system (Owner/Admin/Member), least privilege, logging of access.
- Separation control: Tenant separation per organization (org_id); separation of production and test systems.
2. Integrity
- Transfer control: Encrypted transmission (TLS/HTTPS); JWT-based API authentication.
- Input control: Activity/audit logs (who, when, what) for changes and deletions.
3. Availability and Resilience
- Regular, automated backups (separate from the production system); monitoring; timely security updates; firewalls.
4. Deletion
- Personal data is deleted from the production database and file systems on the controller’s instructions or after the end of the contract.
- Data contained in backup copies is overwritten as part of the regular backup cycle.
- The physical destruction of data carriers is the responsibility of the hosting provider (Hetzner) according to its procedures.
- With sub-processors, deletion takes place in accordance with the respective DPAs.
5. Review
- Review of the measures at least annually and on a case-by-case basis; careful selection and review of sub-processors; commitment of employees to confidentiality.