Skip to main content

Data Processing Agreement (DPA)

When we look after IT systems for you as a company, we may process personal data on your behalf. Pursuant to Art. 28 GDPR, we conclude a data processing agreement (DPA) with you for this purpose. This page summarises the key points.

When a DPA is required

A data processing agreement is always required whenever, in the course of our services, we have access to personal data for which you are responsible as the controller — for example when supporting email mailboxes, cloud storage, backups or workstation systems.

Subject matter and duration

The subject matter of the data processing is the processing of personal data solely for the purpose of delivering the agreed IT services. The duration corresponds to the term of the underlying main contract.

Nature, scope and purpose of the processing

The nature and purpose of the processing, as well as the categories of data concerned, depend on the systems being supported and are described specifically in the DPA. Processing takes place exclusively on the documented instructions of the controller.

Categories of data subjects and data

The data subjects are generally the controller's employees, customers and business partners. The data processed typically includes master data, communication data and content data stored in systems, in each case depending on the system being supported.

Obligations of the processor

In particular, we undertake to:

  • process data exclusively on the documented instructions of the controller
  • commit the personnel involved to confidentiality
  • implement appropriate technical and organisational measures pursuant to Art. 32 GDPR
  • support the controller with data subject requests and reporting obligations
  • delete or return the data once the service has been completed
  • demonstrate compliance with these obligations

Technical and organisational measures

We take appropriate measures to protect the data, including access and entry controls, encrypted transmission and storage, regular backups and the separation of customer data. The specific measures are documented in the DPA.

Sub-processors

The use of additional service providers (e.g. hosting or cloud providers) takes place only under a corresponding contractual obligation pursuant to Art. 28 GDPR and within the framework of the agreement reached with you.

Your control and data subject rights

As the controller, you retain control over the processing. We support you in exercising the rights of data subjects and in carrying out any necessary checks and providing evidence.

Request the DPA

We provide the complete data processing agreement on request. Please contact info@grawert-it.com for this. Last updated: August 2026