Data Processing Agreement (DPA)
Last updated: 2026-09-20 · Version 2026.09
Data Processing Agreement (DPA)
Version 2026.09. Consent to this agreement is obtained during studio setup and recorded in your studio settings. This is a courtesy translation of the German Auftragsverarbeitungsvertrag; in case of doubt the German version prevails.
Between Alexander Leonhartsberger-Schrott, 6065 Thaur, Dörferstrasse 26c, Österreich ("Processor") and the registered owner of the kofel studio account ("Controller"), the following agreement on data processing pursuant to Art. 28 GDPR is concluded. It forms part of the contractual relationship between the parties regarding the use of kofel studio (kofel.studio).
1. Subject Matter and Duration
The Processor processes personal data on behalf of the Controller. The duration corresponds to the term of the usage agreement. The Processor shall process the data exclusively on the instructions of the Controller and in accordance with the provisions of this agreement, unless it is obliged to process the data by Union or Member State law.
2. Nature and Purpose of Processing, Categories of Data, Categories of Data Subjects
The Processor processes the data that the Controller stores in kofel studio or that is received via the service's interfaces, namely:
- Purpose: provision and operation of kofel studio as software-as-a-service in accordance with the usage agreement, including synchronisation, search, notifications and the additional functions activated by the Controller.
- Categories of data: master and contact data (e.g. names, email addresses), content data (e.g. projects, items, notes, documents and file attachments), billing data, technical usage data (e.g. logs), and any other data uploaded by the Controller.
- Categories of data subjects: employees, contacts, customers and any other persons whose data the Controller enters into the system or imports via interfaces.
3. Instructions
Instructions are issued by the Controller or its designated representatives via the functionalities of kofel studio (configuration, data and account management) or in writing to hello@kofel.io. The Processor shall inform the Controller immediately if it considers an instruction to infringe data protection law; it is entitled to suspend the execution of such an instruction until the matter is clarified.
4. Confidentiality
The Processor binds persons entrusted with processing to confidentiality and ensures that they can only access the data they require to perform their tasks.
5. Technical and Organisational Measures (Annex II)
The processor has implemented the following technical and organisational measures to ensure the security of processing within the meaning of Art. 32 GDPR. The measures are adapted to technical progress and risk developments without reducing the level of protection.
- Confidentiality (Art. 32(1)(a) GDPR)
- Personal data is stored on encrypted volumes and databases; all transmission takes place over TLS-encrypted connections.
- Access controls: role- and permission-based access control at the application level, gated authentication, multi-factor authentication at minimum for administrative access.
- Physical access control is ensured by the hosting provider in data centres within the EU.
- Integrity (Art. 32(1)(b) GDPR)
- Automated, encrypted backups of databases and file storage; regular restore tests.
- Version control and traceable deployments; data changes captured in application audit logs.
- Availability and resilience (Art. 32(1)(b) GDPR)
- Redundant hosting infrastructure, monitoring of system load and availability, tiered alerting.
- Rapid recoverability (Art. 32(1)(c) GDPR)
- Incident response plan with documented recovery procedures and defined recovery times.
- Records of processing and separation of responsibilities
- Records of processing pursuant to Art. 30(2) GDPR; collection, processing and use of personal data only within the scope of documented instructions.
- Data protection by default
- Minimisation of collected data (Art. 5(1)(c) GDPR); deletion deadlines and routines; encryption of particularly sensitive access credentials (e.g. API keys, bank access tokens) using AES-256.
- Training and confidentiality (Art. 32(4), Art. 29 GDPR)
- All persons involved in processing are bound to confidentiality and trained in handling personal data.
- Transfer control (Art. 32(1)(b) GDPR)
- Disclosure of personal data only to documented sub-processors under a reviewed DPA; encryption of transfers, logging of data transmissions.
- Separability (Art. 32(1)(b) GDPR)
- Separate storage of different customers' data (multi-tenancy with tenant isolation), enabling purpose-specific processing.
6. Sub-processing
The Processor may engage sub-processors only with the Controller's prior authorisation. Such authorisation is deemed granted for the sub-processors published in the sub-processor list at https://kofel.studio/sub-processors. The Processor shall inform the Controller of intended changes (adding or replacing sub-processors) at least 30 calendar days in advance so that the Controller may object. The Processor ensures that an agreement within the meaning of Art. 28(4) GDPR providing at least the obligations of this agreement is in place with every sub-processor.
7. Assistance with Data Subject Rights
The Processor assists the Controller, to the extent of the service's functionalities (in particular access, export and deletion within the application), in responding to data subjects' requests to exercise their rights under Art. 15 to 22 GDPR.
8. Notification of Personal Data Breaches
The Processor shall notify the Controller of any personal data breach occurring at the Processor or a sub-processor without undue delay, at the latest 48 hours after becoming aware, where the breach is likely to result in a risk to the rights of data subjects. The notification contains the information pursuant to Art. 33(3) GDPR insofar as available at the time of notification.
9. Return and Deletion
Upon termination of the engagement, the Processor shall delete all personal data processed in connection with the engagement at the latest 90 calendar days after the end of the agreement, unless Union or Member State law requires further storage (in which case the Processor shall return the data unaffected by this obligation and block it from further processing). Before expiry of this period, the Controller may export its data in common formats.
10. Controls and Audits
The Controller may verify the Processor's compliance with its obligations after reasonable prior notice during normal business operations or have them verified by a third party to be bound by confidentiality. The Processor shall provide the necessary support; upon request, it shall make available the results of its own audits.
11. Transfers to Third Countries
Transfers to Third Countries
Where service providers based outside the EU process personal data (in particular providers based in the United States), the transfer takes place only on one of the following bases:
- an adequacy decision of the EU Commission, in particular the EU-US Data Privacy Framework (DPF), where the respective provider is certified; or
- the EU Commission's Standard Contractual Clauses (Decision 2021/914) supplemented by additional measures (including encryption, data minimisation); or
- explicit consent (Art. 49(1)(a) GDPR), where none of the above bases applies.
The current overview of providers and the safeguards applied is available in the sub-processor list.
12. Final Provisions
Amendments and supplements to this agreement require text form; this also applies to any waiver of the text form requirement. Should individual provisions of this agreement be invalid, the validity of the remaining provisions shall remain unaffected. Otherwise, the contractual agreements concluded between the parties apply, in particular the terms and conditions. This agreement is governed by — subject to deviating agreements in the main contract — Austrian law.