Data Processing Agreement (DPA)
pursuant to Art. 28 GDPR – octoja GmbH
octoja GmbH — As of: August 2026
This is a courtesy translation. The legally binding version is the German original.
Preamble
octoja GmbH (hereinafter "Processor") processes personal data on behalf of the respective contractual partner (hereinafter "Controller") in the course of providing the octoja RMM platform. This Data Processing Agreement (hereinafter "DPA") governs the rights and obligations of both parties with regard to such processing pursuant to Art. 28 GDPR and supplements the existing main contractual documents (Terms of Use) between the parties.
§ 1 Subject Matter and Duration of Processing
- The Processor processes personal data on behalf of the Controller exclusively for the provision, operation, and maintenance of the octoja RMM platform and the associated support services.
- Processing takes place for the duration of the existing main contractual relationship. Upon termination of the main contract, the provisions on return and deletion pursuant to § 9 of this DPA shall apply.
§ 2 Nature and Purpose of Processing
Purpose of Processing: Operation of a Remote Monitoring & Management (RMM) SaaS platform for the management, monitoring, and automation of IT systems by the Controller (MSP/Reseller) for its end customers.
Nature of Processing: Collection, storage, transmission, modification, retrieval, use, deletion in the course of platform operations.
Categories of Data Subjects:
- Employees and user accounts of the Controller (MSP/Reseller)
- Employees and IT users of the Controller's end customers
- Technical contacts at end customers
Categories of Personal Data:
- Account data: name, email address, username, role, password hash
- System data of managed endpoints: device name, IP address, MAC address, hostname, operating system data, installed software, hardware information
- Connection and access data: login timestamps, IP addresses, session data
- Support and communication data: ticket content, email communication in a support context
- Log data: activity logs, script executions, patch logs
Special Categories of Personal Data (Art. 9 GDPR): The processing of special categories of personal data is not intended and must be refrained from by the Controller unless separately agreed in writing.
§ 3 Obligations of the Processor
- The Processor processes personal data exclusively on documented instructions of the Controller – including with regard to the transfer of personal data to a third country – unless required to do so by EU or member state law.
- The Processor shall inform the Controller without delay if it believes that an instruction violates the GDPR or other Union or Member State data protection provisions. The Processor is entitled to suspend the execution of the instruction concerned until the Controller confirms or amends it.
- The Processor ensures that persons authorized to process personal data have committed to confidentiality or are subject to an appropriate statutory obligation of secrecy and, where applicable, are bound by obligations under § 203 of the German Criminal Code (StGB) (see § 11).
- The Processor takes all measures required pursuant to Art. 32 GDPR. The specific technical and organizational measures are documented in Annex 1 (TOM) to this DPA.
- The Processor assists the Controller, where possible, through appropriate technical and organizational measures in fulfilling its obligation to respond to requests from data subjects pursuant to Chapter III GDPR.
- The Processor assists the Controller in complying with obligations pursuant to Art. 32–36 GDPR (data security, notification obligations, data protection impact assessment).
- The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor commissioned by the Controller. Audits must be announced at least 4 weeks in advance, be limited to octoja's business hours, and must not unreasonably disrupt business operations. The costs of the audit shall be borne by the Controller. The Controller shall not bear the costs for incident-related audits following a personal data breach attributable to the Processor.
§ 4 Obligations of the Controller
- The Controller is the responsible party within the meaning of the GDPR – or, insofar as it processes the data as a processor on behalf of its end customers, their processor – for all personal data processed or caused to be processed via the Platform. The Controller ensures that a sufficient legal basis exists for each processing activity, including any required data processing agreements with its end customers; in that case, the Processor acts as a further processor (sub-processor).
- The Controller issues processing instructions exclusively in writing or via the functions provided for this purpose on the Platform. Oral instructions must be confirmed in writing without delay.
- The Controller shall inform the Processor without delay if it discovers errors or irregularities in the course of reviewing instructions or processing.
- The Controller ensures that it fulfils the data protection information obligations required towards its end customers and their employees.
§ 5 Sub-Processors (Subcontractors)
- The Controller hereby grants the Processor a general authorization to engage sub-processors. The Processor shall inform the Controller at least four weeks prior to the intended engagement or replacement of a sub-processor in text form (email or notification via the Platform). The Controller may object to the change within two weeks of receipt in text form for important data protection reasons. If no mutually agreed solution is reached in the event of an objection, the Controller is entitled to terminate the main contract extraordinarily at the time the change takes effect.
- Current Sub-Processors:
Sub-Processor Location Processing Purpose Hetzner Online GmbH Germany (Nuremberg/Falkenstein) Hosting, data centre operations, data storage Hetzner Online GmbH (Object Storage) Germany Storage of encrypted database backups Supabase Pte. Ltd. Singapore; data processed exclusively in the EU (Frankfurt am Main region); safeguarded via EU Standard Contractual Clauses Database for customer management CORDNET OÜ (d/b/a Featurebase) Estonia (Viimsi, Harju maakond, EU) Ticket system, customer support Microsoft Ireland Operations Ltd. Ireland (EU) Email communication in the context of support (may contain personal data from support requests) BunnyWay d.o.o. (Bunny CDN) Slovenia (EU) Content delivery network, delivery of static platform content Sendinblue GmbH (Brevo) Germany (Berlin) Email notifications, transactional emails seven communications GmbH & Co. KG Germany Alerting via phone call, SMS and WhatsApp. Note: When alerting via WhatsApp, phone numbers are transmitted to WhatsApp Ireland Ltd. / Meta; use of the WhatsApp channel is optional and activated by the Controller. - Third-party services that the Controller activates and configures independently via the Platform (e.g., ThreatDown, Lywand, Acronis; current overview at https://octoja.de/en/features/integrations) are not sub-processors within the meaning of this DPA. In this respect, the Processor acts solely as a technical integration layer; responsibility under data protection law for the use of these services lies with the Controller (cf. § 8 of the Terms of Use).
- All sub-processors are contractually obligated to maintain a level of data protection equivalent to that of this DPA, including the obligations under § 11. For sub-processors located outside the EU/EEA, the Processor ensures an adequate level of data protection through appropriate safeguards (e.g., EU Standard Contractual Clauses).
- The Processor is liable to the Controller for the fulfilment of data protection obligations by its sub-processors to the same extent as for its own violations.
§ 6 Data Subject Rights
- The Processor shall forward requests from data subjects who contact it directly to the Controller without delay. The Processor shall not respond to such requests independently unless expressly instructed to do so by the Controller.
- The Processor shall assist the Controller upon request in fulfilling data subject rights (access, rectification, erasure, restriction, data portability, objection), insofar as this is technically possible and feasible within the scope of platform operations.
§ 7 Notification Obligations in Case of Data Breaches
- The Processor shall report to the Controller any breach of protection of personal data (Art. 4 No. 12 GDPR) affecting data processed on behalf without undue delay after becoming aware, generally within 24 hours. If not all information pursuant to para. 2 is available at that point, a preliminary notification shall be made first; further information will be provided without delay thereafter.
- The notification shall contain at minimum:
- the nature of the breach and affected data categories,
- the approximate number of affected individuals and data records,
- the likely consequences of the breach,
- measures taken or proposed to remedy the breach.
- The Controller is solely responsible for notifying the competent supervisory authority and, where applicable, the affected data subjects pursuant to Art. 33 f. GDPR.
§ 8 Data Protection Impact Assessment
If a processing activity of the Controller requires a data protection impact assessment pursuant to Art. 35 GDPR, the Processor shall assist the Controller upon request by providing relevant information about platform operations and the technical measures employed.
§ 9 Deletion and Return After Contract End
- Upon termination of the main contract, the Processor shall delete all personal data of the Controller, unless statutory retention obligations apply. Deletion shall take place no later than 30 days after contract end.
- Upon request by the Controller, which must be made before the expiry of the 30-day period, the Processor shall provide the data in a commonly used export format. The costs for a data export may be charged to the Controller.
- The Processor shall confirm complete deletion in writing to the Controller upon request.
§ 10 Liability
The liability of the parties under this DPA is governed by the liability provisions of the main contract (Terms of Use § 6). In relation to data subjects, Art. 82 GDPR applies.
§ 11 Professional Secrecy Holders (§ 203 German Criminal Code – StGB)
- Insofar as the Controller is itself a professional secrecy holder within the meaning of § 203 (1) StGB or uses the Platform for end customers who are professional secrecy holders (in particular tax advisors, auditors, lawyers, physicians and other members of the health professions, insurance companies), the Processor acts as an other participating person within the meaning of § 203 (3) sentence 2 StGB.
- The Processor undertakes to maintain secrecy regarding all third-party secrets that become known to it in the course of providing the services, in particular secrets pertaining to the personal sphere of life as well as trade and business secrets, and to neither disclose nor exploit them without authorization. The Processor takes note of protected information only to the extent necessary for the proper performance of the contractual services.
- The Processor obligates all persons who are involved in the provision of services or who may gain access to the Controller's data, in writing and prior to commencing their activities, to maintain confidentiality pursuant to § 203 StGB and instructs them about the criminal liability of unauthorized disclosure pursuant to § 203 (4) StGB. The Processor shall provide the Controller with evidence of such obligation upon request.
- If the Processor engages sub-processors pursuant to § 5 who may gain access to protected information, it shall obligate them to confidentiality pursuant to § 203 StGB in the same manner and ensure that they in turn obligate the persons working for them accordingly.
- The Processor is entitled to disclose information insofar as it is legally obligated to do so; it shall inform the Controller thereof in advance, where legally permissible.
- The obligations under this section shall continue to apply without any time limitation beyond the termination of the main contract.
§ 12 Final Provisions
- This DPA forms an integral part of the main contract and is subject to the same applicable law (German law).
- In the event of conflicts between this DPA and the main contract, this DPA shall prevail with respect to data protection matters.
- Amendments to this DPA require text form. The Processor shall notify the Controller of amendments in text form at least 30 days before they take effect; § 5 para. 1 remains unaffected for sub-processor changes.
octoja GmbH – As of August 2026