Cookie Settings

We use cookies to ensure the basic functionality of our website. Essential cookies (theme preference, session, consent status) are required and cannot be disabled. Optional cookies for analytics and payment processing are only set with your explicit consent. Privacy Policy

Legal Information

Data Processing Agreement

DPA pursuant to Art. 28 GDPR

Last updated: March 2026

§1 Preamble and Subject Matter

(1) This Data Processing Agreement (hereinafter "DPA") is entered into between the Customer as the Controller within the meaning of Art. 4(7) GDPR (hereinafter "Controller") and GraphCapsule, operated by Oliver Czempas, Feldbergstrasse 18, 68163 Mannheim, Germany, as the Processor within the meaning of Art. 28 GDPR (hereinafter "Processor").

(2) This DPA specifies the data protection obligations of the parties in connection with the processing of personal data by the Processor on behalf of the Controller in the context of the SaaS service "GraphCapsule" in accordance with the Terms of Service.

(3) This DPA is an integral part of the Terms of Service and shall take precedence in the event of any conflict regarding data protection provisions.

§2 Subject Matter and Duration of Processing

(1) The Processor processes personal data on behalf of the Controller for the purpose of providing Microsoft 365 backup, archiving, and restoration services. This includes:

  • Automated backup and indexing of Microsoft 365 data (Exchange Online, OneDrive, SharePoint, Teams)
  • Encrypted storage of backed-up data in EU data centers
  • Full-text indexing to enable search and retrieval
  • On-demand restoration of backed-up data to the Controller's Microsoft 365 environment
  • Management of retention periods and automated enforcement of retention policies

(2) The duration of processing corresponds to the term of the main agreement (Terms of Service) plus the data export period pursuant to §12(6) of the Terms of Service and the subsequent deletion period.

§3 Nature and Purpose of Processing

(1) The nature of processing includes: collection (via Microsoft Graph API), storage, encryption, compression, indexing, querying, transmission (during restore), and deletion.

(2) The purpose of processing is exclusively the provision of the backup, archiving, and restoration services as defined in the Terms of Service and the Service Description.

§4 Types of Personal Data

The following categories of personal data may be processed depending on the content of the Controller's Microsoft 365 environment:

  • Email messages including senders, recipients, subject lines, message content, and attachments
  • Calendar entries including meeting invitations, attendees, and appointment details
  • Contact data including names, email addresses, phone numbers, and organizational information
  • OneDrive and SharePoint files and associated metadata (file names, authors, modification dates)
  • Teams channel messages, chat content, and shared files
  • User profile information from Microsoft 365 (display names, email addresses, job titles, departments)

The Processor has no influence over the types of personal data stored in the Controller's Microsoft 365 environment. The Controller shall ensure that the processing of such data by the Processor is lawful.

§5 Categories of Data Subjects

The processed personal data may relate to the following categories of data subjects:

  • Employees and staff of the Controller
  • External contacts whose data is contained in Microsoft 365 communications (e.g., email correspondents, meeting participants)
  • Other individuals whose personal data is contained in the backed-up Microsoft 365 data

§6 Obligations of the Processor

(1) The Processor undertakes to:

  • process personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law to which the Processor is subject (Art. 28(3)(a) GDPR);
  • ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR);
  • take all measures required pursuant to Art. 32 GDPR regarding the security of processing (see Technical and Organizational Measures (TOM));
  • assist the Controller in fulfilling its obligation to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, data portability, objection);
  • assist the Controller in ensuring compliance with the obligations pursuant to Art. 32 to 36 GDPR;
  • at the choice of the Controller, delete or return all personal data after the end of the provision of processing services, and delete existing copies unless Union or Member State law requires retention of the personal data;
  • make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allow for and contribute to audits, including inspections.

(2) The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions (Art. 28(3), third sentence, GDPR).

§7 Sub-processors

(1) The Processor currently engages the following sub-processors:

Sub-processorRegistered OfficePurposeLocations
Infrastructure provider (ISO 27001 certified)EUS3 object storage, server infrastructureGermany (primary), Finland (secondary)

Note: Microsoft Corporation is the operator of the Microsoft 365 platform and data source. Microsoft is not a sub-processor in relation to the Processor. Access to Microsoft 365 data is authorized exclusively by the Controller via OAuth.

(2) The Controller grants the Processor general authorization to engage additional sub-processors. The Processor shall inform the Controller of any intended changes at least thirty (30) calendar days in advance in text form.

(3) The Controller may object to the change within fourteen (14) calendar days of receipt of the notification on justified grounds. In the event of a justified objection, the parties shall endeavor to reach an amicable resolution. If no agreement can be reached, the Controller shall have the right to terminate the agreement with thirty (30) calendar days' notice.

(4) The Processor shall ensure that each sub-processor is subject to at least the same data protection obligations as set out in this DPA.

§8 Transfers to Third Countries

(1) All personal data is stored and processed exclusively within the European Union (EU) or the European Economic Area (EEA). No transfer to third countries takes place during normal operations.

(2) Should a transfer to a third country become necessary, the Processor shall ensure that appropriate safeguards pursuant to Art. 46 GDPR (in particular Standard Contractual Clauses) or an adequacy decision pursuant to Art. 45 GDPR are in place. The Controller shall be informed in advance.

(3) If the Controller uses the BYOB option (Bring Your Own Bucket) and selects a storage location outside the EU/EEA, the Controller bears the data protection responsibility for such transfer.

§9 Technical and Organizational Measures

(1) The Processor shall implement the technical and organizational measures required pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk. A detailed description of the measures is documented in the annex Technical and Organizational Measures (TOM).

(2) The Processor shall review the measures regularly and adapt them to the state of the art.

§10 Notification of Personal Data Breaches

(1) The Processor shall notify the Controller of any personal data breach (Art. 4(12) GDPR) without undue delay, and in any event no later than 48 hours after becoming aware of it. The notification shall include:

  • a description of the nature of the breach, including the categories and approximate number of data subjects and personal data records concerned;
  • the name and contact details of the Processor's contact person;
  • a description of the likely consequences of the breach;
  • a description of the measures taken or proposed to address and mitigate the breach.

(2) The Processor shall assist the Controller in fulfilling its notification obligations pursuant to Art. 33 and 34 GDPR.

§11 Audit Rights of the Controller

(1) The Controller shall have the right to conduct audits, including inspections, to verify compliance with this DPA and the requirements of Art. 28 GDPR. The Controller may engage an independent third party to conduct the audit.

(2) The Processor shall make available to the Controller the information necessary to demonstrate compliance and shall grant reasonable access to its premises, systems, and records.

(3) Audits shall be conducted with reasonable prior notice during normal business hours and shall not unreasonably disrupt business operations. The Controller shall bear the costs of the audit.

§12 Return and Deletion of Data

(1) Upon termination of the main agreement, the Controller shall have a period of thirty (30) calendar days to export its data using the export functionality of the service.

(2) After the expiry of the export period, the Processor shall irrevocably delete all personal data processed on behalf of the Controller, including all backup copies in S3 storage and search indexes. The Processor shall confirm the deletion in writing upon the Controller's request.

(3) The obligation to delete shall not apply insofar as a statutory retention obligation prevents deletion. In such cases, the Processor shall restrict processing to the extent required by law.

§13 Liability

(1) The liability of the parties shall be governed by the Terms of Service and Art. 82 GDPR.

(2) The Processor shall be liable for damages caused by processing that does not comply with the GDPR only where it has not complied with obligations specifically directed to processors or where it has acted outside of or contrary to the lawful instructions of the Controller (Art. 82(2) GDPR).

§14 Final Provisions

(1) Amendments and supplements to this DPA must be made in text form.

(2) Should any provision of this DPA be or become invalid, the validity of the remaining provisions shall not be affected.

(3) This DPA shall be governed by the laws of the Federal Republic of Germany.

Contact

For questions regarding this DPA, please contact:

GraphCapsule

Oliver Czempas

Feldbergstrasse 18

68163 Mannheim, Germany

Email: [email protected]