Data processing agreement for business customers
Status: 12 September 2026 – draft for legal review
1. Parties and precedence
Controller: [CUSTOMER]
Processor: Daniel Mörbitz, trading as confacAI, Seebacher Straße 66, 67098 Bad Dürkheim, Germany
This agreement supplements the SaaS agreement. In the event of conflict, it takes precedence for processing personal data on behalf of the controller.
2. Subject, duration and purpose
confacAI provides the controller with a cloud-based platform for processing and creating digital content. Processing takes place for the duration of the SaaS agreement and only to provide the agreed functions following the controller’s documented instructions.
3. Data, persons and processing
| Area | Draft – to be specified by lawyer and customer model |
|---|---|
| Types of data | Account/contact details, brief content, text, image, audio and video files, social-connection data and technical usage data. |
| Data subjects | Employees, customers, contacts, creators, and persons depicted or audible for the controller. |
| Processing | Storing, reading, structuring, transforming, transmitting to approved sub-processors, generating and providing results, deleting. |
| Special categories | [DECISION: Not intended; processing only after separate review and agreement.] |
4. Instructions and confidentiality
confacAI processes data only on documented instruction from the controller unless a legal obligation requires otherwise. Persons with data access are bound to confidentiality.
5. Security
confacAI takes appropriate technical and organisational measures. The specific TOM annex forms part of this agreement and must reflect actual operations.
6. Sub-processors
The controller authorises the sub-processors listed in the sub-processor list. confacAI informs the controller of intended changes with appropriate advance notice and grants a reasoned right to object.
[LEGAL DECISION: Add period, form and consequences of objection, and list of sub-processors.]
7. Assistance and data breaches
Taking account of the nature of processing, confacAI assists the controller with data-subject requests, data-protection impact assessments and consultations. confacAI informs the controller of personal-data breaches without undue delay after becoming aware and provides available information.
8. Audit
On reasonable request, confacAI demonstrates compliance with agreed measures by suitable evidence. On-site audits require adequate prior notice, may not disproportionately impair operations and must respect other customers’ security interests.
9. Return and deletion
At the end of the SaaS agreement, confacAI deletes or returns personal data at the controller’s choice unless statutory retention obligations apply.
[SPECIFY TECHNICALLY AND LEGALLY: Export format, period, deletion of active data, backups, logs and invoice data.]
10. Third-country transfers
Where a sub-processor processes data outside the EEA or access from a third country is possible, confacAI ensures the required legal basis and supplementary safeguards under Art. 44 et seq. GDPR.
11. Annexes
- Annex 1: Description of processing
- Annex 2: Technical and organisational measures
- Annex 3: Sub-processors