Data processing agreement for business customers

Status: 12 September 2026 – draft for legal review

1. Parties and precedence

Controller: [CUSTOMER]
Processor: Daniel Mörbitz, trading as confacAI, Seebacher Straße 66, 67098 Bad Dürkheim, Germany

This agreement supplements the SaaS agreement. In the event of conflict, it takes precedence for processing personal data on behalf of the controller.

2. Subject, duration and purpose

confacAI provides the controller with a cloud-based platform for processing and creating digital content. Processing takes place for the duration of the SaaS agreement and only to provide the agreed functions following the controller’s documented instructions.

3. Data, persons and processing

4. Instructions and confidentiality

confacAI processes data only on documented instruction from the controller unless a legal obligation requires otherwise. Persons with data access are bound to confidentiality.

5. Security

confacAI takes appropriate technical and organisational measures. The specific TOM annex forms part of this agreement and must reflect actual operations.

6. Sub-processors

The controller authorises the sub-processors listed in the sub-processor list. confacAI informs the controller of intended changes with appropriate advance notice and grants a reasoned right to object.

[LEGAL DECISION: Add period, form and consequences of objection, and list of sub-processors.]

7. Assistance and data breaches

Taking account of the nature of processing, confacAI assists the controller with data-subject requests, data-protection impact assessments and consultations. confacAI informs the controller of personal-data breaches without undue delay after becoming aware and provides available information.

8. Audit

On reasonable request, confacAI demonstrates compliance with agreed measures by suitable evidence. On-site audits require adequate prior notice, may not disproportionately impair operations and must respect other customers’ security interests.

9. Return and deletion

At the end of the SaaS agreement, confacAI deletes or returns personal data at the controller’s choice unless statutory retention obligations apply.

[SPECIFY TECHNICALLY AND LEGALLY: Export format, period, deletion of active data, backups, logs and invoice data.]

10. Third-country transfers

Where a sub-processor processes data outside the EEA or access from a third country is possible, confacAI ensures the required legal basis and supplementary safeguards under Art. 44 et seq. GDPR.

11. Annexes