Data processing agreement (DPA) 1.0
As of: 29.04.2026
This English text is a convenience translation. The legally binding version is the German Auftragsverarbeitungsvereinbarung; in case of discrepancies, the German version prevails.
1. Subject and scope
This agreement governs the processing of personal data by Systempilot on behalf of the client within the scope of the collaboration.
It applies to all services of Systempilot in which access to personal data cannot be excluded.
2. Nature and purpose of the processing
Systempilot processes personal data within the scope of the contractually agreed services, in particular for the following purposes:
There is no processing for its own purposes.
- the implementation, configuration and support of IT solutions
- the analysis, validation and transfer of data
- error analysis, support and optimisation
3. Type of data and categories of data subjects
Depending on the project, in particular the following data may be processed:
Data subjects are in particular:
- Business and contact data
- System and usage data
- Other data processed within the respective systems
- Employees of the client
- Business partners of the client (e.g. customers, suppliers)
4. Obligations of Systempilot
Systempilot processes personal data exclusively within the scope of the contractually agreed services and only on documented instructions of the client. Documented instructions are in particular this agreement, the underlying project agreement, agreed service descriptions and other instructions of the client documented in writing or electronically.
This also applies to any transfer of personal data to a third country or an international organisation, provided such transfer occurs within the scope of the agreed services or is legally permissible.
Systempilot informs the client if Systempilot is of the opinion that an instruction violates data protection provisions.
Systempilot ensures that persons authorised to process personal data are committed to confidentiality or are subject to an appropriate statutory duty of confidentiality.
Systempilot takes appropriate technical and organisational measures to protect the personal data processed.
5. Use of third parties / sub-processors
Systempilot is entitled to use third parties to fulfil the contractual services.
Insofar as these third parties process personal data on behalf of Systempilot, they are sub-processors within the meaning of Art. 28 GDPR. Systempilot uses sub-processors only if they have been contractually committed to complying with the statutory data protection requirements. Insofar as the sub-processor processes personal data on behalf of Systempilot, the data protection obligations relevant to its service under this agreement or under Art. 28 GDPR are imposed on it.
The client grants Systempilot a general authorisation to use sub-processors. The sub-processors used at the time of conclusion of the contract result from the sub-processor list provided by Systempilot and are deemed approved upon conclusion of this agreement.
Systempilot informs the client in an appropriate manner about intended changes regarding the addition or replacement of sub-processors. The information may in particular be provided by email to the contact person named by the client or by updating the sub-processor list with corresponding notification.
The client may object to such a change within 14 days of information for an important data protection reason. The objection must be justified in writing or in text form. If no justified objection is made within this period, the change is deemed approved.
In the event of a justified objection, the parties will jointly seek an appropriate solution. Systempilot is not obliged to replace a sub-processor if this is not reasonable technically, economically or organisationally, or if the provision of services would thereby be materially impaired.
If the provision of services is not possible without the relevant sub-processor, or only with disproportionate effort, Systempilot is entitled to suspend the affected services or to terminate the contract to that extent for an important reason.
Systempilot remains responsible to the client for the data-protection-compliant involvement of the sub-processors to the extent provided by law.
6. Support obligations
Taking into account the nature of the processing and the information available to Systempilot, Systempilot supports the client to the necessary and reasonable extent in complying with data protection obligations, in particular in handling requests from data subjects and with obligations regarding the security of processing, notification of data breaches, data protection impact assessments and any consultations with supervisory authorities.
Systempilot is entitled to invoice separately, after prior coordination, for any effort arising from this insofar as it exceeds the contractually agreed scope of services.
7. Data transfer
Processing of personal data outside the EU or the EEA occurs only insofar as this is necessary within the scope of the contractually agreed services and the statutory requirements for it are met.
8. Deletion and return
After completion of the provision of the processing services, Systempilot, at the client's choice, deletes personal data or returns it and deletes existing copies, unless there is an obligation to store the personal data under Union law or the law of the member states.
Completion of the processing services is not already deemed to be the completion of an implementation project, provided Systempilot continues to be commissioned with support, maintenance, error analysis, optimisation or other contractually agreed services and the further processing is necessary for this.
During an ongoing support, maintenance or contractual relationship, Systempilot is entitled to continue to process and store personal data to the necessary extent, insofar as this is necessary for the provision of the contractually agreed services, for error analysis, for the traceability of project decisions or for ensuring ongoing operation.
After final termination of all contractual services that require the processing of personal data, return or deletion occurs at the client's choice, provided no statutory retention obligations conflict.
9. Audit rights
Upon reasonable request, Systempilot provides the client with all information necessary to demonstrate compliance with the obligations under this agreement and Art. 28 GDPR.
The client is entitled to verify compliance with this agreement to a reasonable extent. Audits are primarily carried out by submitting suitable evidence, information, documentation, technical and organisational measures and other suitable documents.
Insofar as this evidence is not sufficient in an individual case, further audits may be carried out after prior coordination. On-site audits come into consideration only insofar as they are necessary to fulfil the client's statutory audit obligations and the audit purpose cannot be achieved by milder means, in particular written information, document review or remote audit.
Audits must be announced in writing at least 14 days in advance, carried out during normal business hours, and must not disproportionately impair Systempilot's business operations. The client must ensure that auditors it uses are committed to confidentiality and are not competitors of Systempilot.
Audits may relate exclusively to systems, processes and information relevant to the processing of the client's personal data under this agreement. Trade and business secrets of Systempilot as well as third-party rights are to be appropriately protected.
Each party bears its own costs arising from an audit. If the client causes effort beyond the usual extent through an audit, Systempilot is entitled, after prior announcement, to invoice this effort separately at the agreed hourly rates.
10. Liability
The liability provisions of the underlying contract documents (in particular the terms & conditions and project agreement) apply.
11. Final provisions
This agreement supplements the contractual arrangements existing between the parties.
This agreement applies from conclusion and for the duration of the respective associated main contract under which Systempilot processes personal data on behalf of the client. Termination of the respective main contract automatically also results in the termination of this agreement, insofar as no further processing of personal data on behalf of the client takes place on the basis of another contractual relationship. An isolated termination of this agreement is excluded.
Amendments and additions to this agreement require text form, unless a stricter form is prescribed by law. Electronic form is sufficient.
Data protection notices, in particular in connection with instructions, sub-processors, audit rights, data subject rights or deletion and return requests, are to be addressed to the following email address: privacy@systempilot.net
The client is obliged to provide Systempilot with a current email address for data protection notices. Notices from Systempilot in connection with this agreement, in particular information about changes to sub-processors, may be sent to this email address or to the main contact person named by the client.
The current technical and organisational measures and the current sub-processor list are available in their respective valid version at the following links and are part of this agreement:
TOM: systempilot.net/en/tom
Sub-processor list: systempilot.net/en/uav