Back to home

Data Processing Agreement (DPA) under Art. 28 GDPR

Last updated: July 10, 2026

Only the German version of this Data Processing Agreement is legally binding. Translations into other languages are provided for convenience and are not legally binding.

1. Parties

This Data Processing Agreement (the "DPA") is concluded under Art. 28(3) GDPR between the following parties:

Processor ("Capwork"):

Capwork e.U.

Inhaber: Nikolas Kain

Am Europlatz 2, 1120 Wien

FN 677603a, Handelsgericht Wien

Email: office@capwork.io

Controller ("Customer business"):

The natural or legal person registering on the Capwork platform on whose behalf personal data of end customers, employees, suppliers, or other data subjects is processed via the platform. The exact details of the controller follow from the company, address, and representation information given at registration and from the main agreement (Terms of Service / AGB) concluded with Capwork.

By registering on the Capwork platform and ticking the corresponding consent, the controller concludes this DPA in electronic form (Art. 28(9) GDPR). The acceptance is logged in an audit-proof manner together with version number, timestamp, IP address, and user agent.

2. Subject matter, duration, nature and purpose of the processing

Subject matter: The subject matter of this DPA is the processing of personal data by Capwork on behalf of and according to the instructions of the controller, in the context of the Capwork platform (SaaS) and its modules (including appointment booking, customer management, order processing, inventory, vehicle management, finance, communication channels, task and workflow management, feedback collection).

Duration: The DPA runs for an indefinite term and ends automatically when the underlying main agreement (Terms of Service / AGB) between controller and Capwork ends. Early termination of this DPA is only possible together with the main agreement.

Nature of processing: Collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction — all in electronic form on the servers of the subprocessors named in section 7.

Purpose of processing:

  • Provision, operation, and maintenance of the platform features booked;
  • Appointment scheduling, confirmation, and notification to end customers;
  • Management of orders, invoices, inventory, vehicles, employees, and tasks of the controller;
  • Sending transactional messages (email, SMS, WhatsApp) on behalf of the controller to its end customers;
  • AI-assisted preprocessing (e.g. text extraction from documents, feedback analysis, scheduling suggestions) exclusively on the controller’s instruction, without using the data to train the underlying foundation models, and without any solely automated decisions producing legal or similarly significant effects within the meaning of Art. 22 GDPR. Which specific model is used — typically from Google (e.g. Gemini) or from Anthropic (e.g. Claude) via Vertex AI — is chosen by Capwork according to fit for the use case; all AI outputs are non-binding, non-deterministic suggestions whose use requires substantive confirmation by the controller or its staff;
  • Technical security of the service, troubleshooting, backup, recovery, and auditability.

3. Categories of data subjects

The processing covers in particular the following categories of data subjects:

  • End customers of the controller (people booking, contact persons, recipients of services);
  • Employees, staff, or freelancers of the controller, where managed via the platform;
  • Suppliers, business partners, external service providers of the controller;
  • Persons contacting the controller via integrated communication channels (email, SMS, WhatsApp, web forms);
  • Authorised users of the controller’s platform accounts (e.g. owner, management, administrators).

4. Categories of personal data

The following categories of personal data are processed, to the extent the controller enters them into the platform or instructs the platform to collect them:

  • Master and contact data (name, salutation, address, phone number, email address, optionally date of birth);
  • Appointment, booking, and order data (services booked, times, status, notes, attachments);
  • Communication content (messages, chat history, emails, SMS, WhatsApp messages, uploaded documents);
  • Vehicle, inventory, and workshop data, where personal (e.g. holder data, logbook entries, license plates);
  • Billing and payment-flow data, where captured via the platform (e.g. invoice line items, payment status); raw card and bank-account data of end customers is handled in tokenised form via the payment provider and is generally not accessible to Capwork in cleartext;
  • Authentication and security data of the controller’s platform users (email address, password hash via Firebase Authentication, login timestamps, IP address, session IDs);
  • Usage, log, and telemetry data, to the extent required for diagnostics, security, and billing.

Special categories of personal data within the meaning of Art. 9 GDPR (health data, biometrics, religious beliefs, etc.) are not part of this DPA. The controller may only enter such data into the platform if it has its own legal basis and dedicated safeguards; in this case the controller shall inform Capwork in writing before processing.

5. Obligations of the processor (Capwork)

Capwork undertakes to process personal data exclusively within the scope of the controller’s instructions and the requirements of this DPA. In particular:

  • Processing only on documented instructions of the controller — the main agreement, this DPA, and the controller’s in-platform configuration count as documented instructions. Further instructions may be issued through the in-platform support function; where the platform does not technically permit a specific instruction, the controller may submit it via e-mail to office@capwork.io (Art. 28(3)(a) GDPR);
  • Commitment of all persons authorised to process the data to confidentiality, or appropriate statutory duty of confidentiality (Art. 28(3)(b), Art. 29 GDPR);
  • Implementation of appropriate technical and organisational measures under Art. 32 GDPR, as detailed in section 9 (TOMs) (Art. 28(3)(c) GDPR);
  • Engagement of further processors only under the conditions of section 7 of this DPA (Art. 28(2) and (4) GDPR);
  • Assistance to the controller — as far as possible and with appropriate technical and organisational measures — in fulfilling its obligation to respond to requests by data subjects (Art. 12–22 GDPR; Art. 28(3)(e) GDPR);
  • Assistance to the controller in complying with its obligations under Art. 32–36 GDPR (security, breach notification, data protection impact assessment, prior consultation), taking into account the nature of the processing and the information available to Capwork (Art. 28(3)(f) GDPR);
  • Return or deletion of the data after the end of the provision of services as set out in section 13 (Art. 28(3)(g) GDPR);
  • Provision of all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and enabling audits and inspections under section 12 (Art. 28(3)(h) GDPR);
  • Use of AI models exclusively via Google Vertex AI with region-pinning to the EU, contractually safeguarded against use of the inputs for model training. Capwork selects the model best suited to the respective use case — typically Google’s own models (e.g. Gemini) or partner models offered via the Vertex Model Garden (e.g. Anthropic Claude). The model choice is at Capwork’s technical and commercial discretion, provided the level of protection assured in section 9 is not lowered; under the contract no data is transmitted to the model providers, since all inference is operated by Google Cloud;
  • Instructions that go beyond the standard platform functionality or its built-in configuration capabilities, or that cause exceptional effort, may be implemented by Capwork following a prior effort estimate against reasonable market remuneration; Art. 28 GDPR does not preclude this insofar as the duties for compliance with the statutory minimum requirements are performed free of charge.

6. Rights and obligations of the controller

The controller remains solely responsible for the lawfulness of the data processing and for safeguarding the rights of data subjects (Art. 4(7), Art. 24 GDPR). The burden of proof for the lawfulness of the instructions issued lies with the controller; Capwork is not obliged to actively assess the legal admissibility of every instruction, but will inform the controller without delay of any instruction that is manifestly unlawful (Art. 28(3) sentence 3 GDPR). The controller is in particular obliged:

  • To inform Capwork in good time and in full of all facts necessary for the proper performance of the engagement, including any deviating or additional instructions;
  • To maintain its own GDPR-compliant privacy notice and to inform its end customers of the use of the Capwork platform as a processor, including AI-assisted preprocessing, the third-country transfers under section 8, and the current subprocessor list under section 7;
  • To establish appropriate legal bases (e.g. contract performance, legitimate interest, consent) for the respective processing and — where necessary — to obtain, document, and demonstrate consents itself;
  • To answer requests by data subjects (access, rectification, erasure, restriction, portability, objection) primarily itself and to involve Capwork only where the platform’s self-service capabilities are insufficient;
  • To assign and maintain platform access, roles, and permissions of its employees with care and to suspend or reset compromised credentials without delay;
  • Before the productive use of AI-assisted features, to instruct its staff on the non-deterministic, preliminary nature of AI outputs and to verify the substantive plausibility of every AI output before further use — in particular before any external communication, invoicing, or legally effective decision; AI outputs may not be used as the sole basis for automated decisions producing legal effects within the meaning of Art. 22 GDPR;
  • To inform Capwork in advance in writing and to maintain its own legal basis if special categories of personal data (Art. 9 GDPR) or data on criminal convictions (Art. 10 GDPR) are to be entered into platform features — in particular AI-assisted ones; without such prior notice, the processing of such data in the platform is not covered by the general processing engagement;
  • To indemnify Capwork against third-party claims, including administrative fines and reasonable costs of legal defence, to the extent these result from a breach of this DPA or the GDPR for which the controller is responsible — in particular from entering inadmissible data into the platform, missing or unlawful legal bases, unlawful instructions, or insufficient transparency to data subjects.

7. Subprocessors

The controller hereby grants Capwork the general written authorisation under Art. 28(2) sentence 1 GDPR to engage further processors ("subprocessors") for the performance of the contract. Capwork contractually obliges every subprocessor to comply with data-protection obligations equivalent to those set out in this DPA (Art. 28(4) GDPR).

Capwork informs the controller of intended changes to the engagement or replacement of further processors at least 30 days in advance, by email to the contact address on file or via an in-platform notice. The controller may object to such changes for an important data-protection reason; mere preferences or commercial considerations do not constitute an important reason. If a valid objection is raised, the parties shall seek an amicable solution; if none is found within 30 days, the controller is entitled to extraordinary termination of the main agreement, but not to retention of the previous subprocessor. By way of derogation, the prior-notice period may be shortened in emergency situations — in particular insolvency, short-notice termination by the subprocessor, regulatory order, or compelling reasons of security or platform availability — to what is technically and organisationally feasible; Capwork informs the controller without delay after the fact.

Current list of subprocessors engaged (Annex 2):

ServiceFunctionLegal entityProcessing regionCategories of dataSafeguard for third-country transfers
Google Cloud Platform (Firestore, Cloud Functions, Cloud Storage, Cloud Build, Cloud Logging)Hosting of the platform, database, backend compute, backups, logging, CI/CDGoogle Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, IrelandEU (europe-west, primarily Frankfurt/Belgium); backups distributed across EU regionsall platform data in storage form: master, appointment, order, communication, inventory dataEU Commission Standard Contractual Clauses (SCC) via Google Cloud Data Processing Addendum; supplementary technical measures (encryption at rest and in transit); ISO 27001 / ISO 27018 / ISO 27701 / SOC 2 Type II
Firebase AuthenticationIdentity and access management for platform users (login, password reset, session tokens)Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (for EEA customers)global; authentication metadata may be processed in the United Statesemail address and password hash of platform users, login timestamps, IP address, user agentFirebase Data Processing and Security Terms (SCC); participation of Google LLC in the EU-U.S. Data Privacy Framework
Google Vertex AI (the provider's own models, e.g. Gemini, as well as partner models offered in the Vertex Model Garden, e.g. Anthropic Claude)AI-assisted preprocessing (text extraction, order analysis, document scanning, insights, feedback analysis, translation). Capwork selects the model best suited to the respective use case — typically from Google (e.g. Gemini) or from Anthropic (e.g. Claude), in both cases via Vertex AIGoogle Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, IrelandEU region (e.g. europe-west1 / europe-west4); for some models possibly EU multi-regionexclusively the content passed for the respective function (e.g. document or message content); no use of the data to train the foundation models per the Vertex AI terms. When using partner models offered in the Vertex Model Garden (e.g. Anthropic Claude), the entire inference is operated by Google Cloud — under the contract no transmission of data to the respective model providers (e.g. Anthropic PBC) takes place; they are therefore not independent subprocessors in the relationship with CapworkVertex AI Data Processing Addendum (SCC); region-pinning to the EU; explicit training-exclusion; equivalent safeguards for partner models under the Vertex AI terms
Twilio (Programmable Messaging — SMS, WhatsApp Business API, Voice)Sending transactional SMS and WhatsApp messages to end customers of the controllerTwilio Ireland Limited, 25-28 North Wall Quay, Dublin 1, IrelandEU region (Ireland) for data at rest; message content is transmitted to the respective mobile carriers for deliveryphone number, message content, delivery status, timestamps of end customersTwilio Data Protection Addendum with SCC; participation of Twilio Inc. in the EU-U.S. Data Privacy Framework
Bird (transactional email)Sending transactional emails (appointment confirmations, reminders, invoice emails) to end customers of the controllerBird B.V., Amsterdam, NetherlandsEuropean Union (Netherlands)email address, message content, subject, delivery status, bounce/click metadata of end customersData processing agreement under Art. 28 GDPR; processing within the EU — no third-country transfer
Stripe (payment processing, account verification, billing)Verification of the controller’s payment method, processing of platform subscription fees, optionally payments by the controller’s end customersStripe Payments Europe Limited, 1 Grand Canal Street Lower, Dublin 2, IrelandEU/Ireland for contract data; card and authentication data is processed worldwide via Stripe Inc. (USA)name and email of the controller, card token (no plaintext PAN), amount, receipt metadata; for end-customer payments additionally their payment and identity dataStripe Data Processing Agreement with SCC; PCI-DSS Level 1 certification; participation of Stripe Inc. in the EU-U.S. Data Privacy Framework. Note: For the fulfilment of statutory obligations (PSD2, KYC, AML, fraud prevention) Stripe simultaneously acts as an independent controller; in this respect a controller-to-controller transfer takes place rather than a processing arrangement.
Google Maps Platform (Places, Maps JavaScript API, Time Zone, Distance Matrix)Address search, map and distance calculation (geocoding, distance matrix) for appointment, order, and vehicle features as well as on the public registration pageGoogle Ireland Limited, Gordon House, Barrow Street, Dublin 4, IrelandEU processing; individual API calls may be handled globally via Google LLC (USA)entered or stored address data (customer, order, vehicle locations); when loaded on public pages, the device’s IP addressGoogle Maps Platform Data Processing Terms (SCC); participation of Google LLC in the EU-U.S. Data Privacy Framework

This list names every service individually (instead of just "Google" or similar) because Art. 28 GDPR requires specificity: each service has its own legal entity, its own contractual terms, its own processing region, and its own risk profile — and the controller must be able to object to each change separately.

8. Third-country transfers

A transfer of personal data to third countries outside the EEA only takes place where one of the conditions of Art. 44 et seq. GDPR is met — in particular an EU Commission adequacy decision, the use of Standard Contractual Clauses (SCC, Implementing Decision (EU) 2021/914), or another appropriate safeguard under Art. 46 GDPR.

Google LLC, Twilio Inc., and Stripe Inc. are certified under the EU-U.S. Data Privacy Framework and thus provide an adequate level of data protection within the meaning of the EU Commission adequacy decision of 10 July 2023. In addition, the respective Standard Contractual Clauses are part of the data processing agreements with these subprocessors.

Where required, Capwork carries out a transfer impact assessment (TIA) and implements supplementary technical measures (encryption in transit and at rest, region-pinning, pseudonymisation) to maintain the level of protection of Art. 44 GDPR.

9. Technical and organisational measures (TOMs, Annex 1)

Capwork aligns the following technical and organisational measures with the state of the art, the protection needs of the data being processed, and industry standards (in particular ISO 27001, ISO 27018, and ISO 27701, the certification basis of which is provided by the underlying cloud infrastructure — Google Cloud):

  • Encryption — TLS at the current state of the art for all data transmission, AES-256 or equivalent for storage in Firestore and Cloud Storage; key management via Google Cloud KMS;
  • Access and authorisation control — Google IAM with a role-based permissions model, granular platform roles (permissions system) for the controller’s employees;
  • Authentication — Firebase Authentication with password hashing at the current state of the art, optional email verification and password reset tokens with short validity;
  • Separation control — strict multi-tenancy via `companyId` scoping; Firestore security rules and server-side authorisation checks prevent access across tenant boundaries;
  • Availability and recoverability — automated daily backups, point-in-time recovery (PITR) on Firestore, cross-project backup vault, disaster-recovery project with a documented recovery procedure;
  • Pseudonymisation — card tokens instead of plaintext PAN, separate storage of technical identifiers and personal data wherever operationally reasonable;
  • Logging and auditability — Cloud Logging with retention of critical security logs, audit trail of all administrative actions and legal acceptances (version, timestamp, IP, user agent);
  • Staff commitment — all persons with access to personal data are committed to data secrecy and confidentiality; regular awareness training;
  • Vulnerability and patch management — automated dependency scanning, regular security updates of platform components, incident-response process.

Capwork may evolve the TOMs to adapt to the state of the art, provided the level of protection is not lowered; material changes are communicated to the controller in line with section 7. Capwork owes compliance with the state of the art, not a specific configuration or a specific outcome; absolute security against every conceivable attack cannot be technically guaranteed.

10. Assistance with data-subject requests

Capwork supports the controller with appropriate technical and organisational measures in fulfilling its obligations to respond to requests by data subjects (Art. 12–22 GDPR). The platform provides self-service functions for access (data export in a structured format), rectification, erasure ("right to be forgotten" including anonymisation of related records), and restriction of processing.

If the self-service functions are insufficient, the controller may request support in writing at office@capwork.io. Capwork responds without undue delay, generally within 7 working days. If a data subject contacts Capwork directly, Capwork forwards the request to the controller without delay and does not respond on the merits itself. Effort for support that goes beyond the standard platform functionality may be billed by Capwork following a prior effort estimate against reasonable market remuneration, provided the statutory minimum duties are performed free of charge.

11. Notification of personal-data breaches

Capwork informs the controller without undue delay after confirmed knowledge of any breach of personal-data security ("data breach" within the meaning of Art. 4(12) GDPR) that has occurred within the responsibility of Capwork or a subprocessor. Mere suspicions that require further investigation, as well as obvious false-positive results from automated security systems, do not yet trigger the notification duty. The notification contains, to the extent known at the time of notification, at least:

  • a description of the nature of the breach, where possible with an indication of the categories and approximate number of data subjects and records concerned;
  • the name and contact details of the contact person for further information;
  • a description of the likely consequences of the breach;
  • a description of the measures taken or proposed to address the breach and to mitigate possible adverse effects.

The statutory notification duties towards supervisory authorities (Art. 33 GDPR) and towards data subjects (Art. 34 GDPR) remain with the controller; Capwork is not obliged to make such notifications and does not make them on behalf of the controller. Capwork supports the controller in fulfilling these duties with appropriate technical and organisational measures and by providing the necessary information to the extent Capwork has it available.

12. Evidence and audits

Capwork demonstrates compliance with the obligations under Art. 28 GDPR primarily by providing current certificates and audit reports (in particular ISO 27001, ISO 27018, and ISO 27701 of Google Cloud, SOC 2 Type II reports of subprocessors, the Vertex AI Data Processing Addendum, and PCI-DSS reports of Stripe) and by answering written data-protection questionnaires. An on-site audit is only permissible where these forms of evidence are insufficient for the controller’s due-diligence purposes.

On-site audits are permissible at most once per calendar year, with reasonable prior notice of at least 14 working days, during normal business hours, and without unreasonable disruption of Capwork’s business operations. An extraordinary audit is only permissible upon a concrete data-protection trigger — in particular a confirmed personal-data breach in Capwork’s sphere. Competitors of Capwork are excluded as auditors; before the start of the audit, the controller or its appointed auditor concludes a reasonable confidentiality agreement with Capwork. The scope, timing, and methodology of the audit are agreed in writing in advance.

The cost of the audit is borne by the controller, unless the audit reveals a material breach by Capwork of this DPA or the GDPR; in that case Capwork bears the reasonable costs incurred. Effort to support the audit by Capwork personnel beyond ten person-hours is billed at standard market day rates.

13. Termination of the engagement

When the main agreement ends, this DPA also ends. Capwork will, at the controller’s choice, either delete the personal data processed on its behalf or return it to the controller in a structured, commonly used, machine-readable format. The choice must be made in text form within 30 days after the end of the contract (an email to office@capwork.io is sufficient); if the controller does not make a choice, deletion is deemed to have been chosen.

Unless the controller elects otherwise, all personal data processed on its behalf is deleted within 30 days after termination of the contract. Backups and logs that remain due to automatic retention periods for a maximum of a further 90 days, accessible during this period exclusively for restoration and security purposes, are excluded. The provision of the data in non-structured or customer-specific export formats and complex migration services are performed against reasonable market remuneration following a prior effort estimate.

Longer retention takes place only insofar as Capwork is required to do so under EU law or the law of the Member States to which Capwork is subject (e.g. retention obligations under UGB/BAO/GoBD); in that case the data is restricted from further processing.

14. Liability

Liability of the parties towards data subjects is governed by Art. 82 GDPR and remains unaffected by the limitations below. Where the parties are held jointly and severally liable, internal recourse follows Art. 82(5) GDPR according to each party’s share of fault and contribution.

In the internal relationship, each party is liable to the other for damages from a culpable breach of this DPA or the GDPR according to the general provisions of the main agreement and the liability caps agreed there, insofar as no more specific provision in this DPA applies.

Liability of Capwork for slight negligence is excluded; to the extent legally permissible, this also applies to ordinary gross negligence. Capwork's total liability arising from or in connection with this DPA — regardless of the legal basis — is limited in amount to the fees actually paid by the controller in the 12 months preceding the event giving rise to the damage; this cap corresponds to the liability cap agreed in the main agreement. Liability for lost profits, missed savings, consequential damages, indirect damages, data loss (insofar as no failure of the contractually owed backup measures has occurred), and other pecuniary damages is excluded to the extent permitted by law.

The above limitations do not apply to (a) intent and blatant gross negligence, (b) damages from injury to life, body, or health, (c) claims under the Product Liability Act (PHG) or other mandatory product liability law, and (d) other mandatory statutory liability. Claims of data subjects under Art. 82 GDPR remain unaffected; for the controller's claims for compensation and recourse in the internal relationship (Art. 82(5) GDPR), the foregoing limitations of liability apply to the extent legally permissible.

The controller indemnifies Capwork from third-party claims — including administrative fines and reasonable costs of legal defence — to the extent these are based on a breach of this DPA or the GDPR for which the controller is responsible, in particular on entering inadmissible data into the platform, missing or unlawful legal bases, unlawful instructions, or insufficient transparency to data subjects.

Capwork is not liable for outages or breaches caused by force majeure, strikes, lockouts, regulatory orders, acts of war or terrorism, pandemics, internet and telecommunications outages outside Capwork’s sphere of influence, or by acts of third parties for which Capwork is not responsible (in particular distributed denial-of-service attacks, zero-day vulnerabilities before a patch is available).

AI outputs are provided according to the state of the art; Capwork makes no warranty as to their accuracy, completeness, currency, or fitness for any particular purpose. Responsibility for substantive plausibility checks and the use of AI outputs remains with the controller (section 6 lit. f). Liability of Capwork for damages resulting from the unchecked adoption or faulty use of AI outputs by the controller or its staff is excluded to the extent permitted by law and unless an exception under paragraph 4 applies.

The burden of proof that a damage is based on a duty breach by Capwork and not on a different cause (in particular an act of the controller, an end customer, a subprocessor outside the contractually owed selection diligence of Capwork, or a cause under paragraph 6) lies with the controller, to the extent permitted by law.

15. Versioning, changes, final provisions

This DPA is maintained under a unique version number (see "Last updated"). Material changes that affect the rights or obligations of the controller are communicated with at least 30 days’ prior notice; within this period the controller may object to the change for an important data-protection reason, with the consequences described in section 7. Changes that are purely clarifying, that implement statutory adjustments, or that do not worsen the controller’s legal position may be made by Capwork without prior notice.

This DPA is part of the main agreement. In the event of conflicts between the provisions of this DPA and those of the main agreement, the provisions of this DPA prevail in data-protection matters; in all other matters the provisions of the main agreement prevail. If a provision of this DPA is or becomes invalid, the validity of the remaining provisions remains unaffected; the invalid provision is replaced by a valid arrangement that comes closest to the economic and legal purpose of the invalid provision (severability clause).

The law of the Republic of Austria applies, excluding the UN Sales Convention and conflict-of-law rules. The exclusive place of jurisdiction for all disputes arising from or in connection with this DPA is Vienna, Austria, insofar as the controller is an entrepreneur within the meaning of the UGB.

16. Contact for data-protection requests

Capwork e.U.

Inhaber: Nikolas Kain

Am Europlatz 2, 1120 Wien

FN 677603a, Handelsgericht Wien

Email: office@capwork.io