Legal

Data Processing Agreement

The terms under which SaaSVisionary processes personal data in your account on your behalf as your processor under Art. 28 GDPR.

Last updated September 27, 2026

Last updated: September 27, 2026

This Data Processing Agreement (“DPA”) is concluded between:

  • the business customer that has entered into a subscription for SaaSVisionary (“Customer”, the controller); and
  • Lars Eppendahl, sole proprietor, trading as saasvisionary.com, Wasserstr. 496 (Bürocenter am Schlosspark), 44795 Bochum, Germany, VAT ID DE311436984 (“SaaSVisionary”, the processor).

This DPA forms part of the Terms of Service between the parties (the “Agreement”). It becomes effective when the Customer accepts the Agreement (by confirming the Terms of Service including this DPA at checkout) and applies for as long as SaaSVisionary processes personal data on behalf of the Customer. The Customer may additionally be asked to accept a data processing agreement (client agreement) inside the app. That in-app agreement and this DPA together form the data processing terms between the parties; if they differ, the provision that offers the higher level of protection for the personal data prevails.

1. Definitions

Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning given in Art. 4 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”). “Customer Personal Data” means personal data that SaaSVisionary processes on behalf of the Customer when providing the service. “Sub-processor” means another processor engaged by SaaSVisionary.

2. Subject matter, duration, nature and purpose

2.1 Subject matter. SaaSVisionary provides the Customer with a cloud software service for customer relationship management, business telephony, messaging, email, AI features and marketing automation, accessible at app.saasvisionary.com. In doing so, SaaSVisionary processes Customer Personal Data on behalf of the Customer.

2.2 Duration. The processing lasts for the term of the Agreement and, after its end, until the Customer Personal Data has been deleted in accordance with section 11.

2.3 Nature of processing. Collection, recording, storage, organization, retrieval, use, transmission to services connected by the Customer, restriction and deletion, as well as hosting, backup and technical support.

2.4 Purpose. Processing takes place solely to provide the service under the Agreement, including support and the maintenance of security and stability.

2.5 Data categories and data subjects are described in Annex 1.

3. Instructions

3.1 SaaSVisionary processes Customer Personal Data only on documented instructions from the Customer, unless required to do so by Union or Member State law. In that case, SaaSVisionary informs the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

3.2 The Agreement, this DPA and the Customer’s configuration and use of the service (including connecting third-party services) constitute the Customer’s complete initial instructions. Further instructions must be given in text form (for example, by email to privacy@saasvisionary.com) and must be consistent with the Agreement.

3.3 SaaSVisionary informs the Customer without delay if it believes that an instruction infringes the GDPR or other data protection law. SaaSVisionary may suspend the execution of such an instruction until the Customer confirms or changes it.

3.4 The Customer is responsible for the lawfulness of the processing, in particular for having a legal basis, informing data subjects and, where the Customer connects third-party services (such as telephony, email delivery or AI model providers) under its own contracts, for its relationship with those providers. Such providers are not Sub-processors of SaaSVisionary.

4. Confidentiality

SaaSVisionary ensures that all persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process the data only on the Customer’s instructions.

5. Technical and organizational measures

5.1 SaaSVisionary implements appropriate technical and organizational measures in accordance with Art. 32 GDPR to ensure a level of security appropriate to the risk. A summary is set out in Annex 2; further information is available at /legal/security.

5.2 The measures are subject to technical progress. SaaSVisionary may adapt them, provided that the overall level of protection is not reduced.

6. Sub-processors

6.1 The Customer grants SaaSVisionary general authorization to engage Sub-processors. The Sub-processors engaged at the time this DPA is concluded are listed at /legal/subprocessors and are deemed approved.

6.2 SaaSVisionary informs the Customer at least 30 days in advance of any intended addition or replacement of a Sub-processor, by email to the account owner’s address and/or by an update to the list.

6.3 The Customer may object to the change in text form within this 30-day period on reasonable data protection grounds. The parties will then try to find a solution in good faith. If no solution is found, the Customer may terminate the affected parts of the service with effect from the date the change takes effect. No further claims arise from the objection.

6.4 SaaSVisionary imposes on each Sub-processor, by contract, data protection obligations that provide at least the same level of protection as this DPA, in particular sufficient guarantees for appropriate technical and organizational measures. SaaSVisionary remains liable to the Customer for the performance of its Sub-processors’ obligations in accordance with Art. 28(4) GDPR.

7. International data transfers

7.1 The service is technically operated by a Sub-processor based in the United States. Customer Personal Data is therefore processed in the USA.

7.2 Where SaaSVisionary engages a Sub-processor in a third country without an adequacy decision, SaaSVisionary concludes with that Sub-processor the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), Module 3 (processor to processor), together with the UK Addendum where UK data is concerned, and implements supplementary measures where required. The platform provider in turn bases onward transfers to its own sub-processors on the Standard Contractual Clauses. Where a Sub-processor is certified under the EU-U.S. Data Privacy Framework, the transfer may also be based on the corresponding adequacy decision.

7.3 On request, SaaSVisionary provides the Customer with information about the transfer safeguards used.

8. Assistance

8.1 Data subject requests. Taking into account the nature of the processing, SaaSVisionary assists the Customer by appropriate technical and organizational measures in responding to requests from data subjects exercising their rights under Chapter III GDPR. The service provides functions to access, correct, export and delete data, in particular a data-request tool that finds a data subject and exports or erases their data across all records, configurable automatic retention windows and a full workspace export. If a data subject contacts SaaSVisionary directly, SaaSVisionary forwards the request to the Customer without undue delay where the Customer can be identified, and does not respond itself unless instructed.

8.2 Other obligations. SaaSVisionary assists the Customer, taking into account the information available to it, in complying with its obligations under Art. 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation).

8.3 Costs. Assistance that goes beyond the functions of the service and beyond what is required by law may be charged at reasonable rates, provided SaaSVisionary has informed the Customer of this in advance.

9. Personal data breaches

9.1 SaaSVisionary notifies the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

9.2 The notification includes, as far as available, the information set out in Art. 33(3) GDPR: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information that is not yet available will be provided without undue delay as soon as it becomes available.

9.3 SaaSVisionary takes reasonable steps to contain the breach and mitigate its effects. Notifying the supervisory authority and data subjects remains the responsibility of the Customer.

10. Rights and obligations of the Customer

The Customer informs SaaSVisionary without delay if it detects errors or irregularities regarding data protection in the processing results. The Customer ensures that it does not upload special categories of personal data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10 GDPR) unless this is permitted by law and the Customer has verified that the measures in Annex 2 are appropriate for this data.

11. Deletion and return

11.1 During the term of the Agreement, the Customer can export and delete Customer Personal Data using the functions of the service.

11.2 After the end of the Agreement, SaaSVisionary deletes or anonymises Customer Personal Data within 90 days, unless Union or Member State law requires further storage. Backups are kept on a rolling basis with a recovery window of about 7 days, so deleted data disappears from them shortly afterwards. The Customer is responsible for exporting its data before the end of the Agreement. On request made before the end of the Agreement, SaaSVisionary supports the Customer in exporting its data.

11.3 On request, SaaSVisionary confirms the deletion in text form.

12. Audits and information

12.1 SaaSVisionary makes available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR. This can primarily be done by providing up-to-date documentation, certificates or audit reports of SaaSVisionary or its Sub-processors, where available.

12.2 If this information is not sufficient in a specific case, the Customer may carry out an audit, itself or through an independent auditor bound to confidentiality who is not a competitor of SaaSVisionary. Audits must be announced at least 30 days in advance, take place during normal business hours, not unreasonably disrupt business operations, and generally take place no more than once per calendar year, unless there is a specific reason (for example, a personal data breach or a supervisory authority request).

12.3 On-site audits at the premises of the Sub-processor based in the USA are replaced by the provision of that Sub-processor’s documentation and audit reports, as far as the Sub-processor’s contractual terms do not provide otherwise. Each party bears its own costs of an audit; SaaSVisionary may charge reasonable costs for audits that go beyond the scope of section 12.1 if it has informed the Customer in advance.

13. Liability

Liability of the parties under this DPA is governed by the liability provisions of the Agreement (Terms of Service). Art. 82 GDPR remains unaffected in relation to data subjects.

14. Final provisions

14.1 In the event of a conflict, this DPA prevails over the Agreement with regard to data protection. The Standard Contractual Clauses, where applicable, prevail over this DPA.

14.2 Amendments to this DPA require text form. SaaSVisionary may amend this DPA where required by changes in law, by decisions of supervisory authorities or courts, or by changes to the service, provided the level of protection is not reduced; the Customer will be informed in advance.

14.3 This DPA is governed by German law. The place of jurisdiction is Bochum, Germany.

14.4 Should individual provisions be invalid, the validity of the remaining provisions remains unaffected.

Annex 1 – Data subjects and data categories

Categories of data subjects

  • Customer’s employees and other authorized users of the Customer’s account;
  • Customer’s contacts, leads, prospects and clients;
  • persons who communicate with the Customer via the service (for example, by phone, SMS, email, chat or forms);
  • visitors to websites, forms, booking pages or funnels that the Customer creates with the service.

Categories of personal data

  • Contact and master data: names, email addresses, phone numbers, postal addresses, company and job title;
  • Communication data: content of emails, SMS and chat messages, call metadata (numbers, time, duration) and, if enabled by the Customer, call recordings and transcripts;
  • CRM data: notes, tags, pipeline stages, appointments, tasks, opportunities and custom fields;
  • Files and documents uploaded by the Customer;
  • AI inputs and outputs where the Customer uses AI features;
  • Usage and log data of the Customer’s users (for example, IP addresses, login times, actions in the app);
  • any other data the Customer chooses to store in the service.

Special categories of data

Processing of special categories of personal data (Art. 9 GDPR) is not intended. If the Customer nevertheless processes such data, section 10 applies.

Annex 2 – Technical and organizational measures (summary)

The following measures apply. More detail is available at /legal/security.

  • Encryption: data in transit is encrypted using TLS 1.2 or higher; data at rest is encrypted by the storage layer; credentials and access tokens for connected services are additionally encrypted at application level (AES-256-GCM).
  • Access control: access to systems is limited to authorized persons, protected by individual accounts and strong authentication; two-factor authentication where supported.
  • Least privilege and separation: permissions are granted only to the extent necessary; role-based access within each workspace; tenant isolation enforced in the database (row-level security); support access to a workspace is explicit and logged.
  • Availability and resilience: globally distributed hosting with automatic failover, a managed and replicated database, continuous backups with point-in-time recovery (recovery window of about 7 days); availability target of 99% per month (not a guaranteed service level).
  • Logging and monitoring: security-relevant events are logged and monitored.
  • Incident management: defined process for handling and reporting security incidents, including notification under section 9.
  • Vendor management: Sub-processors are selected with care and bound by data processing agreements.
  • Organizational measures: confidentiality obligations, secure handling of devices and credentials, and regular review of the measures.
Open in new tab ↗

Loading…