Data Processing Agreement
Last updated: 15 September 2026
Parties
This data processing agreement ("DPA") is concluded between the customer that holds an account for its team in the application Wealth Management by Zahlenwerk at app.zahlenwerk.studio ("controller" or "customer") and Zahlenwerk Studio GbR Seelingstraße 5, 14059 Berlin, Germany represented by the partners Laura Nogales De La Cruz and Lukas Beier Email: hello@zahlenwerk.studio ("processor" or "Zahlenwerk").
This DPA sets out the parties' data protection obligations under Zahlenwerk's terms of service (the "main agreement"). It takes effect once the customer accepts it in the application, and is concluded in electronic form within the meaning of Art. 28(9) GDPR.
1. Subject matter and duration
The subject matter is the processing by Zahlenwerk of personal data that the customer brings into or creates in the application while using it ("customer data"), in order to provide the application under the main agreement.
This DPA runs for the term of the main agreement. Obligations that by their nature survive its end, in particular under section 11 and on confidentiality, continue to apply.
This DPA does not cover data that Zahlenwerk processes as a controller in its own right, as described in the privacy policy: in particular the customer's contract and billing data, the customer relationship in the CRM, and processing to operate the website securely.
2. Nature and purpose of the processing
Nature of the processing: collection, storage, organisation and structuring; reading and extracting information from uploaded or forwarded documents using AI models, after names of people and entities have been replaced with placeholders; querying, analysing and displaying; answering questions in the assistant; sending email; mirroring to services the customer connects; transfer to the sub-processors under section 8; backup and erasure.
Purpose of the processing: solely to provide, operate, secure and support the application for the customer, namely recording and analysing portfolio positions and fund holdings, fund reports and capital account statements, a directory of companies and natural persons, bookkeeping and invoices per legal entity, and documents. Zahlenwerk does not process customer data for its own purposes and does not use it to train AI models.
3. Types of personal data and categories of data subjects
Types of personal data:
- Identification and contact data such as name, address, email address, phone number, role and organisation
- Team member data: name, email address, profile photo, team membership, roles and permissions, and audit and change logs
- Asset and holdings data: positions, commitments, cashflows, valuations, ownership, capital account statements, capital call and distribution notices
- Bank and bookkeeping data: bank account details, bank transactions, receipts, invoices and ledger entries
- Contracts and tax documents, and the information they contain
- Content of conversations with the assistant and the actions it proposed
- Technical data from operating the service, where it relates to customer data, such as log and error output
Processing of special categories of personal data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10 GDPR) is not intended.
Categories of data subjects:
- The customer's users, such as partners, employees and external advisors with access to the team
- Family members, shareholders, beneficial owners and managing directors of the legal entities the customer records
- Natural persons recorded in the directory, and contacts at companies, funds, banks and advisors
- Co-investors, fund managers and other persons named in fund reports, notices and contracts
- Business partners, suppliers, and invoice recipients and issuers in the bookkeeping
4. The controller's instructions
Zahlenwerk processes customer data only on documented instructions from the customer, including with regard to transfers to third countries, unless required to do so by Union or Member State law. In that case Zahlenwerk informs the customer of that legal requirement before processing, unless that law prohibits such information.
The instructions are set out in full in this DPA and the main agreement, and are given concrete form by the customer's use and configuration of the application, such as uploading and deleting documents, connecting integrations, or deleting the account. The customer gives further instructions in writing (email suffices) to hello@zahlenwerk.studio. Instructions beyond the application's functionality are carried out once the effort has been agreed with the customer; that effort is billed at the agreed hourly rate, and any AI usage it causes as extra credits under the customer's package.
If Zahlenwerk considers that an instruction infringes the GDPR or other data protection law, it informs the customer without undue delay and may suspend carrying out the instruction until the customer confirms or changes it.
5. The controller's obligations
The customer is responsible for the lawfulness of processing the customer data, including informing data subjects and having a legal basis for bringing the data into the application. It informs Zahlenwerk without undue delay if it finds errors or irregularities in the processing.
Where the customer supplies its own model provider API key, that provider is, under section 5 of the main agreement, a processor of the customer's own choosing. Processing on that key is governed by the customer's agreement with the provider.
6. Confidentiality
Zahlenwerk ensures that persons authorised to process customer data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Those persons have access to customer data only as far as necessary to provide, operate or support the application.
7. Technical and organisational measures
Zahlenwerk implements all technical and organisational measures required under Art. 32 GDPR to ensure a level of security appropriate to the risk. These include in particular:
- Database, authentication and documents stored in the EU (Supabase West EU region, Ireland); model calls and PDF preprocessing pinned to EU regions, with no fallback to other regions
- Transmission encrypted over HTTPS only, with HTTP Strict Transport Security
- Tenant isolation through row-level security in the database, and role- and module-based permissions
- Passwordless sign-in, and two-factor authentication that a team can enforce
- Tamper-proof audit logs of team administration, and change logs on records
- Pseudonymisation of the names of natural persons and entities before anything is sent to an AI model
- Envelope encryption of stored third-party credentials with a key held in a key vault
- Private document storage with no public read access
- Human approval of low-confidence extractions and of every change the assistant proposes
The measures are described in more detail at zahlenwerk.studio/security. Zahlenwerk may adapt them to technical progress provided the level of protection is not reduced.
8. Sub-processors
The customer gives Zahlenwerk general authorisation to engage sub-processors (Art. 28(2) GDPR). On conclusion of this DPA the following sub-processors are authorised:
- Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 – database, authentication and document storage; processing in the West EU region (Ireland); transfer basis: Standard Contractual Clauses
- Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA – application hosting and, only with consent, Web Analytics and Speed Insights; the application runs in Dublin (Ireland), with administration also in the USA; transfer basis: Standard Contractual Clauses
- Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland – Vertex AI for document extraction and the assistant; processing pinned to EU regions
- Modal Labs, Inc., Delaware, USA – converting uploaded PDFs to text; processing pinned to an EU region; transfer basis: Standard Contractual Clauses
- AC PM, LLC (Postmark), 1 N Dearborn Street, Suite 500, Chicago, IL 60602, USA – transactional email, including sign-in links, invitations, invoice delivery and reports forwarded to the drop address; processing in the USA; transfer basis: EU-US Data Privacy Framework and Standard Contractual Clauses
- sevDesk GmbH, Im Unteren Angel 1, 77652 Offenburg, Germany – invoicing and accounting; processing in Germany
- Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland – Azure Key Vault for custody of keys protecting stored third-party credentials; Microsoft Teams and SharePoint only where the customer's team connects them; transfer basis for access from third countries: EU-US Data Privacy Framework and Standard Contractual Clauses
- Slack Technologies Limited, Salesforce Tower, 60 R801, North Dock, Dublin, Ireland – notifications, only where the customer's team connects Slack; transfer basis: EU-US Data Privacy Framework and Standard Contractual Clauses
- Google Drive – document mirroring into the customer's own Google account, only where the customer's team connects it; copies stored there are governed by the customer's agreement with Google
- Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland, OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, and Google Cloud EMEA Limited (Gemini API) – only where the customer's team supplies its own API key; processing may take place outside the EU; transfer basis: Standard Contractual Clauses, for Google additionally the EU-US Data Privacy Framework
- Odoo S.A., Chaussée de Namur 40, 1367 Grand-Rosière (Ramillies), Belgium – Zahlenwerk's CRM; only the customer's name and the names and email addresses of its team members are mirrored; processing in Europe
Map services the application uses to display locations, namely OpenFreeMap by Hyperknot Software Kft. (Hungary) for map tiles and the Mapillary API by Meta Platforms Ireland Limited (Ireland) for street-level imagery, receive only what the request requires, such as the browser's IP address or a location's coordinates. They act on their own terms as independent recipients and are not sub-processors under this DPA.
Zahlenwerk informs the customer of any intended addition or replacement of a sub-processor at least 30 days in advance by email to the team's owners. The customer may object to the change in text form (e.g. email) within 14 days after receipt of the notice for an important data-protection reason. If the parties cannot agree, the customer may terminate the main agreement with effect from the date the change takes effect. If no objection is made, the change is deemed approved.
Zahlenwerk imposes on each sub-processor by contract substantially the same data protection obligations as set out in this DPA, in particular sufficient guarantees of appropriate technical and organisational measures (Art. 28(4) GDPR). Where a sub-processor fails to fulfil its data protection obligations, Zahlenwerk remains liable to the customer for the performance of those obligations.
Transfers to a country outside the EU or EEA take place only where the conditions of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision, such as the EU-US Data Privacy Framework, or the European Commission's Standard Contractual Clauses.
9. Assistance to the controller
Taking into account the nature of the processing, Zahlenwerk assists the customer by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR. The customer can view, correct and delete records in the application itself; Zahlenwerk provides a copy of the data or deletes specific documents on request. If a data subject contacts Zahlenwerk directly, Zahlenwerk forwards the request to the customer without undue delay and does not respond to it without the customer's instruction.
Taking into account the nature of the processing and the information available to it, Zahlenwerk assists the customer in complying with its obligations under Art. 32 to 36 GDPR: security of processing, notification and communication of personal data breaches, data protection impact assessments, and prior consultation of the supervisory authority. This assistance is free of charge where it concerns a breach or failure on Zahlenwerk's part, or information already available in the application or Zahlenwerk's documentation. Assistance beyond that, such as contributing to a data protection impact assessment, is provided once the effort has been agreed, at the agreed hourly rate.
10. Personal data breaches
Zahlenwerk notifies the customer of a personal data breach affecting customer data without undue delay, and at the latest within 48 hours of becoming aware of it, by email to the team's owners. The notification contains, as far as known, the information set out in Art. 33(3) GDPR; information not yet available is provided without undue further delay.
Zahlenwerk takes the necessary measures without undue delay to contain the breach and mitigate its possible adverse effects on data subjects, in consultation with the customer. A notification is not an acknowledgement of fault or liability.
11. Deletion and return at the end of the agreement
Before the main agreement ends, the customer can export its data under section 8 of the main agreement. After the end of the provision of services, Zahlenwerk deletes all customer data unless Union or Member State law requires its storage. If the customer deletes its account in the settings, this counts as an instruction to delete the records owned by the account.
Copies in backups, and copies and logs remaining with sub-processors, are deleted at the latest 90 days after deletion, unless a sub-processor must keep them longer because of a legal obligation or to investigate abuse. Zahlenwerk ensures that its sub-processors also delete the customer data, and confirms deletion in writing on request. This does not cover copies the customer has transferred to its own storage through an integration it connected, such as its Google Drive or SharePoint; those are solely at the customer's disposal and are not deleted by Zahlenwerk.
12. Information and audits
Zahlenwerk makes available to the customer all information necessary to demonstrate compliance with Art. 28 GDPR, primarily in the form of this DPA, the description of technical and organisational measures, and available certificates or audit reports of its sub-processors.
Where that information demonstrably does not suffice, Zahlenwerk allows for and contributes to audits, including inspections, by the customer or an auditor it mandates who is bound to confidentiality and is not a competitor of Zahlenwerk. Audits must be announced at least 30 days in advance, take place during normal business hours, must not disrupt operations disproportionately, and are limited to once per calendar year unless a personal data breach or an order of a supervisory authority gives cause. Each party bears its own costs of an audit; in particular, the customer bears the costs of any auditor it mandates. Zahlenwerk may bill its effort exceeding one working day per audit at the agreed hourly rate, unless the audit reveals a material breach of this DPA by Zahlenwerk.
13. Liability
Liability of the parties towards data subjects is governed by Art. 82 GDPR. Otherwise, liability between the parties is governed by section 13 of the main agreement (limitation of liability).
14. Order of precedence and final provisions
In the event of any conflict between this DPA and the main agreement, this DPA prevails as regards the protection of personal data. In all other respects the main agreement applies.
Changes to this DPA must be made in writing (electronic form suffices). If any provision is invalid, the validity of the remaining provisions is unaffected.
This DPA is governed by the laws of the Federal Republic of Germany; where permitted by law, the place of jurisdiction is Berlin. The German version is authoritative; translations are for information only.
Zahlenwerk is currently not required to designate a data protection officer (Art. 37 GDPR, section 38 BDSG). The contact for data protection matters is Lukas Beier, hello@zahlenwerk.studio. If Zahlenwerk designates a data protection officer in future, it will inform the customer of their contact details.
← Back to home