Skip to content
TeamsDashboard.com
FeaturesPricingDocsDemo
Sign inTry itStart free trialENDE
FeaturesPricingDocsDemoSign in
LanguageENDE

Data Processing Agreement (DPA)

pursuant to Art. 28 GDPR · for TeamsDashboard.com (T-Dashboard) · Courtesy translation · Version: 2026-08-6

Courtesy translation

This English version of the Data Processing Agreement is provided for your convenience only and corresponds to the German version 2026-08-6. Only the German version is legally binding: Auftragsverarbeitungsvertrag (AVV).

Below is the full wording of our data processing agreement including Annex 1 (TOM), as a courtesy translation. The binding contract text is the German version, which the accepting person of our customers concludes in the customer portal – the contract is made in writing, which may be in electronic form (Art. 28(9) GDPR). Acceptance is recorded there bound to version and hash and made available as a PDF record. The Terms and Conditions and the privacy policy apply in addition.

This Data Processing Agreement (“DPA”) specifies the data protection obligations of the parties for the processing of personal data in the course of using the service “TeamsDashboard.com” (T-Dashboard). It supplements the General Terms and Conditions (§ 11) and the privacy policy (section 4).

The Controller within the meaning of Art. 4(7) GDPR is the business customer that uses the Service in its Microsoft 365 tenant. The Processor within the meaning of Art. 28 GDPR is SSIG-IT GmbH, Zum weißen Jura 3, 89143 Blaubeuren, Germany (“Provider”).

Clarification of roles: The subject matter of this DPA is exclusively the processing, on behalf of the Controller, of the presence and profile data read via the Microsoft Graph API. Insofar as the Provider processes personal data solely for its own contract performance, billing, abuse prevention, and operational security (including invoicing and payment data, administrator contact details, sales inquiries, server log files), it is an independent controller in this respect; this is not the subject matter of this DPA but of the privacy policy.

§ 1 Subject matter, nature, and purpose of the processing

The subject matter of the engagement is the processing of personal data by the Provider on behalf of the Controller, exclusively for the provision of the service described in the main contract (GTC): the Service reads user profile data and presence status from the Controller’s Microsoft 365 tenant via the Microsoft Graph API and displays them visually as a real-time presence and availability dashboard. These Graph data are processed exclusively transiently in the browser of the respective user and are automatically discarded after a short time or upon re-authentication; the Provider does not store these data on the server side.

§ 2 Duration and contract instance

This DPA is the framework agreement for the processing on behalf during the ongoing customer relationship and applies as long as the Controller uses the Service in its Microsoft 365 tenant. Temporary suspensions (e.g., payment or administrative holds) do not terminate it. It ends with the definitive end of the main contract (GTC § 8). If access is set up again for the same tenant after a definitive end of the contract, this constitutes a new contract instance and requires renewed acceptance of this DPA.

§ 3 Types of personal data and categories of data subjects

Exclusively the following types of data read via Microsoft Graph are processed:

  • User and account information (e.g., name, email address, user ID)
  • Organizational data (e.g., job title, department, location/office, phone numbers)
  • Presence status and availability information from Microsoft Teams
  • Users’ profile photos

These data are processed and displayed exclusively transiently in the browser of the respective user. Server log files, invoicing and payment data, administrator contact details, and technical operating and access logs are NOT the subject matter of this engagement; the Provider processes them – where applicable – under its own responsibility (see preamble and privacy policy, section 6).

The data subjects are the employees and other authorized users (including guest users) of the Controller whose data are stored in the Microsoft 365 tenant.

§ 4 Place of processing

The presence and profile data from Microsoft Graph that are subject to this engagement are processed and displayed exclusively transiently in the browser of the respective user – that is, at that user’s location; they do not reach the Provider on the server side. Any server-side processing by the Provider (operation and delivery) takes place in the European Union (Frankfurt am Main). Processing outside the EU or the EEA takes place only via the sub-processors named in § 7 and only under the safeguards named there.

§ 5 Instructions of the Controller

The Provider processes the data exclusively within the scope of the Controller’s documented instructions. This DPA and the main contract constitute the complete initial instruction. Further instructions are given in text form to the contact address designated by the Provider. If the Provider considers an instruction to infringe data protection law, it informs the Controller without undue delay; it is entitled to suspend execution until confirmation.

The Provider also transfers personal data to a third country or an international organization only on the documented instruction of the Controller. If the Provider is required to make such a transfer by Union law or the law of a Member State to which it is subject, it informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28(3)(a) GDPR).

§ 5a Obligations and rights of the Controller

The Controller is responsible for the lawfulness of the processing and for the existence of a legal basis (Art. 6 GDPR). It issues its instructions within the scope of applicable law, ensures the accuracy of the data provided or stored in its Microsoft 365 tenant, and fulfils its information obligations towards the data subjects. It designates a competent point of contact to the Provider and cooperates in the performance of the engagement to the extent required.

The rights of the Controller remain unaffected; in particular, it has the right to issue supplementary instructions to the Provider at any time, to request information and evidence pursuant to § 11, to carry out reviews pursuant to § 11, to demand return or deletion pursuant to § 10, and to object to the engagement or replacement of sub-processors pursuant to § 7. Statutory obligations of the Provider as processor (in particular under Art. 28 to 33 GDPR) are not shifted to the Controller hereby.

§ 6 Obligations of the Processor (Art. 28(3) GDPR)

The Provider undertakes in particular:

  • to process personal data only on documented instructions;
  • to commit the persons authorized to process the data to confidentiality, unless they are already subject to a statutory obligation of secrecy;
  • to implement the technical and organizational measures required under Art. 32 GDPR (Annex 1 – TOM);
  • to comply with the conditions for engaging sub-processors (§ 7);
  • to assist the Controller, as far as possible, in fulfilling data subject rights (§ 8) and in its obligations under Art. 32 to 36 GDPR;
  • to carry out the deletion or return pursuant to § 10;
  • to make available to the Controller all information necessary to demonstrate compliance with these obligations and to allow for reviews (§ 11).

§ 7 Sub-processors

The Controller grants a general authorization for the engagement of sub-processors for the processing on behalf. For the processing of the Graph presence and profile data that is subject to this engagement, the Provider currently engages no sub-processor, as these data are processed exclusively transiently in the browser of the respective user (Annex 2). Microsoft 365 / Microsoft Graph is the platform and data source provided by the Controller itself and, in this respect, is not engaged by the Provider as a sub-processor.

If the Provider intends to engage or replace a sub-processor for the processing on behalf in the future, it informs the Controller in good time in text form; the Controller may object within 14 days on important data protection grounds. Contracts pursuant to Art. 28 GDPR are in place with every sub-processor. Insofar as data are transferred to a third country in this context, this takes place on the basis of an adequacy decision (in particular the EU-US Data Privacy Framework, Art. 45 GDPR) or appropriate safeguards pursuant to Art. 46 GDPR, in particular EU standard contractual clauses.

§ 8 Assistance with data subject rights

The Provider assists the Controller by appropriate technical and organizational measures in fulfilling requests of data subjects for access, rectification, erasure, restriction, data portability, and objection (Art. 15 to 21 GDPR). If a data subject contacts the Provider directly, the Provider forwards the request to the Controller without undue delay and does not act on its own without the Controller’s instruction.

§ 9 Notification of personal data breaches (Art. 33 GDPR)

The Provider notifies the Controller of a personal data breach that has come to its knowledge without undue delay after becoming aware of it, providing the information available in each case pursuant to Art. 33(3) GDPR. It assists the Controller, as far as possible, with the Controller’s notification and communication obligations (Art. 33, 34 GDPR).

§ 10 Deletion and return

After the end of the provision of the processing services, the Provider, at the choice of the Controller, deletes all personal data or returns them and deletes existing copies, unless Union or Member State law requires storage of the personal data (Art. 28(3)(g) GDPR). The Controller may request deletion or return in text form.

As the Graph presence and profile data subject to this engagement are processed exclusively transiently in the browser and are not stored on the server side, the Provider holds no copies of such data to be returned or separately deleted in this respect; processing ends with the deactivation of access and the removal of the tenant configuration. Personal operating and log data from the Provider’s processing under its own responsibility are deleted or anonymized in accordance with the automated deletion concept (Annex 1 / TOM, section 4.5).

The integrity-protected record of the conclusion of this DPA is retained for statutory reasons (retention analogous to Section 257 of the German Commercial Code (HGB) / Section 147 of the German Fiscal Code (AO)) until the end of the sixth full calendar year after the definitive end of the contract and is then deleted automatically, unless a legal hold prevents this.

§ 11 Evidence and audits

The Provider demonstrates compliance with the agreed obligations primarily by means of suitable evidence (including the TOM, self-disclosures, and current attestations or certificates of its data center providers). If these are insufficient in an individual case, the Provider enables the Controller to carry out further reviews, including on-site inspections, to the extent necessary and reasonable – with reasonable advance notice (at least 14 days), during normal business hours, as a rule no more than once a year, by a person bound to confidentiality, and against reimbursement of the Provider’s reasonable expenses. An additional review is permissible without these restrictions if a specific occasion (in particular a data protection incident) or an order of a competent supervisory authority requires it. Ongoing operations must not be impaired thereby. Both parties maintain the confidentiality of the information obtained in the process.

§ 12 Liability

Art. 82 GDPR applies to liability between the parties and towards data subjects. In all other respects, the liability provisions of the main contract (GTC § 10) apply in addition.

§ 13 Final provisions

The law of the Federal Republic of Germany applies. Amendments must be made in text form. Should a provision of this DPA be invalid, the validity of the remaining provisions remains unaffected. In the event of conflicts between this DPA and the main contract, the provisions of this DPA prevail for the processing on behalf.

Annex 1 – Technical and organizational measures (Art. 32 GDPR)

The technical and organizational measures implemented pursuant to Art. 32 GDPR (TOM, version 2026-08-1) form part of this DPA. Their full wording is reproduced below and is frozen together with this DPA (bound to version and hash); it is additionally attached to the electronic record as the file “TOM.txt”. The wording reproduced there is authoritative, not a later amended version at teamsdashboard.com/en/tom.

Annex 2 – Sub-processors

The presence and profile data from Microsoft Graph that are subject to this engagement are processed exclusively transiently in the browser of the respective user and are not stored on the Provider’s systems. The Provider engages no further sub-processor for this processing on behalf.

Microsoft 365 / Microsoft Graph is the platform provided by the Controller itself and at the same time the data source; in this respect, Microsoft is not engaged by the Provider as a sub-processor but lies within the Controller’s sphere of responsibility.

The service providers used by the Provider for its processing under its own responsibility (operation, delivery, billing, communication, and abuse prevention) – not the subject matter of this DPA – are named exhaustively and transparently in the privacy policy (section 6).

Annex 1 (full text) – Technical and Organizational Measures (TOM)

pursuant to Art. 32 GDPR · Annex 1 to the DPA · for TeamsDashboard.com (T-Dashboard)

Version: 2026-08-1

This document describes the technical and organizational measures pursuant to Art. 32 GDPR implemented by SSIG-IT GmbH (“Provider”) for the service “TeamsDashboard.com”. It is Annex 1 to the Data Processing Agreement (DPA) and supplements the privacy policy. The measures are structured according to the protection goals of the GDPR.

1. Confidentiality (Art. 32(1)(b) GDPR)

1.1 Physical access control

The Provider does not operate its own data center. Processing takes place exclusively at certified cloud operators (Vercel – application compute in the Frankfurt am Main region, delivery via a global CDN; Supabase – eu-central-1, Frankfurt am Main), which ensure physical access security through ISO 27001 / SOC 2 certified data centers. The workplaces of SSIG-IT GmbH are protected by building and room access controls.

1.2 System access control

Authentication takes place exclusively via Microsoft Entra (MSAL); the Provider stores no passwords of its own. Access tokens are verified server-side for their RS256 signature and validated against a fixed allowlist of client identifiers and the permission scope “access_as_user”. Administrative access exists only for persons from the SSIG-IT GmbH tenant registered by object ID (oid). Enforcement of multi-factor authentication is handled by the policies (Conditional Access) of the respective Microsoft Entra tenant and lies within its responsibility; multi-factor authentication is enabled for SSIG-IT GmbH’s own tenant.

1.3 Data access control

Row-level security without any permissive policy is enabled on all database tables – access is possible exclusively via the server-side service role. The service role key technically never reaches the browser’s client bundle. Write operations of the customer portal are validated against the respective target tenant identifier; the client receives no database key. Every administrative write mutation is recorded in an audit log.

1.4 Separation control

Tenant separation via the tenant identifier on every record; separate authentication instances for customer portal, administration, and trial; strictly separated development and production environments with their own databases.

1.5 Pseudonymization and data minimization

Presence, profile, photo, and name data from Microsoft Graph are never stored server-side but are processed exclusively transiently in the browser. Onboarding binding attempts store a SHA-256 hash instead of the raw tenant identifier; usage telemetry consists exclusively of aggregated counters without personal reference; the consent proof relies on a server-side secret.

2. Integrity (Art. 32(1)(b) GDPR)

2.1 Transfer control

All data transmission takes place exclusively TLS-encrypted (HTTPS). Security headers are set per path; embedding in a frame is permitted only for the app path. Card payment data are processed exclusively by the payment service provider (Stripe, PCI DSS) and do not reach the Provider’s systems.

2.2 Input control

Traceability via the administration audit log (retention two years). Payment events are permanently recorded as a signature-verified raw record before they are processed; the processing paths are idempotent (protection against duplicate processing).

3. Availability and resilience (Art. 32(1)(b), (c) GDPR)

3.1 Availability

Operation on highly available, managed infrastructure. Application compute and database: Frankfurt am Main; CDN and static delivery via the global Vercel network. Protection against overload and abuse through rate limiting and bot checks. Transactional emails run through a fault-tolerant queue with retry, error detection, and operational alerting.

3.2 Rapid recoverability

Database backup and restore are handled via the managed backups of the database operator (regular, at least daily backups; point-in-time recovery where enabled for the project). The application code is versioned and can be deployed reproducibly.

4. Procedures for regular review (Art. 32(1)(d); Art. 25 GDPR)

4.1 Data protection management

An external data protection officer has been appointed (Datenschutz & Informationssicherheit Alb e.K.). This TOM and the record of processing activities are updated as the occasion arises.

4.2 Incident response and reporting chain

Operations are monitored via an ops panel (backlog, error queues, cron heartbeats, configuration readiness). Critical error events trigger exactly one alert to an operations address. In the event of a personal data breach, the Provider as processor informs the controller without undue delay (Art. 33(2) GDPR).

4.3 Engagement control

Sub-processors are engaged exclusively on the basis of contracts pursuant to Art. 28 GDPR; EU regions are preferred (Frankfurt am Main or EU). For providers with a third-country connection, an adequacy decision (in particular the EU-US Data Privacy Framework) or EU standard contractual clauses together with supplementary measures apply.

4.4 Data protection by design and by default (Art. 25 GDPR)

License and permission checks follow the fail-closed principle; presence data are processed only in the browser; Microsoft Graph access is limited to what is necessary (read-only access to user and presence data); deletion takes place automatically after defined periods (section 4.5).

4.5 Deletion concept (automated)

Deletion or anonymization takes place automatically after the following periods:

  • Sales inquiry (open): deletion after 180 days.
  • Sales inquiry (rejected): deletion after 30 days.
  • Sales inquiry (converted): anonymization after 180 days (audit trail remains).
  • Email queue (sent): deletion after 30 days.
  • Email log: deletion after 90 days.
  • Payment processing event data (processed): deletion after 90 days.
  • Administration audit log: deletion after two years (730 days).
  • Orphaned trial records: deletion upon expiry of the activation token.
  • Record of the conclusion of the DPA: integrity-protected retention; automated deletion at the end of the sixth full calendar year after the definitive end of the contract (retention analogous to Section 257 of the German Commercial Code (HGB) / Section 147 of the German Fiscal Code (AO)), unless a legal hold exists.

Records with errors are deleted only after their resolution plus the respective period.


Questions about the data processing agreement: .

TeamsDashboard.com

Real-time presence for your entire Microsoft 365 organization – right inside Microsoft Teams.

Contact us

Product

Free trialLive demoOpen appPricing

Resources

DocumentationBlogProduct overview (PDF)Personal demo

Legal

Legal noticePrivacyTermsDPATOM
© 2026 SSIG-IT GmbHHosted in Frankfurt · GDPR compliantENDE