SIEDELMANN
DPA according to
Art. 28 GDPR.
Terms and technical-organizational security measures (TOMs) pursuant to Art. 28 & 32 GDPR for business customers processing customer data in Siedelmann software solutions.
1. Subject Matter & Scope
This Data Processing Agreement (DPA) governs the processing of personal data by Stefan Siedelmann (Processor) on behalf of the customer (Controller) within the scope of providing custom software, ERP integration, E-invoicing, or the Siedelmann Business Suite.
2. Categories of Data & Data Subjects
The processing encompasses customer master data, invoice and accounting data, contact information of business partners, bank details (IBAN/BIC), and communication logs.
3. Technical and Organizational Measures (TOMs) - Art. 32 GDPR
Vollständige TLS 1.3 / HTTPS-Verschlüsselung aller Web- und API-Aufrufe. Sicheres Hashing von Passwörtern mit Bcrypt.
Strikte logische Mandantentrennung auf Datenbankebene (Tenant-Isolation). Zugriff ausschließlich für autorisierte Benutzer.
Automatisierte tägliche verschlüsselte Backups zur Wiederherstellbarkeit bei technischen Ausfällen.
Hosting in nach ISO/IEC 27001 zertifizierten deutschen Rechenzentren (EU-DSGVO-konform).
4. Requesting an Individual DPA
If your company requires a formally signed individual Data Processing Agreement including your specific annexes, please send an inquiry to stefan@siedelmann.com.
Stefan Siedelmann IT- & Softwareentwicklung
E-Mail: stefan@siedelmann.com
Telefon: 01523 3790716