Legal

    Data Processing Agreement

    Version 2.0 · valid from 1 November 2026

    Until 31 October 2026, the previous version applies (archive). The German version prevails (Deutsche Fassung).

    Annex 1 to the General Terms and Conditions of Structify Solutions UG (haftungsbeschränkt)
    Version 2.0 · valid from 1 November 2026

    The German version prevails.


    Preamble – Parties and Conclusion

    (1) This Data Processing Agreement (DPA) applies between the Customer as controller within the meaning of Article 4(7) GDPR (the "Controller") and Structify Solutions UG (haftungsbeschränkt), Gartenstraße 8, 92348 Berg, Germany, Local Court (Amtsgericht) of Nuremberg HRB 46012, as processor within the meaning of Article 4(8) GDPR ("Structify").

    (2) The Controller is an entrepreneur (Unternehmer) within the meaning of Section 14 of the German Civil Code (BGB) or a legal entity under public law.

    (3) This DPA is an annex to and forms part of Structify's General Terms and Conditions (the "Terms"). It is concluded in Text Form upon their acceptance by a person authorised to represent the Controller; this electronic format satisfies Article 28(9) GDPR. A separate signature is not required. Structify logs the time and the version of the acceptance. The DPA can be accessed and saved at any time at structify.solutions/rechtliches/avv.

    (4) If the parties have concluded an individual data processing agreement, that agreement takes precedence (§ 11).

    § 1 Subject Matter and Duration

    (1) The subject matter is the processing of personal data on behalf of the Controller in the provision of the products Structify Web, Structify Desktop, Structify Mobile and Structify Operate and of the underlying platform (together the "Platform") under the contract that the parties have concluded on the basis of the Terms (the "Main Agreement").

    (2) The DPA begins with the Main Agreement and ends with it, without the need for termination. Obligations relating to erasure, return and confidentiality continue to apply after the end of the contract.

    § 2 Nature, Purpose and Place of Processing

    (1) The nature and purpose of the processing, the types of data and the categories of data subjects are described for each product in Schedule 1 to this DPA.

    (2) Hosting and storage of the Platform data take place in Germany (EU). For AI analyses (voice, text, images), Structify uses US providers (OpenAI, Anthropic); further service providers with a third-country connection are listed in Schedule 3. Transfers to third countries take place only in accordance with § 8.

    § 3 Obligations of Structify (Article 28(3) GDPR)

    Structify
    a) processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless Structify is required to process them by Union or Member State law; in such a case, Structify informs the Controller of that legal requirement beforehand, unless that law prohibits it. If Structify considers an instruction to be unlawful, Structify informs the Controller without undue delay and may suspend its execution until it is confirmed or amended;
    b) ensures that all persons authorised to process the data have committed themselves to confidentiality or are under a statutory obligation of confidentiality, including after the end of their activity;
    c) takes all technical and organisational measures required under Article 32 GDPR in accordance with Schedule 2 and develops them further in line with the state of the art, without falling below the agreed level of protection;
    d) complies with the conditions for sub-processors under § 5;
    e) assists the Controller by appropriate measures in responding to requests from data subjects (Articles 12 to 23 GDPR), in particular through access, rectification, erasure and export functions, and forwards requests received by Structify to the Controller without undue delay;
    f) assists the Controller with the obligations under Articles 32 to 36 GDPR, in particular with notifications of personal data breaches, communication to data subjects, data protection impact assessments and prior consultations;
    g) after the end of the provision of services, deletes all personal data or makes them available for export, unless there is an obligation to store them (§ 10);
    h) makes available all information necessary to demonstrate compliance with the obligations under Article 28 GDPR and allows for audits in accordance with § 7.

    § 4 Instructions

    (1) This DPA and the Main Agreement constitute the documented instructions. The use of the Platform features in accordance with the contract by the Controller, its users and the external parties it has invited is deemed an instruction for the corresponding processing. This also covers transfers that the Controller initiates itself, for example to calendar or storage services in its own accounts, to project participants or by email. This also applies to the map display of the location where photos were taken: the map section from the OpenStreetMap Foundation is only loaded when a user expressly requests it („Karte laden“ ("Load map")); the user's browser then retrieves the map directly from the OpenStreetMap Foundation, which acts as an independent controller in doing so and is not a sub-processor.

    (2) The Controller is responsible for the lawfulness of the processing and for the rights of the data subjects. This includes informing data subjects, for example where employees or third parties are captured in photos or voice recordings or where location data relating to recordings are stored.

    (3) The Controller issues individual instructions in Text Form, for example by email to support@structify.solutions; it confirms oral instructions in Text Form without undue delay. The persons authorised to issue instructions are the Controller's legal representatives, the persons designated by them in Text Form and the users with the Management role.

    (4) If an individual instruction requires services beyond the contractual scope, Structify may demand reasonable remuneration for the additional effort, provided that Structify points this out in advance.

    § 5 Sub-processors

    (1) The Controller grants Structify general authorisation to engage other processors (sub-processors) (Article 28(2) GDPR). The sub-processors engaged are listed in Schedule 3; the current list is available at structify.solutions/rechtliches.

    (2) Prior information. Structify informs the Controller in Text Form at least 30 days in advance of any intended addition or replacement of a sub-processor. The information states the name, registered office, service, data location and the basis of any third-country transfer.

    (3) Objection. The Controller may object to the change in Text Form within 14 days of receipt of the information for an important reason relating to data protection. If the Controller does not object in due time, the change is deemed approved; Structify points out the deadline and this consequence in the information.

    (4) If the Controller objects with justification, the parties seek an amicable solution, for example that the new sub-processor is not used for this Controller. If this is not successful, the Controller may terminate the Main Agreement with effect from the date of the change; Structify refunds, on a pro rata basis, fees already paid for the period thereafter.

    (5) Urgent cases. If Structify has to replace a sub-processor at short notice because the sub-processor discontinues its service or there is a significant security risk, the period under paragraph 2 may be shorter. Structify then informs the Controller without undue delay; the right of objection and termination under paragraphs 3 and 4 remains in place.

    (6) Structify imposes on each sub-processor by contract the same data protection obligations as set out in this DPA (Article 28(4) GDPR) and is liable to the Controller for their compliance.

    § 6 Notification of Personal Data Breaches

    (1) Structify notifies the Controller of any breach of the security of the data processed on its behalf without undue delay after becoming aware of it. The notification contains, where available, the information under Article 33(3) GDPR; Structify provides any missing information in phases without undue further delay.

    (2) Structify assists the Controller with the obligations under Articles 33 and 34 GDPR and documents every breach. The assessment of the notification obligation, the notification to the supervisory authority and the communication to data subjects are the responsibility of the Controller.

    § 7 Audits

    (1) The Controller may satisfy itself of compliance with this DPA before the start of and during the processing. Structify provides evidence primarily by means of current self-assessments, reports from independent bodies, where available, and evidence from the sub-processors.

    (2) Where necessary, Structify allows on-site inspections by the Controller or by an auditor bound to confidentiality who is not a competitor of Structify, after reasonable notice in Text Form, during normal business hours, without disproportionate disruption and while safeguarding trade secrets and the data of other customers.

    (3) Each party bears its own costs. For audits without specific cause that take place more than once per calendar year, Structify may demand reasonable remuneration; audits for a specific cause remain unaffected.

    § 8 Transfers to Third Countries

    (1) Hosting and storage of the Platform data take place in Germany (EU): the database and the file storage in the data centre in Frankfurt am Main, and the encrypted backup copies in the data centre in Falkenstein.

    (2) A transfer to a country outside the EU and the European Economic Area (third country) takes place only if the conditions of Articles 44 et seq. GDPR are met. The basis for all sub-processors with a third-country connection is the standard contractual clauses adopted by the European Commission under Article 46(2)(c) GDPR (Commission Implementing Decision (EU) 2021/914), Module Three (transfer from processor to processor). Structify is the data exporter, and the respective sub-processor is the data importer. Structify passes on the Controller's instructions to the sub-processor.

    (3) If a sub-processor is certified under the EU-U.S. Data Privacy Framework (adequacy decision (EU) 2023/1795), Schedule 3 states this in addition. The certification does not replace the standard contractual clauses; if it ceases to apply, the standard contractual clauses remain authoritative. Structify checks the information in the official register at least once a year.

    (4) For each sub-processor with a third-country connection, Structify has assessed the consequences of the transfer (Clause 14 of the standard contractual clauses) and has laid down supplementary measures, in particular transport encryption, the contractual exclusion of training AI models with content, the limitation of the storage period at the sub-processor, the selection of a processing region in the EU where available, and data minimisation. The assessment is reviewed at least once a year and in the event of material changes.

    (5) On request, the Controller receives a copy of the standard contractual clauses and a summary of the assessment; trade secrets and security details may be redacted.

    § 9 No AI Training, Anonymised Statistics

    (1) Structify has contractually agreed with all AI providers that they will not use the Controller's content for training AI models.

    (2) Structify itself does not use the Controller's content for training AI models unless the Controller has given its express consent in accordance with § 14(2) of the Terms. Such consent is an instruction within the meaning of § 4; it may be withdrawn at any time.

    (3) Anonymised usage statistics. The Controller instructs Structify to aggregate usage events (which feature was used and when, timestamps and technical metrics), without content, into anonymous, consolidated statistics. Structify may use these anonymous statistics for its own purposes, namely to improve the products, to safeguard operations, to plan capacity and to substantiate its own performance claims. Anonymisation is carried out in such a way that a link to a person and a link to the individual Controller can no longer be established; raw data containing personal data are deleted after aggregation, at the latest after 90 days. Once anonymised, the statistics are no longer subject to this DPA.

    § 10 Term, End of the Contract and Erasure

    (1) After the end of the Main Agreement, the Controller's previous users have read-only access for 30 days in order to view and export data (§ 25 of the Terms). Export in common, machine-readable formats constitutes the return of the data within the meaning of Article 28(3)(g) GDPR. The Controller may request a different form of return against reimbursement of the effort involved.

    (2) After the 30 days have expired, Structify erases all personal data processed on behalf of the Controller. Structify erases them earlier on instruction. On request, Structify confirms the erasure in Text Form.

    (3) Data are not removed individually from backup copies. They expire with the respective backup state, in the database after six months at the latest and in the file storage after 90 days (Schedule 2 No. 3), and are protected against any further processing until then. The confirmation of erasure points this out.

    (4) Structify restricts the processing of data that it is required to retain under Union or Member State law and erases them once the retention period has expired.

    (5) The confidentiality obligations continue to apply after the end of the contract.

    § 11 Liability and Order of Precedence

    (1) Article 82 GDPR applies to liability towards data subjects. As between the parties, each party is liable for the part of the damage that is attributable to its breach of the GDPR or of this DPA. Otherwise, the liability provisions of the Terms apply, unless mandatory law provides otherwise.

    (2) In matters of data protection, this DPA takes precedence over the Terms, the Terms of Use and any other agreements. An individual data processing agreement between the parties takes precedence over this DPA. Mandatory law, in particular the GDPR, takes precedence over all contractual provisions.

    § 12 Controllers in Switzerland

    If the Controller is established in Switzerland or the processing is subject to the Swiss Federal Act on Data Protection (FADP), the following applies in addition:
    a) References to the GDPR include the corresponding provisions of the FADP.
    b) The competent supervisory authority for processing under the FADP is the Federal Data Protection and Information Commissioner (FDPIC).
    c) Under Swiss law, Germany and the EU are deemed to be states with an adequate level of data protection. For transfers to third countries, the standard contractual clauses under § 8 apply with the adaptations for Switzerland recognised by the FDPIC.
    d) The term "Member State" in the standard contractual clauses includes Switzerland, so that data subjects habitually resident in Switzerland can enforce their rights there.

    For Controllers in Liechtenstein, the GDPR applies directly; the competent authority is the Data Protection Authority of Liechtenstein (Datenschutzstelle Liechtenstein).

    § 13 Final Provisions

    (1) The law of the Federal Republic of Germany applies, excluding the United Nations Convention on Contracts for the International Sale of Goods, including for Controllers established in Austria, Switzerland or Liechtenstein; mandatory data protection law at the Controller's place of establishment remains unaffected.

    (2) Amendments to this DPA are made in accordance with the procedure for amendments to the Terms (§ 26 of the Terms). In addition, § 5 applies to new or replaced sub-processors.

    (3) This DPA is available in German and English; in the event of any discrepancy, the German version prevails.

    (4) If any provision is invalid, the remaining provisions remain valid; the invalid provision is replaced by the statutory provisions, in particular the GDPR.


    Schedule 1 – Description of the Processing by Product

    A. Common to all products

    Nature of the processing: collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure by transmission to recipients designated by the Controller, alignment, restriction, erasure.

    Categories of data subjects:

    • employees and other users of the Controller;
    • external parties invited by the Controller (for example contractors, subcontractors, clients (building owners), bidders, specialist planners, viewers);
    • contact persons of clients, public authorities, suppliers and service providers;
    • persons captured in photos, videos or voice recordings or named in documents.

    General types of data: master data of users (name, email address, role, function), contact details of participants, communication and minutes content, usage and log data (login times, IP addresses in the case of security events, technical logs).

    B. Structify Web and Structify Desktop

    Purpose: project management and project documentation for planning and construction, in particular project and task organisation, contact and customer management (CRM), tickets, defects and acceptance inspections, drawing and document management, construction diary and site documentation with photo, video and audio recordings and their transcription, walkable 3D tours generated from site inspection videos, tendering and contract award including a bidder portal, appointments and calendars, time recording, fee calculation, invoicing and dunning, sending of emails and notifications, electronic signature, interfaces (API, MCP, CLI, webhooks, calendar feeds) and AI-supported features (assistant "KAI", analyses, suggestions).

    Additional types of data: project, construction and defect data; photo, video and audio material and transcripts; location information for photos, where available; drawing and document content; bid and tender data of bidders; billing and fee data relating to individuals; signature data of the signatories.

    Structify Desktop accesses the same data as Structify Web; locally, the desktop app stores only session data (the login encrypted in the operating system's keychain), settings and, temporarily, incomplete entries such as drafts and technical information on uploads not yet completed.

    C. Structify Mobile

    Purpose: data capture on the construction site and at installations (site inspections, voice notes, dictations, photos, tickets, defects, acceptance inspections, site measurements), synchronisation with the Platform, analysis by AI features, login by device pairing.

    Additional types of data: photos including metadata (time of capture, device model, location, where enabled); voice recordings and transcripts; location at the time of a recording (only where enabled, not in the background); device identifier as a hash value, platform designation and times of pairing.

    Particularity: Data captured without a network connection are held locally on the device by the app until they are transferred and are deleted after successful transfer. Local data are subject to the protection of the device; Structify does not back them up.

    D. Structify Operate

    Purpose: digital operations log for operators of technical installations, for example heating plants, heating networks, biomass and utility plants: operating and log entries, maintenance and deadlines, faults and tickets, input materials, deliveries and orders, components with installation and replacement history, meter readings and measured values, evidence, reports and audit exports, notifications of deadlines and anomalies, the roles Admin, Standard User and Viewer, and AI-supported features (assistant "KAI", analyses of operating and measurement data, calculations, recommendations, for example on maintenance, orders and consumption, reports, text recognition from photos of meters, delivery notes and invoices, transcription of voice notes and shift handovers).

    Additional types of data: names and roles of the persons who create, review or approve entries, with timestamps; information on on-call duty and notification settings (name, email address, telephone number, selected types of notification); shift log and handover content; information on maintenance and inspection service providers and suppliers and their contact persons (for example supplier, vehicle, quantity, time); photos and documents relating to installations, faults, deliveries and invoices; voice recordings and transcripts.

    Particularity: Structify Operate runs on the same platform as the other products (database and file storage in Frankfurt am Main, § 8(1)). The AI features use the AI providers listed in Schedule 3 (Anthropic; for transcription, OpenAI). Structify Operate does not issue control commands to installations and does not intervene in their operation; recommendations of the AI are only implemented after review and approval by an authorised person. This excludes automatic notifications according to fixed rules, for example when set thresholds are exceeded or in the case of unprocessed faults: in such cases, Structify Operate creates tickets without prior approval, marks them as „eskaliert“ ("escalated") and notifies the persons entered for this purpose by the Controller in the application and by email; the AI merely formulates explanations and message texts and does not decide whether a notification is triggered. Viewers have read-only access to the extent released by the Admin.

    Schedule 2 – Technical and Organisational Measures (Article 32 GDPR)

    Structify takes in particular the following measures and develops them further in line with the state of the art.

    1. Confidentiality

    • Physical access: operation exclusively in data centres of the providers listed in Schedule 3 with physical access control (Frankfurt am Main, Falkenstein); Structify does not operate its own server rooms.
    • System access: login only after authentication. Two-factor authentication is mandatory for the Controller's user accounts (one-time codes in accordance with TOTP or security keys and passkeys in accordance with the WebAuthn standard). Exempt are test and demo accounts until the end of the test phase and a review account with fictitious data for app store review. The two accounts of Structify's platform administration log in without a second factor; every login is logged on the server side and reported to the administrators; permanent device trust requires a second factor. Protection of the login against automated attacks. Device pairing by a QR code that can be redeemed only once (valid for 5 minutes); device trust for at most 30 days, for test and demo accounts at most until the end of the test phase, revocable at any time.
    • Data access: tenant separation at database level (Row Level Security): each organisation sees only its own data; role-based authorisation concept within the organisation; access only for project members; administrative access by Structify only on a need-to-know basis and logged.
    • Separation: separate processing of test, showroom and production data through separate organisations.

    2. Integrity

    • Input control: logging of security-relevant operations; immutable audit logs for operations relevant to billing and retention.
    • Transfer control: transmission only via encrypted connections (TLS); connection of external services only via authenticated interfaces.

    3. Availability, Resilience and Restoration

    • Operation of the database in the data centre in Frankfurt am Main.
    • Backup of the database every hour; tiered retention: hourly backup states for 48 hours, daily for 35 days, weekly for 12 weeks, monthly for 6 months. File storage is mirrored every hour; deleted or overwritten files are retained for 90 days.
    • In addition, the hosting provider of the database creates its own backup every day and retains it for seven days.
    • Restoration is made to an existing backup state, as a rule the most recent hourly one. Point-in-time restoration to any given minute is not offered.
    • Second, separate backup location in the data centre in Falkenstein (Hetzner Online GmbH): the backups are created on a server managed by Structify (access only by SSH key, firewall, automatic security updates) and stored in encrypted form (database: BorgBackup with AES; file storage: rclone crypt with AES, including file and folder names). Only encrypted data are held in the storage; the keys remain with Structify. In addition, daily snapshots of the backup storage.
    • Weekly automatic check of the backups for completeness and readability; automatic alerting of the management in the event of missing or failed runs.
    • Restore tests every quarter; first tests on 26 and 27 September 2026 with complete restoration of the database and the file storage into an isolated environment.
    • Recovery times (committed, from becoming aware of the loss): partial loss (individual records, tables, files) no more than 2 hours; total loss (database or provider account) no more than 8 hours until the Platform can be used again in a web browser. Target maximum data loss: one hour. Excluded are apps distributed via app stores that, following a total loss, require a new version to be reviewed by the store operator, as well as periods during which an infrastructure provider is itself unavailable on a large scale.
    • Deletions take effect in backup copies as these expire (at the latest after six months); in the event of a restoration, previously deleted data are not reactivated.

    4. Encryption

    • Transport encryption (TLS) for all connections.
    • Encryption of stored data at the hosting providers.

    5. Review and Further Development

    • regular internal security reviews, in particular of the access rules and tenant separation;
    • automated checks that verify central security requirements (including access rules at database level) before every release;
    • adjustment of the measures on the basis of the results.

    6. Sub-processors

    • selection according to the level of data protection and security; contracts in accordance with Article 28 GDPR; in the case of a third-country connection, standard contractual clauses and an assessment of the consequences of the transfer (§ 8); contractual exclusion of AI training for AI providers.

    Schedule 3 – Sub-processors

    Basis for transfers. To the extent that a sub-processor listed below processes data in a third country or access from a third country cannot be ruled out, Structify bases the transfer on the standard contractual clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914), Module Three (Structify as processor to the sub-processor), with a documented assessment of the consequences of the transfer (§ 8). Certification under the EU-U.S. Data Privacy Framework is stated in addition for all certified providers; the basis remains the standard contractual clauses and the assessment. Status of review: 30 September 2026. Processing for which Structify itself is the controller (for example the website, protection of the login, embedded content, approaching potential customers) is not processing on behalf of the Controller; such processing and the standard contractual clauses applicable to it (Module Two) are described in the Privacy Policy.

    Engaged on a permanent basis

    Sub-processor Service Data location Third country and basis
    Supabase Pte. Ltd., Singapore database, authentication, file storage, server functions (hosting of the Platform data) Frankfurt am Main, Germany Contracting party in Singapore; support or group access from Singapore or the USA cannot be ruled out. SCC Module Three; no DPF
    Vercel Inc., USA hosting and delivery of the web application delivery via Frankfurt am Main; processing also possible in the USA USA. SCC Module Three; additionally DPF-certified
    Hetzner Online GmbH, Gunzenhausen, Germany data backup: creation and storage of exclusively encrypted backup copies Falkenstein, Germany no third country
    Anthropic PBC, USA (contracting entity in the EEA: Anthropic Ireland, Limited) AI analysis of text, images and documents, assistant "KAI", suggestions; in Structify Operate additionally analyses, calculations and recommendations USA USA. SCC Module Three; no DPF
    OpenAI, L.L.C., USA (contracting entity in the EEA: OpenAI Ireland Ltd.) transcription of voice recordings, including in Structify Operate USA USA. SCC Module Three; no DPF
    Plus Five Five, Inc. ("Resend"), USA sending of system and notification emails USA USA. SCC Module Three; additionally DPF-certified
    RunPod, Inc., USA computing power for walkable 3D tours generated from site inspection videos; persons depicted are automatically made unrecognisable beforehand EU region of the Secure Cloud US legal entity. SCC Module Three; no DPF
    Oneflow AB, Stockholm, Sweden electronic signature of documents, including the data of the signatories EU (Ireland, backup in Sweden) no third country
    IONOS SE, Montabaur, Germany Structify's email mailboxes for communication with customers, for example support by email Germany no third country

    Only when the respective feature is used

    Sub-processor Service Data location Third country and basis
    Cal.com, Inc., USA booking of appointments for meetings with Structify from within the application USA USA. SCC Module Three; no DPF

    Not sub-processors

    • Stripe (Stripe Payments Europe, Ltd., Ireland) processes payments as an independent controller. Card data are not stored in the Platform.
    • Services that the Controller connects itself and to which it transmits data into its own accounts (for example calendar services or its own code and storage repositories) do not act as sub-processors of Structify; the transfer takes place on the Controller's instructions (§ 4(1)).
    • Services for which Structify itself is the controller (for example the help voice assistant in the help section of the application, which serves Structify's support, and, where used, the protection of the login page against automated attacks) are described in the Privacy Policy; Module Two of the standard contractual clauses applies there to transfers to third countries.

    Changes to this list are made in accordance with § 5. The current version is available at structify.solutions/rechtliches.

    Download this document as PDF · Previous versions