Skip to content
← SteerSuite

Data Processing Agreement (DPA)

As of / version: 2026-07-23

Between the parties

Processor

SteerSuite GmbH
Königsallee 19, 40212 Düsseldorf, Germany
Contact: info@steersuite.com
Court of registration and commercial-register number: Amtsgericht Düsseldorf, HRB 112346
VAT identification number: DE356926334
Authorised managing director(s): Athanasios Tabakis
— hereinafter the "Processor" —

Controller

The customer using the "SteerSuite HQ" and/or "SteerSuite Finance" services on the basis of the main contract (the "Main Contract"), with the master and contact data provided in the Main Contract or upon registration.
— hereinafter the "Controller" —

— Processor and Controller each a "Party" and together the "Parties" —

Recital

The Processor provides AI-assisted decision-intelligence services for finance and controlling teams to the Controller in the form of a web-based software-as-a-service application. In the course of providing these services, the Processor processes personal data on behalf of and on the instructions of the Controller. This Data Processing Agreement (the "DPA" or "Agreement") sets out the data-protection rights and obligations of the Parties within the meaning of Art. 28 of Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR"). It forms part of the Main Contract. Unless expressly agreed otherwise, in the event of conflict between this DPA and the Main Contract on data-protection matters, this DPA prevails.

Sec. 1 Subject matter, scope and duration of processing

(1) The subject matter of the processing is the processing of personal data by the Processor for the Controller in the course of providing the services agreed in the Main Contract (provision and operation of the SteerSuite HQ and SteerSuite Finance services).

(2) The nature and purpose of the processing, the categories of data subjects and the types of personal data processed are set out conclusively in Annex 1 to this Agreement.

(3) Processing takes place solely within the European Union or the European Economic Area, unless otherwise stated in Annex 3 and Sec. 11. Processing in third countries only takes place under the conditions of Sec. 6 and Sec. 11 of this Agreement.

(4) The duration of the processing corresponds to the term of the Main Contract. This Agreement ends upon termination of the Main Contract, without the need for separate termination; the obligations under Sec. 9 (deletion and return) and surviving obligations (in particular confidentiality) remain unaffected.

(5) As between the Parties, the Controller alone is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects (Art. 24 GDPR). The Processor processes the data solely within the scope of this Agreement and the Controller's instructions.

Sec. 2 Nature, purpose, data categories and data subjects

(1) The processing comprises the operations described in Annex 1; it serves solely to provide the contractually agreed services and the purposes directly connected therewith (including provision of the user workspace, authentication, payment processing of the prepaid credit balance, transactional system communication, operation, maintenance, error handling and ensuring the availability and security of the services).

(2) The Processor does not process special categories of personal data within the meaning of Art. 9 GDPR on behalf of the Controller, unless the Controller itself enters such data into the services; in that case the provisions of this Agreement apply accordingly, and the Controller alone is responsible for the admissibility of such processing.

Sec. 3 Controller's right to issue instructions (Art. 28(3)(a) GDPR)

(1) The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation. Any deviating processing is permissible only where the Processor is required to do so by Union or Member State law to which it is subject. In such a case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

(2) The provisions set out in the Main Contract and in this DPA together with its Annexes constitute the Controller's initial and standing instructions. The Controller is entitled to issue individual, supplementary or amending instructions within the scope of the services described in the Main Contract.

(3) Instructions are given in text form (e.g. by e-mail to info@steersuite.com) or via the functions provided for that purpose within the services. Oral instructions must be confirmed in text form without undue delay. The Processor documents the instructions given.

(4) If the Processor is of the opinion that an instruction infringes the GDPR or other Union or Member State data-protection provisions, it informs the Controller without undue delay. The Processor is entitled to suspend implementation of the instruction concerned until it is confirmed or amended by the Controller.

(5) If an instruction that goes beyond the contractually owed service and beyond the standard self-service functions of the services results in additional effort, the Processor may claim reasonable remuneration for it at its applicable standard rates. Vis-à-vis consumers, such remuneration is calculated on a cost basis and without unreasonable disadvantage (Sec. 307 et seq. BGB).

Sec. 4 Confidentiality (Art. 28(3)(b) GDPR)

(1) The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The confidentiality obligation continues to apply after the end of the respective activity or of this Agreement.

(2) The Processor engages only such persons for processing who have previously been made familiar with the relevant data-protection provisions and who are bound to confidentiality.

(3) Access to the Controller's personal data is limited to those employees and agents of the Processor who require such access to perform the contractual obligations (need-to-know principle).

Sec. 5 Technical and organisational measures (Art. 28(3)(c) in conjunction with Art. 32 GDPR)

(1) Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the varying likelihood and severity of the risks to the rights and freedoms of natural persons, the Processor implements the technical and organisational measures required to ensure a level of security appropriate to the risk (Art. 32 GDPR).

(2) The technical and organisational measures in place at the time of conclusion of this Agreement are described in Annex 2. They are deemed contractually agreed and, to the extent legally permissible, appropriate.

(3) The technical and organisational measures are subject to technical progress and further development. The Processor is permitted to amend or adapt the measures, provided that the level of protection agreed under Annex 2 is not fallen below. The Processor documents material changes and makes them available to the Controller on request.

(4) The Processor reviews the effectiveness of the technical and organisational measures regularly and adapts them where necessary.

Sec. 6 Sub-processors (Art. 28(2) and (3)(d) GDPR)

(1) The Controller grants the Processor general written authorisation within the meaning of Art. 28(2) sentence 1 GDPR to engage further processors (sub-processors). The sub-processors engaged at the time of conclusion of this Agreement are listed conclusively in Annex 3 and are authorised by the Controller.

(2) The Processor informs the Controller of any intended change concerning the addition or replacement of sub-processors in good time before the change, but at least 30 days before it takes effect. Notification is given by an active, individual notice to the Controller in text form (e-mail to the contact address provided by the Controller); updating the publicly accessible sub-processor list at https://www.steersuite.com/subprocessors is merely supplementary and does not replace the individual notice.

(3) The Controller may object to a change on important, data-protection-related grounds within 30 days of receipt of the notification in text form. If the Controller does not object within the period, the change is deemed authorised. If the Controller objects, the Parties will seek an amicable solution. If no agreement is reached, the Controller has a special right of termination for the part of the service affected by the objection, and the Processor is entitled to refuse performance of that part. Any prepaid credit that has not been used for the affected part of the service is refunded on a pro-rata basis.

(4) By way of a contract or another legal instrument under Union or Member State law, the Processor imposes on the sub-processor the same data-protection obligations as set out in this Agreement, in particular the requirement to provide sufficient guarantees to implement appropriate technical and organisational measures. Where the sub-processor fails to fulfil its data-protection obligations, the Processor remains fully liable to the Controller for the performance of that sub-processor's obligations.

(5) Where a sub-processor is engaged with processing in a third country, the Processor ensures that the requirements of Art. 44 et seq. GDPR are complied with (Sec. 11).

(6) Services that the Processor uses as ancillary services and that do not involve the processing of the Controller's product customer data (e.g. pure website and pre-sales tools) are not deemed sub-processors within the meaning of this provision.

Sec. 7 Assistance in safeguarding data-subject rights (Art. 28(3)(e) GDPR)

(1) Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests by data subjects to exercise their rights under Chapter III GDPR (Art. 12 to 23 GDPR), in particular as regards access, rectification, erasure, restriction of processing, data portability and objection.

(2) If a data subject contacts the Processor directly to exercise its rights, the Processor forwards this request to the Controller without undue delay and does not respond to it itself, unless the Controller has instructed it to do so.

(3) Insofar as the Controller depends on the Processor's cooperation to fulfil data-subject rights, the Processor takes the necessary measures on the Controller's instructions. The self-service functions included in the standard scope of the services and standard support are provided free of charge. For assistance beyond that, the Processor may claim reasonable remuneration at its applicable standard rates. Vis-à-vis consumers, the calculation is cost-based and without unreasonable disadvantage (Sec. 307 et seq. BGB).

Sec. 8 Assistance with security, notification duties and data-protection impact assessment (Art. 28(3)(f) in conjunction with Art. 32 to 36 GDPR)

(1) Taking into account the nature of processing and the information available to it, the Processor assists the Controller in ensuring compliance with the obligations pursuant to Art. 32 to 36 GDPR, in particular in ensuring the security of processing, in notifying personal-data breaches to the supervisory authority and communicating them to data subjects, and in carrying out a data-protection impact assessment and prior consultation of the supervisory authority.

(2) The Processor notifies the Controller of any personal-data breach affecting the Controller's data of which it becomes aware, without undue delay after becoming aware. The notification contains, insofar as available, at least the information referred to in Art. 33(3) GDPR (nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed) and names a contact point for further information. The obligation to notify the supervisory authority under Art. 33(1) GDPR lies with the Controller.

(3) The Processor takes the necessary and appropriate measures to remedy and mitigate a breach and assists the Controller with its notification and communication obligations.

Sec. 9 Deletion and return after termination (Art. 28(3)(g) GDPR)

(1) After the end of the provision of the processing services, the Processor, at the choice of the Controller, deletes or returns all personal data to the Controller and deletes existing copies, unless Union or Member State law requires storage of the personal data.

(2) The Controller communicates its choice (deletion or return) in text form by the effective date of termination at the latest. If the Controller makes no choice, the Processor first gives the Controller the opportunity to export the data for a reasonable period of 30 days and deletes the data thereafter.

(3) A statutory retention obligation within the meaning of paragraph 1 exists in particular for records that the Processor must retain to fulfil its own legal obligations (e.g. commercial and tax retention obligations for payment and billing records of the prepaid credit balance, and the logging of data-protection-relevant consents and evidence). Such data is stored beyond the end of the contract solely for evidence and retention purposes, correspondingly restricted in processing, and deleted after expiry of the statutory periods.

(4) Deletion is carried out in accordance with the procedures described in Annex 2. The Processor confirms complete deletion to the Controller in text form upon request.

Sec. 10 Evidence obligations and audit rights (Art. 28(3)(h) GDPR)

(1) The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and in this Agreement.

(2) The Processor allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Evidence of compliance may primarily be provided by suitable means, in particular by presenting current attestations, reports or report extracts from independent bodies, suitable certifications or documentation of the technical and organisational measures. As evidence, the Processor currently relies on the infrastructure certifications of its cloud sub-processor Microsoft Azure (in particular ISO/IEC 27001 and SOC 2); the available documents are made available to the Controller on request. The Processor's own certifications (e.g. ISO/IEC 27001, SOC 2) or summaries of external penetration tests are added as soon as they are available.

(3) If the evidence provided under paragraph 2 is insufficient in an individual case, the Controller is entitled, after prior notice with reasonable lead time, during normal business hours and without disrupting operations, to satisfy itself of the Processor's compliance. The Processor may make on-site audits conditional on the signing of an appropriate confidentiality agreement. The audit does not extend to information of other customers or to trade secrets that are not the subject of the audit. Audits take place at most once a year and, in addition, where there is specific cause; they must be announced with 30 days' notice. The Controller bears the costs of regular audits; the Processor bears the costs of for-cause audits where a breach is confirmed. Competitors of the Processor may not be engaged as auditors.

(4) The Processor informs the Controller without undue delay if it considers that an instruction or an audit measure infringes data-protection provisions.

Sec. 11 Third-country transfers (Art. 44 et seq. GDPR)

(1) Processing of personal data in a third country (outside the EU/EEA) takes place only insofar as the requirements of Art. 44 to 49 GDPR are met, in particular on the basis of an adequacy decision of the European Commission (Art. 45 GDPR) or appropriate safeguards (Art. 46 GDPR), namely the standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), supplemented where necessary by additional protective measures.

(2) Processing takes place within the EU/EEA as a matter of principle. The following sub-processors listed in Annex 3 may involve a third-country element:

  • GitHub, Inc.: storage of in-app bug-report snapshots in the United States. The transfer is safeguarded by EU standard contractual clauses.
  • AI inference (Anthropic Claude via Azure AI Foundry; Azure OpenAI Embeddings): provided via Microsoft Azure AI Foundry with an EU deployment/at-rest region (Sweden and Germany respectively). The models run under the "GlobalStandard" SKU; with this SKU the specific inference-processing region may be routed globally. A zero-data-retention (ZDR) configuration is agreed for the model calls, so that no persistent storage of content occurs at the model provider. Processing takes place within the EU as a matter of principle (Azure EU Data Boundary). Insofar as inference under the "GlobalStandard" SKU is exceptionally routed outside the EU, the transfer is safeguarded by the EU standard contractual clauses (Art. 46 GDPR) agreed via the contract with Microsoft (which engages Anthropic as a sub-processor).

(3) On request, the Processor makes available to the Controller information on the appropriate safeguards in place for the transfers concerned and the means to obtain a copy.

(4) The Processor does not transfer the Controller's personal data to a third country on the basis of its own decision, but only on the Controller's instructions or insofar as it is legally required to do so (Sec. 3(1)).

Sec. 12 Data protection officer and contact

(1) The Processor's contact for matters relating to this Agreement is available at info@steersuite.com.

(2) The Processor is not legally obliged to appoint a data protection officer, as the conditions of Art. 37 GDPR and Sec. 38 BDSG are not met. Data-protection enquiries should be addressed to info@steersuite.com.

Sec. 13 Liability

The Parties' liability inter se is governed by the provisions of the Main Contract, unless this DPA provides otherwise and unless mandatory law provides otherwise. This is without prejudice to the mandatory liability towards data subjects under Art. 82 GDPR and to the limits of Sec. 309 no. 7 BGB; liability for intent and gross negligence and for injury to life, body or health is not excluded.

Sec. 14 Final provisions

(1) Order of precedence. In the event of conflicts between this DPA and the Annexes, the Annexes prevail on technical detail; otherwise the clause part of this DPA prevails. In the event of conflicts between this DPA and the Main Contract, this DPA prevails on data-protection matters.

(2) Amendments and text form. Amendments and supplements to this Agreement and its Annexes must be made in text form. This also applies to any amendment of this text-form requirement. Individual agreements take precedence.

(3) Severability. Should any provision of this Agreement be or become invalid or unenforceable, the validity of the remaining provisions remains unaffected. The Parties will replace the invalid or unenforceable provision with a valid provision that comes closest to its economic and data-protection purpose.

(4) Governing law and jurisdiction. The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods. Vis-à-vis merchants, legal persons under public law and special funds under public law, the exclusive place of jurisdiction for all disputes arising out of or in connection with this DPA is Düsseldorf. Vis-à-vis consumers, the statutory place of jurisdiction applies.

Annex 1 — Subject matter, nature and purpose of processing, data categories and data subjects

1. Subject matter and purpose of processing

Provision and operation of the web-based services SteerSuite HQ and SteerSuite Finance as an AI-assisted decision-intelligence application for finance and controlling teams, including user administration, authentication, payment processing of the prepaid credit balance, transactional system communication, operation, maintenance, error handling and ensuring availability and security.

2. Nature of processing

Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure (to sub-processors), restriction, erasure and destruction of personal data by automated means in the course of providing the services.

3. Categories of data subjects

  • The Controller's users (employees, members of the finance/controlling team, other authorised persons) who create an account or use the services;
  • the Controller's contact and billing contacts;
  • other natural persons whose personal data the Controller enters into the services in the course of using them (content data).

4. Types of personal data

  • Registration and master data: business e-mail address, company name, role/function, size of the finance team, optional description of the use case;
  • Authentication data: login data and the data required to send login links;
  • Billing and payment data: credit balance and transaction history of the prepaid credit balance and payment-related data; card and payment-method data is processed directly by the payment processor Stripe and is not stored at the Processor. For this card/payment data, Stripe acts as a separate controller (not a sub-processor); the pass-through of obligations under Sec. 6(4) does not apply to it in that respect;
  • Usage/log data: pseudonymous or aggregated usage events (e.g. feature used, session duration) for operational, security and error-handling purposes; the content of user inputs is not logged;
  • Content data: data entered into the services by the Controller or its users (e.g. finance/controlling content, analysis inputs, generated artefacts);
  • Bug-report data (upon active submission by the user): a forensic snapshot for error reproduction, consisting of the last messages with routing metadata, recent artefact versions, recent notifications, browser and viewport metadata, and a screenshot of the current view.

5. Duration of processing / storage

For the term of the Main Contract; beyond that only within the scope of the deletion/return provided for in Sec. 9 and statutory retention obligations. After the end of the Main Contract, personal data is returned or deleted within 30 days; data contained in backups is deleted in the course of the rolling backup cycle. These statements are consistent with the privacy policy.

Annex 2 — Technical and organisational measures (Art. 32 GDPR)

The following measures describe the level of protection in place at the time of conclusion of this Agreement. Certifications and standard-specific statements are expressly marked; unmarked statements reflect the actual operational state.

1. Confidentiality (Art. 32(1)(b) GDPR)

  • Physical access control: operation exclusively in the data centres of the cloud sub-processors used (Microsoft Azure) within the EU/EEA; physical security is ensured by the data-centre operator. The infrastructure evidence is provided by the data-centre certifications of Microsoft Azure (ISO/IEC 27001, SOC 2).
  • System access control: authentication of users via secured login (including via login link); administrative access limited to authorised engineering personnel on a need-to-know basis.
  • Data access control: role/permission-based access control; management of secrets/keys via a dedicated secret store (Azure Key Vault); access on a need-to-know basis.
  • Separation control / tenant isolation: logical separation of customer data per tenant, including by row-level security at the database level, so that users can access only data of their own tenant.
  • Data access control / bug-report snapshots: Bug-report snapshots are stored as private records accessible only to SteerSuite engineering.

2. Integrity (Art. 32(1)(b) GDPR)

  • Transfer control / encryption: encryption of data in transit via secured transport encryption (TLS 1.2+, TLS 1.3 where supported) and encryption of data at rest in the database and storage services (AES-256, Azure standard).
  • Input control: logging of security- and operationally-relevant events (operational telemetry via Application Insights); traceability of administrative access.
  • Zero data retention for model calls: AI inference and embeddings are operated with a zero-data-retention configuration; the content of the model calls is not persistently stored at the model provider and is not used for training.
  • Transfer control / e-mail dispatch: Transactional e-mails are sent via an EU communication service (Azure Communication Services).

3. Availability and resilience (Art. 32(1)(b) and (c) GDPR)

  • operation on a managed, highly available cloud infrastructure (Microsoft Azure) with the provider's availability and redundancy properties;
  • regular, platform-managed backups of the database with point-in-time restore through the backup mechanisms provided by the managed database service (Azure PostgreSQL Flexible Server); concrete RPO/RTO values are provided on request;
  • protection against unauthorised access and operational disruptions through the security mechanisms of the cloud platform.

4. Procedures for regular review, assessment and evaluation (Art. 32(1)(d) GDPR)

  • regular review of the effectiveness of the technical and organisational measures;
  • commitment of persons authorised to process to confidentiality;
  • job/order control: engagement of sub-processors only with a contractual commitment to equivalent data-protection obligations (Annex 3, Sec. 6);
  • procedures for handling data-protection incidents and for supporting the notification and communication obligations (Sec. 8).

5. Data minimisation and deletion

  • Logical deletion of records and subsequent removal from backups within the rolling backup cycle.

The Processor does not currently hold its own certifications; it relies on the infrastructure certifications of Microsoft Azure (ISO/IEC 27001, SOC 2). The Processor's own certifications (e.g. ISO/IEC 27001, SOC 2) and summaries of external penetration tests are added here as soon as they are available.

Annex 3 — Authorised sub-processors

List as of: 2026-07-16. The current version is available at https://www.steersuite.com/subprocessors. Data residency is generally EU/EEA unless stated otherwise.

Sub-processorPurpose of processingProcessing region
Microsoft (Azure)Hosting & compute (app), database (PostgreSQL), secret management (Key Vault), operational telemetry (Application Insights).EU — Netherlands (West Europe/Amsterdam) for app hosting + database; Germany (Germany West Central) for secrets + telemetry.
Anthropic (Claude)AI inference (assistant, analysis and reporting features), provided via Microsoft Azure AI Foundry; zero-data-retention configuration.EU (deployment/at-rest) — Azure AI Foundry, deployment region Sweden. Inference under the "GlobalStandard" SKU may be routed outside the EU; the transfer is safeguarded by EU standard contractual clauses (Art. 46 GDPR) (see Sec. 11(2)).
Microsoft (Azure OpenAI Service)Text embeddings for semantic search and the vector index (no model training; zero data retention ensured contractually or by configuration).EU (deployment/at-rest) — Azure AI Foundry, deployment region Germany. Inference under the "GlobalStandard" SKU may be routed outside the EU; the transfer is safeguarded by EU standard contractual clauses (Art. 46 GDPR) (see Sec. 11(2)).
Microsoft (Azure Communication Services)Sending transactional e-mail (login links, system and notification mail, sender noreply@steersuite.com).EU — data location "Europe".
GitHub, Inc.Storage of in-app bug-report snapshots as private issues (accessible only to SteerSuite engineering).United States, safeguarded by EU standard contractual clauses.

Independent controllers / recipients (not sub-processors)

Stripe Payments Europe, Ltd.: payment processing (credit top-ups). Card and payment data is processed directly by Stripe as a separate controller (not a sub-processor); the pass-through of obligations under Sec. 6(4) does not apply to it in that respect. Contracting party in Ireland (EU); card processing may touch the United States. Stripe safeguards any third-country transfers on its own responsibility.

Note: Pure website and pre-sales tools (Microsoft Bookings for scheduling; Plausible for cookieless analytics without personal data) do not process product customer data and are not part of this DPA list; they are covered by the website privacy policy.

Auftragsverarbeitungsvertrag (AVV/DPA) — SteerSuite