Data Processing Agreement (Art. 28 GDPR)
Version 2026-10-07 — based on the standard contractual clauses of Commission Implementing Decision (EU) 2021/915.

This Data Processing Agreement ("DPA") applies between the organization that uses jidAI (the "Controller") and Silvertip IT-Solutions GmbH (the "Processor"). An administrator of the organization accepts it on the organization's behalf. It follows the structure of the standard contractual clauses between controllers and processors adopted by the European Commission in Implementing Decision (EU) 2021/915.

1. Purpose and scope

This DPA ensures compliance with Art. 28(3) and (4) GDPR. It applies to the processing of personal data described in Annex II, which the Processor carries out on behalf of the Controller when providing jidAI. Annexes I to IV form an integral part of this DPA.

This DPA is without prejudice to the obligations to which the Controller is subject under the GDPR, in particular as employer towards its employees.

2. Invariability and hierarchy

The parties may not modify these clauses, except to add information to the Annexes or update information in them. In the event of a conflict between this DPA and the Terms of Service or other agreements between the parties, this DPA prevails with regard to data protection.

3. Instructions

The Processor processes personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law. The Controller's settings and actions in jidAI, including the decision whether AI features are enabled for the organization, are documented instructions. The Processor informs the Controller without delay if, in its opinion, an instruction infringes data protection law.

4. Purpose limitation, duration, deletion

The Processor processes personal data only for the purposes set out in Annex II and for the duration of the contract. After the end of the provision of services, the Processor deletes all personal data processed on behalf of the Controller after a 30-day export period, unless Union or Member State law requires storage. Backups are overwritten in the normal backup cycle.

5. Security of processing and confidentiality

The Processor implements at least the technical and organisational measures specified in Annex III. Persons authorised to process the personal data are bound to confidentiality. The Processor grants its staff access only to the extent strictly necessary; operator access to an organization's data requires a documented support session with a reason.

6. Documentation and audits

The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, primarily through documentation and certifications, and on-site only with reasonable notice, during business hours, at most once per calendar year unless there are concrete indications of a breach of this DPA, and at the Controller's expense.

7. Use of sub-processors (general written authorisation)

The Controller grants general written authorisation for the engagement of the sub-processors listed in Annex IV. The Processor informs the Controller's administrators by email at least 30 days in advance of any intended addition or replacement of a sub-processor. The Controller may object within that period on reasonable data protection grounds; if no solution is found, the Controller may terminate the affected service.

The Processor imposes the same data protection obligations on each sub-processor by contract and remains fully responsible to the Controller for the performance of the sub-processor's obligations.

8. International transfers

Personal data covered by this DPA is stored and processed in the European Union (Google Cloud region europe-west3 and Vertex AI location "eu"). Any transfer to a third country takes place only in compliance with Chapter V GDPR, on the basis of documented instructions of the Controller.

9. Assistance to the Controller

The Processor assists the Controller with appropriate technical and organisational measures in fulfilling its obligation to respond to requests for exercising the data subject's rights (Art. 12 to 22 GDPR), and with its obligations under Art. 32 to 36 GDPR, including data protection impact assessments. Requests received directly from data subjects are forwarded to the Controller without delay.

10. Personal data breaches

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach concerning data processed on behalf of the Controller, so that the Controller can meet its obligations under Art. 33 and 34 GDPR. The notification contains the information required by Art. 33(3) GDPR as far as available; information not yet available is provided in phases without undue further delay. The Processor assists the Controller in notifying the supervisory authority and data subjects.

11. Non-compliance and termination

If the Processor is in breach of its obligations under this DPA, the Controller may instruct the Processor to suspend the processing until compliance is restored, and terminate the contract as far as it concerns the processing of personal data if compliance is not restored within one month.

Annex I — Parties

  • Controller: the organization registered in jidAI, represented by the administrator who accepts this DPA (name, email and time of acceptance are recorded).
  • Processor: Silvertip IT-Solutions GmbH, Grabenweg 68, 6020 Innsbruck, Austria, info@silvertip-it.at.

Annex II — Description of the processing

  • Categories of data subjects: employees and other workers of the Controller, administrators and coordinators.
  • Categories of personal data: account and contact data, organization membership and roles, working-time and absence records, projects and tasks, notes entered by users, work profiles and time balances, approval decisions, audit data.
  • Special categories: none intended. Sick-leave bookings record the absence type only, not diagnoses; users must not enter health data in notes.
  • Nature and purpose: provision of the jidAI time-tracking service, including the recording of working time required by law, approvals, reports and exports, and — only if the Controller has enabled AI features — AI-assisted drafting of time entries, transcription and setup recommendations.
  • Duration: for the term of the contract and the deletion period in clause 4.

Annex III — Technical and organisational measures

  • Hosting in the EU (Google Cloud, europe-west3); AI processing on Vertex AI in the EU multi-region.
  • Encryption in transit (TLS) and at rest (Google Cloud default encryption).
  • Access control: role-based permissions per organization; authentication with hashed passwords (bcrypt) or Google sign-in; session revocation.
  • Tenant isolation: every request is checked against the caller's organization memberships.
  • Operator access only through reasoned, time-limited support sessions; all privileged actions are written to an append-only audit log.
  • Data minimisation for AI: prompts with search grounding contain only non-personal information; no training on customer data.
  • Backups, restore tests and monitoring; documented incident response.

Annex IV — Sub-processors

  • Google Cloud EMEA Ltd. (Google Cloud Platform): hosting, database and file storage in the EU (europe-west3).
  • Google Cloud EMEA Ltd. (Vertex AI, Gemini): AI processing in the EU (location "eu"), only when the Controller has enabled AI features. Google may store requests for a limited period for abuse monitoring; requests with search grounding (work-profile generation, AI-assisted onboarding) are retained for 30 days.
  • Google Ireland Ltd. (Google Workspace / Gmail API): sending transactional emails.

Google reCAPTCHA protects public forms; it does not process the Controller's workforce data and is therefore not a sub-processor under this DPA.