Data processing
Data processing agreement
If we process personal data on your behalf within a project, we conclude an agreement pursuant to Art. 28 GDPR in advance. The ready-to-sign template is sent to you on request through our ticket system or by email to office@aiqsat.com.
Last updated: August 2026
When an agreement is required
An agreement is concluded as soon as we can access personal data of your staff or customers - for example operating, shift or login data - in the context of digitalisation, monitoring, remote access or operating our applications.
Subject matter and duration
The subject matter is processing exclusively on your instructions for the term of the main contract. Purpose, data types and categories of data subjects are specified in the annex to the agreement.
Instructions and place of processing
Processing takes place exclusively within the EU/EEA. Processing in third countries only occurs with your express approval and with appropriate safeguards (for example EU standard contractual clauses).
Technical and organisational measures
- Role-based access control, multi-factor authentication for remote access
- Encryption in transit (TLS) and at rest
- Access logging, separated tenant and project environments
- Backup and recovery concept, documented deletion periods
- Confidentiality obligations for everyone involved, regular training
The complete annex on security measures is part of the agreement template.
Sub-processors
Sub-processors in use (for example hosting, remote maintenance) are listed by name in the agreement and contractually bound to the same level of protection. We announce changes in advance; you may object.
Support, notifications and deletion
We support you with data subject requests, data protection impact assessments and accountability obligations, report security incidents without delay and, at your choice, delete or return data after the end of the contract.
Requesting the agreement
The agreement template including the list of security measures and sub-processors, as well as the contact details of the responsible contact person and - where appointed - of the data protection officer, are not published publicly. Request the documents through the ticket system; we will send them to the company address or functional email address you provide.
