1. Scope, Roles and Definitions

1.1 This Data Processing Agreement ("DPA") sets out in concrete terms the data-protection obligations of the parties insofar as the Contractor processes personal data on behalf of the Client in connection with the provision and use of Oxolo.

This DPA applies exclusively to B2B relationships. Use of the Oxolo software by natural persons exclusively for personal or household purposes within the meaning of Art. 2(2)(c) GDPR is not covered by the Contractor's range of services; the conclusion of a DPA with such persons is excluded.

1.2 In the event of a conflict between this DPA and the GTC for Oxolo, a quote, an Order Form or any other Usage Agreement, this DPA takes precedence with respect to data processing and data-protection obligations.

1.3 The Client is the controller within the meaning of Art. 4(7) GDPR for personal data whose purposes and means of processing it determines and which are processed via Oxolo. The Contractor is the processor within the meaning of Art. 4(8) GDPR insofar as it processes such personal data on behalf of the Client.

Insofar as the Contractor processes personal data for its own purposes, for example for contract administration, billing, product security, abuse prevention, its own compliance purposes, statutory documentation obligations or aggregated/anonymised analyses, the Contractor acts as an independent controller. This independent processing is not the subject of this DPA.

1.4 The definitions of the GDPR apply to this DPA. In addition, the following terms apply:

  • "Client": The natural or legal person or partnership that uses or wishes to use Oxolo on the basis of the GTC for Oxolo or any other Usage Agreement in a business capacity. The Client is the controller within the meaning of Art. 4(7) GDPR.

  • "Contractor": Oxolo GmbH, Bohnenstraße 2, 20457 Hamburg, Germany. The Contractor is the processor within the meaning of Art. 4(8) GDPR insofar as it processes Client Personal Data on behalf of the Client.

  • "Usage Agreement": The contract concluded between the Client and the Contractor for the use of Oxolo, including the GTC for Oxolo, a quote, an Order Form or other contract documents.

  • "Parties": The joint designation for the Client and the Contractor.

  • "Oxolo" / "Services": The Contractor's software solution for digital project, deployment, construction-site and field documentation, including the functions booked, activated or technically provided in each case.

  • "Client Input": All content and data that the Client or its Users enter, upload, record, capture, generate, connect, synchronise into Oxolo or otherwise provide to the Contractor for processing within the framework of Oxolo.

  • "Client Output": Content, reports, transcripts, summaries, tasks, analyses, labels, translations, project documentation and other results that Oxolo generates or structures on the basis of the Client Input on behalf of the Client.

  • "Client Personal Data": Personal data that form part of Client Input or Client Output or that are processed in connection with the use of Oxolo on behalf of the Client.

  • "Users": Natural persons authorised by the Client to use Oxolo, in particular employees, representatives, contractors, administrators or other authorised persons of the Client.

  • "Voice Profile" / "Voiceprint": A biometric pattern or other technical representation of a voice that can be used for speaker recognition or speaker identification.

  • "Subprocessor": Any further processor that the Contractor engages to process Client Personal Data within the framework of Oxolo.

2. Subject Matter and Duration of the Processing

2.1 The subject matter of this DPA is the processing of Client Personal Data by the Contractor for the provision of Oxolo as a software solution for digital project, deployment, construction-site and field documentation. The processing includes, in particular, insofar as booked, activated or used by the Client:

  • capture, upload, storage, structuring, analysis, translation and display of project, deployment, field and construction-site data;

  • audio recording or upload of audio content;

  • automated transcription;

  • speaker assignment and, insofar as activated, voice-profile-based speaker identification;

  • processing of photos, videos, signatures, evidence files and associated metadata;

  • creation of reports, logs and other project documentation, including PDF, DOCX and other output formats, insofar as supported;

  • extraction and structuring of tasks, variation orders, delays, labels and further project signals;

  • team collaboration, invitations, role and permission management, shares, tokenised links and external access workflows;

  • audit-trail, security and system logging to the extent technically available in each case;

  • account, subscription, billing, support and service-operation processes, insofar as this processing takes place on behalf of the Client;

  • authentication of Users by means of telephone number and one-time password (OTP SMS) as well as email magic link, including the logging of authentication events;

  • insofar as activated, recording and transcription of external online meetings by means of a Meeting Bot;

  • dispatch of push notifications to registered devices;

  • optional WhatsApp companion channel for inbound/outbound communication and media processing, insofar as activated.

2.2 This DPA is concluded together with the Usage Agreement. Its term corresponds to the term of the Usage Agreement. The obligations under this DPA continue to exist after termination of the Usage Agreement for as long as the Contractor has not returned, deleted, anonymised or otherwise destroyed Client Personal Data in a data-protection-compliant manner in accordance with this DPA.

2.3 The Contractor processes Client Personal Data exclusively on documented instruction from the Client, unless a statutory obligation of the Contractor requires processing. In this case, the Contractor informs the Client of the relevant legal requirements before the processing, unless the respective law prohibits such notification on grounds of an important public interest. The documented instructions result from this DPA, the Usage Agreement, the use and configuration of Oxolo by the Client, as well as permissible individual instructions of the Client.

2.4 The Client remains solely responsible for the lawfulness of the personal data provided to the Contractor and for ensuring that the collection, disclosure and further processing of these data by the Contractor in accordance with the Client's documented instructions are compatible with applicable data-protection law. This includes, in particular:

  • the lawfulness of the collection, disclosure and transmission of Client Personal Data to the Contractor;

  • the lawfulness of the processing of Client Personal Data by the Contractor on the Client's instruction;

  • compliance with transparency obligations towards data subjects;

  • obtaining consents, insofar as these are required;

  • carrying out a data protection impact assessment, insofar as it is required under Art. 35 GDPR;

  • assessing whether Oxolo provides an adequate level of protection for the respective use and the respective data.

2.5 The parties are aware that Oxolo provides an optional function for voice-profile-based speaker identification ("Voiceprints"). Voiceprints are biometric data for the unique identification of a natural person and thus special categories of personal data within the meaning of Art. 9(1) GDPR, insofar as they are used or can be used for unique identification. Voiceprints are processed in isolation on an organisation-specific basis; no cross-organisational speaker recognition or cross-organisational voiceprint matching takes place.

Insofar as the Client activates this function, has it activated by its Users or triggers corresponding processing through its use of Oxolo, it instructs the Contractor to process Voiceprints within the framework of the documented instructions and the product-specific parameters of Oxolo.

The Client is solely responsible, before the processing of biometric data, for ensuring a suitable legal basis under Art. 6(1) GDPR and an exception or authorisation under Art. 9(2) GDPR, in particular for obtaining the explicit consent of the data subjects pursuant to Art. 9(2)(a) GDPR or maintaining another suitable authorising provision, as well as for providing the information required under Art. 13/14 GDPR. This applies to every speaker who can be captured by the function, and thus also to third parties whose voice is captured within a recording, not only to employees of the Client. The Contractor provides a function in the Product with which Users of the Client give consent when registering their own voice profile and with which this consent is logged in a versioned manner. This function is provided on behalf and for the account of the Client as controller; the Contractor does not thereby become a controller. The Client remains obliged to review, on its own responsibility, the wording of the consent declaration used in the Product for effectiveness under Art. 9(2)(a) GDPR; the Contractor makes the respective current wording available to it on request.

The Client must refrain from, deactivate or organisationally avoid the use of voice profiles / Voiceprints insofar as it cannot ensure the required transparency, legal basis, consent or other data-protection prerequisite.

2.6 The parties are aware that Oxolo contains an automatic speaker identification that is activated by default at the organisation level and can be deactivated organisation-wide by the organisation owner and by Users with an administrator role. With this function, unknown speakers are automatically created as identities with an anonymised placeholder label (e.g. "Speaker b74bj73"); at the same time, a voice profile (Voiceprint), and thus a biometric datum within the meaning of Art. 9(1) GDPR, is generated and stored for the respective speaker. Subsequent naming is carried out by authorised Users of the Client. Insofar as the Client leaves this function activated or has it activated by its Users, it may only use it if it has, in advance, ensured the required legal basis, transparency and, where necessary, explicit consent of all data subjects. A deactivation takes effect only for the future; Voiceprints already generated continue to exist until their deletion pursuant to Section 7.4.

2.7 Beyond Voiceprints, further special categories of personal data within the meaning of Art. 9(1) GDPR are not primarily intended for processing. Nevertheless, audio recordings, photos, videos, transcripts, signatures or project content may, depending on the content provided by the Client, contain or reveal special categories of personal data, for example health data, trade-union membership, religious or philosophical beliefs or other sensitive information.

The Client is responsible for the lawfulness of this processing and must, in particular, ensure transparency, a legal basis, consents and protective measures. The Contractor may suspend the processing insofar as this is necessary to comply with applicable law.

2.8 The parties are aware that Oxolo, insofar as booked and activated by the Client, provides a function for recording external online meetings, in which a Meeting Bot joins a meeting on third-party platforms (in particular Zoom, Google Meet, Microsoft Teams) and records audio and/or video content of the meeting. The recorded content is subsequently transferred into the same recording, transcription and analysis pipeline as other recordings; this includes transcription, speaker assignment and, insofar as activated, voice-profile-based speaker identification.

This function may capture all meeting participants, including persons who are neither Users nor employees of the Client. Insofar as voices are recorded and used for speaker identification, Section 2.5 applies accordingly; biometric data within the meaning of Art. 9(1) GDPR may be processed.

The Client is solely responsible, before the use of the Meeting Bot, for informing all meeting participants about the recording and its purpose, for ensuring a suitable legal basis under Art. 6(1) GDPR and, where applicable, an authorisation under Art. 9(2) GDPR, and for obtaining the consents required under applicable law. This includes, in particular, observance of the criminal-law protection of the confidentiality of the non-publicly spoken word (§ 201 StGB, German Criminal Code) and comparable provisions of other legal systems. The Client must refrain from using or deactivate the Meeting Bot insofar as it cannot ensure these prerequisites.

The Contractor does not owe any obtaining of consent of its own vis-à-vis meeting participants and no review of whether a recording is permissible in the individual case.

3. Specification of the Processing Content, Places of Processing and Third-Country Transfers

3.1 The processing includes, depending on the use and configuration of Oxolo, in particular the collection, capture, recording, upload, storage, ordering, structuring, querying, display, categorisation, conversion, transcription, analysis, summarisation, translation, provision, transmission to authorised recipients, disclosure to authorised Subprocessors, anonymisation, restriction, deletion and destruction of Client Personal Data.

3.2 The purpose of the processing is the provision, operation, maintenance, safeguarding and support of Oxolo in accordance with the Usage Agreement and the documented instructions of the Client. The purposes are further specified in Annex 1.

3.3 The categories of personal data result in particular from Annex 1. The Client determines, through its use, configuration, user permissions and provided content, which personal data are specifically processed.

3.4 The categories of data subjects result in particular from Annex 1. They may include, in particular, Users of the Client, employees, contractors, subcontractors, project participants, customers, suppliers, visitors, report recipients, persons in audio recordings, persons in photos or videos, as well as signatories of signatures.

3.5 The Contractor processes Client Personal Data primarily within the European Union or the European Economic Area. The central infrastructure is operated in the EU, in particular the AWS region eu-west-1 (Ireland) for compute, object storage (S3) and the application database (AWS RDS Postgres), the AWS region eu-west-1 (Ireland) for the transcript embedding database (AWS RDS Postgres), the AWS Key Management System (KMS) in eu-west-1 for the signing keys of the authentication tokens, the Sentry instance in Germany and the PostHog instance in the EU.

Processing and/or transfers to third countries may take place insofar as this is necessary for the provision of Oxolo, in particular through the use of the Subprocessors with a third-country nexus named in Annex 3.

3.6 The parties are aware that the transcription and batch diarisation of audio recordings takes place exclusively via the EU endpoint of the Subprocessor AssemblyAI (api.eu.assemblyai.com/v2). Audio content is not transmitted to US endpoints of AssemblyAI; a real-time/streaming endpoint is no longer used.

A third-country nexus exists, by contrast, in the case of the Subprocessors correspondingly identified in Annex 3, in particular for SMS/OTP delivery (Twilio), the dispatch of push notifications (Expo), the dispatch of transactional emails (Postmark) and — insofar as activated — the recording of external online meetings (Recall.ai). These transfers take place on the basis of suitable safeguards pursuant to Chapter V GDPR, in particular the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and/or the EU-US Data Privacy Framework, insofar as the respective Subprocessor is certified. The Contractor implements supplementary measures where necessary.

3.7 Third-country transfers take place only if the requirements of Art. 44 et seq. GDPR are met and a suitable transfer mechanism applies, in particular an adequacy decision, the EU-U.S. Data Privacy Framework, the EU Standard Contractual Clauses or other suitable safeguards. Where necessary, the Contractor implements supplementary measures taking into account the nature, scope, purpose and risk of the transfer. The Client hereby consents to the relocation of individual processing operations to the third countries named in Annex 3, insofar as this is necessary for the provision of the service and a permissible transfer mechanism exists.

3.8 Image files uploaded by Users (evidence photos, project images, profile pictures) may contain embedded EXIF/GPS/device metadata, for example geo-coordinates, time of capture, device model, camera/app information and comparable metadata. These metadata are not removed. The Client is responsible for informing its Users and, where applicable, for corresponding notices to third parties.

4. Technical and Organisational Measures

4.1 The Contractor takes technical and organisational measures pursuant to Art. 28(3)(c) and Art. 32 GDPR in order to ensure a level of protection for Client Personal Data appropriate to the risk. The measures take into account the state of the art, the costs of implementation, the nature, scope, circumstances and purposes of the processing, as well as the likelihood and severity of possible risks to the rights and freedoms of natural persons.

4.2 The specifically documented technical and organisational measures are described in Annex 2. The Client accepts these measures as the basis of the processing. As evidence, the Contractor may present, in particular, the respective current SOC 2 report, internal security documentation in appropriately summarised or redacted form, current certificates, security reports, extracts of reports from independent bodies, technical documentation, data-protection reports or comparable evidence.

4.3 The technical and organisational measures are subject to technical further development. The Contractor may implement alternative or amended measures, provided that the contractually agreed level of security is not fallen below. Material changes are to be documented.

5. Instructions of the Client

5.1 The Client instructs the Contractor to process Client Personal Data insofar as this is necessary in order to provide Oxolo in accordance with the Usage Agreement, this DPA, the configuration chosen by the Client and the functions activated by the Client.

5.2 The Client may issue individual instructions in text form. Oral instructions are to be confirmed in text form without undue delay. Instructions that go beyond the contractually agreed scope of services, the standard functions of Oxolo or statutory requirements may be made conditional by the Contractor on reasonable remuneration.

5.3 The Contractor informs the Client without undue delay if it is of the opinion that an instruction infringes applicable data-protection law. The Contractor may suspend the execution of the instruction concerned until the Client confirms, amends or withdraws it.

6. Obligations of the Contractor

6.1 The Contractor ensures that persons authorised to process Client Personal Data have committed themselves to confidentiality or are subject to an appropriate statutory duty of confidentiality. This obligation continues to exist even after the end of the activity.

6.2 The Contractor processes Client Personal Data only for the provision of Oxolo and the associated services in accordance with the Usage Agreement, this DPA and the documented instructions of the Client. The Contractor may not use Client Personal Data for other purposes and may not pass them on to third parties, except to approved Subprocessors pursuant to Section 8 and Annex 3 or insofar as legally required.

6.3 The Contractor does not use Client Personal Data to train its own general AI models. The Contractor also does not use Client Personal Data to train the third-party large language models used by it, insofar as this is excluded under the respective product and contract terms of these third-party providers. Insofar as Oxolo uses AI functions or AI Subprocessors, the processing takes place only within the scope of the service and in accordance with this DPA. Any use of Client Personal Data for product improvement, quality assurance or the further development of algorithms takes place only insofar as the Client has expressly activated the corresponding system setting within the meaning of the GTC for Oxolo (Clause 10.2). Any such activation does not affect the prohibition on training the Contractor's own general AI models and the prohibition on third-party LLM training under the preceding sentences.

6.4 The Contractor supports the Client, taking into account the nature of the processing and the information available to it, to a reasonable extent in complying with its obligations pursuant to Art. 32 to 36 GDPR, insofar as the support concerns the processing of Client Personal Data under this DPA and the Contractor's effort is not disproportionate.

6.5 If the Contractor is required by a supervisory authority, a law-enforcement body or another state body to hand over or disclose personal data of the Client, it informs the Client — insofar as legally permissible — without undue delay before the disclosure and reviews, with due care, the lawfulness of the request.

7. Data Subject Rights, Rectification, Restriction and Deletion

7.1 The Contractor does not rectify, delete or restrict Client Personal Data of its own accord, but only on documented instruction from the Client, unless the Usage Agreement, the standard functions of Oxolo, statutory obligations or this DPA provide otherwise.

7.2 If a data subject contacts the Contractor directly in order to assert rights under Art. 12 to 23 GDPR in relation to Client Personal Data, the Contractor forwards the request to the Client without undue delay, insofar as an assignment is possible and legally permissible. The Contractor does not answer such requests itself, unless it is legally obliged to do so or the Client instructs it to do so.

7.3 The Contractor supports the Client to a reasonable extent through suitable technical and organisational measures in fulfilling data subject rights. Non-standardised support services may be reasonably remunerated, insofar as they are not based on a breach of duty by the Contractor. The Client directs corresponding requests to gdpr@oxolo.com or a data-protection contact point of the Contractor named in the Usage Agreement.

7.4 The parties are aware that the deletion of a voice profile / Voiceprint removes the biometric template in the transcript embedding database, the associated records in the application database, as well as the associated S3 audio object, insofar as it is used specifically for the voice profile. Historical transcripts are not thereby automatically deleted or anonymised and may continue to contain the speaker name used at the time of the recording.

The deletion of a Voiceprint takes place in particular where (i) a User deletes their own Voiceprint via the app, (ii) a User is removed from an organisation, in which case that User's own Voiceprints in the organisation concerned are deleted, (iii) the account is deleted or archived, (iv) the organisation owner or a User with an administrator role deletes an identity via the settings, or (v) a speaker is marked as "noise"; on the Client's individual instruction, the Contractor additionally deletes Voiceprints, provided that this is technically possible and not otherwise prescribed by law.

The Client remains the controller for the decision whether and when historical transcripts, recordings or content derived therefrom must be deleted, rectified, restricted or anonymised.

8. Subprocessors

8.1 The Client approves the use of the Subprocessors named in Annex 3 for the purposes described therein. A prerequisite is a contractual agreement between the Contractor and the respective Subprocessor in accordance with Art. 28(2) to (4) GDPR.

8.2 The Client grants the Contractor a general authorisation to use further Subprocessors or to replace existing Subprocessors, provided that the requirements of this Section 8 are complied with.

8.3 The Contractor informs the Client at least thirty (30) days before the use of a new or replacing Subprocessor or before a material change concerning existing Subprocessors. The information is provided in text form to the Client's contact email stored in the Usage Agreement and/or through the updating of a subprocessor list on the website or in the Product.

8.4 The Client may object within the notification period for documented, objective data-protection reasons. General commercial, competitive or non-data-protection-related reasons are not sufficient. If no objection is made within this period, the change is deemed approved.

In the event of a justified objection, the parties cooperate in good faith to address the objection, in particular through additional protective measures, explanations, technical configurations or a reasonable alternative, insofar as available. If the objection cannot be reasonably resolved and the Subprocessor concerned is necessary for a separable part of Oxolo, the Client may terminate the affected part of the Services, insofar as that part is separable. If separation is not possible or unreasonable for the Contractor, the Contractor is entitled to terminate the Usage Agreement at reasonable notice.

8.5 The Contractor concludes with each Subprocessor a contract that meets the requirements of Art. 28(4) GDPR and obliges the Subprocessor to data-protection and security requirements that substantially correspond to the requirements of this DPA. The Contractor is liable to the Client for the Subprocessors' fulfilment of the data-protection obligations in accordance with Art. 28 GDPR and the Usage Agreement.

9. Control and Audit Rights

9.1 The Contractor makes available to the Client, on request, the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and this DPA. Evidence may be provided, in particular, by current certificates, security reports, extracts from audits, technical documentation, data-protection reports or comparable evidence.

9.2 The Client may carry out audits itself or have them carried out by an independent auditor bound to confidentiality, provided that the auditor is not a competitor of the Contractor. Audits are to be announced at least thirty (30) days in advance in text form, may only take place during usual business hours and may not unreasonably impair the Contractor's business operations.

Regular audits are limited to once per calendar year and, as a rule, to one working day. Event-related audits are permissible where there is legitimate cause, in particular in the case of a specific suspicion of a material data breach or a substantiated request by an authority.

9.3 The Contractor may demand reasonable remuneration for audits and support services, insofar as the audit was not occasioned by a breach of duty for which the Contractor is responsible.

10. Support with Security, Data Breaches and Data Protection Impact Assessment

10.1 The Contractor supports the Client to a reasonable extent in complying with obligations under Art. 32 to 36 GDPR, insofar as the support concerns the processing of Client Personal Data under this DPA. This includes, in particular, reasonable support with the security of processing, the notification of personal data breaches, the notification of data subjects, data protection impact assessments and prior consultations with supervisory authorities.

10.2 The Contractor informs the Client without undue delay after becoming aware of a personal data breach, insofar as it concerns Client Personal Data processed under this DPA. The notification is made to the Client's contact email specified in the Usage Agreement and contains the information required under Art. 33(3) GDPR, insofar as it is available. If this information is not yet available at the time of the initial notification, it is provided subsequently without undue delay.

Insofar as a fixed deadline is agreed in the Usage Agreement or in an internal incident policy, that deadline applies in addition. Absent any agreement to the contrary, the Contractor aims to provide an initial notification no later than within seventy-two (72) hours after becoming aware, provided that the information is available and the notification is legally permissible.

10.3 Insofar as further relevant information becomes known to the Contractor after the initial notification, the Contractor makes it available to the Client without undue delay.

11. Return, Deletion and Retention

11.1 After termination of the Usage Agreement or earlier on documented instruction from the Client, the Client retains access, for at least thirty (30) days after the termination takes effect, to the export and download functions available in Oxolo in order to export Client Personal Data, insofar as this is technically available, legally permissible and justifiable for security reasons. In addition, the Client may, within this period, request an export in text form to team@oxolo.com or the contact point named in the Usage Agreement. Thereafter, the Contractor deletes Client Personal Data in a data-protection-compliant manner or returns them, insofar as no statutory retention obligations, legitimate interests in evidence or Art. 17(3) GDPR conflict with this.

11.2 At the Client's choice, the Contractor deletes Client Personal Data, including existing copies, or returns them to the Client within a reasonable period after termination of the Usage Agreement, in principle no later than within ninety (90) days. If the Client does not make a choice within the period pursuant to Section 11.1, the Contractor deletes the data. This does not apply where a longer statutory retention obligation, a legitimate interest in evidence, a technical backup retention or a deviating documented instruction of the Client conflicts with this.

11.3 Transcripts and recordings are stored for the term of the contract as Client Data, insofar as the Client does not delete them beforehand or trigger a deletion via the functions of Oxolo. Voice profiles / Voiceprints are deletable on request and are, in particular, automatically deleted upon account closure, upon removal of the User from an organisation and upon archiving of the organisation, in each case with respect to the affected User's own voice profiles. Voice profiles of automatically captured third parties are deleted when the organisation owner or a User with an administrator role deletes the associated identity or the speaker is marked as "noise". The deletion covers the biometric template in the transcript embedding database, the associated records in the application database, as well as the associated S3 source audio.

11.4 Documentation, security evidence, billing data, audit-trail data and other evidence that is necessary for the fulfilment of statutory obligations or for the defence, exercise or assertion of legal claims may be retained beyond the end of the contract, insofar as this is legally permissible.

12. Liability

The liability of the parties inter se is governed by the Usage Agreement, unless mandatory data-protection law, in particular Art. 82 GDPR, provides otherwise.

The Contractor is liable to the Client for damage arising from a breach of this DPA or of the statutory data-protection provisions by the Contractor or by Subprocessors engaged by it, in accordance with the statutory provisions and in accordance with the liability arrangements effectively agreed in the Usage Agreement, insofar as these do not conflict with mandatory law.

The parties inform each other without undue delay if, in connection with the processing under this DPA, claims for damages, official measures, fines or other sanctions are threatened or asserted, and support each other appropriately in defending against such claims.

13. Final Provisions

13.1 Amendments and supplements to this DPA require text form, unless mandatory law requires a stricter form. This also applies to the amendment of this form clause.

13.2 Both parties are obliged to treat confidentially all knowledge of trade and business secrets and data-security measures of the respective other party obtained within the framework of the contractual relationship. This obligation also continues to exist after termination of this DPA.

13.3 A right of retention of the Contractor over Client Personal Data is excluded, unless mandatory law requires otherwise.

13.4 If Client Personal Data at the Contractor is endangered by attachment, seizure, insolvency proceedings, composition proceedings or other measures of third parties, the Contractor informs the Client without undue delay, insofar as legally permissible.

13.5 The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods. The place of jurisdiction for all disputes arising from or in connection with this DPA is — insofar as legally permissible — Hamburg.

13.6 The following annexes are a component of this DPA:
Annex 1: Description of the Processing;
Annex 2: Technical and Organisational Measures;
Annex 3: Subprocessors.

13.7 This DPA enters into force upon acceptance by both parties and, with effect from its entry into force, replaces the previous data processing agreement.



Annex 1: Description of the Processing

1. Description of the Service

Oxolo is a mobile-first software-as-a-service solution for digital project, deployment, construction-site and field documentation, distributed exclusively to business customers (B2B). Depending on the booked scope of services, the Client's configuration, the permissions granted by the Client's Users, the activated functions and the project workflows, Oxolo may capture, record, upload, structure, analyse, translate, share and display information in connection with project, deployment, construction-site and field documentation workflows.

  • audio recording of on-site conversations or upload of audio content and capture of associated metadata, including timestamps, device context and — insofar as activated — location/GPS information;

  • automated transcription, including speaker assignment and — as an optional feature — voice-profile-based speaker identification ("Voiceprints"; biometric data within the meaning of Art. 9 GDPR);

  • AI-supported analysis of transcripts and project data, including summaries, labels, tasks, variation orders, delays and associated project signals;

  • creation of reports and project documentation, including PDF, XLSX and DOCX outputs, as well as — insofar as applicable — embedded evidence files;

  • capture and storage of evidence, including photos, videos, signatures and associated metadata including EXIF/GPS data;

  • team collaboration, role-based project access, invitations, report downloads and activity logging;

  • sharing and external access workflows for selected recordings, reports or other project outputs via tokenised links or email notifications;

  • translation and multilingual display of project content;

  • optional WhatsApp companion channel for inbound/outbound communication and media processing;

  • cross-platform availability via iOS, Android and web application;

  • authentication of Users via telephone number and one-time password (OTP) by SMS as well as via email magic link, including logging of the authentication events;

  • insofar as booked and activated: recording and transcription of external online meetings by means of a Meeting Bot that joins the meeting on third-party platforms (e.g. Zoom, Google Meet, Microsoft Teams);

  • dispatch of push notifications to registered mobile devices;

  • account, support, billing and service-management functions.

2. Purposes of the Processing

The processing takes place exclusively for the provision of Oxolo on the Client's instruction, in particular for:

  • digital project, deployment, construction-site and field documentation;

  • recording, transcription and structuring of conversations and project events;

  • creation, storage, translation and sharing of project documentation and reports;

  • extraction, organisation and display of tasks, delays, variation orders and action items;

  • management of projects, team collaboration, permissions, invitations, shares and audit trails;

  • speaker recognition and speaker identification, insofar as lawfully activated and used;

  • support, security, error analysis and service operation;

  • billing and contract administration, insofar as this takes place on behalf of the Client.

3. Types of Processing

The processing includes, in particular, the collection, capture, recording, upload, storage, ordering, structuring, querying, display, categorisation, transcription, analysis, summarisation, translation, enrichment by AI-supported methods, provision, sharing, transmission, anonymisation, restriction, deletion and destruction.

4. Categories of Data Subjects
  • Users of the Client;

  • employees, managers, administrators and representatives of the Client;

  • customers, suppliers and business partners of the Client;

  • contractors, subcontractors, service providers and their employees;

  • project participants, construction-site participants, site managers, architects, engineers, visitors and other persons present on site;

  • persons whose voice is contained in audio recordings;

  • persons who appear in photos, videos, evidence files or signatures;

  • recipients of shared reports, recordings, links or other project outputs;

  • participants in external online meetings that are recorded via the Meeting Bot, including persons outside the Client's organisation;

  • support or contact persons of the Client.

5. Categories of Personal Data
  • identification data, in particular name, user ID, role, title, company, team or project assignment;

  • contact data, in particular email address, telephone number and communication data;

  • account and permission data, in particular login data, roles, access rights, organisation and project memberships;

  • project and construction-site data, in particular project names, addresses, location information, project status and documentation context;

  • audio recordings and audio metadata;

  • transcripts, speaker labels, speaker assignments and summaries;

  • voice profiles / Voiceprints and associated technical identifiers, insofar as activated;

  • photos, videos, signatures, evidence files and associated metadata;

  • tasks, variation orders, delays, labels, comments and other project signals;

  • reports, logs, exported documents and shared views;

  • device, system, security and log data, in particular IP addresses, timestamps, device context, session data, error reports, audit-trail data and access data;

  • billing, contract and support data, insofar as processed on behalf of the Client;

  • authentication and event data, in particular telephone number, request and result of one-time passwords, login time, IP address and user agent;

  • push tokens of registered devices and associated platform information;

  • recordings of external online meetings including audio, video, transcripts and participant details, insofar as activated;

  • AI-generated or automatically derived data, insofar as they are based on Client Input and contain personal data.

6. Special Categories of Personal Data

Insofar as Oxolo processes voice profiles / Voiceprints for speaker identification, biometric data within the meaning of Art. 9(1) GDPR may be processed. In addition, audio recordings, photos, videos, transcripts or project content may, depending on the content provided by the Client, contain or reveal special categories of personal data, for example health data, trade-union membership, religious or philosophical beliefs or other sensitive information.

The Client is responsible for the lawfulness of this processing and must, in particular, ensure transparency, a legal basis, consents and protective measures.

7. Image Metadata

Uploaded images may contain metadata, in particular location data, GPS data, device model, camera/app information, creation timestamps and further EXIF or comparable metadata.

8. Duration of the Processing and Retention

The processing lasts, in principle, for the term of the Usage Agreement plus the duration necessary for the fulfilment of statutory retention obligations. Transcripts and recordings are stored for the term of the contract as Client Data, insofar as the Client does not delete them beforehand or trigger a deletion via the functions of Oxolo.

Voice profiles / Voiceprints are deleted in the following cases in accordance with the documented deletion logic:

(i) the User deletes their own Voiceprint via the app;
(ii) the User is removed from an organisation, in which case that User's own Voiceprints in the organisation concerned are deleted;
(iii) the account is deleted or archived;
(iv) the organisation owner or a User with an administrator role deletes an identity via the settings;
(v) a speaker is marked as "noise".

Upon deletion, the biometric template in the transcript embedding database, the associated records in the application database, as well as the associated S3 source audio, are removed. Historical transcripts, original recordings and audit-trail data are retained as Client Data, insofar as no separate deletion takes place.

Audit-trail data are protected against modification and deletion at the database level by triggers and are retained without an automated deletion deadline; upon deletion of a user account, the actor identifier is anonymised and the record is otherwise retained. Authentication event data are retained without an automated deletion deadline; the link to the user account is severed upon its deletion. Consent logs for the WhatsApp companion channel are maintained exclusively on an additive basis (insert-only) and retained without an automated deletion deadline; they are removed as soon as the associated user record is completely deleted. The retention takes place in each case insofar as it is necessary for the fulfilment of statutory evidence and accountability obligations (Art. 5(2) GDPR) and for the assertion, exercise or defence of legal claims.

Specific further deletion periods are governed by the Usage Agreement, the functions of Oxolo, statutory retention obligations and documented instructions of the Client.

Annex 2: Technical and Organisational Measures

The measures described below correspond to Art. 32 GDPR and are taken by the Contractor to protect the Client's personal data. The measures are subject to the state of the art and may be further developed by the Contractor, provided that the level of protection is not lowered.

1. Hosting and Data Residency

  • Cloud workloads are operated in AWS eu-west-1 (Ireland).

  • The application database is an AWS RDS Postgres instance in eu-west-1 (Ireland).

  • The RDS region for the transcript embedding database is eu-west-1.

  • Biometric voice-profile data (Voiceprints) are held in two separate databases: in the transcript embedding database (AWS RDS, eu-west-1) and, in addition, in the application database (AWS RDS Postgres, eu-west-1). The deletion paths pursuant to Annex 1 Section 8 act on both storage locations.

  • The signing keys for authentication tokens are held in the AWS Key Management Service (KMS) in eu-west-1; the private key does not leave the KMS.

  • PostHog is used on an EU instance.

  • Sentry is used on a DE instance.

  • Speech transcription and batch diarisation take place exclusively via the AssemblyAI EU endpoint (api.eu.assemblyai.com/v2). A streaming method is not used.

  • AI inference for vision/text takes place via Anthropic Ireland Ltd. in Ireland/EU.

  • Insofar as activated, the recording of external online meetings takes place via Recall.ai (client region eu-central-1).

  • The delivery of OTP SMS takes place via Twilio (USA); push notifications are delivered via the Expo Push Service (USA).

2. Physical Access Control (Entry Control)

The physical protection of the data-centre infrastructure is primarily ensured by the respective hosting and infrastructure providers. Physical access to server and hosting environments is implemented by the respective infrastructure providers, in particular AWS; the data processing takes place in their data centres with video surveillance, alarm and access-control systems. The Contractor's business premises are protected against unauthorised access outside business hours; visitors are accompanied and do not obtain unsupervised access to systems on which Client Personal Data are processed.

3. System Access Control

Access to systems takes place via individual user accounts. Administrative access is granted on a role and permission basis. Multi-factor authentication is used for administrative systems and — insofar as technically supported — for employee systems. The authentication of Users vis-à-vis Oxolo takes place via cryptographically signed access tokens (RS256); the associated private signing key is managed in the AWS Key Management Service and does not leave it at any time. State-changing requests from cookie-based sessions are additionally secured by a CSRF protection. Changes to roles, permissions and memberships are re-evaluated with each individual request and therefore take effect immediately; requests from deleted or deactivated accounts are rejected with each request. Access rights follow the need-to-know principle and are reviewed as required or regularly. Passwords and secrets are managed in suitable password and secret-management systems. The Contractor's devices are protected by passwords, screen lock and hard-disk encryption.

4. Data Access Control and Separation Requirement

Role and permission concepts limit access to the necessary user groups. Customer data are processed on a tenant-specific basis and logically separated by technical and organisational access restrictions. Permission concepts ensure that Users can only access organisations, projects and content for which they are authorised. Test and production environments are operated in organisationally separate form.

5. Transmission Control

Data are transmitted via encrypted connections, in particular HTTPS/TLS. Authenticated API endpoints are protected by suitable authentication and authorisation mechanisms (in particular JWT/bearer token, service keys). Incoming webhooks from Subprocessors are verified via signature (HMAC) or bearer-token verification. A single public callback endpoint of the optional WhatsApp companion channel is currently operated without signature verification for compatibility reasons and is secured by supplementary measures (input validation, logging, monitoring). No physical data carriers are used for the transmission of personal data. External transmissions to Subprocessors take place only insofar as they are necessary for the provision of the respective function.

6. Storage Control and Encryption

Data are stored at suitable infrastructure and platform services. Encryption at rest and in transit is used, insofar as supported by the respective infrastructure and application, in particular at AWS S3 and AWS RDS. The database connections of both RDS instances are configured to be TLS-mandatory. Mobile work devices are protected against unauthorised access and encrypted, insofar as technically provided for.

7. Availability and Recoverability Control

Infrastructure providers and platform services are used to ensure availability and recoverability. Backups, recovery mechanisms and emergency measures are used within the framework of the technical possibilities and the services deployed. Protection against malware on the Contractor's systems and devices, security updates, monitoring and technical hardening are implemented according to risk-based standards. Files uploaded by Users are stored directly in the object storage; a content-based malware scan and a server-side restriction of permissible file types do not take place. The Client is responsible for ensuring that no malicious content is uploaded, stored or distributed to other Users via Oxolo.

8. Input Control, Logging and Monitoring

Oxolo uses audit-trail, security, monitoring and error-analysis mechanisms to the extent technically available in each case. Audit-trail records are protected against deletion on an append-only basis via database triggers. Sentry is used for error analysis and monitoring. PostHog is used for product analysis, feature flags and LLM cost or usage analyses, insofar as configured.

9. Instruction Control and Subprocessors

Subprocessors are selected according to data-protection criteria. Agreements are concluded with Subprocessors insofar as they process personal data as processors on behalf of the Contractor. Third-country transfers take place only in accordance with Chapter V GDPR.

10. Data Minimisation and Deletion Concept

Client Personal Data are deleted or returned in accordance with the Usage Agreement, this DPA, the available product functions and documented instructions. Voice profiles / Voiceprints and associated S3 audio objects are deletable in accordance with the documented product functions. Historical transcripts and recordings are treated separately therefrom as Client Data.'

11. Personnel

Employees and other persons authorised to process are committed to confidentiality. Access to Client Personal Data is limited to persons who need it to fulfil their tasks. Data-protection and security training takes place on a risk-based and event-related basis.

12. Incident and Breach Management

Defined processes exist for the detection, reporting, assessment and handling of data breaches. Data-protection incidents are reported to the Client in accordance with Section 10 of this DPA.

Annex 3: Subprocessors

The Client consents to the engagement of the Subprocessors listed in this Annex. This Annex lists exclusively Subprocessors that process Client Personal Data on behalf of the Client. Services that the Contractor uses as an independent controller for its own purposes (in particular for internal communication, its own customer-relationship and marketing management, website analysis and consent management) do not process Client Personal Data on behalf of the Client, are not the subject of this Annex and are disclosed in the Contractor's Privacy Policy. Third-country transfers take place only in accordance with Section 3.7 of this DPA. In the case of third-country transfers, the Contractor additionally concludes with the respective Subprocessor the EU Standard Contractual Clauses in the respective applicable module variant, regularly Module 3 – processor to processor, and implements — insofar as necessary — supplementary measures. Insofar as a Subprocessor is certified under the EU-US Data Privacy Framework, this may also be taken into account as a suitable transfer mechanism.

Subprocessor

Address / Country

Place of Processing

Service

Transfer Mechanism

Amazon Web Services EMEA SARL / Amazon Web Services

38 Avenue John F. Kennedy, L-1855 Luxembourg / Marcel-Breuer-Str. 12, 80807 Munich; further AWS locations or branches depending on contract structure

EU (eu-west-1, Ireland)

Cloud infrastructure, hosting, storage, compute, S3, infrastructure services

Intra-EU; supplementary AWS DPA with EU SCC, insofar as applicable

AssemblyAI, Inc.

100 Pine Street, Suite 1250, San Francisco, CA 94111, USA

EU (api.eu.assemblyai.com/v2)

Speech transcription and batch diarisation; no streaming/real-time method

EU processing; supplementary EU SCC (Module 3) vis-à-vis the US parent company; DPF, insofar as certified; see Section 3.6 of this DPA

Pyannote.ai

ALLEE DE L'AUTAN, 31320 AUZEVILLE-TOLOSANE, France

EU (eu-west-3, France)

Speaker diarisation and voiceprint identification

Intra-EU processing; DPA pursuant to Art. 28 GDPR with Pyannote on file

Anthropic Ireland Ltd.

6th Floor South Bank House, Barrow Street, Dublin 4, Dublin, Ireland

Ireland (EU)

Generative AI / LLM inference (vision and text)

Intra-EU; third-country transfer possible at the level of Anthropic Subprocessors, insofar as applicable

AC PM LLC (Postmark)

1 N Dearborn Street, Suite 500, Chicago, IL 60602, USA

USA

Dispatch of transactional emails

DPF certification and/or DPA with EU Standard Contractual Clauses

Functional Software, Inc. (Sentry)

45 Fremont St, 8th Floor, San Francisco, CA 94105, USA

Germany (Sentry DE instance, ingest.de.sentry.io)

Monitoring, error analysis, error tracking

Intra-EU (processing in DE); supplementary EU SCC (Module 3) vis-à-vis US parent company; DPF certification

PostHog, Inc.

2261 Market Street #4008, San Francisco, CA 94114, USA

EU (eu.i.posthog.com)

Product analysis, feature flags, usage and cost analysis / cost tracking

EU processing; supplementary EU SCC (Module 3) vis-à-vis US parent company

Stripe Payments Europe Limited

1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland

Possible third-country nexus via the Stripe group

Payment processing

EU SCC (Module 3); DPF certification Stripe Inc., insofar as applicable

Google Ireland Limited (Google Maps / Geocoding)

Gordon House, Barrow Street, Dublin 4, Ireland

Ireland (EU); group links to USA possible

Map display, geocoding and location-based services for Oxolo

Intra-EU; supplementary EU SCC; DPF certification Google LLC

Google Play / Google Commerce Limited / Google Ireland Limited or Google LLC

Google Commerce Limited: Gordon House, Barrow Street, Dublin 4, Ireland

Ireland (EU); group links to USA possible

App distribution, in-app purchases; independent controller for payment and store transaction data, processor exclusively for receipt verification

Controller Terms / DPA and suitable safeguards, insofar as necessary; supplementary EU SCC; DPF certification Google LLC

Apple Distribution International Ltd. / Apple

Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, insofar as the EMEIA contract structure is applicable

Ireland (EU); group links to USA possible

App distribution, in-app purchases; independent controller for payment and store transaction data, processor exclusively for receipt verification

Intra-EU; Apple contract terms; supplementary EU SCC for any intra-group transfers, insofar as necessary

Meta Platforms Ireland Ltd. (WhatsApp Business / Cloud API)

Merrion Road, Dublin 4, D04 X2K5, Ireland; further processing by WhatsApp LLC, 1 Meta Way, Menlo Park, CA 94025, USA, as a Subprocessor of Meta Platforms Ireland Ltd.

Ireland (EU); group links to USA

WhatsApp companion channel for inbound/outbound communication, messaging and media handling, insofar as activated

Intra-EU; supplementary EU SCC; DPF certification Meta group and DPF certification for the onward transfer to the USA

AppsFlyer Germany GmbH

Schönhauser Allee 180

10119 Berlin

Germany

Germany

Mobile attribution, marketing and campaign analysis, install tracking, insofar as activated

Adequacy decision Israel; supplementary EU SCC

Twilio Inc. (or Twilio Ireland Limited, insofar as contracting party)

101 Spear Street, Fifth Floor, San Francisco, CA 94105, USA

USA

Authentication by means of one-time password (Twilio Verify) as well as dispatch of transactional SMS (Programmable Messaging); processes in particular Users' telephone numbers

EU SCC (Module 3); DPF certification Twilio Inc., insofar as applicable; Twilio DPA

Hyperdoc Inc. (Recall.ai)

2261 Market Street #4339, San Francisco, CA 94114, USA

EU (client region eu-central-1); group nexus USA

Meeting Bot for the recording and provision of external online meetings (including Zoom, Google Meet, Microsoft Teams) including audio, video, transcripts and participant details, insofar as activated

EU SCC (Module 3); DPF, insofar as certified; supplementary measures; see Section 2.8 of this DPA

650 Industries, Inc. (Expo)

624 University Ave, Palo Alto, CA 94301, USA

USA

Delivery of push notifications to registered devices; processes push tokens and notification content

EU SCC (Module 3); DPF, insofar as certified