← Back To sign-in
de en fr es 中文

Data processing agreement

pursuant to Art. 28 GDPR

This is a non-binding English translation. In case of doubt, the German version prevails.

§ 1 Preamble

The General Data Protection Regulation (“GDPR”) obliges you as the client (“controller”) to conclude an agreement with every contractor (“processor”) that processes personal data on your behalf.

The statutory rights and obligations of the controller and the processor must be explicitly stated in an agreement pursuant to the GDPR (subject matter and purpose, duration and place of processing, nature and categories of personal data, confidentiality, security measures, deletion, audit rights).

In order to meet these requirements, this agreement is concluded — in addition to the effective usage contract between CHAOS GmbH (processor within the meaning of the GDPR) — hereinafter CHAOS — and the party entitled to use CHAOS’s services (controller within the meaning of the GDPR) — hereinafter User — as an integral part of the usage contract.

In the following, the term

  • A. “Products” means any software that the User has already acquired from CHAOS, will acquire in the future or uses, in each case within the scope of the licences acquired.
  • B. “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).

When using CHAOS’s products, data of the User may where necessary become visible (e.g. in connection with the Azure AD app registration, dashboard usage, reseller/Xvantage integration) and/or be transmitted to CHAOS. The processing of this data is a processing commissioned by the User and carried out by CHAOS (processing on behalf).

CHAOS GmbH is the software manufacturer and operator of the platform. A sales partner (reseller) is not a sub-processor for the Microsoft Graph analysis of employee data insofar as it only provides sales and onboarding and does not obtain access to the analysis data.

Retrieval from the Microsoft 365 tenant via Microsoft Graph and the administrator consent for the app are subject to the User’s contract with Microsoft (Microsoft Customer Agreement or Microsoft Online Services Data Protection Addendum). Subsequent storage and analysis at CHAOS are subject to this data processing agreement.

CHAOS is entitled to adapt these supplementary terms for processing on behalf to changed legal or business conditions (e.g. changes to data protection standards, changes to the range of services offered). Such changes are to be announced to the User in writing, i.e. by letter or e-mail, and are deemed accepted unless the User objects within 4 weeks of the announcement.

§ 2 Subject matter and purpose of the processing

  1. The subject matter of the processing is exclusively that data which is necessary or expedient for the fulfilment of the respective processing order (e.g. evaluation of user data for Microsoft 365 licence optimisation). Apart from this data, no further data is processed.
  2. CHAOS processes personal data only on the documented instructions of the User. The User agrees that the usage contract, together with the product documentation and the User’s use and configuration of the product features, constitutes the complete and documented instructions of the User to CHAOS regarding the processing of personal data or the documentation of the User’s use of the products. Product documentation and configuration of the product features form, as an annex, an integral part of this contract.
  3. Additional or different instructions of the User require agreement in accordance with the procedure for amending the usage contract.

§ 3 Duration of the processing

In an individual case of processing, the processing generally ends upon fulfilment of the respective individual order. If data is transferred to CHAOS, the retention period for this data is defined already upon receipt of the data. The retention period is one month by default and can be extended to a maximum of one year.

§ 4 Place of processing

CHAOS GmbH (formerly DRG Services GmbH, renamed August 2026, same legal entity) operates the SaaS platform on Microsoft Azure in the region West Europe (EU). The registered office and administration of CHAOS GmbH are in Austria. If the User is domiciled outside Austria, the processing also extends geographically to the User’s country of domicile, whereby only states within the EU/EEA are eligible, plus the infrastructure operated by Microsoft Azure in the EU.

§ 5 Nature of the processing

In CHAOS’s IT environment, transferred data is integrated into an in-house developed system. A retention period is defined in the process. Access to the integrated data is only possible after prior authentication and is logged.

Further details are set out in § 10 “Measures for secure processing”.

§ 6 Nature of the personal data

The processing covers personal data (master data) of users, user master data and assigned licences, activity and usage data (including SharePoint/OneDrive usage and storage metadata, no site contents) and — depending on the chosen setup mode — security-posture metadata (Secure Score, Identity Protection, Conditional Access). Write operations for licence changes occur only in full mode, not with -Readonly or -LeastPrivilege.

AI & Copilot (optional, only if the module is enabled): Microsoft 365 Copilot usage and licence data, Copilot audit events (counts, no contents), security alerts and sensitivity-label definitions, Copilot Studio agent inventory and Copilot credit consumption (Power Platform/Dataverse), Azure AI costs and metrics. If the permission AiEnterpriseInteraction.Read.All is granted, CHAOS reads the Copilot interaction history; prompt and response texts are only classified transiently in memory and are neither stored nor logged – only metrics (e.g. number of prompts, repeated questions, unanswered prompts, fallback answers) are stored per day, app, agent and person. If works council mode is active, this analysis only takes place after category K6 has been released.

§ 7 Categories of data subjects

Categories of data subjects (from the User’s perspective) are employees or third parties commissioned by the User and their employees.

§ 8 Mutual rights and obligations of the contracting parties

  1. CHAOS may process personal data exclusively on the documented instructions of the User, unless it is obliged to process it under Union law or the law of the Member States.
  2. CHAOS informs the controller without undue delay if it is of the opinion that an instruction of the User infringes the GDPR or other data protection provisions of the Union or the Member States.
  3. As far as possible, CHAOS supports the User with appropriate technical and organisational measures in fulfilling its obligation to respond to requests for exercising the data subjects’ rights set out in Chapter III GDPR (rights to information, rectification, erasure, restriction of processing, data portability, objection and protection against automated decision-making). If a data subject should submit a request to CHAOS, CHAOS forwards the request to the User.
  4. Taking into account the nature of the processing and the information available to it, CHAOS supports the User in complying with the obligations set out in Articles 32 to 36 GDPR (security of processing, notification of data breaches, data protection impact assessment). Insofar as this exceeds the obligations under the usage contract, CHAOS may charge the associated expenses on the basis of the hourly rate calculated by CHAOS for IT services.
  5. Upon the User’s request, CHAOS makes available all information necessary to demonstrate the obligations laid down in Article 28 GDPR (“processing on behalf”). Upon request, CHAOS also allows for and contributes to audits — including inspections — conducted by the User or an auditor mandated by the User. Expenses arising in this context are charged by CHAOS on the basis of the hourly rate CHAOS charges for IT services. The User is obliged to check at regular intervals whether CHAOS guarantees an appropriate level of data protection through suitable technical or organisational measures.
  6. CHAOS undertakes to appoint a data protection officer where the conditions under Article 27 GDPR are met.
  7. CHAOS is obliged to treat confidentially the personal data and information disclosed, transmitted or otherwise made available to it. Likewise, the knowledge gained of the processing results is covered by this confidentiality obligation.

§ 9 Obligation of confidentiality

  1. All persons attributable to CHAOS (in particular employees) who are involved in the processing of personal data are contractually obliged to maintain secrecy and confidentiality of the data that has become or will become known to them in the course of their work, and to process this data fairly and in good faith. The confidentiality and secrecy obligation continues to apply even after the end of the activity for CHAOS.
  2. In addition, all persons commissioned by CHAOS with the processing of personal data are obliged to transmit this data only on the basis of instructions. Furthermore, these persons have been (and newly joining persons will be) informed about the transmission requirements applicable to them and about the consequences of a breach of data secrecy.

§ 10 Measures for secure processing

  1. CHAOS has taken very extensive technical and organisational measures to ensure security during processing. These include, among others:
    • Physical access control: Control of access to the company’s premises, among other things through suitable key management, security doors and alarm systems with mandatory code entry;
    • System access control: Control of access to data processing systems, among other things through passwords, fingerprint scan and Virtual Private Network (VPN);
    • Data access control: Control of access to data within the system through an authorisation system including logging of access;
    • Data protection: Safeguards to prevent the destruction or loss of personal data through modern backup and update concepts, firewalls and antivirus software;
    • Separation: Separation of data processing through separate storage and separate access protection (user separation);
    • Transfer control: No unauthorised reading, copying, altering or removal during electronic transmission;
    • Input control: All inputs are logged in a traceable manner on the basis of a documentation policy;
    • Availability/recoverability: Recovery, e.g. due to technical faults, lost or destroyed data, is possible within the shortest time on the basis of corresponding recovery concepts;
    • Deletion periods: Deletion periods must be defined for every data transfer. Deletion is carried out automatically after the period expires;
    • Data protection management system: The existing data protection system is continuously evaluated and adapted;
    • Order control: No processing takes place without documented instruction from the User.

§ 11 Compliance with the GDPR by CHAOS

  1. CHAOS has implemented all necessary technical and organisational measures to ensure security pursuant to Art. 32 GDPR and adapts them to technological change and new findings in the sense of a self-learning data protection management system.
  2. CHAOS has created a record of processing activities pursuant to Art. 30 GDPR and keeps it up to date at all times. This record also covers all processing activities under the present agreement.

§ 12 Sub-processing and processing on the basis of legal provisions

  1. CHAOS engages Microsoft Azure (region West Europe) as a sub-processor for hosting and database. Further sub-processors are notified to the User in sufficient time for the User to object. Third parties commissioned by the User (e.g. IT support providers) are involved only insofar as the User so wishes.
  2. CHAOS is entitled to engage sub-processors where this serves to optimise processes, in particular in connection with technological progress. The User is to be notified of such engagement in sufficient time to be able to object to it if necessary. CHAOS concludes the necessary agreements within the meaning of Art. 28(4) GDPR with the sub-processor. It must be ensured that the sub-processor enters into the same obligations to which CHAOS is subject under this agreement. If the sub-processor fails to fulfil its data protection obligations, CHAOS is liable to the User for the sub-processor’s compliance with its obligations.

§ 13 Deletion after termination of the contract

  1. Insofar as personal data is still stored at CHAOS after termination of the contract and provided there is no legal obligation for further retention or processing, it is deleted immediately. If the User so wishes, all data transmitted to CHAOS and still stored can also be returned.
  2. If the User sends e-mails or support requests to CHAOS, these must not contain any personal data. This is because such data is stored permanently as part of the internal support documentation. Where necessary, personal data should be redacted. Upon the User’s request, CHAOS deletes the complete support documentation concerning the User, provided that the User signs an indemnification agreement in favour of CHAOS in which it undertakes to hold CHAOS harmless in every respect.

§ 14 DORA (financial and insurance undertakings only)

Where the User is a financial entity or insurance undertaking within the meaning of Regulation (EU) 2022/2554 (DORA), or DORA otherwise applies to the User, the DORA addendum applies in addition and is accepted by confirming the AGB, the privacy policy and this DPA — no separate signature is required. For other users, the DORA addendum does not apply.

Annex: System description

Technical and organisational details result from the product documentation and the agreed configuration, including the setup modes full version, -Readonly and -LeastPrivilege and the optional switch -CopilotIntelligence (see privacy notice sections 3.5 and 4).

To the privacy policy, the DORA addendum and the cookie notice.