Data Processing Agreement
under Art. 28 GDPR for FilesPal Business
This agreement applies between the Business customer as controller (“Customer”) and Umbolement UG (haftungsbeschränkt), Ulmenweg 10, 85221 Dachau, Germany, as processor (“we”, “us”). It is part of every Business contract and takes effect with it; no signature is required. We will send you a countersigned copy on request: info@filespal.com.
1. Subject matter and duration
We process personal data on behalf of the Customer to the extent the Customer and its users use FilesPal in “Recommended” mode, and to manage the license. This agreement runs as long as the Business contract. In “Private” mode, the software processes everything on the Customer’s devices; we then receive no content.
2. Nature, purpose and scope of processing
- Answers and suggestions: users’ questions and the passages found; the recognized text of individual documents for name and filing suggestions.
- Search by meaning: the text of documents in selected folders, in sections, to calculate numeric vectors. Only the app stores the vectors, on the device.
- Voice input: short recordings and, to help recognition, the names of selected folders.
- License management: hashes of device IDs, activation time and last use per seat.
We process content from the first three items only transiently, to return the result to the app. We do not store or log it and do not use it for any other purpose, in particular not to train AI models.
Types of data: all personal data contained in the Customer’s documents, questions and recordings, such as names, contact, contract, invoice and employee data; depending on the documents, also special categories under Art. 9 GDPR. In addition, license and device data.
Data subjects: the Customer’s users and employees, and persons named in its documents, such as customers, suppliers, patients or clients.
3. Instructions
We process the data only on documented instructions from the Customer. Instructions are this agreement, the Business contract and the settings the Customer or its users choose in the software, for example “Private” mode set by Group Policy. The Customer gives further instructions in writing or by email. If we believe an instruction violates data protection law, we will point this out without delay. We will inform the Customer in advance of any legal obligation to process data (Art. 28(3)(a) GDPR), unless the law prohibits this.
4. Our obligations
- Everyone at our company with access to the data is bound to confidentiality.
- We take the technical and organizational measures in Annex 1 and adapt them to the state of the art without lowering the level of protection.
- We support the Customer with requests from data subjects and with its obligations under Art. 32 to 36 GDPR, for example a data protection impact assessment.
- We report personal data breaches without undue delay, if possible within 24 hours of becoming aware of them, with the information under Art. 33(3) GDPR as far as available.
- We keep a record of processing activities under Art. 30(2) GDPR.
5. Sub-processors
The Customer approves the sub-processors in Annex 2. We announce new or different sub-processors at least four weeks in advance by email to the address of the Business contract. The Customer may object within this period for an important data protection reason. If we cannot resolve the objection, the Customer may terminate the Business contract as of the date of the change; we refund amounts paid in advance pro rata. We impose the same data protection obligations on sub-processors as in this agreement.
If an AI provider fails or is overloaded, the service automatically switches to the next AI provider listed in Annex 2. This fallback processing is covered by the approval.
6. Processing outside the EU
We transfer data to a country outside the EU or the EEA only if the requirements of Art. 44 et seq. GDPR are met – for example through the EU-U.S. Data Privacy Framework or standard contractual clauses.
7. Evidence and audits
On request, we demonstrate compliance with this agreement with suitable documents. In addition, the Customer may carry out audits or have them carried out by an auditor bound to confidentiality, with reasonable notice, during normal business hours and without avoidable disruption of operations. The Customer reviews the data centers of our sub-processors through their certificates and reports.
8. Deletion and return
We do not store content from the AI service; there is nothing to return. We delete license and device data after the end of the Business contract unless the law requires us to keep it; the Customer may request information before that. In encrypted backups, deleted data is overwritten as the backups expire.
9. Liability and final provisions
Liability is governed by Art. 82 GDPR; otherwise, the liability provisions of the Terms of Service apply. In case of conflict, this agreement takes precedence over the Business contract in matters of data protection. Changes must be made in writing or by email. German law applies. If any provision is invalid, the rest of the agreement remains valid.
Annex 1: Technical and organizational measures (Art. 32 GDPR)
Confidentiality
- Physical access: server in the data center of Hetzner Online GmbH in Nuremberg (ISO/IEC 27001 certified) with access control, video surveillance and security staff.
- System access: administration only via encrypted SSH with keys; password login is disabled; the firewall only allows the necessary services.
- Data access: the service runs under its own system account without administrator rights; credentials for AI providers and the payment provider are stored only on the server, readable only by the administrator and the service, and never included in the app.
- Data minimization and pseudonymization: content from the AI service is neither stored nor logged. We store device IDs and license keys only as one-way hashes, and IP addresses only as a hash that changes daily and is deleted after two days. The web server keeps no access logs for the website and the service.
- Separation: the service, the database and the website run separately from other applications in their own directories and processes.
Integrity
- Transmission: all connections between the app, the server and AI providers are encrypted with TLS (HTTPS).
- Backups: encrypted with AES-256 before they leave the server.
- Input control: licenses are changed only by the payment provider (signed notifications whose signature is verified) and by the administrator.
Availability and resilience
- Nightly encrypted backup to a separate storage location in the EU, with regularly tested restores.
- Automatic restart of the services.
- Automatic switch to a second AI provider during outages.
- Protection against overload and misuse through a computing task at registration and limits per connection.
- In “Private” mode, the software also works without our service.
Review
- Security updates of the operating system are installed automatically.
- We review these measures at least once a year and after significant changes.
- Privacy-friendly defaults: IT can enforce “Private” mode by Group Policy.
Annex 2: Sub-processors
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany – operation of the server in the Nuremberg data center.
- Anthropic, PBC, San Francisco, USA, with Anthropic Ireland, Limited, Dublin, Ireland – AI for answers, suggestions and voice commands. No training with the data. Transfer to the USA possible on the basis of the EU-U.S. Data Privacy Framework and standard contractual clauses.
- OpenAI Ireland Ltd., Dublin, Ireland, with OpenAI, L.L.C., San Francisco, USA – search by meaning and speech output (read-aloud); backup AI for answers, suggestions, voice commands and voice input. No training with the data; deletion after 30 days at the latest. Transfer to the USA possible on the basis of the EU-U.S. Data Privacy Framework and standard contractual clauses.
- Mistral AI SAS, 15 rue des Halles, 75001 Paris, France – voice input; backup AI during outages for answers, suggestions and voice commands. No training with the data.
- Cloudflare, Inc., 101 Townsend St., San Francisco, USA – storage for the encrypted backups of license management, storage location in the EU. Cloudflare has no access to the key.
Last updated: October 9, 2026