FilesPal

Data Processing Agreement

under Art. 28 GDPR for FilesPal Business

This agreement applies between the Business customer as controller (“Customer”) and Umbolement UG (haftungsbeschränkt), Ulmenweg 10, 85221 Dachau, Germany, as processor (“we”, “us”). It is part of every Business contract and takes effect with it; no signature is required. We will send you a countersigned copy on request: info@filespal.com.

1. Subject matter and duration

We process personal data on behalf of the Customer to the extent the Customer and its users use FilesPal in “Recommended” mode, and to manage the license. This agreement runs as long as the Business contract. In “Private” mode, the software processes everything on the Customer’s devices; we then receive no content.

2. Nature, purpose and scope of processing

We process content from the first three items only transiently, to return the result to the app. We do not store or log it and do not use it for any other purpose, in particular not to train AI models.

Types of data: all personal data contained in the Customer’s documents, questions and recordings, such as names, contact, contract, invoice and employee data; depending on the documents, also special categories under Art. 9 GDPR. In addition, license and device data.

Data subjects: the Customer’s users and employees, and persons named in its documents, such as customers, suppliers, patients or clients.

3. Instructions

We process the data only on documented instructions from the Customer. Instructions are this agreement, the Business contract and the settings the Customer or its users choose in the software, for example “Private” mode set by Group Policy. The Customer gives further instructions in writing or by email. If we believe an instruction violates data protection law, we will point this out without delay. We will inform the Customer in advance of any legal obligation to process data (Art. 28(3)(a) GDPR), unless the law prohibits this.

4. Our obligations

5. Sub-processors

The Customer approves the sub-processors in Annex 2. We announce new or different sub-processors at least four weeks in advance by email to the address of the Business contract. The Customer may object within this period for an important data protection reason. If we cannot resolve the objection, the Customer may terminate the Business contract as of the date of the change; we refund amounts paid in advance pro rata. We impose the same data protection obligations on sub-processors as in this agreement.

If an AI provider fails or is overloaded, the service automatically switches to the next AI provider listed in Annex 2. This fallback processing is covered by the approval.

6. Processing outside the EU

We transfer data to a country outside the EU or the EEA only if the requirements of Art. 44 et seq. GDPR are met – for example through the EU-U.S. Data Privacy Framework or standard contractual clauses.

7. Evidence and audits

On request, we demonstrate compliance with this agreement with suitable documents. In addition, the Customer may carry out audits or have them carried out by an auditor bound to confidentiality, with reasonable notice, during normal business hours and without avoidable disruption of operations. The Customer reviews the data centers of our sub-processors through their certificates and reports.

8. Deletion and return

We do not store content from the AI service; there is nothing to return. We delete license and device data after the end of the Business contract unless the law requires us to keep it; the Customer may request information before that. In encrypted backups, deleted data is overwritten as the backups expire.

9. Liability and final provisions

Liability is governed by Art. 82 GDPR; otherwise, the liability provisions of the Terms of Service apply. In case of conflict, this agreement takes precedence over the Business contract in matters of data protection. Changes must be made in writing or by email. German law applies. If any provision is invalid, the rest of the agreement remains valid.

Annex 1: Technical and organizational measures (Art. 32 GDPR)

Confidentiality

Integrity

Availability and resilience

Review

Annex 2: Sub-processors

Last updated: October 9, 2026

Your download is starting.

Ready in a minute.

  1. Open the file. FilesPal-Setup.exe appears in your browser’s downloads.
  2. If Windows shows a warning: choose “More info,” then “Run anyway.” This appears because FilesPal is new.
  3. You’re ready. FilesPal opens automatically and walks you through the first step.

Nothing happening? Download again