Data processing agreement (DPA)
Last updated: 8 October 2026
This is a courtesy translation. The German version is legally binding.
between the customer (the “Controller”) and Teamox – Philipp ten Eicken, Zur Hoppecke 22–26, 34508 Willingen (Upland), Germany (the “Processor”), together the “Parties”.
This agreement is concluded when an organisation is registered in Teamox and confirmed by the customer. It supplements the terms of service (main contract) and takes precedence over them in matters of data protection. The legally binding German version and a PDF are available at teamox.app/avv.
§ 1 Subject matter and duration
(1) The Processor provides the Controller with the software “Teamox” as a service for the collaborative handling of email mailboxes and messenger channels in Microsoft Teams. In doing so it processes personal data on behalf of the Controller. Subject matter, nature and purpose of the processing, type of data and categories of data subjects follow from annex 1.
(2) The duration of this agreement corresponds to the term of the main contract. The deletion obligations under § 9 apply beyond that.
§ 2 Instructions
(1) The Processor processes personal data exclusively within the agreements made and on documented instruction of the Controller, unless it is required to process by Union or member state law; in that case it informs the Controller of the legal requirement before processing, unless the law prohibits this.
(2) Instructions are generally given through the configuration of the service (release of mailboxes, set-up of users, activation of add-ons). Further instructions are to be sent in text form to datenschutz@teamox.app. The Processor informs the Controller without delay if it believes an instruction infringes data protection law; it may suspend execution until confirmation.
§ 3 Obligations of the Processor
(1) The Processor implements the technical and organisational measures described in annex 3 and keeps them at the state of the art. It may develop them further provided the level of protection is not reduced.
(2) It ensures that persons authorised to process are bound to confidentiality or subject to an appropriate statutory obligation of secrecy.
(3) It supports the Controller with appropriate technical and organisational measures in fulfilling data subject rights (Art. 12 to 22 GDPR) and in complying with the obligations under Art. 32 to 36 GDPR (security, breach notification, data protection impact assessment, consultation).
(4) It names a contact for data protection matters: Philipp ten Eicken, datenschutz@teamox.app.
(5) It provides the Controller with all information necessary to demonstrate compliance with Art. 28 GDPR and allows audits under § 7.
§ 4 Notification of personal data breaches
The Processor notifies the Controller of any personal data breach affecting the Controller’s data without undue delay, at the latest within 36 hours of becoming aware, by email to the stored administrator address. The notification contains, as far as known, the nature of the breach, affected data categories and persons, likely consequences and measures taken.
§ 5 Sub-processors
(1) The Controller approves the sub-processors listed in annex 2.
(2) The Processor informs the Controller of intended changes (addition or replacement) at least 30 days in advance by email to the administrator address and by updating the list at teamox.app/en/security. The Controller may object within 30 days for important data protection reasons. If no agreement is reached, either party may terminate the main contract as of the date of the change.
(3) The Processor imposes on sub-processors by contract the same data protection obligations as set out in this agreement and is liable for their fulfilment.
(4) Purely ancillary services without access to content data (e.g. telecommunications, maintenance without data access) do not constitute sub-processing.
§ 6 Processing in third countries
Processing takes place in the European Union (Microsoft Azure, region Germany). Transfers to third countries occur only as set out in annex 2 and only under the conditions of chapter V GDPR (adequacy decision, in particular the EU-US Data Privacy Framework, or standard contractual clauses). The AI features via OpenAI only become active once the Controller itself enters an API key; by doing so it also issues the instruction for this transfer.
§ 7 Audit rights
(1) The Controller may satisfy itself of compliance with the obligations before and during processing. For this purpose the Processor provides current evidence on request (description of measures, data centre certifications, reports of independent auditors, results of security tests).
(2) If this evidence is insufficient in an individual case, the Controller may, after coordination and with reasonable notice (at least 14 days), carry out an audit during normal business hours or have it carried out by a third party bound to confidentiality, at most once a year unless there is specific cause. The Processor may charge reasonable expenses.
§ 8 Liability
Art. 82 GDPR and the provisions of the main contract apply to liability. The parties indemnify each other to the extent a party proves that it is in no way responsible for the event giving rise to the damage.
§ 9 Deletion and return
(1) After termination of the main contract the Processor makes the Controller’s stored data (notes, assignments, history, settings) available for export in a common format for 30 days.
(2) After this period the Processor deletes all data of the Controller including copies, unless a statutory retention obligation applies. Backups are overwritten after their 30-day retention period. Deletion is confirmed in writing on request.
(3) The emails themselves remain at all times in the Controller’s Exchange Online mailbox and are not affected by this agreement.
§ 10 Final provisions
(1) Amendments and additions to this agreement require text form. (2) German law applies. Place of jurisdiction is Willingen (Upland), Germany. (3) Should individual provisions be invalid, the validity of the remaining provisions remains unaffected. (4) In case of discrepancies the German version prevails.
Annex 1: Subject matter of processing
| Subject matter and purpose | Provision of a shared inbox in Microsoft Teams: display and reply to emails from released Exchange Online mailboxes and WhatsApp Business channels, assignment, status tracking, internal notes, snooze, templates, reporting; optionally display of customer data from connected systems (add-ons). |
|---|---|
| Nature of processing | Retrieval, display, transient caching, transmission (sending replies), storage of collaboration metadata, deletion. |
| Categories of data subjects | Employees of the Controller (users), customers, prospects, suppliers and other communication partners of the Controller. |
| Type of data | User data (name, email, Microsoft object ID, job title); communication data (sender, recipient, subject, content, attachments of emails and messages); collaboration metadata (assignment, status, notes, history, labels, snooze); with activated add-ons: order, document, project and call data from Shopware, Lexware Office, HERO or Placetel. |
| Special categories | Not intended. If communication partners transmit such data it is treated like other content data. |
| Location of processing | Microsoft Azure, region Germany West Central (Frankfurt am Main). |
Annex 2: Approved sub-processors
| Company | Service | Location / third country |
|---|---|---|
| Microsoft Ireland Operations Ltd., One Microsoft Place, Dublin 18, Ireland | Hosting (Azure, region Germany West Central), Microsoft Graph (Exchange Online, Teams, Entra ID) | EU; Microsoft standard contractual clauses for any support access from third countries |
| Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland | Invoicing and payment processing (customer account data only, no content data) | EU |
| OpenAI Ireland Ltd., Dublin, Ireland (optional) | AI features; only if the customer enters its own API key; processing in the USA under the EU-US Data Privacy Framework or standard contractual clauses | USA, optional |
Annex 3: Technical and organisational measures
| Physical and system access control | Operation exclusively in Microsoft Azure data centres (ISO 27001, SOC 2). No physical access by the processor. Administrative access only via personal accounts with multi-factor authentication; access is logged. |
|---|---|
| Data access control | Role and tenant separation in the application (administrator, editor, observer; data per organisation in its own database). Mailbox access only within the Application Access Policy set by the customer. Credentials for third-party systems stored encrypted, never delivered to clients. |
| Transfer control | Encryption of all connections with TLS 1.2 or higher. No transfer of personal data on data carriers. No disclosure to third parties except the sub-processors named in annex 2. |
| Input control | Assignments, status changes, sending, deletions and notes are logged with user and time in the history of the respective conversation. |
| Availability control | Daily database backup with 30 days retention, encrypted in the same data centre; monthly restore rehearsal. Availability monitoring, notification on outage. |
| Separation control | Each customer organisation receives its own database and runtime environment within the service; mapping via the Entra tenant ID. Test and production systems are separated. |
| Data minimisation | Emails are not stored permanently but retrieved from Exchange Online on demand and cached only transiently. Only collaboration metadata is stored (assignment, status, notes, history, snooze). |
| Deletion concept | After the contract ends 30 days of export, then complete deletion of all data of the organisation including backups after their retention period. |