Blog

Compliance Documents on Demand: DPA, TOMs and Sub-Processors

· Application Platform · 3 min read

ComplianceOrganisations
Compliance Documents on Demand: DPA, TOMs and Sub-Processors

The question comes up in almost every customer project: “Could you send us the data processing agreement and an overview of the services you use?” What follows is a search through old emails and a document from a previous project, with no certainty it is current.

Since 5 August there is a dedicated area for this, generating the paperwork from what is actually configured in your organisation.

What the compliance area contains

Four documents are available for every organisation, each in German and English:

On top of that there is a list of sub-processors — exactly the information customers need for their own record of processing activities.

You download each document as a PDF, or as a single ZIP export for a complete handover.

The documents are generated from your data

The difference: these documents are not static. In your organisation settings you enter the legal details — company name, address, contact person — and those flow automatically into the generated PDFs, so a contract never starts with a placeholder like “Company, Street, City.”

A project overview complements this: Firebase in one project, Sentry in another, Mailtrap in a third — all visible in the compliance area instead of collected separately.

The audit log complements the paperwork with evidence of who changed what and when. The audit log complements the paperwork with evidence of who changed what and when.
The audit log complements the paperwork with evidence of who changed what and when.

Where this helps day to day

Three situations come up regularly:

Customer onboarding. A new customer asks for data protection paperwork before signing. Instead of several rounds of questions, you send the ZIP export.

Audits and certifications. During an ISO 27001 review you are asked to evidence which providers are involved and which contracts exist. The sub-processor list covers exactly that.

Tenders. In the public sector and regulated industries, a DPA and TOMs are often part of the required documentation. Supplying them at short notice saves a round trip.

A note on scope

The platform provides documentation and describes what happens on its side, but it does not replace legal advice. Whether your use case needs additional measures — a data protection impact assessment for sensitive data, say — is a question for your legal counsel. What it automates is current documents, correctly filled in, in both languages, available whenever you need them.

Alongside operating in the EU

The compliance area complements a property the platform has had from the start: operation and data processing happen inside the EU, on servers you select yourself — often the condition under which projects with public-sector, healthcare or finance customers happen at all. More on this on the page about GDPR compliant hosting.

Compliance documents for your project

Create an organisation and see which documents the platform generates for you.

Back to blog