This English translation is provided for convenience only. In case of any discrepancies, the German version prevails.
Last updated: 20 August 2026
This data processing agreement (“DPA”, Art. 28 GDPR) is concluded between the customer as controller and Christian Gerloff, Kaupmanns Kamp 5, 33775 Versmold, Germany (“processor”, operator of Tiro). It becomes part of the usage contract upon registration (terms of use) and is concluded in electronic form (Art. 28(9) GDPR). Its substance is modelled on the European Commission’s standard contractual clauses for controller-processor agreements (Implementing Decision (EU) 2021/915).
1. Subject matter and roles
The customer uploads documents that may contain personal data of third parties. The customer is the controller for this data; Tiro processes it exclusively on the customer’s behalf to provide the service. Annex A describes the details of the processing.
2. Instructions
Tiro processes the data only on documented instructions from the customer. The instructions follow from the usage contract and from the operation of the service (e.g. uploading, reprocessing, exporting, retention settings, deleting). If Tiro considers an instruction to infringe data protection law, it informs the customer.
3. Confidentiality
Persons authorised to process the personal data have committed themselves to confidentiality. The operator is currently the only person with access; future employees will be bound accordingly before taking up their duties.
4. Security of processing
Tiro implements the technical and organisational measures set out in Annex B (Art. 32 GDPR) and adapts them to the state of the art; the level of protection must not be reduced in doing so.
5. Sub-processors
The customer approves the sub-processors listed in Annex C. Tiro informs the customer of intended changes at least 30 days in advance by email; if the customer objects for good cause relating to data protection, they may terminate the usage contract up to the time the change takes effect. A contract pursuant to Art. 28 GDPR with at least equivalent obligations is in place with every sub-processor.
6. Assistance to the customer
Tiro assists the customer in responding to requests from data subjects (Art. 12–23 GDPR) and with the obligations under Art. 32–36 GDPR, insofar as the information is held by Tiro. Requests from data subjects received directly by Tiro are forwarded to the customer without undue delay.
7. Notification of personal data breaches
Tiro notifies the customer of any personal data breach concerning the customer’s personal data without undue delay after becoming aware of it, to the account email address, and provides the information required for a notification under Art. 33 GDPR, insofar as available.
8. Deletion and return
Documents and results are deleted automatically according to the retention period configured by the customer; the customer can delete them or retrieve them as an export at any time. Upon termination of the usage contract, all personal data processed on the customer’s behalf is deleted unless a statutory retention obligation applies. Backups are overwritten within a further 7 days at the latest.
9. Demonstrating compliance
Tiro provides the customer with the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR (in particular this document, the description of the measures in Annex B and, on request, the contracts with sub-processors) and enables reasonable audits. On-site inspections require reasonable advance notice and must be limited to what is necessary.
10. Duration
This DPA applies for the duration of the usage contract.
Annex A — Description of the processing
Subject matter and nature: Storage of uploaded documents (PDF), automated extraction of structured data from them using AI models, provision of the results for viewing, as export (CSV/Excel) and via the API.
Purpose: Provision of the Tiro service for the customer.
Types of personal data:The data contained in the customer’s documents, typically business correspondence and invoice data (e.g. names, addresses, contact details, bank details, line-item and amount data).
Categories of data subjects: Business partners, contact persons, employees and customers of the customer, as well as other persons named in the documents.
Duration: According to the retention period configured per extractor, at most until the end of the usage contract (section 8).
Annex B — Technical and organisational measures
Processing exclusively in data centres in Germany or the EU (hosting: Germany; AI extraction: AWS region Frankfurt with an EU inference profile). Transport encryption (TLS) for all connections. Access control via passwordless account login with email codes; login codes, session tokens and API keys are stored only in hashed form. Server access only via SSH keys, firewall, services in containers without root privileges. Tenant separation at the application level (document-related objects are assigned to the account). Technical logs contain no document contents; access logs with IP addresses are deleted after at most 7 days. Daily backups with a 7-day rotation. Retention periods and deletion routines as described in the privacy policy.
Annex C — Approved sub-processors
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany — hosting (servers, database, document storage), email delivery; processing in Germany.
Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg — AI extraction via Amazon Bedrock, AWS region Frankfurt (EU inference profile); no training with customer data.