Data Processing Agreement for CertMap for Organizations
As of: 2026-09-14Version 0.7
1. Parties
Controller is the company or institution for which an organization is created in CertMap. The person creating the organization confirms that they are entitled to act for the controller and that the use is for business purposes. The organization's name, country and the contact address given at creation are stored together with the acceptance of this agreement.
Processor is Threat-Informed Cybersecurity Solutions GmbH, Ober-Saulheimer Str. 15, 55291 Saulheim, Germany (Amtsgericht Mainz, HRB 53346), represented by its managing director Daniel Thomas Heessel, e-mail kontakt@certmap.de, as operator of CertMap.
2. Subject matter and duration
2.1 The subject matter is the processing of the controller's personal data in providing and using "CertMap for Organizations" as software as a service. The processing activities are listed in Annex 1.
2.2 The agreement is concluded when the organization is created and applies as long as the organization exists in CertMap. It ends with the deletion of the organization.
2.3 Every newly created organization starts with a 14-day trial with full functionality for up to 15 people. Afterwards the organization is in read-only access for 30 days: all data remains visible, a complete data copy can be downloaded at any time, changes and reports are no longer possible. If no plan is chosen during this time, the organization's data is deleted completely after the read-only period ends (section 11). Choosing a plan ends the trial or the read-only period immediately.
2.4 For organizations on a plan the agreement applies until the cancellation of the plan takes effect. Afterwards the organization is in read-only access for 90 days; deletion then follows according to section 11.
3. Nature and purpose of processing
3.1 The purpose is to provide the functions of CertMap for Organizations, in particular:
- managing employees as linked accounts or as entries recorded by the employer without their own account
- defining roles with required certifications and comparing target and actual state
- recording and displaying certifications, validity periods and evidence
- cost and training overviews
- evidence for standards and roles as reports and exports
- CSV import of employee data
- inviting employees to link their personal CertMap account
3.2 Nature of processing: collecting, recording, organizing, storing, adapting, retrieving, consulting, using, aligning, combining, restricting, erasing.
4. Types of personal data
Depending on the controller's configuration:
- identification data of employees (name, e-mail address where applicable)
- role and function assignments
- certification data (certification, validity, evidence numbers, notes)
- training and cost data where recorded
- identifiers of administrators (account, e-mail, timestamps of actions)
- log entries of administrative actions (audit log)
5. Categories of data subjects
- employees of the controller (with a linked account or as a recorded entry)
- administrators of the controller
6. Rights and obligations of the controller
6.1 The controller is the controller within the meaning of Art. 4 No. 7 GDPR for the processing activities listed in Annex 1.
6.2 The controller ensures that a legal basis exists for processing its employees' data and confirms this when creating the organization.
6.3 The controller issues its instructions through the configuration options of the application. Written special instructions are possible; the processor confirms them in text form.
6.4 The controller informs its employees about the processing in accordance with Art. 13 and 14 GDPR.
7. Obligations of the processor
7.1 The processor processes data only within the scope of this agreement and on documented instructions of the controller.
7.2 The processor informs the controller without delay if it considers an instruction to infringe data protection law.
7.3 The processor is bound to confidentiality and binds every person involved in the processing accordingly. At present this is solely the managing director; there are no further employees.
7.4 The processor implements the technical and organizational measures set out in Annex 2.
7.5 The processor supports the controller in fulfilling data subject rights (Art. 15 to 22 GDPR):
- Access: the organization's stored data can be downloaded at any time as a complete, machine-readable data copy.
- Rectification: directly in the application by the controller.
- Erasure: deletion of individual entries by the controller; deletion of the whole organization according to section 11.
- Restriction and objection: the processor implements corresponding instructions of the controller.
7.6 The processor supports the controller in complying with Art. 32 to 36 GDPR.
7.7 The processor provides the controller with the information necessary to demonstrate compliance with the obligations under Art. 28(3) GDPR.
8. Technical and organizational measures
The measures in Annex 2 apply. The processor adapts the level of protection to the state of the art and informs the controller of material changes.
9. Sub-processors
9.1 The controller authorizes the sub-processors listed in Annex 3.
9.2 When replacing or adding a sub-processor, the processor informs the controller at least 30 days in advance in text form. The controller may object within 14 days; in case of a justified objection it may terminate the agreement extraordinarily.
9.3 The processor binds every sub-processor contractually to a comparable level of protection.
10. Notification of personal data breaches
10.1 The processor notifies a personal data breach that has come to its knowledge without undue delay in text form to the controller's administrators.
10.2 The notification contains the nature of the breach, the categories and approximate number of data subjects and records concerned, the contact point, the likely consequences and the measures taken or proposed.
10.3 The controller's duty to notify the supervisory authority under Art. 33 GDPR remains unaffected.
11. Deletion and return
11.1 The controller can download its organization's data at any time, including during read-only access, as a complete, machine-readable data copy. This fulfils the return of data under Art. 28(3)(g) GDPR.
11.2 Organizations that never chose a plan are deleted without undue delay and completely once 44 days have passed since creation (end of read-only access): members, roles, projects, evidence, reports and the organization's audit log. Seven days before deletion the administrators are informed by e-mail; deletion takes place at the stated time regardless of whether this e-mail could be delivered. Deletion is final. Restoring deleted data is excluded; the controller secures the data it wants to keep beforehand via the data copy under section 11.1. The personal CertMap accounts of employees are not affected by the deletion; they belong to the employees, not to the organization.
11.3 Organizations on a plan are deleted without undue delay and completely once 90 days have passed since the cancellation took effect (end of read-only access); section 11.2 sentences 2 to 4 apply accordingly. Where statutory retention obligations exist, the affected entries are retained only as long and only to the extent required by law.
11.4 Backup copies are overwritten by the processor's regular backup rotation and are not retained separately.
11.5 A record of the deletion is kept that no longer contains personal data (time, number of recorded people, trigger of the deletion). The processor provides it to the controller on request.
12. Final provisions
12.1 German law applies.
12.2 Should individual provisions be or become invalid, the validity of the remaining provisions remains unaffected.
12.3 Changes to this agreement are published as a new version. The version accepted by the controller is stored per organization and shown in the settings. In case of conflict between the terms of service and this agreement, this agreement prevails for the processing of personal data.
Annexes
The annexes are part of this document. Expand to read; each annex is also available as a PDF download.
Annex 1: Processing activities
| Processing | Data categories | Data subjects | Retention |
|---|---|---|---|
| Recorded employees without an account | name, role, certifications, validity, notes | employees of the controller | until deleted by the controller or deletion of the organization |
| Linked accounts | link, certifications released by the employee | employees with a CertMap account | until the release is revoked, the link ends or the organization is deleted |
| Roles and requirements | role name, required certifications, levels | not directly personal | until deleted by the controller or deletion of the organization |
| CSV import | imported employee data | employees | as recorded employees |
| Reports and data copy | compilations of the data above | employees, administrators | not stored; generation is logged |
| Audit log | action, acting person, affected entry, time | administrators, employees | until deletion of the organization; anonymized when an employee account is deleted |
| Deadline e-mails | administrators' e-mail addresses, delivery status | administrators | until deletion of the organization |
Annex 2: Technical and organizational measures
The processor's TOM document in its current version applies. For CertMap for Organizations the following apply in addition:
- Tenant separation: every database access runs in an organization context; the database additionally enforces separation via row-level rights. Every interface checks the acting person's authorization for exactly this organization.
- Access: login with one-time code by e-mail, session cookies only over encrypted connections, time-limited sessions.
- Release principle: the controller sees from linked accounts only the certifications the employees have explicitly released. A release can be revoked at any time, including while the organization is in read-only access.
- Input control: validation of all inputs against fixed schemas; limits on imports by size and scope; immutable audit log.
- Logs: application logs contain no real names or e-mail addresses; IP addresses are pseudonymized.
- Deletion: deadline-driven lifecycle with notice e-mails and complete deletion according to section 11; deletion record without personal data on request; backups with limited, rotating retention.
- Encryption: transport encryption for all connections.
- Review: regular security reviews focusing on tenant separation.
Annex 3: Sub-processors
| Sub-processor | Location | Processing | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Germany | hosting of the platform and the database | data processing agreement, processing in the EU |
| Microsoft Ireland Operations Ltd. (Microsoft 365) | Ireland, data centers in the EU | sending e-mails (invitations, deadline notices) | data processing agreement, EU data residency, standard contractual clauses for sub-processors outside the EU |
| Plausible Insights OÜ | Estonia | anonymous, cookie-free reach measurement | processing in the EU, no personal data |
No payment provider is currently involved; plans are agreed directly with the processor. If a payment provider is added, section 9.2 applies.