KS CRM
Back to home
Back

Data Processing Agreement (DPA)

Agreement on the processing of personal data on behalf of the controller pursuant to Art. 28 GDPR · Version: 7 July 2026

This English translation is provided for convenience only. The legally binding version is the German version (Auftragsverarbeitungsvertrag). In the event of any discrepancy, the German version prevails.

This Data Processing Agreement forms part of the service contract for KS CRM pursuant to Section 17 of the Terms of Service and takes effect upon conclusion of the service contract. It is modelled on the European Commission's standard contractual clauses under Implementing Decision (EU) 2021/915 of 4 June 2021. On request, we provide the DPA for mutual signature: [email protected].

Section 1: Parties and Subject Matter

  1. This agreement is concluded between the customer of the KS CRM service (the "Controller") and

    Khan Solutions (sole proprietorship), Owner: Bilal Khan,
    Martin-Luther-Straße 30, 46284 Dorsten, Germany
    (the "Processor").
  2. The Processor provides the Controller with the SaaS solution KS CRM (the "Main Contract"). In performing the Main Contract, the Processor processes personal data for which the customer is the controller within the meaning of Art. 4(7) GDPR. This agreement specifies the parties' data protection obligations pursuant to Art. 28 GDPR.
  3. The subject matter, duration, nature and purpose of the processing, the type of personal data and the categories of data subjects are described in Annex 1.
  4. In the event of a conflict between this agreement and the Main Contract, this agreement prevails.

Section 2: Instructions

  1. The Processor processes the personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28(3)(a) GDPR).
  2. The Main Contract, this agreement and the Controller's use of the features of the service (including configuration and the active use of optional AI features) constitute documented instructions. Additional instructions must be sent in text form to [email protected].
  3. The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions. The Processor may suspend the execution of the instruction concerned until it is confirmed or amended.

Section 3: Confidentiality

The Processor ensures that the persons authorized to process the personal data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR). Access to personal data is limited to the persons who need it to perform the Main Contract.

Section 4: Security of Processing

  1. The Processor implements all technical and organizational measures required pursuant to Art. 32 GDPR. The measures implemented at the time the contract is concluded are described in Annex 2.
  2. The Processor may adapt the measures to the state of the art, provided the agreed level of protection is not reduced. Material changes are documented.

Section 5: Sub-processors

  1. The Controller grants a general authorization for the engagement of sub-processors (Art. 28(2) GDPR). The sub-processors engaged at the time the contract is concluded are listed in Annex 3.
  2. The Processor informs the Controller in text form at least four weeks before the intended addition or replacement of a sub-processor. The Controller may object on substantiated data protection grounds. If no amicable solution can be reached, either party may terminate the Main Contract with effect from the intended date of engagement.
  3. The Processor imposes on each sub-processor, by way of contract, the same data protection obligations as set out in this agreement (Art. 28(4) GDPR). Where the sub-processor fails to fulfil its obligations, the Processor remains fully liable to the Controller for the performance of the sub-processor's obligations.

Section 6: Transfers to Third Countries

  1. Processing takes place, as a rule, in data centers within the European Union (Germany).
  2. To the extent individual sub-processors process personal data in third countries (see Annex 3), transfers take place only where appropriate safeguards pursuant to Chapter V GDPR are in place — in particular on the basis of an adequacy decision (e.g. the EU-US Data Privacy Framework) or the European Commission's Standard Contractual Clauses under Implementing Decision (EU) 2021/914.

Section 7: Assistance to the Controller

  1. Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organizational measures in fulfilling the Controller's obligation to respond to requests by data subjects exercising their rights (Art. 12 to 22 GDPR) (Art. 28(3)(e) GDPR). If the Processor receives such a request directly, it forwards it to the Controller without undue delay.
  2. Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in ensuring compliance with the obligations under Art. 32 to 36 GDPR (security of processing, notification of personal data breaches, data protection impact assessments, prior consultation) (Art. 28(3)(f) GDPR).

Section 8: Notification of Personal Data Breaches

  1. The Processor notifies the Controller without undue delay after becoming aware of any personal data breach affecting the data processed on behalf of the Controller (Art. 33(2) GDPR).
  2. To the extent possible, the notification contains the information listed in Art. 33(3) GDPR (nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, measures taken and proposed). Information not yet available is provided subsequently without undue delay.
  3. Notification to the supervisory authority (Art. 33(1) GDPR) and communication to data subjects (Art. 34 GDPR) are the responsibility of the Controller.

Section 9: Evidence and Audits

  1. The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR (Art. 28(3)(h) GDPR).
  2. Compliance may be demonstrated by current attestations, certifications, audit reports by independent bodies or a meaningful self-assessment (including documentation of the measures under Annex 2).
  3. Where this is not sufficient, the Processor allows for and contributes to audits — including inspections — conducted by the Controller or an auditor mandated by the Controller. Audits take place after reasonable advance notice (generally at least two weeks), during usual business hours, no more than once per year (except for cause), and with due regard to confidentiality and the business secrets of the Processor and its other customers.

Section 10: Deletion and Return

  1. During the term of the Main Contract, the Controller may export its data at any time in a common, machine-readable format using the export functions provided.
  2. After termination of the Main Contract, the Processor keeps the export option available for 30 days. It then deletes all personal data processed on behalf of the Controller, including backup copies (after expiry of the backup rotation cycles described in Annex 2), unless Union or Member State law requires further storage (Art. 28(3)(g) GDPR). Deletion is confirmed in text form on request.

Section 11: Term and Final Provisions

  1. This agreement applies for the term of the Main Contract and beyond, for as long as the Processor processes personal data on behalf of the Controller.
  2. The parties' liability is governed by Art. 82 GDPR and the provisions of the Main Contract.
  3. The law of the Federal Republic of Germany applies. In all other respects, the final provisions of the Main Contract apply.

Annex 1 — Description of the Processing

Subject matter and duration

Provision of the SaaS CRM solution KS CRM (hosting, storage, display, analysis and processing of the data entered by the Controller) for the term of the Main Contract.

Nature and purpose of the processing

Storage, structuring, display, analysis (dashboards, reports), automation (workflows, notifications), optional AI-supported processing (assistant features) and data backup — in each case for the purpose of the Controller's customer relationship, sales and service management.

Categories of data subjects

  • Contacts, leads, customers and prospects of the Controller and their contact persons
  • Employees and other users of the Controller (user accounts)
  • Suppliers and business partners of the Controller, to the extent recorded in the CRM

Type of personal data

  • Master data (name, company, position)
  • Contact data (email address, phone number, postal address)
  • Contract and order data (quotes, orders, revenue, pipeline status)
  • Communication data (notes, email threads, tasks, appointments)
  • Usage data of user accounts (login data, log data)

Special categories of personal data (Art. 9 GDPR) are not part of the intended use. The Controller ensures that such data is entered only if the requirements of Art. 9(2) GDPR are met, and informs the Processor in advance.

Annex 2 — Technical and Organizational Measures (Art. 32 GDPR)

1. Confidentiality

  • Physical access control: operation in ISO 27001-certified data centers in Germany (physical access protection, video surveillance, access control systems operated by the data center provider).
  • System access control: authentication with individual credentials; passwords stored exclusively as salted hashes; administrative access only via encrypted connections with key-based/multi-factor authentication.
  • Data access control: role and permission model within the service; access to production data restricted to the owner and expressly authorized persons bound to confidentiality.
  • Separation control: tenant separation through a dedicated workspace with its own database and its own subdomain per customer.

2. Integrity

  • Transfer control: transport encryption of all connections via TLS (HTTPS).
  • Input control: logging of security-relevant events and administrative access.

3. Availability and resilience

  • Regular, automated backups with defined rotation cycles; backups stored within the EU.
  • Redundant infrastructure and monitoring (alerting) at the data center provider level.
  • DDoS protection and web application firewall (upstream CDN).
  • Regular security updates of the system components used.

4. Procedures for regular review, assessment and evaluation

  • Regular review of the technical and organizational measures and adaptation to the state of the art.
  • Selection of sub-processors based on data protection and security criteria; data processing agreements concluded with all sub-processors.
  • Documented process for handling personal data breaches (incident response).

Annex 3 — Sub-processors

Sub-processor Service Place of processing Safeguard for third-country transfers
netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany Hosting of the application and databases, email delivery (transactional emails) Germany (Nuremberg data center) — (no third-country transfer)
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA DNS, CDN, DDoS protection (processing of technical connection data) EU / USA EU-US Data Privacy Framework; EU Standard Contractual Clauses (Decision (EU) 2021/914)
Anthropic, PBC, 500 Howard Street, San Francisco, CA 94105, USA AI-supported features (only upon active use by the Controller; content not used for model training) USA EU-US Data Privacy Framework; EU Standard Contractual Clauses (Decision (EU) 2021/914)

The current version of this list is available at kscrm.de/en/avv.html. The Processor gives notice of changes in accordance with Section 5 (2) of this agreement.


© 2026 Khan Solutions — all rights reserved. · Legal Notice (Impressum) · Terms of Service · Privacy Policy