Skip to document
KKalman FAT SuiteIndustrial acceptance testing
← Company website
Terms of usePrivacy policyImprintData processing agreement

Data Processing Agreement

Article 28 GDPR · Version 2026-10-11 · Prepared 11 October 2026

This agreement requires separate confirmation. A personal account’s acceptance of the Terms does not sign a processing agreement for an unidentified employer, client or other controller.

Before uploading personal data on behalf of an organisation, email info@kalmancontrol.de with its legal name, address, authorised representative, privacy contact and intended processing. We must confirm the parties, processing details, applicable providers, transfer safeguards and security measures in writing or electronically. Until then, do not upload third-party organisational personal data. If it is already stored, contact us promptly.

1. Parties, conclusion and priority

The processor is Kalman Control UG (haftungsbeschränkt), Kastanienstr. 5, 47269 Duisburg, Germany, represented by Hamid Pedram (“Kalman Control”, “we”). The controller (“Customer”) is the legal person or individual identified in the separate confirmation, acting through its authorised representative. Both parties’ contact details and the effective date are recorded in that confirmation.

This text becomes binding when both parties expressly agree to it in writing or electronically and complete the processing schedule below. The confirmation may incorporate this published version by reference and must be retained with it. It supplements the service agreement and takes priority over conflicting terms about the processing of Customer-controlled personal data. It does not change mandatory law or replace a transfer agreement required by Chapter V GDPR.

If the Customer is itself a processor, it must have authority from its controller to appoint us as subprocessor and pass on lawful instructions. Our own processing of account administration, security and compliance information as controller is described in the Privacy Policy and is outside this processor agreement.

2. Subject, purpose and duration

We process Customer-controlled personal data only to provide the agreed Kalman FAT Suite functions: receiving and storing project records and files, organising tests, synchronising authorised changes, managing collaborators and permissions, presenting information to authorised people, generating requested exports/reports, and providing necessary technical operation and support.

Processing lasts for the relevant service agreement and any authorised export, deletion or lawful residual retention. The kinds of data, people concerned, permitted operations and additional requirements are identified in Annex 1. The Customer must not use the service for materially different or more sensitive processing without a separately agreed amendment.

3. Instructions and purpose limitation

We process personal data only on the Customer’s documented instructions, including for transfers outside the EEA, unless EU or Member State law binding on us requires otherwise. In that case, we inform the Customer before processing unless that law prohibits notice for important public-interest reasons.

The service agreement, this agreement, the completed schedule and the Customer’s authorised use of settings and features constitute the initial instructions. Additional instructions may be sent by an authorised contact in text form. We promptly inform the Customer if, in our opinion, an instruction infringes the GDPR or other applicable EU or Member State data-protection law, and may suspend the affected instruction until the matter is resolved.

We do not sell Customer personal data, use it for advertising, disclose it to unrelated customers, or train AI models on it. Providing the service can require access by authorised personnel and agreed providers; this does not grant them permission for their own unrelated purposes.

4. Customer responsibilities

The Customer determines the purposes and lawful bases for its processing, provides required notices, obtains permissions or consents where needed, ensures the accuracy and minimisation of uploaded information, and issues lawful instructions. It manages collaborator permissions, retention periods and the use of downloaded information. These responsibilities do not release us from our processor obligations.

The Customer must notify us of relevant risks and requirements before upload. The default scope excludes special-category personal data under Article 9 GDPR, criminal-offence data under Article 10, credentials/private keys and data requiring safeguards the parties have not agreed. Inclusion requires a documented lawful basis, risk assessment and agreed measures. The service is not a records archive or a qualified electronic-signature service unless separately agreed.

5. Confidentiality and security

We ensure that persons authorised to process Customer personal data are subject to appropriate confidentiality obligations and have access only where needed for their work. We implement and maintain appropriate technical and organisational measures under Article 32 GDPR, taking account of the processing risks, current technology, cost and nature of the agreed service. The measures are described in Annex 2 and any confirmed additions.

We may improve measures without reducing the agreed level of protection. We notify the Customer of material changes relevant to its risk assessment. An assurance of absolute security or uninterrupted availability is not given; this does not reduce the duty to take appropriate measures.

6. Subprocessors and transfers

The Customer authorises only the subprocessors listed in the completed Annex 3 and any additions approved through this procedure. Before appointing or replacing a subprocessor, we provide at least 30 days’ written notice describing its identity, purpose, processing location and relevant safeguards, so the Customer has a genuine opportunity to object on reasonable data-protection grounds.

Where an objection is raised before the change, we work with the Customer to find a lawful alternative or resolve the concern. If no appropriate solution is available, the affected processing must not proceed for that Customer and either party may end the affected service without a penalty for the objection, subject to lawful export and deletion arrangements. Urgent action required by law or to address a concrete security incident is notified as soon as possible with an explanation and an opportunity to review the replacement.

We bind subprocessors to written obligations offering the protection required by Article 28 GDPR and remain responsible to the Customer for their performance of those obligations. Provider downstream subprocessors and their change-notification processes must be reviewed and included in the agreed authorisation. A public provider list alone does not evidence that the Customer’s agreement or required provider safeguards have been completed.

Transfers to countries outside the EEA may take place only on documented instructions and with a valid Chapter V GDPR mechanism. Depending on the actual transfer, this may be an applicable adequacy decision or the correct European Commission Standard Contractual Clauses, supported by the required assessment and supplementary measures. The completed Annex 3 identifies the applicable mechanism. We do not promise exclusive EU processing: the database region is Ireland, while application hosting is configured in US East and provider support can be international.

7. Assistance and requests from individuals

Taking account of the nature of processing and the information available, we assist the Customer through appropriate measures in responding to access, rectification, erasure, restriction, portability and other data-subject requests. We notify the Customer promptly of a request concerning Customer-controlled data and do not independently respond except on instructions or where legally required.

We assist the Customer with its obligations under Articles 32–36 GDPR, including relevant security information, breach assessment, notifications, data-protection impact assessments and consultation with a supervisory authority. Any exceptional assistance charges require a separate reasonable agreement; charges must not obstruct mandatory duties or remedying our own breach.

8. Personal-data breaches

We notify the Customer without undue delay after becoming aware of a personal-data breach affecting its data. We provide information available about the nature of the breach, affected people and records, likely consequences, contact point, and measures taken or proposed to contain and mitigate it. Where complete information is not immediately available, we provide it in stages without undue further delay.

We document the incident, take appropriate steps to contain and investigate it, preserve necessary evidence and assist with the Customer’s legal notifications. The Customer remains responsible for deciding its notification obligations as controller. We must not delay our notice until a complete investigation or a finding of liability.

9. Information, audits and cooperation

We make available the information necessary to demonstrate compliance with this agreement and Article 28 GDPR and allow and contribute to audits, including inspections, conducted by the Customer or a qualified auditor it appoints. The parties arrange reasonable notice, scope and confidentiality safeguards that protect other customers and service security, without removing the Customer’s statutory audit rights.

Current relevant independent reports may be used first where they answer the audit questions. A concrete incident, material compliance concern or competent authority’s requirement may justify further or urgent verification. We cooperate with competent supervisory authorities and notify the Customer of relevant proceedings or binding demands where legally permitted.

10. Return, deletion and termination

At the Customer’s choice, we return or delete its personal data after the end of the processing service and delete existing copies unless EU or Member State law requires retention. The parties agree the export format and completion timetable in the confirmation; available project workbook, report and file exports can be used where suitable. The Customer can also instruct deletion during the service where it has the necessary authority.

Residual provider backup copies may remain only for the documented applicable cycle, isolated from normal processing and subject to confidentiality and security, then be overwritten or deleted. If restoration occurs, the relevant deletion instructions must be reapplied. Any legally required retention is limited to the required data, purpose and period and must be explained where lawful. We provide confirmation of completed deletion on request.

Confidentiality, security and applicable assistance duties continue while we or our subprocessors retain the Customer’s personal data. The Terms of use do not exclude mandatory data-protection liability or rights of affected individuals.

Annex 1 — Processing schedule

The following default description must be confirmed or narrowed for the Customer. Its identity, contacts, any additional processing and termination arrangements must be recorded before the agreement takes effect.

Customer and controller contact
Full legal name, service address, authorised representative, privacy contact and any controller on whose behalf the Customer acts: supplied and confirmed separately.
Processor contact
Kalman Control UG (haftungsbeschränkt), Kastanienstr. 5, 47269 Duisburg, Germany; info@kalmancontrol.de.
People concerned
Authorised project users, employees, contractors, testers, witnesses, customer/supplier contacts and people whose information is lawfully included in agreed project records.
Data categories
Names and business contact details, project roles, test contributions, comments, audit timestamps, authorised invitations, and ordinary personal information included in project photos or documents. Special-category and criminal-offence data are excluded unless separately agreed.
Operations and purpose
Collection on upload, recording, storage, organisation, retrieval, display within permissions, modification, synchronisation, export/report generation, authorised support access and deletion, for industrial test and project documentation.
Duration and frequency
Continuous or user-triggered processing for the agreed service term and authorised closure period. Start date, export/deletion choice and timetable: confirmed separately.
Authorised instructions and contacts
The Customer identifies authorised contacts, project owners and permission managers and notifies changes promptly.

Annex 2 — Technical and organisational measures

Before conclusion, the parties confirm that these measures and any necessary additions are suitable for the intended data and risks. Provider documents complement the application controls; they must be reviewed with the actual configuration.

  • Transport and authentication: HTTPS for website and API access; individual authenticated accounts; provider-managed authentication and recovery; privileged credentials kept outside public client code.
  • Project access: project ownership, member roles and phase permissions; database access policies and server-side checks for applicable operations; permission changes and relevant project actions recorded for accountability.
  • Operational confidentiality: restricted administrator and provider access, confidentiality obligations, authorised support instructions and review of privileged access.
  • Separation and minimisation: restrictions between customer projects; collection limited to requested functions; optional behavioural analytics disabled; personal data omitted from unnecessary technical metrics.
  • Availability and recovery: agreed provider backup configuration and restore/deletion procedures documented for the Customer; independent customer exports remain necessary. No particular recovery-point or restoration-time commitment exists without separate agreement.
  • Device copies: local offline drafts may contain full project data and file contents. They have account-scoped application access but no application-level encryption at rest. The Customer must use suitable devices, protect local operating-system access and manage local deletion and archives.
  • Organisational controls: documented incident contacts and response procedures, handling of rights and deletion requests, provider and transfer assessments, necessary staff access controls and periodic review of measures.

Any requirements for dedicated encryption, additional identity verification, regulated data, specific retention deadlines or certified archival integrity require separate confirmation before processing.

Annex 3 — Provider and transfer confirmation

These providers are used by the current service. They must be included in the confirmed subprocessor authorisation together with the applicable contractual entity, agreement, downstream processors, actual access locations, transfer mechanism and backup/log retention. This page alone does not certify completion of those checks.

ProviderService and known locationProvider information to review
SupabaseAuthentication and project database. Database region: Ireland (eu-west-1). Provider entity/support and downstream processing can be outside the EEA.Processing addendum; subprocessor list.
VercelWebsite delivery and application hosting. Application deployment: US East (iad1). Delivery and provider operations can use other locations.Processing addendum; subprocessor list.
Configured transactional email deliveryAccount confirmation and password recovery through the authentication service. Applicable provider, location and downstream processing must be identified in the confirmation.The current mail configuration and delivery safeguards are supplied for the completed schedule.

To conclude this agreement or request its completed schedules, contact info@kalmancontrol.de. Retain the confirmation and this exact version together.

You can save or print these documents using your browser’s Print function, including Save as PDF.

Kalman FAT Suite

By Kalman Control UG (haftungsbeschränkt)

User manualCompany websiteTerms of usePrivacy policyImprintData processing agreementContact
© 2026 Kalman Control UG (haftungsbeschränkt) · Kastanienstr. 5, 47269 Duisburg, Germany. Customer content belongs to its rights holders.