Data processing / DPA
Last updated: 7 October 2026
Local operation without processing on your behalf
No data processing agreement with Daniel Schlager is required solely for supplying Kivanto Solo or the self-managed Server edition if we do not process personal data on your behalf. Your installation processes the work content you connect on your computer or infrastructure you operate.
The service actually agreed and performed is decisive. The location of a server alone does not determine whether processing on behalf of a customer takes place.
Setup, maintenance and support
A DPA is required before we start processing personal data on your behalf, for example during data migration, commissioned operation or maintenance and support with systematic access to such data. This also applies when the data remains on your infrastructure.
Purely technical setup or troubleshooting without processing personal data does not in itself constitute processing on your behalf. Support can use anonymised examples. Personal content, database copies or access to production data should only be provided after the scope of service and required data protection agreements have been clarified.
AI providers and connectors you choose
If you connect external AI models, cloud services or connectors under your own contracts and accounts, you must assess their data processing for your use. Depending on the service’s role, a DPA and, where applicable, safeguards for transfers to third countries are required. Merely connecting these services to your installation does not make them our subprocessors.
Website, downloads and contact
Personal data is processed when operating the website and handling download requests, app submissions, appointment bookings and contact enquiries. We act as controller for these purposes; this does not create a DPA between you and us as the software supplier. Details are provided in the privacy policy.
DPA for a commissioned service
For a service involving processing on your behalf, we agree the DPA and its specific annexes before the first data access. It specifies the subject matter, duration and purpose of processing, data types, data subjects, instructions, confidentiality, technical and organisational measures, subprocessors and processing locations, and assistance with data subject rights, personal data breaches and audits. It also governs returning and deleting data when the service ends.
A DPA is concluded for the specific service. Visiting this page or downloading the software does not conclude a DPA.