Effective date: 1 July 2026
This Data Processing Agreement ("DPA") forms part of, and is governed by, the mandera Terms of Service (the "Agreement") between Mandera Software GmbH, Marktplatz 6, 73525 Schwäbisch Gmünd, Germany ("mandera", the "Processor") and the customer ("Customer", the "Controller").
It applies where, and to the extent that, mandera processes personal data on behalf of the Customer in the course of providing the AI features of the Service (Art. 28 GDPR).
Out of scope. mandera's cookieless analytics does not process personal data of website visitors (see Terms §7.2) and is therefore not subject to this DPA. Data that mandera processes as a controller (e.g. account and billing data) is governed by mandera's Privacy Policy, not this DPA.
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given in the General Data Protection Regulation (EU) 2016/679 ("GDPR"). "Services" means the mandera Service as defined in the Agreement; "Subprocessor" means a third party engaged by mandera to process Customer personal data.
The Customer is the controller (or itself a processor) of the personal data it submits to the AI features; mandera acts as processor (or sub-processor) on the Customer's behalf. mandera processes personal data only to provide the AI features and as set out in Annex 1.
mandera processes Customer personal data only on the Customer's documented instructions, which comprise the Agreement, this DPA, and the Customer's use and configuration of the Services, unless required to act by EU or Member-State law (in which case mandera informs the Customer beforehand, unless that law prohibits it). mandera does not process Customer personal data for its own purposes and will inform the Customer if, in its opinion, an instruction infringes data protection law.
This DPA applies for as long as mandera processes Customer personal data under the Agreement.
mandera ensures that persons authorized to process Customer personal data are bound by an appropriate obligation of confidentiality.
mandera implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex 2.
The Customer grants mandera general authorization to engage Subprocessors. The Subprocessors engaged for the AI features are listed in Annex 3; the current company-wide list is published at mandera.ai/subprocessors.
mandera imposes data-protection obligations on each Subprocessor that are materially equivalent to those in this DPA. mandera will notify the Customer of any intended addition or replacement of a Subprocessor (e.g. by updating the list and/or by email) at least 14 days in advance, giving the Customer the opportunity to object on reasonable data-protection grounds. If the Customer reasonably objects, the parties will work in good faith to find a solution; if none is found, the Customer may terminate the affected feature. mandera remains responsible for its Subprocessors' performance.
Taking into account the nature of the processing and the information available to it, mandera assists the Customer by appropriate technical and organizational measures with:
mandera notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, and provides information reasonably available to it to help the Customer meet its obligations under Art. 33 and 34 GDPR.
On termination of the AI features or the Agreement, mandera will, at the Customer's choice, delete or return the Customer personal data it processes under this DPA, and delete existing copies, unless EU or Member-State law requires storage. Unless the Customer requests return, mandera deletes such data within 90 days; backups are purged on a rolling basis.
mandera makes available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits take place on reasonable prior notice, during business hours, subject to confidentiality, and not more than once per year unless required following an incident or by a supervisory authority. mandera may satisfy audit requests by providing relevant certifications, reports or summaries of its measures.
mandera processes Customer personal data under this DPA within the EU/EEA (the AI subprocessor Mistral AI and the hosting provider Hetzner are EU-based). Should any processing of Customer personal data nonetheless occur outside the EU/EEA, mandera ensures appropriate safeguards under Art. 44 et seq. GDPR, in particular the EU Standard Contractual Clauses.
The Customer warrants that it has a valid legal basis for the processing, that its instructions comply with data protection law, and that it is entitled to submit the relevant personal data to mandera for processing.
Liability is governed by the Agreement and Art. 82 GDPR. In case of conflict between this DPA and the Agreement on matters of personal-data processing, this DPA prevails. This DPA is governed by the laws of the Federal Republic of Germany.
(A more detailed description of the measures is available to the Customer on request.)
| Subprocessor | Purpose | Location |
|---|---|---|
| Mistral AI | AI model inference for the AI features | France (EU) |
| Hetzner Online GmbH | Hosting / infrastructure | Germany (EU) |
The current, company-wide list of all subprocessors is published at mandera.ai/subprocessors.