Data Processing Agreement (DPA)
Processing on behalf under Art. 28 GDPR and FADP, including the TOM annex. Excluded: Power Apps for Power Platform in the customer environment.
Version 1.4 · As of 03 October 2026
between the customer (controller) and Power Manufaktur GmbH, UID CHE-153.237.765, Mettenwilstrasse 1, 6203 Sempach Station, Switzerland, data protection contact: Heinz Süess, info@powermanufaktur.com (processor, hereinafter the «provider»).
The provider is domiciled in Switzerland and provides its services to customer organisations throughout the DACH region (Germany, Austria and Switzerland). For personal data that the provider processes on behalf of the customer, Swiss law applies irrespective of the customer's domicile, unless mandatory law of the customer's state of domicile or of the data subjects' residence provides otherwise.
This DPA supplements the terms of service; in case of conflict it prevails over the terms and the EULA. Individual written agreements always take precedence.
Scope of this DPA: This DPA applies to modules operated or technically managed by Power Manufaktur GmbH where personal data may flow through infrastructure of the provider or its subprocessors. It does not apply to Power Apps for Microsoft Power Platform that run entirely in the customer's environment; for these the customer remains the sole controller.
This English version is a convenience translation. In case of discrepancies the German version prevails.
1. Subject matter and duration
The processor processes personal data exclusively to provide the contractually agreed services (provision and operation of the Power IMS product family). Processing continues for as long as the provider actually provides services involving processing on behalf under a subscription or following a purchase; a perpetual right of use for a purchased version alone does not create indefinite processing on behalf.
This DPA does not cover processing on the websites of Power Manufaktur GmbH (www.power-ims.com, www.powermanufaktur.com, www.power-copilot.com and www.power-vibecoding.com) such as website analytics, newsletter, contact and quote forms or the AI chat. For those, Power Manufaktur GmbH is the controller itself; the website privacy notice applies.
2. Nature, purpose, data categories, data subjects
| Item | Content |
|---|---|
| Nature of processing | Collecting, storing, reading, altering, transmitting (to the customer's tenant), deleting, logging |
| Purpose | Operation of the software, support, error analysis, security, optional AI text features |
| Data subjects | Employees, managers and external participants of the customer (e.g. risk owners, audit leads, action owners), contact persons |
| Data categories | Identity and contact data (name, email/UPN, object ID, tenant ID), role and permission data, business content including personal references, attachments, technical log data |
| Special categories | Depending on the module, particularly sensitive personal data may be recorded (e.g. in occupational safety). Processing of such data is expressly agreed in writing. |
3. Instructions
3.1 Processing takes place only on documented instructions of the customer, including instructions embodied in the main contract and the product configuration.
3.2 If the processor considers an instruction unlawful, it informs the customer and may suspend execution.
3.3 Instructions are given in writing to info@powermanufaktur.com.
4. Confidentiality
All persons involved in the processing are bound to confidentiality and trained on data protection requirements.
5. Technical and organisational measures (TOM)
See Annex A. The processor may further develop measures provided the level of protection is not reduced.
6. Subprocessors
6.1 The customer generally approves the subprocessors listed in the subprocessor register.
6.2 Changes are announced at least 30 days in advance. The customer may object; if no solution can be found, it may extraordinarily terminate the affected part of the services.
6.3 The processor imposes equivalent obligations on subprocessors and is liable for them as for its own conduct.
7. Data location and third-country transfers
7.1 Business content, personal data and attachments stored in the software remain in the customer's Microsoft 365 tenant and therefore in the region chosen by the customer. Technical logs and inputs transmitted for AI features are subject to the separate provisions of this DPA.
7.2 In standard operation, AI processing takes place via Azure OpenAI in the West Europe region.
7.3 Where processing takes place outside Switzerland/the EEA, it is based on an adequacy decision or on the EU Standard Contractual Clauses in the version recognised by Switzerland, supplemented by appropriate additional measures.
8. Assistance to the customer
The processor reasonably assists the customer with:
- requests from data subjects (access, rectification, erasure, restriction, portability, objection);
- data protection impact assessments and prior consultation;
- notification obligations under Art. 33/34 GDPR resp. Art. 24 FADP.
The processor does not answer data subject requests itself but forwards them without delay.
9. Personal data breaches
The processor notifies the customer of a personal data breach that comes to its attention as soon as possible, with the information then available on its nature, scope, categories affected, likely consequences and measures taken. Missing information is provided subsequently.
10. Audit rights
10.1 The customer may verify compliance, primarily through self-assessments, TOM documentation and evidence from subprocessors.
10.2 On-site or remote audits are permitted with 30 days' notice, during business hours, at most once a year and without disrupting operations; additional audits on specific cause. Effort beyond 1 person-day may be charged on a time and material basis.
11. Deletion and return
11.1 Business data resides in the customer's tenant and remains there after contract end; return by the processor is not required.
11.2 Data in the processor's area of responsibility (e.g. error logs, licence and trial data) is deleted within 90 days after contract end, unless statutory retention obligations apply.
12. Liability
The liability provisions of the terms of service apply unless mandatory data protection law provides otherwise.
Annex A – Technical and organisational measures
Physical and system access control
- Operation exclusively in data centres of certified providers (Microsoft Azure; hosting provider of the web application).
- Sign-in exclusively via Microsoft Entra ID (single sign-on); MFA and conditional access are controlled by the customer.
Access control
- Role-based permissions in the application; privileged actions are validated server-side.
- Data access via Microsoft Graph on behalf of the signed-in user; the customer's SharePoint permissions remain effective.
- Least privilege principle for the requested Graph permissions.
Transmission and storage control
- Transport encryption (TLS) for all connections.
- Encryption at rest by the platform services.
- Outgoing notification emails are restricted to recipients within the customer's tenant (protection against open relay abuse). Delivery is via Brevo.
Input and traceability
- Change history for business objects in the application.
- Technical error log with 30-day retention, without payload content and without query parameters.
Availability
- Data stored in Microsoft 365 with the customer's recovery features (recycle bin, versioning, retention policies).
- Redundant delivery of the application via the hosting platform.
Separation control
- Tenant separation via tenant identifier; business data resides physically in the respective customer tenant.
Organisation
- Confidentiality undertaking of all employees.
- Data protection officer: Heinz Süess.
- Versioned releases, code review and automated security checks before publication.
- Backup concept: daily automated backups of business-critical systems with encrypted storage and regular restore tests.
- Incident response process: documented escalation plan with defined roles, reporting channels and deadlines; on suspicion of a data breach we inform the customer without delay.
- Training cadence: annual data protection and information security training for all employees with documented evidence.