Data Processing Agreement
Version 2026-08-27 · Effective August 27, 2026
This Data Processing Agreement (DPA, or Auftragsverarbeitungsvertrag / AVV) is between the Super44 business customer identified in the account (the Controller) and Super44 GmbH, Rheinwerkallee 6, 53227 Bonn, Germany (the Processor). It forms part of the Super44 Terms of Service. Electronic acceptance by an authorised business representative is binding.
1. Scope, roles and applicable law
This DPA applies whenever Super44 processes personal data on the Controller's behalf to provide Super44 or Superstaff. The Controller determines the purposes and essential means; Super44 processes only as documented by the Agreement and the Controller's lawful instructions.
For EEA processing, references to GDPR mean Regulation (EU) 2016/679. For UK processing, they mean the UK GDPR and Data Protection Act 2018. The same Article 28 processor terms apply under either regime.
2. Processing details
The subject matter is hosting and operating the contracted business-assistant, expense and staffing services. Processing lasts for the Agreement term plus the deletion and backup periods described below. Its nature includes collecting, recording, structuring, storing, retrieving, analysing, transmitting at the Controller's direction, restricting, exporting and deleting data. Its purpose is to provide, secure, support and maintain the services selected by the Controller.
- Data subjects: the Controller's owners and authorised users; workers, including young workers where their employment is lawful; employees, contractors, applicants or former staff entered into Superstaff; and customer contacts contained in connected business data.
- Data categories: identifiers and contact details; date of birth; roles, employment classifications and legal status; employment start date; agreed rates and weekly hours; holiday-pay method, leave-year start and vacation entitlements; right-to-work and onboarding-compliance evidence; availability; schedules; leave, absence and swap records; clock, kiosk, timesheet and payroll-export records; chat instructions; POS, receipt and connected-service data; device, security and support telemetry.
- Special-category data is not required. The Controller must not submit it unless necessary, lawful and expressly supported by the service. Sick-leave status can reveal health information; the Controller must minimise detail and apply the appropriate lawful basis and safeguards.
3. Controller obligations and instructions
The Controller is responsible for the lawfulness, fairness, transparency and accuracy of personal data and instructions; for giving notices and handling lawful bases, employee consultation and rights; and for ensuring authorised users only enter data they may process. The Agreement, product configuration, documented support requests and lawful use of product controls are documented instructions.
If Super44 believes an instruction infringes applicable data-protection law, it will inform the Controller unless legally prohibited and may suspend the affected processing while the parties resolve it.
4. Processor duties
- Process personal data only on documented instructions, including for international transfers, unless Union, Member State or UK law requires otherwise; where permitted, tell the Controller before that processing.
- Ensure people authorised to process personal data are bound by confidentiality.
- Implement and maintain appropriate technical and organisational security measures under Article 32.
- Respect the subprocessor conditions in section 6.
- Taking account of the nature of processing, assist the Controller with data-subject requests through appropriate technical and organisational measures.
- Assist with Articles 32–36 obligations, including security, breach response, impact assessments and regulator consultation, considering the nature of processing and information available to Super44.
- At the Controller's choice, delete or return personal data after services end and delete copies unless applicable law requires storage.
- Provide information necessary to demonstrate compliance and allow reasonable audits or inspections under section 9.
5. Security and incidents
Super44 applies risk-appropriate measures including least-privilege access, encryption in transit and at rest where supported, EU-region primary application hosting, tenant-scoped authorization, logging and monitoring, secure development and change controls, backups, recovery procedures, vulnerability management and incident response. Bedrock model inference may use the safeguarded cross-region processing described in section 7. Measures may evolve if overall protection does not materially decrease.
Super44 will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller data. The notice will include available information needed for the Controller's obligations and will be supplemented as facts become known. Super44 will take reasonable steps to contain, investigate and remediate the incident.
6. Subprocessors
The Controller gives general written authorisation for the subprocessors below. Super44 will impose materially equivalent data-protection obligations and remains responsible for their performance. Super44 will give reasonable advance notice of a new or replacement subprocessor that processes Controller personal data. The Controller may object on reasonable data-protection grounds; the parties will work in good faith on a commercially reasonable alternative, and either party may terminate the affected service if none is available.
- Amazon Web Services EMEA SARL / relevant AWS affiliates — EU-primary infrastructure, databases, object storage and delivery services; Anthropic Claude model processing through Amazon Bedrock uses EU and configured global cross-region inference profiles and may involve safeguarded processing outside the EEA or UK; primary application region eu-central-1 (Frankfurt).
- Clerk — authentication and user-account management.
- Upstash — EU-hosted vector storage and retrieval for conversation content.
- Langfuse — filtered AI request, response and trace observability.
- Vercel — web-application hosting, delivery and request logs.
- Expo — mobile application update and push-notification delivery infrastructure.
- Sentry — application error and performance diagnostics.
- PostHog EU Cloud — product analytics and operational product events.
- Better Stack — logs, uptime and operational observability.
- Slack — limited support and operational notifications, including feature activations and assisted staffing-source cutovers.
- Twilio and Meta Platforms Ireland — optional WhatsApp message transport, webhook and delivery processing.
- Google — only for Controller-enabled Google OAuth, Business Profile or Gmail integrations.
7. International transfers
Core service data is primarily processed in the EEA. For UK-restricted transfers to the EEA, the parties rely on the UK's current EEA adequacy regulations while they apply.
Amazon Bedrock's configured global cross-region inference, and any future transfer by Super44 or a subprocessor, may involve processing outside the EEA or UK. Where a transfer is not covered by an applicable adequacy decision or regulation, the parties will use the relevant EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, or another lawful transfer mechanism, together with supplementary measures where required. This DPA incorporates those safeguards to the extent needed for the transfer.
8. Rights requests and assistance
Super44 will promptly forward a request received directly from a data subject where it can identify the Controller, and will not respond substantively except on the Controller's instructions or as required by law. Product controls and reasonable support assistance will help the Controller access, correct, export, restrict or delete data. Super44 may charge reasonable agreed costs for exceptional assistance beyond standard service capabilities.
9. Information and audits
Super44 will make available information reasonably necessary to show compliance. The Controller should first use current security documentation, certifications and written responses. If those are insufficient, the Controller may conduct one audit per year, and additional audits after a relevant breach or regulator request, with reasonable notice, during business hours, subject to confidentiality and safeguards for other customers. The Controller bears its audit costs unless the audit reveals a material breach by Super44.
10. Return, deletion and retention
During the service term, the Controller may use available export and deletion controls. At termination or on a valid instruction, Super44 will delete or return Controller personal data within the periods stated in the Privacy Policy, except data that applicable law requires it to keep. Personal data in backups is isolated from normal use and expires within the stated backup cycle. Statutory records retained by the Controller remain the Controller's responsibility.
11. Priority, liability and changes
If this DPA conflicts with the Terms about processing personal data on the Controller's behalf, this DPA controls. The Terms' liability provisions apply to this DPA to the extent permitted by applicable data-protection law. Changes to this DPA follow the Terms, except that a change required to preserve legal compliance may take effect on notice. A reduction in material protection requires the Controller's agreement or a lawful replacement mechanism.
12. Contact
Data-protection questions, rights assistance, audit requests and incident contacts should be sent to hello@super44.ai. Super44 GmbH's postal address is Rheinwerkallee 6, 53227 Bonn, Germany.