Data processing agreement
Under Art. 28 GDPR. Last updated: 3 September 2026.
1. Parties and subject matter
The processor is Leon Matthies, Rathausstraße 33, 6900 Bregenz, Österreich ("Duskwatch"). The controller is the agency using Duskwatch.
The subject matter is the monitoring of the automation instances connected by the controller: Duskwatch calls their API, records state and incidents, and reports failures. Processing lasts as long as the usage contract runs.
2. Type of data and data subjects
Only operational data of the monitored automations is processed:
- names, schedules and activation state of workflows
- execution IDs, timestamps, status and affected nodes
- error messages truncated to 500 characters
- instance URLs and their API keys, stored encrypted
Execution contents are neither read nor stored. Data subjects are therefore as a rule only employees of the controller and its clients, insofar as they appear in workflow names or error messages. Since error messages originate from the controller's own workflows, the controller can determine what appears there by how those workflows are written.
3. Instructions
Duskwatch processes the data solely on documented instructions from the controller. The usage contract, together with the settings the controller makes in the application, constitutes those instructions. If Duskwatch considers an instruction unlawful, it will say so and may suspend it.
4. Confidentiality
Everyone involved in the processing is bound to confidentiality. Access to production data is limited to those who need it for operation and troubleshooting.
5. Technical and organisational measures
- Transmission exclusively over TLS.
- Instance API keys stored encrypted (AES-256-GCM), not displayable after saving.
- Passwords stored only as hashes.
- Tenant separation: every business row carries the agency identifier; it comes from the session, never from the address bar or a form.
- Data minimisation by design: no execution contents, truncated error messages.
- Servers and database in the EU (Oracle Corporation, Rechenzentrum Frankfurt).
- Daily backup, restore rehearsed and documented.
- Separate environments for development and operation; credentials only in the production environment.
6. Sub-processors
The controller consents to the following sub-processors:
- Oracle Corporation, Rechenzentrum Frankfurt — hosting of application and database, EU.
- Brevo (Sendinblue GmbH), EU-Region — delivery of alert emails, EU.
- Slack or Telegram — only if the controller sets up such channels themselves. These providers process outside the EU; setting them up is voluntary.
Further sub-processors will be announced in text form 30 days in advance. The controller may object; in that case they may terminate for cause.
7. Assistance
Duskwatch assists the controller with data subject requests, data protection impact assessments and notification duties. If a personal data breach becomes known, Duskwatch reports it without undue delay, and at the latest within 48 hours of becoming aware of it.
8. Deletion and return
The controller can delete their data in the application at any time. After the usage contract ends, all data is deleted as soon as no statutory retention obligation stands in the way. Backups expire after their retention period.
9. Evidence and audits
Duskwatch demonstrates compliance with these obligations on request. On-site audits are possible with reasonable advance notice and to an extent that does not impair operations.
10. Final provisions
Austrian law applies, excluding its conflict-of-law rules. If a provision is invalid, the remainder stays in force. Amendments require text form.