Data processing agreement (DPA)
Version 2026-09-15
This version is currently under legal review. We will let you know about any changes before they take effect.
This English version is for information. The German version is binding. Read the German version.
Parties
between the Customer as defined in the miphu Terms of Use
- "Controller" -
and
SwiftLabs UG (haftungsbeschränkt), Schanzenstraße 19, 90478 Nürnberg, Germany, Amtsgericht Nürnberg, HRB 46502, represented by its managing director Felix Straub
- "Processor" -
This agreement is concluded in electronic form (Art. 28(9) GDPR), together with the Terms of Use, in the app's purchase flow: a notice directly at the purchase button names and links both texts, and by purchasing the Owner accepts for the Controller (section 20(1) of the Terms of Use). The Processor stores the version and time of acceptance with account and company.
Section 1 Subject matter and duration
(1) The Processor processes personal data on behalf of the Controller to the extent necessary to provide miphu under the Terms of Use. Terms defined in the Terms of Use have the same meaning here.
(2) This agreement does not cover processing for which the Processor is itself the controller: Users' accounts and sign-ins, the emails for them, the subscription, protection of the service, the website miphu.com and the Processor's own records under section 12(7) of the Terms of Use (acceptances, billing records, records of deletions). These are described in the privacy policy at miphu.com/privacy.
(3) This agreement applies for as long as the contract for the use of miphu exists, and afterwards until all personal data of the Controller has been deleted or returned under section 10.
Section 2 Nature and purpose of processing
(1) The purpose is to provide miphu as software for CRM, quotes, orders, invoices, expenses, tasks, personnel management, shift planning, time recording and insights for the Controller and its Users.
(2) Processing includes in particular collecting, storing, organising, retrieving, displaying and transmitting to the Users' apps, generating documents (PDF, XRechnung) and exports including the Data Export under section 11(1) of the Terms of Use, sending emails to Users, for example to provide a Data Export or to confirm a deletion, backup and restore, transmission to AI apps on a User's instruction (section 12), and erasure.
(3) Annex 1 describes the types of data and categories of data subjects.
Section 3 Rights and obligations of the Controller
(1) The Controller is responsible for the lawfulness of the processing, in particular for the legal basis, for informing data subjects under Art. 13 and 14 GDPR and for safeguarding their rights.
(2) The Controller processes special categories of personal data (Art. 9 GDPR) in miphu only where a function is intended for it and the processing is lawful.
(3) The Controller informs the Processor without undue delay if it detects errors or irregularities in the processing.
Section 4 Instructions
(1) The Processor processes the data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by Union or German law; in such a case it informs the Controller of that legal requirement beforehand, unless that law prohibits such information on important grounds of public interest.
(2) Documented instructions are this agreement, the Terms of Use, and the settings and actions authorised Users of the Controller perform in miphu, such as creating, changing, exporting and deleting data, deleting the account or the company account, assigning rights and approving AI connections. Further instructions are given by the Owner in text form to hello@miphu.com.
(3) If the Processor considers an instruction unlawful, it informs the Controller without undue delay. It may suspend execution until the Controller confirms or changes it.
(4) The Processor carries out instructions that go beyond the functions of miphu where technically possible and reasonable. If the Processor cannot carry out an instruction, either party may terminate the contract for the use of miphu.
Section 5 Obligations of the Processor
(1) The Processor processes the data exclusively for the purposes under section 2. It does not use the data for its own purposes, does not sell it, does not disclose it for advertising and does not use it to train AI models.
(2) It only engages persons who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The commitment continues after their engagement ends.
(3) It implements the technical and organisational measures under Art. 32 GDPR described in Annex 2. It may develop them further as long as the level of protection does not decrease, and it communicates material changes.
(4) Processing takes place in data centres in the European Union unless Annex 3 states otherwise.
Section 6 Sub-processors
(1) The Controller authorises the sub-processors listed in Annex 3 (general written authorisation under Art. 28(2) GDPR).
(2) The Processor informs the Controller in advance, in text form to the Owner's email address, of any intended addition or replacement of a sub-processor. The Controller may object after receipt for an important data protection reason. If no solution is found, the Controller may terminate the contract for the use of miphu before the change takes effect.
(3) The Processor imposes on each sub-processor by contract the same data protection obligations as set out in this agreement (Art. 28(4) GDPR). Where a provider contracts only on its own non-negotiable terms, its data processing agreement suffices to the extent it meets this requirement; it is named in Annex 3.
(4) The following are not sub-processors: providers the Processor uses only for its own purposes, Apple when selling the subscription, and providers of AI apps that a User connects to miphu (section 12).
Section 7 Transfers to third countries
(1) Processing outside the EU and the EEA takes place only if the conditions of Art. 44 et seq. GDPR are met. The transfer mechanism for each sub-processor is stated in Annex 3.
(2) If a transfer mechanism ceases to apply, the Processor informs the Controller without undue delay and suspends the affected transfer until another lawful mechanism exists or the Controller has decided.
Section 8 Assistance to the Controller
(1) The Controller can primarily answer data subject requests under Art. 15 to 22 GDPR using the functions of miphu, such as viewing, changing, exporting and deleting. Where this is not sufficient, the Processor assists with appropriate technical and organisational measures.
(2) If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay, where it can identify the Controller, and does not answer it itself.
(3) The Processor assists the Controller with the obligations under Art. 32 to 36 GDPR, in particular data protection impact assessments and notifications, to the extent the information is available to it.
(4) The Controller remunerates assistance that goes beyond the functions of miphu and cooperation on individual cases, unless the Processor is responsible for the cause.
Section 9 Personal data breaches
(1) The Processor notifies the Controller of any personal data breach affecting the Controller's data without undue delay after becoming aware of it, to the Owner's email address. The notification contains the information under Art. 33(3) GDPR as far as available; missing information is provided without undue further delay.
(2) The Processor takes measures without undue delay to secure the data and mitigate adverse effects, and documents the breach.
Section 10 Deletion and return
(1) The data is returned (Art. 28(3)(g) GDPR) through the Data Export under section 11(1) of the Terms of Use, which the Owner creates and downloads during the term and after the Subscription ends.
(2) After the end of the provision of processing services, the Processor, at the Controller's choice, makes the data available for export and then deletes it, or deletes it without export. The periods follow sections 8, 11 and 12 of the Terms of Use.
(3) If the Owner deletes the company account, the Processor locks the data for all Users at once, keeps it for 30 calendar days so that the deletion can be reversed on request, and then deletes it automatically from the live system (section 12(2) to (4) of the Terms of Use).
(4) Backups are deleted after no more than 90 days. The data is therefore finally deleted no later than 90 days after the end of the 30-day period under subsection 3. Until then it is protected against access in the backups and used only to restore the service as a whole.
(5) The Controller's statutory retention obligations do not oblige the Processor to keep data for the Controller after the contract ends (section 11(8) of the Terms of Use). The Processor is not aware of any statutory obligation of its own to store the Controller's data; if one arises, it will say so.
(6) The Processor confirms the deletion by email with the day of final deletion; on request it confirms completion of the deletion in text form. It may keep records evidencing proper processing beyond the end of the contract.
Section 11 Evidence and audits
(1) The Processor makes available to the Controller the information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it.
(2) Evidence is primarily provided through information in text form, current documentation and, where available, audit reports or certifications. The evidence of the data centre operators (Annex 3) applies to their services.
(3) The Controller announces an on-site inspection at least four weeks in advance. It takes place during normal business hours, without disrupting operations, and at most once per calendar year, otherwise only for a specific cause stated in text form. Mandated auditors must not be competitors of the Processor and are bound to confidentiality. The Processor does not operate the data centres; their inspection follows the operators' terms.
(4) The Controller bears the cost of inspections unless they reveal a breach by the Processor.
Section 12 Connecting AI apps
(1) The Processor provides an interface through which authorised Users of the Controller can connect AI apps of other providers, for example Claude by Anthropic or ChatGPT by OpenAI, to miphu.
(2) A connection only comes into existence through a User's express approval and only as long as the Controller permits the function in miphu. The Controller can revoke connections at any time.
(3) Through a connection, the Processor transmits, on the instruction of the respective User, the data that this User may view in miphu and has approved, to the AI app the User has chosen. Personnel master data, files, credentials, bank details, payment methods and individual recorded payments are not transmitted.
(4) The provider of the connected AI app is not a sub-processor of the Processor. The agreements with that provider and the assessment of the lawfulness of the transfer are the Controller's responsibility.
(5) For each call, the Processor logs time, duration, result, User, company, AI app, tool and the number of records transmitted, but not search terms or content. These logs are deleted after 90 days. The Data Export contains the existing logs.
Section 13 Additional terms under the California Consumer Privacy Act
To the extent the Processor processes personal information of consumers within the meaning of the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq., "CCPA") for a Controller that is a "business" under the CCPA, it acts as a "service provider" and
- does not sell or share that personal information,
- processes it only for the business purposes set out in section 2, for which the Controller discloses it to the Processor solely,
- does not retain, use or disclose it for any other purpose, including any other commercial purpose, or outside the direct business relationship with the Controller,
- does not combine it with personal information received from others or collected from its own interaction with the consumer, except as expressly permitted by the CCPA and its regulations,
- complies with the applicable obligations of the CCPA and provides the same level of privacy protection as the CCPA requires of businesses,
- grants the Controller the right to take reasonable and appropriate steps to ensure use consistent with the Controller's obligations (section 11) and, upon notice, to stop and remediate unauthorised use,
- notifies the Controller if it determines that it can no longer meet its obligations under the CCPA,
- assists the Controller with consumer requests under the CCPA (section 8), and
- binds sub-processors by contract to the same requirements and informs the Controller about them (section 6).
Section 14 Liability
Liability is governed by section 19 of the Terms of Use. Claims of data subjects under Art. 82 GDPR and the allocation between the parties under Art. 82(5) GDPR remain unaffected.
Section 15 Final provisions
(1) In the event of conflict, this agreement prevails over the Terms of Use as regards the protection of personal data.
(2) Changes to this agreement follow section 21 of the Terms of Use; changes to sub-processors follow section 6.
(3) If a provision is invalid, the remainder of the agreement remains valid.
(4) Section 23(1) to (3) of the Terms of Use applies.
Annex 1 - Types of data and data subjects
The data actually processed is determined by the Controller's use. The list describes what miphu has functions for (as of 15 September 2026).
| Area | Types of data | Data subjects |
|---|---|---|
| Sales and CRM | name, company, position, address, email address, phone number, website, notes, activities, tags, imported history | prospects, customers and their contacts |
| Quotes, orders, invoices | recipient data, line items, amounts, tax details, payment status, the Controller's bank details on documents, issued PDF and XML files | customers and their contacts, the Controller's contact persons |
| Payments and expenses | incoming and outgoing payments, receipts and original files with the information on them | customers, suppliers, employees (for example for reimbursements) |
| Tasks | title, description, assignee, references | employees, customers and contacts a task refers to |
| Personnel and team | name, contact details, personnel master data, title, rank, departments, rights, profile photo | the Controller's employees |
| Shift planning | shifts with time, place, customer or order, notes, change history | employees, customers |
| Absences | type (vacation, sickness, other), period, status, optionally a note for vacation and other. The fact of sickness is health data under Art. 9 GDPR; no diagnosis is recorded. | employees |
| Time recording | clock events with server and device time, breaks, corrections with reasons, approvals, reference to shift, customer or order. No location | employees |
| Change log | who made which change when | Users, affected records |
| Request records | who made which request when, with request key, content or checksum of the content, and result | Users, persons in the affected records |
| Data Exports | archive of all data in this Annex, stored for no more than seven days; who started the export and when; email to that User without Customer Data | all listed here |
| Deletions | day of deletion and of final deletion, affected Accesses; after the period the account without email address, password and profile photo | Users |
| Emails to Users | email address, name, message content (for example notices about new AI connections) | Users |
| AI connections | connection, approved scopes, revocations; call log without content (90 days) | Users |
Annex 2 - Technical and organisational measures (Art. 32 GDPR)
1. Confidentiality
Physical access to data centres. The servers are located in data centres of Hetzner Online GmbH. Physical access control there is a measure of the operator.
Access to systems.
- Server sign-in with SSH keys only; host firewall with default deny; only the ingress service (ports 80 and 443) is reachable from the internet.
- The database has no public port. The connection pooler is bound to the private address only and admits only configured clients by address.
Access to data.
- Passwords are stored only as bcrypt hashes; sign-in attempts are limited per IP address and per email address.
- Sessions are stored as a hash of the session key; links in emails are single-use and valid for at most 15 minutes, for activation at most 24 hours.
- Every User has their own Access; rights are assigned per role and per area (owner, administration, members with CRM, finance and planning rights).
- Data Export: only the Owner and Users of the Administration with sales and finance rights, after the Subscription ends only the Owner; rights and session are checked again for every part of the download; no more than five starts per company in 24 hours; the archive is deleted seven days after completion; the notification contains no data.
- Account deletion only with the current password, for the Owner additionally with the company name.
Tenant separation. Each company's data is separated in the database by row-level security; the policies check membership on every statement. The shift planning and time recording schemas run with ENABLE and FORCE RLS and without direct table privileges for the runtime role; the API refuses to start otherwise.
Encryption.
- Transport between app and service over TLS (Let's Encrypt certificates); HTTP is redirected to HTTPS.
- Between the API and database servers the connection runs over the private network; the pooler offers TLS (TLS 1.3 measured), but the API does not verify its certificate. Protection of this path rests on the private network, address checks and SCRAM authentication.
- Backups are encrypted (see 3.).
Operations. API and worker containers run with a read-only file system, without Linux capabilities, with process, memory and CPU limits and without the Docker socket; each service receives only its own secrets; the API server holds neither the database administrator password nor backup material.
2. Integrity
- Issued invoices are immutable; number ranges are gapless; corrections are made by reversal.
- Clock events and corrections of working time cannot be changed or deleted (a trigger refuses UPDATE, DELETE and TRUNCATE for every role); a SHA-256 chain per person secures the order; a verification function reports a break.
- Changes and their change-log entries are written in the same transaction; deletions set a deletion marker with a log entry. Whether and when such entries are finally removed is not defined.
- Access logs at the ingress are deliberately disabled because URLs contain one-time keys; container logs rotate at 3 × 10 MB. Calls from AI apps are logged without content for 90 days.
- The database runs with data page checksums.
3. Availability and resilience
- Two API instances behind a proxy, replaced one at a time during updates.
- Continuous archiving of the transaction log (pgBackRest) into two encrypted repositories (
aes-256-cbc): one on the database server, one on a Hetzner Storage Box, transferred over SFTP with pinned host keys. Full backup on Sundays, differential Monday to Saturday. - Weekly point-in-time restore drill into a separate cluster with verification of all page checksums.
- Daily logical backup in an authenticated AES-256-GCM envelope, additionally stored in an encrypted restic chain on the Storage Box.
- Backup retention: no more than 90 days. pgBackRest by time (7 days on the database server, 21 days on the Storage Box, at most about 15 and 29 days per copy); logical backups and their local archives are removed after 85 days (at most about 86 days, about 89 days with three failed runs), every run monitored.
- Monitoring of both servers with alert emails and an external heartbeat.
4. Process for regular review
- Restore drills as under 3.
Annex 3 - Sub-processors
| Provider | Service | Location of processing | Mechanism |
|---|---|---|---|
| Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany | servers, database including uploaded files and Data Exports, backups | servers and backups in data centres in Germany. Until its deletion, announced for 21 September 2026, a decommissioned server in Helsinki (Finland) still holds volumes with production data. | EU |
| Plus Five Five, Inc. ("Resend"), USA | sending emails to Users | USA; Resend lists Amazon Web Services, Inc. (USA) as its own sub-processor | the provider's Data Processing Addendum with Standard Contractual Clauses under Implementing Decision (EU) 2021/914, Module 3 (processor to sub-processor) |
Not sub-processors for the Controller's data:
- Apple sells the subscription under its own responsibility and receives no Customer Data from miphu. Push notifications that would run through Apple are not built.
- Hostinger International Ltd. operates only the website miphu.com.
- Providers of AI apps receive data only through a connection a User approves (section 12).
- Healthchecks.io receives only a heartbeat from the servers.
- The mailbox hello@miphu.com is hosted by Apple (iCloud Mail). If a customer sends Customer Data by email, Apple processes it.