modelflow
FeaturesPricingSupportFAQ
DE Get in touch
modelflow
FeaturesPricingSupportFAQ
Get in touch

Data processing agreement

Last updated: 25 September 2026

1. Scope

This agreement governs how we, jumoca, Julian Caspary, Am Waldangelbach 67, 69168 Wiesloch, Germany, process personal data on behalf of our customers when they use modelflow (Art. 28 GDPR). The customer is the controller and we are the processor. The agreement is part of the terms of use and applies for as long as we process the customer’s data.

2. Nature, purpose and scope

The subject of the processing is the provision of modelflow. The data processed consists of the submitted documents, the maps and the change journal, including the identifiers of the users involved. The data subjects are the customer’s users and the people named in the documents. We process account data, usage data and billing data under our own responsibility, as described in the privacy policy.

3. Instructions

We process the data within the customer’s documented instructions, including with regard to transfers to third countries. The instructions are the terms of use, this agreement and the settings and actions of the customer’s users in modelflow.

If we consider an instruction unlawful, we point this out to the customer without delay. If EU or Member State law requires us to process the data otherwise, we inform the customer beforehand, unless that law prohibits it.

4. Confidentiality

Everyone at our end with access to the data is committed to confidentiality or is under a statutory duty of secrecy.

If the customer is bound by professional secrecy, for example as a tax adviser, auditor or lawyer, we bind the people involved to secrecy in text form and inform them of their criminal liability under § 203 of the German Criminal Code.

5. Security

We take technical and organisational measures under Art. 32 GDPR, in particular:

Physical access: The server is located in a data centre of Hetzner Online GmbH certified under ISO/IEC 27001.

System and data access: Users sign in through Microsoft Entra ID. The data of each organisation is logically separated. Administrative access is limited to authorised persons and personally authenticated.

Transmission: Connections from the internet are encrypted. Internal services cannot be reached from the internet.

Integrity: Values that modelflow writes to workbooks are logged. Changes to the software are tested before release.

Availability: The database is backed up daily, encrypted, to a separate system. Services restart on their own after failures and are protected against overload.

Review: We review the measures regularly and after material changes. We may develop them further as long as the level of protection does not fall.

6. Sub-processors

The customer authorises us to engage sub-processors. Currently this is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, whose data centre in Helsinki, Finland, we use to run the service and to store backups. We announce new or replaced sub-processors in text form at least 30 days in advance.

The customer may object for a good reason relating to data protection. If we cannot find a solution, the customer may terminate the contract as of the date of the change. We bind every sub-processor by contract to the same data protection obligations.

Microsoft provides sign-in and Excel under its own agreement with the customer and is therefore not a sub-processor. Neither is Stripe, as we handle billing under our own responsibility.

7. Assistance

As far as we are able, we assist the customer with requests from data subjects, with the security of processing, with reporting personal data breaches, with data protection impact assessments and with prior consultation of the supervisory authority (Art. 32 to 36 GDPR). If a data subject contacts us, we forward the request to the customer.

8. Personal data breaches

We notify the customer of a breach affecting its data without undue delay after becoming aware of it, with the information available to us at that point.

9. Deletion

We do not store documents beyond their processing. Entries in the change journal are deleted ten years after they were made.

If the customer closes its account, we delete its data after 90 days. Until then, the customer can export its change journal. Deleted data leaves the backups after a further 14 days. If only a subscription ends, the data is kept.

10. Evidence and audits

We provide the customer with the information it needs to demonstrate compliance with this agreement, and we allow audits by the customer or by an auditor it appoints who is bound to confidentiality. Audits are to be announced with reasonable notice and must neither disrupt operations nor touch other customers’ data.

11. Liability and final provisions

Liability follows Art. 82 GDPR and the terms of use. Changes to this agreement follow the terms of use, and changes to sub-processors follow section 6. German law applies. If the language versions differ, the German version prevails.

modelflow

Auditable data extraction for Excel models.

Resources

Articles Help Provider docs

Legal

Imprint Privacy Terms

Language

Deutsch

A product of jumoca · © 2026