Data processing agreement
Version 2026-10-05, in effect from 5 October 2026.
Under Article 28 of the General Data Protection Regulation (“GDPR”), between the customer (the “controller”) and W24 Service GmbH, Therese-Studer-Straße 14, 80797 München, Germany (“Werk24”, the “processor”).
1. Scope
1.1 This agreement applies whenever Werk24 processes personal data on the customer’s behalf while providing Werk24 under the Terms of Service, or under a signed contract that refers to this agreement (“Customer Personal Data”). It forms part of those terms and needs no separate signature. A customer that needs a record of a named person accepting it can accept it in the API console, under Contract & Legal, or ask privacy@werk24.io for a countersigned copy.
1.2 Annex 1 describes the processing: its subject matter and purpose, the types of personal data, the data subjects, how long each part is kept and where it is processed. Annex 2 sets out the technical and organisational measures. Annex 3 lists the subprocessors.
1.3 Werk24 processes the following on its own account, as a controller, and not under this agreement:
- the data of the customer’s account and its users (names, e-mail addresses, company and billing details), to provide, bill and secure the account;
- data contribution under section 7.3 of the Terms of Service, which is designed to exclude personal data;
- statistics about the use of the service that identify no one.
Werk24’s privacy policy covers that processing. Paddle, which sells the paid plans, processes payment data as an independent controller.
2. Duration
This agreement runs for as long as Werk24 processes Customer Personal Data, including after the end of the Terms of Service until the data is deleted under section 8.
3. Instructions
3.1 Werk24 processes Customer Personal Data only on the customer’s documented instructions. These are: the Terms of Service and this agreement; what the customer sets up and sends through the service (the drawings and questions it submits, the people it invites, shares with or asks to approve, and its settings in the console and in the Studio); and further instructions in text form to privacy@werk24.io that are within the scope of the service.
3.2 Werk24 processes Customer Personal Data otherwise only where European Union or German law requires it, and then tells the customer beforehand unless that law forbids it.
3.3 Werk24 tells the customer without delay if it believes an instruction infringes data protection law, and may suspend carrying it out until the customer confirms or changes it.
4. Werk24’s obligations
4.1 Confidentiality. Werk24 commits everyone it authorises to process Customer Personal Data to confidentiality, unless they are already bound to it by law.
4.2 Security. Werk24 takes the measures in Annex 2 (Article 32 GDPR). It may change them as technology develops, provided the level of protection does not fall.
4.3 Assistance. Werk24 helps the customer, with the functions the service provides and otherwise on request, to answer requests from data subjects (Articles 12 to 23 GDPR) and to meet its duties on security, breach notification, data protection impact assessments and prior consultation (Articles 32 to 36 GDPR). Werk24 passes on to the customer any request it receives from a data subject about Customer Personal Data, and does not answer it itself beyond referring the data subject to the customer.
4.4 Contact. Werk24 has not appointed a data protection officer, because the law does not require one. Questions about data protection go to privacy@werk24.io.
5. Where the data is processed
5.1 Werk24 stores and processes Customer Personal Data in the European Union, with two exceptions. Without the data residency add-on, language models on Amazon Bedrock may serve a request from an AWS region outside the European Union. For an account with data residency in the US, the data is stored and processed in N. Virginia, USA, in place of the European Union. Annex 1, section 6, says where, and section 5.2 applies to every such transfer.
5.2 Werk24 transfers Customer Personal Data to a country outside the European Economic Area only where Chapter V of the GDPR allows it, for example on the basis of an adequacy decision (including the EU-U.S. Data Privacy Framework for certified companies) or of the European Commission’s standard contractual clauses. Annex 3 names the safeguard for each subprocessor.
6. Subprocessors
6.1 The customer authorises Werk24 to engage subprocessors. Annex 3 lists them, and the subprocessors page always shows the current list.
6.2 Werk24 tells the customer at least 30 days before a new subprocessor starts processing Customer Personal Data, by e-mail to the address of the customer’s account and on the subprocessors page. The customer may object in text form within that period on reasonable grounds of data protection. If Werk24 cannot resolve the objection, the customer may end the affected service before the new subprocessor starts, and Werk24 refunds any amount paid in advance for the time after the end.
6.3 Werk24 binds each subprocessor by contract to data protection obligations that protect Customer Personal Data at least as well as this agreement, and remains responsible to the customer for its subprocessors.
6.4 Services that do not involve access to Customer Personal Data, such as telecommunications, are not subprocessing.
7. Personal data breaches
Werk24 tells the customer without undue delay, and at the latest within 48 hours, after it becomes aware of a personal data breach affecting Customer Personal Data. It gives the information listed in Article 33(3) GDPR as far as it has it, adds the rest as soon as it can, and helps the customer meet its own duties. Werk24 takes the measures needed to contain the breach and to limit its effects.
8. Deletion and return
8.1 During the agreement the customer may ask privacy@werk24.io at any time to delete Customer Personal Data, all of it or particular drawings. Werk24 deletes it within 30 days and confirms in text form. Removing a drawing or a project in the Studio removes it from the workspace; the stored files are deleted on such a request or at the end of the agreement.
8.2 When the agreement ends, Werk24 deletes all Customer Personal Data within 30 days. If the customer asks before then for a copy of its results and reports, in the formats the service provides, Werk24 deletes the data once it has provided the copy.
8.3 The following are exceptions:
- data Werk24 must keep by law, such as billing records, which it keeps for the statutory period only and uses for nothing else;
- backups of Werk24’s databases, which expire on their own cycle (Annex 1, section 5) and are restored only to recover from data loss;
- data the service deletes automatically sooner (Annex 1, section 5).
9. Information and audits
9.1 Werk24 makes available the information needed to demonstrate compliance with Article 28 GDPR, starting with this agreement and its annexes, and answers the customer’s reasonable questions about it.
9.2 Where that is not enough, the customer may audit Werk24’s compliance, itself or through an independent auditor who is bound to confidentiality and is not a competitor of Werk24: once a year, and after a personal data breach, with 30 days’ notice, during business hours, without disrupting operations and without access to other customers’ data. Each side bears its own costs.
10. Liability and precedence
10.1 Liability follows the Terms of Service. Article 82 GDPR is unaffected.
10.2 This agreement prevails over the Terms of Service on data protection. Where a signed contract contains its own data processing terms, those prevail.
10.3 German law applies, and the courts named in the Terms of Service have jurisdiction.
Annex 1: Details of the processing
1. Subject matter and purpose
Werk24 reads technical drawings for the customer and makes the results available:
- through the API: receiving a drawing, reading it (text recognition, Werk24’s own detection models, and large language models that interpret parts of the drawing), returning the results to the customer’s systems and, where the customer asks for it, marking the personal data in the title block so it can be masked (redaction);
- in the console’s test reader and in Werk24 Studio: the same reading, plus keeping the drawings, results, balloon drawings and reports in the customer’s workspace, and the sharing, approval, verification and team functions the customer uses;
- sending the e-mails the customer triggers, such as invitations, approval requests and share links;
- support, troubleshooting and the security of the service.
2. Types of personal data
- names, initials, signatures, e-mail addresses, phone numbers and company details that appear on drawings, for example in title blocks, revision tables and approval fields;
- file names and other metadata of the files the customer uploads;
- in the Studio: names and e-mail addresses of team members, approvers, suppliers and customers the customer invites or shares with; who prepared and approved a report; comments and annotations;
- technical data of the people who use the service for the customer, such as IP addresses and times in logs.
The customer does not submit special categories of personal data (Article 9 GDPR).
3. Data subjects
The customer’s employees and contractors (designers, checkers, approvers and users), and people at the customer’s customers and suppliers who are named in drawings or whom the customer invites.
4. Nature of the processing
Receiving, storing, reading and analysing, retrieving, using, disclosing to the people the customer shares with, masking and erasing.
5. How long each part is kept
Zero retention means an account with every data contribution switched off in the console (Terms of Service, 7.3).
| What | Kept |
|---|---|
| A drawing sent to the API | Deleted automatically after 1 day (in practice within 2); with zero retention, as soon as its read has finished |
| The result files of an API request | Deleted automatically after 1 day |
| The state of an API request, including the webhook address and headers | 14 days |
| A cached copy of a result, to answer a repeat of the same request | About 1 day; never with end-to-end encryption or zero retention |
| Cached answers of language models to parts of a drawing | 7 days after their last use; never with end-to-end encryption or zero retention |
| The record of each API request: account, time, pages, what was asked (including the words the customer asked to redact), how the read ended and, except with zero retention, a fingerprint of the file to count repeated requests | 10 years from the end of the year, as a billing record |
| Drawings, results and reports in the Studio and in the console’s test reader | For the term of the agreement, until deleted under section 8 |
| Application logs, which can contain file names, request ids and account names; the reader’s logs leave out text read from drawings | Up to 365 days |
| Error reports, which can contain request ids, account names, file names and, from an account that contributes text fragments, short text fragments | 90 days |
| Backups of the databases | 90 days; a locked copy in a second EU region at most 365 days |
6. Where
- Amazon Web Services in Frankfurt, Germany (eu-central-1), for storage and processing;
- without the data residency add-on (on Pay as You Go, and on Production unless it is booked), Werk24 chooses the region, and language models on Amazon Bedrock may run on AWS’s global inference profiles, which can serve a request from an AWS region outside the European Union;
- with data residency in the EU booked: language models on Amazon Bedrock within the European Union only, in Frankfurt and in the other EU regions of AWS’s EU inference profiles, such as Ireland and Stockholm;
- backups and replicas in Stockholm, Sweden (eu-north-1);
- error reports in Sentry’s EU data region;
- for an account that books data residency in the US (an add-on in the console): Amazon Web Services in N. Virginia, USA (us-east-1), for storage, processing and language models, in place of the EU locations above, once the console shows that region serving the account.
Annex 2: Technical and organisational measures
These are the measures under Article 32 GDPR.
Encryption
- In transit: every connection to Werk24, including the API, the console and the Studio, uses TLS 1.2 or newer. The storage refuses unencrypted connections, and connections to the caches are encrypted. Results sent to a webhook travel encrypted when the customer’s webhook address uses https, which Werk24 recommends.
- At rest: object storage is encrypted with AES-256, for API drawings and results with keys held in AWS Key Management Service that rotate. Databases, caches and disks are encrypted by AWS.
- Optional: with the customer-managed key add-on, the API’s storage uses a key of the customer’s own. With end-to-end encryption, the drawing is encrypted for each request and decrypted only while it is read; the structured results are not end-to-end encrypted.
Access control
- Werk24 runs on AWS, which is responsible for the physical security of its data centres.
- Administrative access is limited to the Werk24 staff who need it, through individual accounts with single sign-on, and through AWS roles that carry only the permissions a task needs.
- The services reach each other through narrowly scoped roles. Databases and caches sit in private networks with no access from the internet.
- Customer API keys are stored only as hashes. Customers sign in through Amazon Cognito with passwords of at least 10 characters, and the console adds a sign-in code sent by e-mail.
- Every customer’s data is stored and served under its account, and the service checks the account on every request.
Integrity and logging
- AWS CloudTrail records administrative actions in every region, with log file validation.
- Network flow logs, threat detection (Amazon GuardDuty) and vulnerability scanning of servers, container images and functions (Amazon Inspector).
- Dependencies are checked for known vulnerabilities daily. The reader’s runtime image has no shell and runs without root rights on a read-only file system.
Availability and resilience
- The reader runs on several servers across two availability zones and replaces failed ones automatically.
- Databases are backed up daily and kept for 90 days, with a locked copy in a second EU region; point-in-time recovery covers the last 35 days. A failed backup raises an alarm.
- Recovery targets: the service is back within 4 hours (RTO), with at most 24 hours of data lost (RPO). A full restoration after a complete failure has been tested.
- The service is checked end to end every half hour, and its status is published.
Data minimisation
- Drawings and results of API requests are deleted automatically (Annex 1, section 5).
- On request, results come with the personal data in the title block marked for masking (redaction).
- The reader’s logs leave out text read from drawings. The error reports of the Studio and the console contain no e-mail addresses, and the addresses they report are cut before any query string or fragment, where share links and access codes are kept. The Studio and the console record no session replays.
Organisation
- Everyone with access is bound to confidentiality.
- Werk24 reviews the security of its service and tracks findings until they are fixed.
- Personal data breaches are handled as section 7 says.
Annex 3: Subprocessors
| Subprocessor | What for | Where | Safeguard for transfers |
|---|---|---|---|
| Amazon Web Services EMEA SARL, Luxembourg | Hosting, storage, databases, sending e-mail (Amazon SES), text recognition (Amazon Textract) and language models (Amazon Bedrock) | European Union; without the data residency add-on, language models also in AWS regions outside the European Union; with data residency in the US, N. Virginia, USA (Annex 1, section 6) | Storage and processing in the EU. AWS’s data processing addendum includes the standard contractual clauses, which cover language model requests served outside the EU without the data residency add-on and any access from outside the EEA; for data residency in the US, the EU-U.S. Data Privacy Framework and those clauses |
| Functional Software, Inc. (Sentry), San Francisco, USA | Error monitoring | Sentry’s EU data region | EU-U.S. Data Privacy Framework and standard contractual clauses |
| Microsoft Ireland Operations Limited, Dublin, Ireland (Microsoft 365, Outlook) | E-mail, for messages and files the customer sends to Werk24’s addresses | Microsoft’s data centres in the EU | Processing in the EU; Microsoft’s data protection addendum includes the standard contractual clauses and relies on the EU-U.S. Data Privacy Framework for any access from outside the EEA |
The subprocessors page shows the current list and explains who is not a subprocessor.
W24 Service GmbH, Therese-Studer-Straße 14, 80797 München, Germany. Questions:support@werk24.io, or privacy@werk24.io on data protection.