Skip to content
  • Features
  • Pricing
  • About
  • Resources
Signup | Login
  • Features
  • Pricing
  • About
  • Resources
Signup | Login
Terms Privacy DPA Imprint

Data Processing Agreement

Effective January 1, 2026 statycs GmbH

This agreement governs how statycs processes personal data on behalf of its customers, in accordance with Article 28 of the GDPR.

  • Parties & Scope
  • Nature & Purpose of the Processing
  • Data Categories & Data Subjects
  • Controller Obligations
  • Processor Obligations
  • Sub-processors
  • International Data Transfers
  • Security Measures
  • Data Breach Notification
  • Liability
  • Termination & Data Deletion

TABLE OF CONTENTS

  • Parties & Scope
  • Nature & Purpose of the Processing
  • Data Categories & Data Subjects
  • Controller Obligations
  • Processor Obligations
  • Sub-processors
  • International Data Transfers
  • Security Measures
  • Data Breach Notification
  • Liability
  • Termination & Data Deletion
01

Parties & Scope

This Data Processing Agreement (the "DPA") is entered into between the customer using statycs' services under a valid service agreement (the "Controller") and statycs GmbH, FN 613704g, Liechtensteinstrasse 59, 1090 Vienna, Austria (the "Processor").

This DPA governs the processing of personal data by statycs on behalf of the Controller in connection with the statycs SaaS platform for financial planning and analysis. It takes effect when the Controller accepts the Terms & Conditions, or otherwise enters into a service agreement with statycs, and remains in force for as long as statycs processes personal data on behalf of the Controller. In the event of a conflict between this DPA and other contractual provisions, this DPA prevails with respect to data protection matters.

Subject matter of the processing. The processing of personal data that is necessary for statycs to provide its financial planning and analysis platform to the Controller.

Duration of the processing. For the term of the underlying service agreement, including any wind-down and deletion period under §11 below.

02

Nature & Purpose of the Processing

statycs processes personal data to provide the Controller with its financial planning and analysis platform. The processing includes the collection, storage, organization, structuring, retrieval, consultation, use, and erasure of data, to the extent necessary to deliver the service.

Processing is carried out exclusively on the basis of the Controller's documented instructions. statycs will not process personal data for any purpose other than delivering the agreed service, unless required by EU or Austrian law. In that case, statycs will inform the Controller of the legal requirement before processing, unless the law prohibits such information.

03

Data Categories & Data Subjects

Categories of personal data. The following types of personal data may be processed: names, email addresses, phone numbers, job titles, company affiliation, IP addresses, browser and device data, and any other personal data the Controller enters into the platform. Financial data uploaded to the platform - such as accounting records, reports, and plans - may contain personal data to the extent the Controller includes it.

Categories of data subjects. Data subjects may include the Controller's employees, contractors, clients, vendors, investors, and any other natural persons whose personal data the Controller processes through the platform.

04

Controller Obligations

The Controller is the data controller under the GDPR and is solely responsible for ensuring the lawfulness of the personal data processing, including having a valid legal basis both for the processing itself and for transferring the data to statycs.

The Controller is responsible for the accuracy, quality, and legality of the personal data provided to statycs, and for compliance with all applicable data protection laws, including informing data subjects about the processing of their data.

05

Processor Obligations

statycs undertakes to:

  • Process personal data only on documented instructions from the Controller, unless required to do otherwise by law
  • Ensure that all persons authorized to process personal data are bound by written confidentiality obligations
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk
  • Assist the Controller in responding to data subject requests under Articles 15 to 22 GDPR
  • Assist the Controller with compliance with Articles 32 to 34 GDPR, data protection impact assessments, and prior consultations with supervisory authorities, taking into account the nature of processing and the information available to statycs
  • Notify the Controller without undue delay upon becoming aware of a personal data breach
  • Delete or return all personal data to the Controller upon termination of the service agreement, unless retention is required by law
  • Immediately inform the Controller if, in statycs' opinion, an instruction infringes the GDPR or other applicable data protection law

statycs satisfies the audit obligations under Art. 28(3)(h) GDPR by providing, on reasonable written request and no more than once per twelve months, its current security summary, sub-processor list, and written responses to the Controller's reasonable questionnaire. In addition, the Controller - or an independent auditor it mandates under a confidentiality obligation - may conduct an on-site audit no more than once every twenty-four months, or at any time following a mandate from a supervisory authority or a substantiated suspicion of a breach. On-site audits take place at the Controller's cost, on thirty days' prior written notice, during business hours, with scope, timing, and confidentiality agreed in writing in advance.

06

Sub-processors

statycs engages the following sub-processors to assist in delivering the service:

  • Google Analytics (Google LLC, USA) - analytics
  • PostHog (PostHog Inc., USA; PostHog Cloud EU hosted in Germany) - product analytics
  • Hanko (Hanko GmbH, Germany) - authentication
  • Zero (Zero Inc., Finland) - CRM
  • Hetzner (Hetzner Online GmbH, Germany) - hosting
  • Chatwoot (Chatwoot Inc., USA) - live chat for website visitors, not app users

statycs ensures that all sub-processors are bound by written agreements imposing equivalent data protection obligations. The Controller will be notified of any intended changes to sub-processors at least thirty days in advance. The Controller may object to a new sub-processor on reasonable grounds within fourteen days of notification. If the objection cannot be resolved, the Controller may terminate the contract effective on the date the sub-processor change takes effect, and statycs will refund prepaid fees on a pro-rata basis for the unused portion of the term.

07

International Data Transfers

statycs stores and processes customer data within the European Union and the European Economic Area. Where data must be transferred to sub-processors located outside the EU or EEA - in particular in the United States - statycs ensures that appropriate safeguards are in place in accordance with Chapter V of the GDPR.

These safeguards include the EU Standard Contractual Clauses adopted by the European Commission and, where applicable, adequacy decisions. statycs regularly assesses the legal framework of recipient countries to ensure ongoing compliance. A copy of the safeguards is available on request at [email protected].

08

Security Measures

statycs implements appropriate technical and organizational measures to protect personal data, including:

  • Encryption of data in transit (TLS) and at rest
  • Role-based access controls following the principle of least privilege
  • Multi-factor authentication for internal systems
  • Periodic security reviews appropriate to the nature and scale of processing, including third-party testing from time to time
  • Automated data backup and disaster recovery procedures
  • Logging and monitoring of access to personal data
  • Security awareness training for employees

A current description of the technical and organizational measures is available on request at [email protected].

09

Data Breach Notification

statycs will notify the Controller without undue delay upon becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects.

The notification will include, to the extent known: the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, the measures taken or proposed to address the breach and to mitigate its effects, and a contact point ([email protected]) from whom the Controller may obtain further information.

statycs will cooperate with the Controller and take reasonable steps to assist in the investigation, containment, and remediation of the breach.

10

Liability

Liability for data processing under this DPA is governed by the Terms & Conditions of the underlying service agreement. Nothing in this DPA alters or extends the liability provisions agreed between the parties.

Each party is liable for damages caused by processing that infringes the GDPR, in accordance with Article 82 GDPR. statycs is liable only for damage caused by processing that does not comply with the obligations specifically directed to processors under the GDPR or with the Controller's lawful instructions.

11

Termination & Data Deletion

This DPA terminates automatically upon termination of the underlying service agreement between the Controller and statycs.

Upon termination, personal data processed on behalf of the Controller is retained for 30 days and is then permanently deleted, unless the Controller requests return of the data in a structured, commonly used format during that period. statycs may retain personal data beyond this period only where required by EU or Austrian law, and will inform the Controller of any such requirement.

This DPA is governed by Austrian law. The exclusive place of jurisdiction is the competent court in Vienna.

Questions about data processing?

We're here to help. Contact our data protection team.

Contact us
Contact us

PRODUCT

  • Features
  • Pricing
  • Documentation

COMPANY

  • About
  • Resources
  • Jobs
2026 statycs GmbH. All rights reserved.
TermsPrivacyDPAImprint

We use cookies

We use cookies to improve your experience and analyze site usage. Privacy Policy