° Data Processing Agreement
for 36T Cloud, pursuant to Art. 28 GDPR · Version: October 2026
This English version is provided for convenience. Only the German version is legally binding.
between the customer (controller, “client”) and 36T Solutions GmbH (processor, “36T”). This agreement is concluded with the order of 36T Cloud and forms part of the contract under 36T’s terms and conditions (Part B, § 24).
§ 1 Subject Matter, Duration, Precedence
(1) 36T processes personal data on behalf of the client to the extent required to provide 36T Cloud. The subject matter, nature and purpose of the processing, the types of data and the categories of data subjects are set out in Annex 1.
(2) This agreement applies for the duration of the main contract and beyond for as long as 36T processes the client’s data.
(3) In the event of conflict, this agreement takes precedence over the terms and conditions on matters of data protection. Otherwise the terms and conditions apply, in particular on liability.
§ 2 Instructions
(1) 36T processes the data only on documented instructions from the client, unless 36T is legally required to process it; in that case 36T informs the client of that legal requirement before processing, unless the law prohibits this.
(2) The instructions are given conclusively by the main contract, this agreement and the client’s use of the functions of the instance and the customer portal. The client gives further instructions in text form. 36T may refuse instructions that go beyond the agreed scope of services or carry them out against separate payment.
(3) If 36T believes that an instruction infringes data protection law, 36T informs the client and may suspend its execution until the instruction is confirmed or changed.
§ 3 Responsibility of the Client
(1) The client is solely responsible for the lawfulness of the processing, for safeguarding the rights of data subjects and for the choice of data it stores in the instance.
(2) If the client stores special categories of personal data (Art. 9 GDPR) or data requiring special protection, it makes the necessary decisions itself; the measures in Annex 2 apply equally to all data.
§ 4 Confidentiality
36T only uses persons for the processing who are bound to confidentiality or subject to a statutory duty of secrecy.
§ 5 Security of Processing
(1) 36T takes the technical and organisational measures under Art. 32 GDPR described in Annex 2.
(2) The measures are subject to technical progress. 36T may change them and replace them with others, provided the overall level of security is not reduced. No notice to the client is required for this.
§ 6 Logs and Metrics
(1) The processing includes 36T collecting, storing and analysing logs and metrics of the instance and the underlying systems, which may contain personal data, such as user names, IP addresses, timestamps and functions used. This serves operation, monitoring, troubleshooting, security, capacity planning and billing.
(2) 36T determines the type, scope and retention period according to operational need.
(3) Anonymised or aggregated data that allows no conclusions about natural persons is not personal data within the meaning of this agreement; 36T may use it for its own purposes (terms and conditions § 22 (3)).
§ 7 Sub-processors
(1) The client gives 36T general authorisation to engage other processors (“sub-processors”), in particular for data centre and hosting, backup, payment processing, communication and operational monitoring.
(2) The current sub-processors are listed in 36T’s customer portal (Annex 3). 36T informs the client of any intended addition or replacement by updating the list and notifying the client in text form or in the customer portal.
(3) The client may object to a change in text form within 14 days of the notice for an important reason under data protection law. If 36T cannot remedy the objection, either party may terminate the main contract with effect from the change. No further claims exist. Without a timely objection, the change is deemed approved.
(4) 36T binds sub-processors contractually in a manner that meets the requirements of Art. 28 (4) GDPR.
(5) Ancillary services that 36T obtains from third parties and that do not involve access to the client’s data, such as telecommunication and transport services, are not sub-processing.
§ 8 Place of Processing
Processing takes place in principle in the European Union or the European Economic Area. Processing in a third country is permitted if the requirements of Art. 44 et seq. GDPR are met, for example through an adequacy decision or standard contractual clauses.
§ 9 Assistance to the Client
(1) Within reason, 36T assists the client with appropriate technical and organisational measures in responding to requests from data subjects (Art. 12–22 GDPR) and with the obligations under Art. 32–36 GDPR, taking into account the nature of the processing and the information available to 36T.
(2) The instance provides the client with the functions to view, correct, export and delete data itself. If a data subject contacts 36T directly, 36T refers them to the client.
(3) The client pays for assistance beyond the provision of these functions by effort, unless it is caused by a breach by 36T.
§ 10 Notification of Breaches
36T notifies the client without undue delay after becoming aware of a personal data breach affecting the client’s data, with the information available to 36T at that time. Notification of the supervisory authority and of data subjects is the client’s responsibility.
§ 11 Evidence and Audits
(1) On request, 36T provides the client with the information necessary to demonstrate compliance with this agreement. Evidence may be provided in particular through self-assessments, documentation, certificates or audit reports, including those of sub-processors.
(2) If this evidence is insufficient in an individual case, the client may carry out an audit itself or have it carried out by an auditor bound to confidentiality who is not a competitor of 36T. Audits must be announced at least four weeks in advance, take place during normal business hours without disrupting operations, at most once per calendar year unless there is a specific reason, and do not extend to other customers’ data or to 36T’s trade secrets. The client bears the costs of the audit, including 36T’s effort.
(3) On-site audits at sub-processors’ data centres are subject to their terms; their certificates and audit reports may take their place.
§ 12 Deletion and Return
(1) After the end of the main contract, 36T returns the data by allowing the client to retrieve or request an export in Odoo’s standard format until deletion (terms and conditions §§ 15 (5), 20). 36T then deletes the data in accordance with the terms and conditions, unless there is a legal obligation to retain it.
(2) Data in backups and logs is deleted in the course of the regular deletion cycles and protected against any further processing until then.
(3) On request, 36T confirms the deletion in text form.
§ 13 Liability
Liability towards data subjects is governed by Art. 82 GDPR. Between the parties, the liability provisions of the terms and conditions (§ 8) apply to the extent permitted by law.
§ 14 Final Provisions
(1) 36T may amend this agreement in accordance with terms and conditions § 12, in particular to adapt it to changes in the law or the services.
(2) German law applies. The place of jurisdiction is 36T’s registered office.
° Annex 1: Details of the Processing
Subject matter and purpose: provision, operation, maintenance, backup, monitoring and billing of an Odoo instance for the client, and support at its request.
Nature of the processing: storing, hosting, backing up and restoring, transferring, logging and analysing operational data, viewing in the course of maintenance and support, deleting.
Types of personal data: all data that the client and its users store in the instance (depending on the applications used, in particular contact and master data, contract, order and billing data, communication content, employee data, files and documents) as well as user accounts, log and usage data (§ 6).
Categories of data subjects: the client’s users, employees, customers, prospects, suppliers and other business partners and their contact persons, and other persons whose data the client stores in the instance.
Duration: term of the main contract plus the periods under § 12.
° Annex 2: Technical and Organisational Measures (Art. 32 GDPR)
As at the conclusion of the contract; changes under § 5 (2).
Confidentiality
- Operation in data centres of professional providers with physical access control.
- Administrative access to servers only via an encrypted, non-public network and only with personal accounts; no shared administrator account for people.
- Access rights on a need-to-have basis; withdrawn when no longer needed.
- Separation of customers: each instance with its own database, its own credentials and its own containers or virtual machine.
- Persons involved are bound to confidentiality.
Integrity
- Transmission between user and instance exclusively encrypted (TLS).
- Logging of operational and access events (§ 6).
Availability and Resilience
- Regular, automated backups; backups are encrypted and kept separately from the production system.
- Monitoring of system health and load.
- Timely application of security-relevant updates.
Restoration
- Ability to restore an instance from a backup.
Review
- Regular review of the measures and adaptation to the state of the art.
° Annex 3: Sub-processors
The current list is available to customers in the customer portal (Navigator). Changes under § 7.