Data Processing Agreement (DPA)
The German version is authoritative.
pursuant to Art. 28 GDPR for the use of the roleALPHA platform
Language note: This is a translation for information purposes. In the event of any discrepancy, the German version prevails.
Version applicable at the time. This agreement and its annexes are published at
https://rolealpha.com/en/legal/data-processing. Annexes 2 and 3 evolve with the product; the
version published there is the one that applies. A printed or signed copy of this agreement
remains unaffected.
Contract data
| Item | Value |
|---|---|
| Customer (controller), company name and full address | as specified in the main contract or the order |
| Customer's VAT or commercial register number | as specified in the main contract or the order |
| Main contract or order (designation and date) | as specified in the main contract or the order |
| Operating model (M1, M2 or M3 per Annex 1.2) | as specified in the main contract or the order |
| Functions ordered (modules) | the Data Nodes switched on by the Customer in the platform |
| Customer's persons authorised to issue instructions | as specified in the main contract or the order; failing that, the persons recorded as administrators in the customer account |
| Customer contact for personal data breaches and notices | as specified in the main contract or the order; failing that, the administrator address recorded in the customer account |
1 Parties and scope
The processor is roleALPHA GmbH, Aschergasse 34, 1130 Vienna, Austria, commercial register number FN 685262p, registry court Commercial Court of Vienna (the "Provider" or "roleALPHA"). Data protection officer: ⟨TODO: name/contact of the data protection officer⟩. The controller is the Customer named in the contract data — the undertaking that is the contractual partner of roleALPHA under the Terms of Service (the "Customer").
This agreement governs the processing of personal data carried out by roleALPHA on behalf of the Customer in providing and operating the roleALPHA platform. It applies to all activities in which staff of roleALPHA or subprocessors engaged by roleALPHA process personal data of the Customer. It takes effect upon acceptance of the Terms of Service and forms an integral part of them; at the Customer's request it is additionally signed separately.
Order of precedence. In the event of a conflict between this agreement and the Terms of Service or other agreements between the parties, this agreement prevails in data protection matters. Mandatory statutory provisions remain unaffected.
Delimitation. Processing that roleALPHA carries out as a controller in its own right is not the subject of this agreement — in particular contract and billing data, user account and sign-in data as such, server logs, usage statistics and the handling of support and feedback cases. These are described in the Privacy Policy. Data processed on behalf of the Customer do not become data processed in roleALPHA's own right merely because they appear in a support case or a log.
Operating model. The scope of processing depends on where the Data Nodes are operated. The three models M1, M2 and M3 are described in Annex 1.2. The model applies per Data Node: it follows from the site the Customer chooses for that Data Node in the platform and may differ within one Customer. A model named in the contract data denotes the default; the site chosen in the platform prevails.
2 Processing
The subject matter is the personal data that the Customer enters into the platform, has generated there or has transferred from its source systems; data categories and categories of data subjects are set out in Annex 1.1.
The purpose is solely the provision of the agreed services: providing and operating the platform for organisational, role and value creation management including the modules activated by the Customer. This covers transfer from source systems, draft and approval procedures, analyses and reports, transmission to AI services released by the Customer, logging for traceability and audit, notification, support, maintenance, backup, restoration, export and deletion. Use for monitoring the performance or conduct of individual employees is not part of the assignment.
The nature of the processing covers collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission to recipients released by the Customer, alignment, restriction, erasure and destruction, in each case to the extent required.
The place of processing is the European Union or the European Economic Area, unless Annex 3 expressly designates a third country; this essentially concerns AI services where the Customer releases them.
Duration. Processing begins when the contract starts and ends when the main contract ends; thereafter section 7 applies.
3 Instructions and Customer obligations
roleALPHA processes personal data solely on documented instructions from the Customer (Art. 28(3)(a) GDPR). The main contract, this agreement including its annexes and the configurations made by the Customer in the platform constitute documented instructions — in particular switching Data Nodes on and off, choosing their site and moving them to another site, the release of data areas for AI functions, the setting up of connectors, the definition of retention periods and the granting of permissions and visibilities. Individual instructions beyond that are issued by the Customer in writing or text form to the contact named in section 9; oral instructions are to be confirmed in text form without delay. Additional effort arising from such instructions may be charged at the rates then applicable.
roleALPHA acting on the Customer's behalf. On the Customer's instruction — for example in a support case — authorised staff of roleALPHA may make configurations in the platform that the Customer would otherwise make itself (Data Nodes, settings of the AI functions, company and billing data). Every such change technically requires a reason to be given; without a reason it is rejected. It is logged with time, acting person, operation and reason and is recognisable to the Customer in its log as an action on behalf of roleALPHA. Merely viewing configurations is not recorded in this way. Such a change counts as the execution of an individual instruction under this section; it does not replace the instruction.
roleALPHA informs the Customer without undue delay if, in its opinion, an instruction infringes data protection law, and is entitled to suspend its execution until the Customer confirms or amends it. roleALPHA does not process the data for its own purposes; in particular, customer content is not used to train or improve AI models of roleALPHA or of third parties unless expressly and separately agreed.
The Customer, as controller, is responsible for the lawfulness of the processing, for a legal basis, for the information duties under Art. 13 and 14 GDPR and for compliance with employment and co-determination law. It does not enter special categories of personal data (Art. 9 GDPR) or data on criminal convictions (Art. 10 GDPR) without prior agreement with roleALPHA and a sound legal basis; the platform is not designed for the targeted processing of such data. It manages permissions and visibilities on its own responsibility, keeps credentials confidential, removes departed users promptly, decides on the use of the AI functions and the scope of the data areas released (consequences: section 5 of this agreement), and in models M2 and M3 secures the infrastructure of its Data Nodes appropriately and cooperates on updates. It confirms that it has taken note of the measures under Annex 2 and assessed them as adequate for its processing; if it requires further measures, these are to be agreed separately in writing.
4 Confidentiality and security
roleALPHA ensures that the persons authorised to process the data are committed to confidentiality — unless they are already under a statutory duty of secrecy — and receive appropriate data protection training (Art. 28(3)(b) GDPR). roleALPHA takes the technical and organisational measures required under Art. 32 GDPR; they are described in Annex 2.
The measures are subject to technical progress. roleALPHA is entitled to adapt them as long as the level of protection is not reduced; roleALPHA documents material changes and communicates them to the Customer in text form on request.
In models M2 and M3 the measures for the infrastructure on which the Data Nodes are operated — physical security, network security, operating system hardening, disk encryption, backups and recoverability — are the responsibility of the Customer or the host it has chosen. There, roleALPHA is responsible for the measures of the software provided and of the Core operated by roleALPHA.
5 Subprocessors and transfers
The Customer grants general written authorisation for the engagement of subprocessors (Art. 28(2) GDPR). The subprocessors engaged are listed in Annex 3 and are thereby authorised.
roleALPHA notifies the intended addition or replacement of a subprocessor with at least 14 days' prior notice in text form (by e-mail to the address named in the contract data or as a notice in the platform), stating name, address, service, data categories, places of processing and, where applicable, third-country safeguards. The Customer may object within that period on substantial data protection grounds. If it objects, the parties seek an amicable solution; if none is possible and roleALPHA cannot provide the service at the agreed quality without that subprocessor, either party may terminate the main contract in respect of the affected service on one month's notice.
roleALPHA concludes a contract with every subprocessor imposing substantially the same data protection obligations, reviews the subprocessor before engagement and thereafter as circumstances require, and is liable for its compliance with data protection obligations as for its own acts.
Not subprocessors within this meaning are: providers of AI services for which the Customer supplies its own access ("BYOK") — they are processors of the Customer, who concludes that contract itself; the host of the Data Nodes in models M2 and M3 — engaged by the Customer; and providers of pure telecommunications services as well as roleALPHA's professionals bound by professional secrecy.
Third-country transfers take place only where Annex 3 designates them and only on a permissible mechanism: an adequacy decision (Art. 45 GDPR, in particular the EU-U.S. Data Privacy Framework) or the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR) together with an assessment of the transfer circumstances. In practice this concerns AI services: they require an express release by the Customer; without release of a data area, no content from that area is transmitted (fail-closed default). The Customer may withdraw the release at any time and operate the platform entirely without third-country transfers. If an authority of a third country demands access to the Customer's data, roleALPHA informs the Customer without undue delay unless legally prohibited from doing so; in that case roleALPHA works towards limiting the access to the extent legally permissible and has its admissibility reviewed.
6 Assistance and incidents
roleALPHA assists the Customer with requests from data subjects under Chapter III GDPR (Art. 15 to 22). The Customer fulfils data subject rights primarily using the platform's own functions — search, display, editing, export and deletion functions as well as permission management. If a data subject approaches roleALPHA directly, roleALPHA will not answer the request on the merits but will forward it to the Customer without delay or refer the person to the Customer. Assistance beyond that is provided at reasonable effort; that effort may be charged unless it is attributable to fault on the part of roleALPHA.
roleALPHA informs the Customer of a personal data breach within its own sphere of responsibility without undue delay and at the latest within 48 hours of becoming aware of it, in text form to the address named in the contract data. The notification contains, as far as available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken and proposed, and a contact point for queries; missing information is supplied subsequently. roleALPHA assists with the obligations under Art. 33 and 34 GDPR; notifications to a supervisory authority or to data subjects are made by the Customer, unless the law provides otherwise. roleALPHA likewise assists with a data protection impact assessment under Art. 35 GDPR and a prior consultation under Art. 36 GDPR; carrying them out and assessing the outcome is for the Customer.
Note on co-determination. A data protection impact assessment is regularly required in particular when using the Interaction Signals (organisational intelligence) function. That function, as well as effort booking and competence assessments, may engage the co-determination rights of employee representatives (§§ 96, 96a ArbVG and, for employees outside Austria, the co-determination law applicable there). Further detail in Annex 1.3.
7 Return and deletion
Switching off is not deletion. If the Customer switches a Data Node off, its data is hidden but not deleted; it stays on the site and returns unchanged when switched on again. Deletion takes place under this section or on express instruction.
During the term the Customer may at any time back up its data via the platform's export function in a structured, commonly used and machine-readable format; safekeeping the exported data is for the Customer. By the end of the contract it states whether it chooses return or deletion; absent such a statement, deletion is deemed agreed.
roleALPHA completes the return and subsequent deletion, or the immediate deletion from the active systems, within 30 days of the end of the contract. Deletion also covers domain audit logs, change histories and any other copies of the data processed on behalf of the Customer. The only exceptions are:
| Retained | Reason and basis |
|---|---|
| Audit logs (default 365 days, may be shortened by the Customer) | evidence and audit obligations; traceability of changes (Art. 6(1)(c) and (f) GDPR) |
| AI usage logs (provider, model, tokens, cost — without content) | basis for billing; retention under tax law (§ 132 BAO) |
| Contract, subscription and invoice data | proof of contract; retention under tax law (§ 132 BAO) |
| User accounts that are also assigned to other tenants | an account may exist in several tenants; the assignment to the terminated tenant is removed together with its associated data |
| Certificates of a customer domain | separate deletion procedure because of side effects in the server configuration; deleted on request |
| Generated contract copies of this agreement including the company details inserted into them | proof of contract: they evidence which version the Customer accepted and when; retention under tax law (§ 132 BAO) |
These data are deleted once the respective retention period expires and their processing is restricted in the meantime. Backups are deleted or overwritten at the latest 90 days after the data concerned have been deleted from the active systems; until then they are excluded from ongoing access and used solely for restoration in the event of a malfunction. Deletions already carried out are applied again before restored data are used productively. roleALPHA confirms deletion in text form on request.
In models M2 and M3 the Customer is responsible for return and deletion on its own infrastructure or at its host; roleALPHA assists it and deletes the data held by roleALPHA and its subprocessors under the rules above.
8 Evidence and inspections
On request, roleALPHA provides the information required to demonstrate compliance with the obligations under Art. 28 GDPR — in particular the technical and organisational measures, the list of subprocessors and any audit reports, attestations or certificates available. roleALPHA maintains a record of all processing activities carried out on behalf of the Customer under Art. 30(2) GDPR and presents it on request.
The Customer is entitled to verify compliance with this agreement — itself or through an auditor bound to confidentiality who is not in competition with roleALPHA. Inspections are to be announced with at least 14 days' notice, confined to business hours and conducted with minimum disruption to operations; absent particular cause, one inspection per calendar year is provided for, and more frequently in the event of an established personal data breach or an order by an authority. Where the available evidence is sufficient for the assessment, it takes precedence. Access to systems containing other customers' data is excluded; inspections preserve tenant separation. The Customer bears its own costs of the inspection; the effort incurred at roleALPHA is charged at the rates then applicable unless the inspection reveals an infringement by roleALPHA.
9 Contact and signing
Data protection enquiries and instructions to roleALPHA: datenschutz@rolealpha.app. roleALPHA keeps a data protection officer appointed and communicates their contact details to the Customer; they appear in the header of this document. In the contract data the Customer names its persons authorised to issue instructions and a reachable contact for personal data breaches and contractual notices; until a separate designation is made, the persons recorded as administrators in the customer account are deemed authorised and the address recorded there is deemed the contact address.
Annexes 1 (description of processing), 2 (technical and organisational measures) and 3 (subprocessors) form part of this agreement. The agreement is concluded in writing, including electronically; separate signature is not required but is possible.
Vienna, on ____________
| Customer | roleALPHA |
|---|---|
| ______________________ |
______________________ |
| Name, function | Name, function |
10 Liability and final provisions
Liability is governed by Art. 82 GDPR and by the provisions of the main contract, in so far as these do not conflict with mandatory law.
Amendments and supplements to this agreement require written or text form; this also applies to any amendment of this clause. Updates to Annexes 2 and 3 under section 4 and section 5 respectively remain unaffected — they are not amendments to the contract.
Should individual provisions be or become invalid, the validity of the remaining provisions remains unaffected; the invalid provision is deemed replaced by a valid one that comes closest to the purpose pursued.
Austrian law applies. The place of jurisdiction is Vienna, in so far as legally permissible.
Annex 1 — Description of processing
1.1 Data subjects and data categories
Those affected are the Customer's employees including managers and apprentices, external staff, contractors, consultants and temporary workers, contacts of the Customer's customers, suppliers and partners, other persons named in the content entered, and the users of the platform on the Customer's side.
The data processed are those required for the functions ordered. Which Data Nodes actually hold data depends on the modules activated by the Customer.
| Data category | Covers in particular | Data Node |
|---|---|---|
| Identity, contact and access data | Master and contact data (name, personnel number, business contact details, profile picture, language); Permission and visibility data; Entitlement assignments taken from source systems (assigned groups, roles, profiles with the date of last use) | Persons, Connectors, Core |
| Organisational and employee data | Organisational and role data (units, role assignments, responsibilities, deputies); Competence data including assessments; Working time and capacity data (contractual weekly working time, level of employment, periods of absence without stating the reason); Effort and time data; Demand and planning data (capacity required, activities and competences required, assignments) | Roles, Org charts, Competences, Effort booking, Demand, Persons |
| Domain content and planning | Value creation and policy data; Objective and project data; Meeting data; IT landscape, risk and cost centre data; Drawings and whiteboards; Scenario and simulation data; Relationship and link data; document references (web addresses and designation only) | Value creation, Policies, Objectives (OKR), Projects, Meetings, IT landscape, Risks, Cost centres, Drawings, Core |
| Procedures and analyses | Draft and approval data including change history and named baselines; Log data; Automation data; Validation data; Governance analysis data; Analysis and reporting data; Interaction metadata (pseudonymous actor identifiers and aggregated weights, maximum retention 90 days) | Core, Automator, Validator, Aggregator, Interaction signals |
| AI and integration data | AI assistance and knowledge data (chat histories, individual messages, attachments, knowledge base); AI agent data including reported consumption; Rehearsal data; Vector representations (embeddings); AI usage logs; Connector data including encrypted credentials of the source systems | Context, Agents, Connectors, Core |
| Operational and communication data processed on behalf of the Customer | Notification data (recipient, occasion as a key, object references, read status); E-mail delivery log; the tenant's e-mail dispatch path including encrypted credentials for the Customer's mail system; External application access (OAuth); sampling data of the suitability check | Core |
What is expressly not processed. The change history in the Core does not hold the changed field values — these remain with the respective Data Node; named baselines are lists of pointers, not a copy of the data. Document references cover no files and no document content; retrieval takes place directly between the browser and the source system. The application provides no field for the reason of an absence; no health data under Art. 9 GDPR therefore arise, and no working times are recorded and no attendance logs are kept. Interaction metadata contain no content and no individual events. Entitlement assignments contain no sign-in history, no device or location data and no time patterns. AI agents are not executed by roleALPHA; their consumption is reported by the Customer's runtime environment. The rehearsal room simulates only archetypes representing five or more people, without names or personal identifiers, and does not feed back into personal data. AI usage logs contain no request content. Sampling data of the suitability check are held in memory only and are not stored. Notifications and the delivery log contain no message text and no object designations; external application access contains no content data and no keys in clear text.
Source systems and recipients in detail. Connectors take data from the Customer's source systems: Entra ID, LDAP directories, SAP HCM, SAP FI and Microsoft Dynamics. The interaction signals evaluate metadata from Microsoft Graph, Jira, Confluence, SharePoint, LDAP, iCal calendars, a file system, a CSV import and a browser-based collection service — in each case only where the Customer sets that source up. The AI providers available are Anthropic, OpenAI, Google and Mistral; only the one designated by the Customer is used, and only for the data areas it has released. Address, place of processing and transfer mechanism per provider are set out in Annex 3. Where the Customer sets up its own e-mail dispatch path for its tenant, roleALPHA hands that tenant's mail to its mail system (its own SMTP server or its own Microsoft 365 tenant); where it switches dispatch off, no mail is sent. These source systems and the Customer's mail system are systems of the Customer and not subprocessors of roleALPHA.
Special categories of personal data under Art. 9 GDPR and data under Art. 10 GDPR are not the subject of the intended assignment; their targeted processing requires a prior separate agreement. Free-text fields, attachments and imports may nevertheless contain such information and are to be limited accordingly by the Customer.
1.2 Operating models and responsibilities
The Core comprises identities, permissions, visibilities, metadata, logs and AI mediation and is operated by roleALPHA in all models. The Data Nodes hold the domain content of the respective functions; only they move between the models. Personal customer content can arise in the Core as well.
| M1 — Fully managed | M2 — Hybrid | M3 — Customer cloud | |
|---|---|---|---|
| Data Nodes | operated by roleALPHA | operated by the Customer on its own infrastructure | operated at a third-party host of the Customer |
| Storage location of the domain content | infrastructure of roleALPHA (netcup, Vienna data centre) | infrastructure of the Customer | infrastructure of the Customer's third-party host |
| Processing of the domain content by roleALPHA | in full under section 2 | only (a) during support and maintenance access, (b) for functions triggered by the Customer that pass through the Core (AI requests, cross-domain search, reports), (c) for export and restoration on instruction | as M2 |
| Backups of the domain content | roleALPHA | Customer | Customer |
| Physical and infrastructure security of the Data Nodes | roleALPHA | Customer | Customer's third-party host |
| The host of the Data Nodes is a subprocessor of | roleALPHA (see Annex 3) | the Customer or self-operated | the Customer |
Model per Data Node. Which model applies is decided by the site of the individual Data Node: a site operated by roleALPHA results in M1, one operated by the Customer itself in M2, one at its third-party host in M3. A Customer may mix models — for example People in its own data centre, OKRs with roleALPHA. Choosing or changing the site of a Data Node (move) counts as a documented instruction under section 3; roleALPHA logs every such operation with time, acting person, source and target site and the model before and after.
rA Cloud. Besides the sites roleALPHA sets up for an individual Customer, roleALPHA operates rA Cloud, a shared site open to the Customers of all realms. A Data Node on rA Cloud is M1: roleALPHA operates it, the domain content resides on roleALPHA's infrastructure (Annex 3), and roleALPHA makes the backups. Data Nodes of several Customers run side by side on rA Cloud; the domain content remains separated per Customer (Annex 2, section 2). A Data Node runs there only if its site has been set to rA Cloud explicitly — never implicitly.
The Data Nodes report their operations via an event bus operated at roleALPHA. Only metadata travel across it — who triggered which operation on which object and when. The changed record itself is written by the Data Node directly into its own change log and does not leave its database. Until September 2026 this was different: the record was sent along and therefore lay in the platform's message store for seven days. That detour no longer exists. Even temporary processing in the Core falls under this agreement; all data held by roleALPHA and its subprocessors on behalf of the Customer are subject to the rules in section 7. Hosts or AI providers engaged directly by the Customer belong to its own contractual relationships; an own access key alone does not determine that classification.
1.3 Processing with elevated risk
| Processing | Risk | Precondition | Responsibility for the risk assessment |
|---|---|---|---|
| Interaction signals (organisational intelligence) | analysis of collaboration patterns; co-determination; possible re-identification in small groups | express activation by the Customer (switching on the interaction signals data node by its administrator) | Customer (DPIA under Art. 35 regularly required; roleALPHA assists under section 6) |
| Transmission to AI services in third countries | third-country transfer, access by authorities under foreign law | release per data area by the Customer (fail-closed default) | Customer; transfer mechanisms see Annex 3 |
| Remote maintenance access to customer-side systems (M2/M3) | roleALPHA gaining knowledge of customer content | provision of the access by the Customer; purpose-bound and logged | jointly; roleALPHA logs and limits the access |
| Effort booking, competence assessments, governance analysis | performance-related data of employees; inferences about responsibilities and ways of working. When comparing booked effort with modelled participation, only an aggregate per object leaves the effort service (sum and number of booking persons, the latter only above the minimum group size) — no person, no booking description, no individual booking day | activation of the modules by the Customer; person-level analysis only after express opt-in by the Customer's administrator (instruction); otherwise aggregated only | Customer (check co-determination) |
| Entitlement review (comparison of assigned permissions with the role model) | inferences about the responsibilities of individual employees; co-determination | activation of the connector by the Customer; the analysis serves the implementation of Art. 32 GDPR and is in the employees' own interest | Customer (check co-determination; DPIA depending on scope) |
1.4 Retention periods
For logging and temporary data the platform provides retention periods that are configurable per tenant; automated deletion runs enforce them. The Customer may set them within the technical limits — the values below are the defaults.
| Data category | Default | Configurable |
|---|---|---|
| Audit logs and change history | 365 days | yes |
| AI chat histories | 365 days | yes |
| Governance findings and analysis runs (open findings do not expire) | 365 days | yes |
| Drafts once decided; open decisions do not expire | 90 days | yes |
| Scenario and simulation data | 90 days | yes |
| Notifications | 90 days | yes |
| Interaction metadata (technically enforced maximum) | 90 days | shorter only |
| Application and server logs | 30 days | yes |
| AI chat attachments | 30 days | yes |
| Operational metrics | 7 days | yes |
| Domain content overall | until deleted by the Customer; after the end of the contract see section 7 | Customer decides |
Annex 2 — Technical and organisational measures
The separate document Technical and Organisational Measures (Art. 32 GDPR) applies in its version applicable at the time, published at https://rolealpha.com/en/legal/security-measures.
Annex 3 — Subprocessors
The separate, versioned document Subprocessors applies in its version applicable at the time, published at https://rolealpha.com/en/legal/subprocessors.
Related documents
Deutsche Fassung (maßgeblich): Auftragsverarbeitungsvertrag
© 2026 roleALPHA GmbH