Skip to content
ProductsServicesProcessAbout Kais SolutionsContact
DEStart a project
Products Services Process About Kais Solutions Contact Start a project
Home/Terms/SmartShelf

SmartShelf

Data Processing Agreement

pursuant to Art. 28 GDPR – SmartShelf

Version 1.0As of 31 August 2026

Also for SmartShelf:Terms for IT and software servicesService level agreement and supportTechnical and organisational measures (TOMs)Sub-processors
This is a convenience translation. Only the German original is legally binding; in case of any discrepancy, the German version prevails.
Contents
  1. 1. Subject matter and purpose
  2. 2. Duration
  3. 3. Categories of data and data subjects
  4. 4. Instructions
  5. 5. Confidentiality
  6. 6. Security of processing
  7. 7. Data subject rights and assistance
  8. 8. Personal data breaches and obligations under Art. 32–36 GDPR
  9. 9. Audits and evidence
  10. 10. Termination, return and deletion
  11. 11. Sub-processors
  12. 12. Processing locations and third-country transfers
  13. 13. Final provisions

1. Subject matter and purpose

1.1.The subject matter is the processing of personal data by Kais Solutions on behalf of the Client in the course of providing, operating, maintaining, supporting, backing up and restoring SmartShelf.

1.2.This agreement supplements the contract on the implementation, provision and operation of the SmartShelf software solution.

1.3.The purpose of the processing is the technical provision and use of the agreed SmartShelf functions.

2. Duration

2.1.This agreement applies for the duration of the processing. After termination, the return and deletion obligations under section 10 continue to apply where necessary.

3. Categories of data and data subjects

CategoryDescription
Data categoriesUser and contact data; roles and permissions; customer/recipient and contact person data; supplier/contact information; reference and document data; warehouse and movement data relating to persons; usage, log and technical metadata; support content; content of uploaded documents to the extent it is personal.
Data subjectsEmployees and users of the Client; contact persons of customers, suppliers and business partners; recipients or contact persons in warehouse/delivery processes; other persons whose data is contained in uploaded documents or support communication.
Special categories under Art. 9 GDPRNot intended. The Client should not enter such data into SmartShelf unless this has been expressly agreed in advance and secured in terms of data protection law.

4. Instructions

4.1.Kais Solutions processes personal data only on documented instructions from the Client, unless a legal obligation requires other processing. In that case, Kais Solutions informs the Client of this legal obligation before processing, unless the law in question prohibits such information on important grounds of public interest.

4.2.If Kais Solutions considers an instruction to infringe data protection law, it informs the Client without delay, to the extent legally permissible.

4.3.As controller, the Client remains responsible for the lawfulness of the processing, the admissibility of the instructions given and the protection of the rights of data subjects.

5. Confidentiality

5.1.Kais Solutions ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

6. Security of processing

6.1.Kais Solutions takes appropriate technical and organisational measures pursuant to Art. 32 GDPR. These are described in the annex “TOMs SmartShelf”.

6.2.The measures are reviewed on a risk basis and adapted in the event of significant technical or organisational changes.

7. Data subject rights and assistance

7.1.Kais Solutions assists the Client to the appropriate and necessary extent in fulfilling data subject rights under Chapter III GDPR.

7.2.Requests addressed directly to Kais Solutions that evidently concern data of the Client are forwarded to the Client, to the extent legally permissible.

8. Personal data breaches and obligations under Art. 32–36 GDPR

8.1.Kais Solutions assists the Client to an appropriate extent with its obligations under Art. 32 to 36 GDPR.

8.2.Relevant personal data breaches are reported to the Client without delay after becoming known, together with the available information.

9. Audits and evidence

9.1.Kais Solutions makes available to the Client the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR.

9.2.Kais Solutions allows for and contributes to necessary audits by the Client or an auditor mandated by the Client, with reasonable advance notice and while safeguarding confidentiality, security and the rights of other customers. Where suitable documentation or evidence suffices, it should be used first.

10. Termination, return and deletion

10.1.After the end of the processing, personal data is returned or deleted at the Client's choice, unless a statutory retention obligation prevents this.

10.2.Backups may continue to exist until the regular expiry of the backup cycle, provided they are kept solely for recovery purposes and are subsequently overwritten or deleted.

10.3.The currently agreed backup retention scheme keeps at least 14 daily backups; additional weekly and monthly backups follow the Restic retention scheme in force at the time.

11. Sub-processors

11.1.The Client grants general authorisation for the use of the subcontractors listed in the annex “Sub-processors SmartShelf”.

11.2.Kais Solutions informs the Client of intended additions or replacements in good time, so that the Client can object on legitimate data protection grounds.

11.3.Kais Solutions contractually binds sub-processors to the data protection obligations required under Art. 28(4) GDPR.

12. Processing locations and third-country transfers

12.1.The primary SmartShelf application and database environment is operated within the EU.

12.2.Further processing locations result from the current list of sub-processors.

12.3.Transfers to third countries only take place in compliance with Art. 44 et seq. GDPR and using a suitable transfer mechanism or appropriate safeguards, where required.

13. Final provisions

13.1.Otherwise, the data protection provisions of the main contract apply. In the event of contradictions regarding the processing, this DPA takes precedence.

Data Processing Agreement SmartShelf, Version 1.0, as of 31 August 2026. Provider: Rani Kais, Kais Solutions – see legal notice.

Custom software and digital solutions for businesses in Austria.

office@kaissolutions.at
ProductsSmartShelfQR TableStammioSnippetQuizSmart ContractsBurevo
Kais SolutionsServicesContactTermsLegal noticePrivacy
© 2026 Kais SolutionsOperator: Rani Kais · Vienna, Austria