The question comes up in almost every customer project: “Could you send us the data processing agreement and an overview of the services you use?” What follows is a search through old emails and a document from a previous project, with no certainty it is current.
Since 5 August there is a dedicated area for this, generating the paperwork from what is actually configured in your organisation.
What the compliance area contains
Four documents are available for every organisation, each in German and English:
- Data processing agreement (DPA) — the contract between you and the platform as the processor
- Technical and organisational measures (TOMs) — the safeguards that apply to access, transmission and availability
- Privacy policy — how processing works in the context of the platform
- Scope statement — what the platform takes on and where your responsibility begins
On top of that there is a list of sub-processors — exactly the information customers need for their own record of processing activities.
You download each document as a PDF, or as a single ZIP export for a complete handover.
The documents are generated from your data
The difference: these documents are not static. In your organisation settings you enter the legal details — company name, address, contact person — and those flow automatically into the generated PDFs, so a contract never starts with a placeholder like “Company, Street, City.”
A project overview complements this: Firebase in one project, Sentry in another, Mailtrap in a third — all visible in the compliance area instead of collected separately.

Where this helps day to day
Three situations come up regularly:
Customer onboarding. A new customer asks for data protection paperwork before signing. Instead of several rounds of questions, you send the ZIP export.
Audits and certifications. During an ISO 27001 review you are asked to evidence which providers are involved and which contracts exist. The sub-processor list covers exactly that.
Tenders. In the public sector and regulated industries, a DPA and TOMs are often part of the required documentation. Supplying them at short notice saves a round trip.
A note on scope
The platform provides documentation and describes what happens on its side, but it does not replace legal advice. Whether your use case needs additional measures — a data protection impact assessment for sensitive data, say — is a question for your legal counsel. What it automates is current documents, correctly filled in, in both languages, available whenever you need them.
Alongside operating in the EU
The compliance area complements a property the platform has had from the start: operation and data processing happen inside the EU, on servers you select yourself — often the condition under which projects with public-sector, healthcare or finance customers happen at all. More on this on the page about GDPR compliant hosting.