Data Processing Agreement
Last updated: 2026-02-25
1. Scope and Parties
This Data Processing Agreement ("DPA") supplements the Terms & Conditions and governs the processing of personal data by Newmatik GmbH ("Processor") on behalf of the customer organization ("Controller") when using the Optysys Service. This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (GDPR).
2. Subject Matter and Duration
The Processor processes personal data on behalf of the Controller for the purpose of providing the Optysys cloud inspection service. Processing continues for the duration of the service agreement between the parties.
3. Nature and Purpose of Processing
The processing involves cloud storage, display, annotation, and AI model management for optical inspection images. This includes storing user account data, inspection images, image metadata, annotations, annotation comments, and AI model files.
4. Types of Personal Data
The following types of personal data may be processed: user account data (email, name), inspection images (which may contain identifiable product or manufacturing data), annotations and metadata, camera and positioning metadata, and AI model configuration data.
5. Categories of Data Subjects
Data subjects include the Controller's employees and authorized users of the Service, as well as any individuals whose data may be contained in inspection images or metadata.
6. Processor Obligations
The Processor shall: process personal data only on documented instructions from the Controller; ensure that persons authorized to process personal data are bound by confidentiality obligations; implement appropriate technical and organizational security measures (including encryption at rest via Supabase, encryption in transit via TLS, and row-level access control); assist the Controller in fulfilling data subject requests; delete or return all personal data upon termination of the service, at the Controller's choice; and make available all information necessary to demonstrate compliance with Article 28 GDPR.
7. Security Measures
The Processor implements the following security measures: encryption at rest (Supabase managed encryption), encryption in transit (TLS/HTTPS for all connections), row-level security policies enforced at the database level, PKCE authentication flow, optional multi-factor authentication (TOTP), role-based access control (admin/member), and regular security monitoring via Sentry.
8. Sub-Processors
The Controller authorizes the use of the following sub-processors:
- Supabase Inc. — Database and object storage, hosted in EU (eu-central-1, Frankfurt, Germany)
- Cloudflare, Inc. — Website hosting and CDN (global edge network, with EU Standard Contractual Clauses)
- Functional Software, Inc. (Sentry) — Error monitoring (EU ingest endpoint: ingest.de.sentry.io)
The Processor will inform the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object.
9. Data Breach Notification
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach. The notification shall include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
10. Audit Rights
The Controller has the right to conduct audits, including inspections, to verify the Processor's compliance with this DPA. The Processor shall cooperate with such audits and make relevant documentation available upon reasonable request.
11. Data Return and Deletion
Upon termination of the service agreement, the Processor shall, at the Controller's choice, return all personal data or delete it, and delete existing copies unless applicable law requires storage. The Controller can export their data at any time using the data export feature in the dashboard.
12. International Transfers
Primary data storage is in the EU (Supabase, Frankfurt). Where personal data is transferred outside the EU/EEA (e.g., Cloudflare edge caching), appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) as required by Chapter V of the GDPR.
13. Contact and Execution
To execute this DPA or for questions regarding data processing, contact Newmatik GmbH at service@newmatik.com. This DPA becomes effective upon the Controller's acceptance of the Optysys Terms & Conditions.