Data Processing Agreement
Last updated: April 21, 2026
This Data Processing Agreement ("DPA") supplements the Terms of Service and governs how ownMDM processes personal data on your behalf in accordance with GDPR Article 28.
1. Definitions
- –Controller: You (the customer)
- –Processor: ownMDM (Choudhary GmbH)
- –Personal Data: any data relating to identified persons
- –Processing: any operation on personal data
2. Scope
This DPA applies to personal data processed through the ownMDM platform.
3. Data Processing Details
- –Purpose: Mac device management, software deployment, compliance monitoring
- –Categories of data: device identifiers, user names, IP addresses
- –Data subjects: your employees whose Macs are managed
- –Duration: for the term of the service agreement
4. Processor Obligations
- –Process data only on documented instructions
- –Ensure personnel are bound by confidentiality
- –Implement appropriate security measures
- –Assist with data subject requests
- –Delete or return data upon termination
- –Submit to audits and inspections
5. Sub-processors
- –Self-hosted: no sub-processors (data stays on your server)
- –Hosted components: listed at ownmdm.com/sub-processors
6. International Transfers
- –Self-hosted: no transfers (your infrastructure, your jurisdiction)
- –Hosted: Standard Contractual Clauses apply where required
7. Security Measures
- –Encryption in transit (TLS 1.3) and at rest (AES-256)
- –Access controls (RBAC, 2FA)
- –Audit logging
- –Regular security assessments
8. Breach Notification
- –We will notify you within 72 hours of discovering a data breach
- –Notification includes: nature of breach, data affected, remediation steps
9. Data Protection Impact Assessment
- –We will assist with DPIAs upon request
- –We will provide necessary information for your assessments
10. Platform Access to Your Data
- –Support access is restricted to authorised platform operators (super-admins); a customer-tenant administrator can never access another tenant.
- –Read access for support is permitted and logged; any change (create / update / delete) additionally requires a typed justification stored with the action.
- –Every action a platform operator performs in your tenant is written to your own tenant's append-only audit log, attributed as platform-staff access (operator identity, justification, IP and timestamp).
- –We notify the tenant owner by email when platform staff first access your tenant in a session.
- –You can review the full platform-access history at any time in the admin portal (Audit → Platform Access). Audit records are append-only, tamper-evident, and retained for 365 days.
Need a signed DPA?
Enterprise customers can request a countersigned DPA for their legal and compliance teams.
Request Signed DPAData Protection Officer: dpo@ownmdm.com