Data Processing Agreement
Last updated: December 18, 2025
Article 28 GDPR / UK GDPR agreement covering personal data processing in absentify's Microsoft 365 absence management service.
Preamble
This Agreement governs the processing of personal data by the Processor on behalf of the Controller pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK General Data Protection Regulation (UK GDPR) as retained in UK law under the European Union (Withdrawal) Act 2018, read together with the Data Protection Act 2018. It ensures that the processing complies with GDPR and UK GDPR requirements and protects the rights of data subjects. The Agreement is tailored to the specific needs of the Software-as-a-Service solution absentify and takes precedence over any conflicting provisions in other agreements. The technical and organizational security is underpinned by the Processor's ISO 27001 certification, which demonstrates a comprehensive Information Security Management System (ISMS) and compliance with appropriate measures under Article 32 GDPR / UK GDPR.
between
the Customer of the Software-as-a-Service solution absentify – hereinafter referred to as Controller –
and
absentify GmbH Rotachstrasse 4 8003 Zürich Switzerland (represented by Marc Hochleutner) – hereinafter referred to as Processor –
EU Representative (Art. 27 GDPR): Prighter EU Rep GmbH Schellinggasse 3, 1010 Vienna, Austria Contact: https://app.prighter.com/portal/absentify
UK Representative (Art. 27 UK GDPR): Prighter Ltd 20 Mortlake High Street, London SW14 8JN, United Kingdom Contact: https://app.prighter.com/portal/absentify
1. Subject Matter and Duration of the Processing
1.1 The subject matter of this Agreement is the processing of personal data in connection with the provision and hosting of the software application absentify for Microsoft 365 for vacation and absence management, as well as the associated processing of the Controller's personal data (including collection, storage, modification, deletion, and transfer).
1.2 The duration of the data processing is determined by the Software-as-a-Service agreement concluded between the parties.
1.3 This Agreement remains in effect as long as the Processor processes personal data of the Controller, including backups.
1.4 In the event of any conflict between this Data Processing Agreement and the provisions of the main contract or other related agreements, this Agreement shall take precedence.
2. Nature, Scope, and Purpose of the Processing
2.1 The Processor shall process personal data exclusively to enable the Controller to use the absentify application, including the operation of an attendance system for Microsoft 365.
2.2 Types of personal data processed:
- Contact, billing, and contractual master data
- Communication data (e.g., IP addresses, system logs)
- Microsoft account information (first name, last name, display name, email, phone number, profile picture, language, and display settings)
- User content data (e.g., absence, vacation, and substitute information)
2.3 Categories of data subjects include the Controller's employees and individuals whose data are entered into absentify by the Controller (e.g., substitutes or external parties).
3. Technical and Organizational Measures
3.1 The Processor has implemented appropriate technical and organizational measures (TOMs) pursuant to Article 32 GDPR to ensure a level of security appropriate to the risk. These measures consider the state of the art, implementation costs, the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons. The measures are detailed in Annex 1 and made available to the Controller for review upon request. They are integrated into the Processor's ISO 27001-certified ISMS, which ensures regular audits and updates.
3.2 The measures shall be adapted to the state of the art, provided that the agreed security level is not compromised. Significant changes will be communicated to the Controller in a timely manner.
3.3 The Processor regularly reviews its internal processes and TOMs to ensure compliance with applicable data protection laws.
4. Rights of Data Subjects
4.1 The Processor shall immediately inform the Controller of any requests from data subjects regarding access, rectification, erasure, restriction of processing, data portability, or objection, insofar as these relate to the Controller's area of responsibility.
4.2 The Processor shall not handle such requests independently but only upon documented instructions from the Controller. Taking into account the nature of the processing, the Processor shall assist the Controller in fulfilling its obligations under Articles 12 to 22 GDPR.
5. Obligations of the Processor
The Processor undertakes to:
- Process personal data solely on documented instructions from the Controller (Article 29 GDPR)
- Oblige its employees and authorized persons to maintain confidentiality (Article 28(3)(b) GDPR)
- Implement and document appropriate security measures (Article 32 GDPR)
- Assist the Controller in complying with its obligations under Articles 32 to 36 GDPR, including Data Protection Impact Assessments (DPIAs), breach notifications, and prior consultations
- Notify the Controller of personal data breaches without undue delay (within 48 hours) and support the Controller in notifying the supervisory authority and data subjects (Articles 33, 34 GDPR)
- Support the Controller in responding to inquiries or audits by the supervisory authority (Article 31 GDPR)
- Maintain a record of processing activities (Article 30(2) GDPR) and make it available to the Controller upon request
- Immediately address instructions that may violate GDPR and suspend them until clarified
The Processor shall only engage employees who are bound by confidentiality and have been familiarized with relevant data protection provisions.
6. Sub-Processing Relationships
6.1 The Processor may only engage sub-processors (further processors) with the Controller's prior express written or documented consent. Sub-processors are carefully selected and contractually obligated under Article 28(4) GDPR to ensure an equivalent level of data protection.
6.2 The currently engaged sub-processors are listed in Annex 2. Changes (additions, replacements, or removals) will be notified to the Controller in writing or text form at least 14 days in advance, allowing the Controller to object.
6.3 The Processor shall conclude agreements with each sub-processor imposing the same data protection obligations as this Agreement. Upon request, the Processor shall provide the Controller with copies of such agreements (with confidential parts redacted if necessary).
6.4 The Processor remains fully responsible for the compliance of its sub-processors with data protection obligations and shall be liable to the Controller accordingly.
7. International Data Transfers
Processing shall generally take place in Switzerland, EU Member States, or the European Economic Area (EEA). Transfers to third countries shall only occur if the requirements of Articles 44 et seq. GDPR are met (e.g., through EU Standard Contractual Clauses, adequacy decisions, Binding Corporate Rules, or other safeguards). Any transfer to a third country requires the prior consent of the Controller.
8. Controller's Audit Rights
8.1 The Controller is entitled to verify the Processor's compliance with its obligations under Article 28 GDPR, including through spot checks or audits (to be announced in advance).
8.2 Compliance may be demonstrated by providing appropriate certificates (e.g., ISO 27001), audit reports, procedural documentation, or equivalent evidence. The Processor shall provide the Controller with all necessary information and documents upon request.
8.3 The Processor shall facilitate and support audits conducted by the Controller or an independent auditor appointed by the Controller.
9. Instructions
The Processor shall process personal data exclusively based on documented instructions from the Controller, including transfers. If the Processor identifies unlawful instructions, it shall suspend them until clarification. Instructions must be given in writing or text form and shall be documented.
10. Deletion and Return of Data
10.1 Upon termination of the main contract or at the Controller's request, the Processor shall delete or return all personal data (including copies and backups), unless legal retention obligations apply.
10.2 The Processor shall confirm the deletion or return in writing. No unauthorized copies shall be retained.
11. Certification and Evidence
The Processor operates an ISO 27001-certified Information Security Management System. A copy of the valid certificate is attached to this Agreement as Annex 3. The Processor maintains a record of processing activities and makes it available to the Controller upon request. The ISO 27001 certification serves as additional evidence of compliance with technical and organizational measures under Article 32 GDPR, complementing the detailed description in Annex 1.
12. Liability and Confidentiality
12.1 Liability
The Processor shall be liable for damages resulting from breaches of its obligations, provided such breaches are due to gross negligence or intent. The Processor shall indemnify the Controller against third-party claims.
12.2 Confidentiality
The Processor shall maintain the confidentiality of all personal data and information accessed under this Agreement. This obligation shall continue beyond the termination of the Agreement.
13. Final Provisions
13.1 This Agreement is an integral part of the usage contract between the Controller and the Processor.
13.2 No separate signature or postal submission is required. Acceptance shall occur electronically within the application.
13.3 The Agreement shall apply in its current online version. Changes shall apply uniformly to all customers and be announced at least 30 days in advance.
13.4 The place of jurisdiction and applicable law shall be governed by the main contract. Should any provision be invalid, the remaining provisions shall remain in effect (severability clause).
Annex 1 – Technical and Organizational Measures (TOMs)
The measures include at least:
Pseudonymization and Encryption
- Encryption of data in transit (TLS 1.2 or higher)
- Encryption of data at rest (AES-256)
Confidentiality
- Access control through role-based authorization and multi-factor authentication
- Confidentiality obligations for all employees
- Training and awareness programs on data protection
Integrity
- Separation of development, testing, and production environments
- Logging and traceability of administrative access
Availability and Resilience
- Firewalls, intrusion detection, and monitoring systems
- Data backups with geo-redundant storage and regular restoration tests
- Disaster recovery and business continuity plans
Regular Review Procedures
- Periodic security and vulnerability assessments
- Internal audits
Additional Measures
- Pseudonymization where feasible
- Ensuring resilience against physical and technical incidents
These measures are part of the ISO 27001-certified ISMS and are subject to continuous review and adaptation.
Annex 2 – Approved Sub-Processors
Microsoft Azure — Dublin (Ireland) / Copenhagen (Denmark) — Hosting, email dispatch, database
Sendinblue GmbH — Berlin (Germany) — Transactional and marketing emails
Paddle.com Market Limited — London (United Kingdom) — Payment and contract processing
Crisp IM S.A.S. — Nantes (France) — Helpdesk / customer support
PostHog, Inc. (EU Cloud) — Frankfurt am Main (Germany) — Product and usage analytics
Frill.co (Enterprise) — European Union — Product feedback and roadmap managementAn up-to-date list is also available at: https://absentify.com/subprocessors
Annex 3 – Certificates and Evidence
The Processor holds an ISO 27001 certification for its Information Security Management System. The valid certificate is attached to this Agreement and included in the PDF version.
Closing Note
This Agreement is concluded electronically within the absentify application. With electronic consent, it shall be deemed mutually binding.
100% Microsoft 365 integrated
directly in Teams, Outlook & Entra ID
GDPR & ISO 27001 certified
certified safety
Rollout in hours, not weeks
without IT implementation
230,000+ active users worldwide
for HR, IT, management and more




