Data protection
Data Processing Agreement (DPA / AVV)
LicenseMeter processes directory and license metadata on your behalf, so a data processing agreement under Art. 28 GDPR is part of every subscription. The full text is below; download the pre-signed PDF in English or German for your records and procurement checklist.
How to put this DPA in place
- 1.It is already in effect: accepting the LicenseMeter Terms also accepts this DPA, which is pre-signed by us.
- 2.Need a signed paper for your files? Download the PDF, fill in your entity details, and counter-sign the signature block.
- 3.Send the signed copy to the contact address in the document if your process requires a fully executed version.
Parties
This Data Processing Agreement ("DPA") forms part of the LicenseMeter Terms and Conditions (the "Principal Agreement") between the Parties for use of the LicenseMeter service (the "Service"). It governs the processing of personal data carried out by the Processor on behalf of the Controller in connection with the Service, in accordance with Article 28 GDPR.
Processor (Auftragsverarbeiter)
UgurLabs UG (haftungsbeschränkt)
Fährstraße 217, 40221 Düsseldorf, Germany
Represented by its Managing Director Ugur Koc
Contact: customer-care@ugurlabs.odoo.com
("LicenseMeter" or the "Processor")
Controller (Verantwortlicher)
The customer organization that uses the Service and is bound by the Principal Agreement (the "Controller").
Its legal name, address and authorized representative are those stated in the Controller's account and in the counter-signature block of this DPA.
Background
On the Controller's instruction, the Processor reads license, directory and activity metadata from the Controller's Microsoft 365 tenant and, where the Controller connects them, from further source systems, and presents the results as analyses, reports and exports. Mailbox, file and message content is never accessed; access to the tenant is technically limited to read-only permissions.
In doing so the Processor processes personal data on behalf of the Controller. The Parties enter into this DPA to meet the requirements of Article 28 GDPR. With regard to the processing of personal data, this DPA prevails over any conflicting provision of the Principal Agreement.
1. Subject matter, duration and scope
The subject matter and duration of the processing, its nature and purpose, the types of personal data and the categories of data subjects are set out in Annex 1. The processing is carried out for the term of the Principal Agreement and ends when that agreement ends, subject to Section 10.
The Processor processes personal data exclusively within the European Union / European Economic Area, save for the transfers described in Section 12. The Processor does not process the data for its own purposes.
The personal data is processed exclusively for the purpose described in Annex 1: identifying unused, oversized and misaligned license assignments and their cost. The Processor does not use the personal data to monitor or evaluate the performance or behavior of individual employees of the Controller, does not create profiles for such purposes, and does not provide the Service as a tool for performance or behavior monitoring. Activity metadata is processed solely to determine whether a paid license seat is used, unused or oversized.
2. Rights and instructions of the Controller
The Controller is responsible for assessing the lawfulness of the processing and for safeguarding the rights of data subjects. The Controller retains sole control and ownership of the personal data.
The Controller's documented instructions are constituted by this DPA, the Principal Agreement and the configuration choices the Controller makes in the Service (for example which tenant and which optional source systems it connects, the price book it maintains and the exports it triggers). Additional or amended instructions must be issued in text form.
3. General obligations of the Processor
The Processor processes personal data only on the Controller's documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which it is subject; in such a case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits it.
The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions. The Processor is not obliged to carry out a legal review of the instructions.
4. Confidentiality
The Processor ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b), Art. 29, Art. 32(4) GDPR). Access to the personal data is limited to those employees and contractors who need it to provide and operate the Service.
5. Technical and organizational measures (Art. 32 GDPR)
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, the Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. The measures in place are described in Annex 2.
The measures are subject to technical progress and further development. The Processor may implement adequate alternative measures, provided the security level is not reduced below that of Annex 2. Material changes are documented.
6. Sub-processors
The Controller grants the Processor general written authorization to engage the sub-processors listed in Annex 3 for the processing on the Controller's behalf. Each sub-processor is bound by a contract imposing data protection obligations equivalent to those of this DPA, in particular sufficient guarantees under Art. 28(3) and (4) GDPR. The Processor remains fully liable to the Controller for the performance of its sub-processors' obligations.
The Processor informs the Controller of any intended change concerning the addition or replacement of a sub-processor at least thirty (30) days in advance, thereby giving the Controller the opportunity to object on reasonable data protection grounds. If the Controller objects and the Parties cannot agree on a solution, the Controller may terminate the affected part of the Service for good cause.
7. Assistance with data subjects' rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests for exercising data subjects' rights under Chapter III GDPR (Art. 12 to 23).
Where a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay and does not respond on the merits itself unless instructed by the Controller.
8. Assistance with the Controller's compliance obligations
Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in ensuring compliance with its obligations under Art. 32 to 36 GDPR, in particular the security of processing, the notification of personal data breaches, the communication of breaches to data subjects, data protection impact assessments and prior consultation.
9. Personal data breaches
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on the Controller's behalf. The notification describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed to address it.
10. Return and deletion of personal data
On termination of the processing, and at the Controller's choice, the Processor deletes or returns all personal data processed on the Controller's behalf and deletes existing copies, unless Union or Member State law requires storage. Disconnecting a workspace in the Service deletes all synchronized data immediately and irreversibly; remaining copies in routine encrypted backups are overwritten within the backup rotation window (currently around seven days).
Where the Service involves billing, the payment subprocessor named in Annex 3 retains invoice and transaction data for the period required by statutory tax and commercial-law retention duties, even after deletion of the workspace.
11. Audits and demonstration of compliance
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
The Processor may satisfy this obligation in the first instance by providing this DPA, the security overview published at the /security page, the subprocessors' own certifications and audit reports (for example SOC 2 / ISO 27001), and written answers to security questionnaires. On-site inspections are carried out on reasonable prior notice, during business hours, without disrupting operations, and subject to confidentiality.
12. International data transfers
Primary storage and the core processing take place in the European Union (see Annex 2 and Annex 3). Where a sub-processor processes personal data outside the EU / EEA without an adequacy decision, such transfer is based on the European Commission's Standard Contractual Clauses (SCCs) together with any supplementary measures required, or on another valid transfer mechanism under Chapter V GDPR. The transfer mechanism applicable to each sub-processor is indicated in Annex 3.
13. Liability
Liability of the Parties is governed by Art. 82 GDPR and by the liability provisions of the Principal Agreement. The liability limitations and caps agreed in the Principal Agreement apply to claims under this DPA to the extent permitted by law.
14. Term and order of precedence
This DPA takes effect together with the Principal Agreement and remains in force for as long as the Processor processes personal data on the Controller's behalf. In the event of a conflict between this DPA and the Principal Agreement regarding the processing of personal data, this DPA prevails. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.
15. Final provisions
This DPA is governed by the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods. The exclusive place of jurisdiction, where permitted, is the registered seat of the Processor. Should individual provisions be or become invalid, the validity of the remaining provisions is unaffected; the invalid provision is replaced by a valid provision that comes closest to its economic intent. Amendments must be made in text form.
Annex 1: Description of the processing
- Subject matter
- Analysis of the Controller's software licensing to surface unused, oversized and misaligned license assignments, and the generation of related reports and exports.
- Nature and purpose
- Read-only collection, storage, aggregation and analysis of license, directory and activity metadata, solely to provide the Service to the Controller. The data is not used to monitor or evaluate the performance or behavior of individual employees (see Section 1).
- Duration
- For the term of the Principal Agreement; data is retained only while the workspace is connected and is deleted on disconnect (see Section 10).
- Frequency
- Continuous / scheduled synchronization (typically nightly) plus on-demand actions triggered by the Controller's users.
- Categories of data subjects
- The Controller's employees and other directory users; holders of seats in connected source systems; the Controller's own workspace members who sign in to the Service.
- Types of personal data
- Display name; user principal name (UPN) / email address; directory object and tenant identifiers; account status and user type; account creation date; assigned license SKUs; last sign-in and per-workload last-activity timestamps; for connected source systems, seat email, status and product assignments; for workspace members, name, email, role and sign-in activity.
- Special categories
- None. The Service is not intended for special categories of personal data (Art. 9 GDPR), and mailbox, file and message content is never accessed.
Annex 2: Technical and organizational measures (Art. 32 GDPR)
Confidentiality - access control
- Workspace access is invite-based; signing in with a tenant account grants nothing by itself. Roles (owner, admin, viewer) enforce least privilege.
- Tenant isolation is enforced in the application on every query and, in addition, by PostgreSQL row-level security with a deny-all default and a least-privilege application database role (no schema or superuser rights).
- Authentication uses OpenID Connect with PKCE and JWKS verification; sessions are signed, httpOnly, secure cookies with a bounded lifetime.
- Access to the production environment is limited to authorized personnel under confidentiality obligations.
Confidentiality - encryption
- All data in transit is protected with TLS and HSTS.
- Data at rest is encrypted by the managed database provider (AES-256).
- Third-party connector credentials are additionally encrypted at the application layer using AES-256-GCM with a key derived via HKDF-SHA256.
Integrity
- Read-only access to the Microsoft 365 tenant: the Service holds no write permissions and cannot change anything in the tenant.
- State-changing requests are protected by origin / CSRF checks; authentication and sensitive endpoints are rate-limited.
- Database integrity is enforced through primary keys, unique constraints and foreign-key constraints.
Availability and resilience
- Hosting in EU data centers (Frankfurt region) on a managed platform with DDoS protection and a content delivery network.
- Automated, managed database backups with point-in-time recovery within the provider's retention window.
- The synchronization is resilient to missing optional permissions and logs each run for recovery and post-incident analysis.
Accountability and review
- A per-workspace audit log records exports and administrative actions and is deleted with the workspace.
- A documented breach-notification process (notification to the Controller without undue delay).
- Subprocessors are selected for documented security postures (e.g. SOC 2 / ISO 27001) and bound by data processing agreements.
Deletion and separation
- Disconnecting a workspace deletes all synchronized data immediately and irreversibly (cascade delete), including the audit log and, where billing applies, the payment-provider customer record.
- Customer data is logically separated per tenant throughout storage and processing.
Annex 3: Approved sub-processors
The Processor engages the following sub-processors for the processing of personal data on the Controller's behalf:
Vercel Inc.
- Purpose
- Application hosting and content delivery
- Processing location
- EU (Frankfurt function region)
- Transfer mechanism
- EU processing; SCCs for any support access from outside the EU
Supabase Inc.
- Purpose
- Managed PostgreSQL database (primary data store)
- Processing location
- EU (AWS eu-central-1, Frankfurt)
- Transfer mechanism
- EU processing; SCCs for any support access from outside the EU
Microsoft (Microsoft Ireland Operations Ltd. / Microsoft Corporation)
- Purpose
- Identity platform (sign-in, admin consent) and Microsoft Graph API
- Processing location
- EU Data Boundary; US fallback
- Transfer mechanism
- EU Standard Contractual Clauses (Microsoft Products and Services DPA)
WorkOS, Inc.
- Purpose
- Authentication and user identity management (AuthKit sign-in), where enabled
- Processing location
- US
- Transfer mechanism
- EU Standard Contractual Clauses (WorkOS DPA)
Stripe (Stripe Payments Europe Ltd. / Stripe, Inc.)
- Purpose
- Billing and subscription management (for paid plans)
- Processing location
- EU and US
- Transfer mechanism
- EU Standard Contractual Clauses (Stripe DPA); retains invoice data to meet statutory tax-retention duties
Resend Inc.
- Purpose
- Transactional and notification email delivery
- Processing location
- EU (Ireland region)
- Transfer mechanism
- EU processing; SCCs where applicable
To be distinguished from sub-processors are the optional source systems named in Annex 1 (Adobe, Zoom, Atlassian, Salesforce, OpenAI, Anthropic) and any member lists the Controller imports by CSV (ChatGPT, Claude). The Processor reads from these systems on the Controller's behalf on a read-only basis. They are data sources, not sub-processors of the Processor; no personal data is disclosed to them beyond the authenticated read request. Where the Controller connects a Microsoft tenant using its own app registration ('bring your own'), the credentials supplied (client secret or certificate private key) are stored encrypted at rest (AES-256-GCM) and used solely to perform the read-only Microsoft Graph sync; they are never logged or disclosed.
Signatures
This DPA is pre-signed by the Processor. It takes effect either automatically when the Controller accepts the Principal Agreement, or on the date the Controller signs below. Controllers whose internal processes require a fully executed copy may return this signed PDF to the contact address above.
For the Processor
UgurLabs UG (haftungsbeschränkt)
Name: Ugur Koc
Title: Managing Director (Geschäftsführer)
Signed electronically with version 1.2, 2 July 2026
For the Controller
Legal entity: ____________________________
Name: ____________________________
Title: ____________________________
Place / Date: ____________________________
Signature: ____________________________