Data Processing Agreement

Last updated: 2026-02-25

This Data Processing Agreement ("DPA") supplements the Terms of Service between the customer ("Controller") and Newmatik GmbH, Am Markt 1, 55619 Hennweiler, Germany ("Processor") and governs the processing of personal data by the Processor on behalf of the Controller in accordance with Art. 28 GDPR.

1. Subject Matter and Duration

The Processor provides the Gerbtrace platform (the "Service") to the Controller. In the course of providing the Service, the Processor processes personal data on behalf of the Controller. This DPA applies for the duration of the service agreement between the parties.

2. Nature and Purpose of Processing

The Processor processes personal data to provide the Controller with:

  • Cloud storage and management of PCB design data, BOMs, and pick-and-place files
  • Team collaboration features including project management and conversations
  • AI-powered BOM enrichment (Spark AI) when triggered by the Controller's users
  • Component pricing and availability lookups
  • User authentication and access management

3. Types of Personal Data

The following categories of personal data may be processed:

  • Names and email addresses of the Controller's team members
  • User profile data (display name, avatar)
  • Team membership and role assignments
  • Project metadata and collaboration data (conversations, comments, mentions)
  • Usage data and consent records

4. Categories of Data Subjects

  • The Controller's employees and contractors who use the Service
  • External collaborators invited to the Controller's teams or spaces

5. Controller Obligations

The Controller shall:

  • Ensure that the processing of personal data through the Service is lawful under applicable data protection law.
  • Provide documented instructions to the Processor regarding the processing of personal data.
  • Inform the Processor without undue delay if instructions may violate applicable data protection law.

6. Processor Obligations

The Processor shall:

  • Process personal data only on documented instructions from the Controller, unless required by EU or member state law.
  • Ensure that persons authorized to process personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption in transit (TLS) and at rest, role-based access control, and row-level security policies.
  • Not engage another processor without prior specific or general written authorization of the Controller. The current list of sub-processors is provided in section 7.
  • Assist the Controller in fulfilling data subject requests under Art. 15–22 GDPR.
  • Assist the Controller in ensuring compliance with obligations under Art. 32–36 GDPR.
  • Delete or return all personal data at the end of the service relationship, at the Controller's choice, unless EU or member state law requires further storage.
  • Make available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR.

7. Sub-processors

The Controller hereby provides general authorization for the Processor to engage sub-processors. The current list of sub-processors is maintained in our Privacy Policy (Section 12: Sub-processors).

The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors at least 14 days in advance, giving the Controller the opportunity to object. If the Controller objects, the Processor shall refrain from engaging the new sub-processor or allow the Controller to terminate the service agreement.

8. International Data Transfers

Where personal data is transferred to countries outside the EU/EEA, the Processor ensures that appropriate safeguards are in place, including the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs) as adopted by the European Commission. Details are provided in the Privacy Policy (Section 13: International Data Transfers).

9. Data Breach Notification

The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach. The notification shall include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

10. Audit Rights

The Controller may request compliance documentation from the Processor to verify compliance with this DPA. Audits shall be conducted with reasonable advance notice and during normal business hours, and shall not unreasonably interfere with the Processor's operations.

11. Data Deletion and Return

Upon termination of the service agreement, the Processor shall delete all personal data processed on behalf of the Controller within 30 days, unless applicable law requires further retention. The Controller may export their data prior to termination using the data export feature available in the Service (Art. 20 GDPR).

12. Liability

The liability of the parties under this DPA is subject to the limitations set forth in the Terms of Service.

13. Contact

For questions about this DPA or to request execution of a signed copy, contact us at software@newmatik.com.