In-manas: intelligent management solutions GmbH
Last updated: September 2026
1. Scope
This data processing agreement applies between in-manas: intelligent management solutions GmbH, Ing.-Etzel-Straße 17, 6020 Innsbruck, Austria ("in-manas" or "Processor"), and the customer designated in the respective offer, order, or main contract ("Controller").
It becomes part of the main contract if it is referenced in the offer, order, order confirmation, or any other contractual agreement. A separate signature is not required in this case.
This agreement applies to all processing activities in which in-manas processes personal data on behalf of the customer.
2. Subject matter and duration
The subject matter of the data processing is the provision, operation, maintenance, and support of the contractually agreed SaaS solution from in-manas.
Data processing begins with the provision of the agreed services and generally ends upon the termination of the main contract. Obligations regarding confidentiality, return, deletion, and proof of contractually compliant processing remain in effect until they have been fully fulfilled.
3. Nature and purpose of processing
in-manas processes personal data to provide the agreed SaaS functions. Processing may include, in particular, the following operations:
The platform specifically supports the capturing, discussion, structuring, analysis, and evaluation of ideas, documents, posts, comments, surveys, and similar content.
The customer determines the specific purpose of use, the participants, the content collected, the permissions granted within their tenant, and the enabled features.
Where AI functions or external language models are used, their deployment is governed by the configuration selected and contractually agreed upon by the customer.
4. Types of data processed
Depending on how the platform is used, the following data in particular may be processed:
Special categories of personal data under Art. 9 GDPR are not part of the standard processing activities. If such data is uploaded by the customer or their users, the customer is responsible for the legality and the necessary additional protective measures.
Data processed by in-manas for the administration, billing, and execution of its own contractual relationships is generally not subject to this data processing agreement.
5. Categories of data subjects
The data subjects may include, in particular:
6. Instruction Binding
in-manas processes personal data exclusively based on documented instructions from the customer, unless there is a legal obligation to process the data otherwise.
Instructions are derived from the main agreement, this agreement, the agreed product configuration, and the authorised use of the platform. Supplementary instructions may be issued in text form.
If in-manas is legally required to process data, it will inform the customer in advance, provided that applicable law does not prohibit such notification.
If in-manas considers an instruction to be in violation of data protection laws, it will notify the customer immediately. Execution may be suspended until the instruction is confirmed or amended.
7. Customer Obligations
As the controller, the customer is specifically responsible for:
The customer shall notify in-manas without undue delay of any identified data protection breaches, errors, or irregularities, insofar as these are relevant to the data processing.
8. Obligations of in-manas
in-manas ensures that persons authorised to process personal data:
in-manas supports the customer, taking into account the nature of the processing and the information available, with:
If a data subject contacts in-manas directly, the request will be assigned and forwarded to the customer, provided this is possible. An independent response will only be provided upon the customer's instruction or due to a legal obligation.
9. Security of processing
in-manas shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk in accordance with Art. 32 GDPR.
The current description of these measures is an integral part of this agreement and is available on the in-manas website under "Technical and organisational measures".
in-manas may adapt the measures to technical and organisational developments and implement equivalent or superior measures. The agreed level of security must not be compromised as a result.
10. Data breaches
in-manas will inform the customer without undue delay after becoming aware of any breach of the protection of personal data processed on behalf of the customer.
The notification shall include, as far as available:
Information that is not yet available may be provided without undue delay.
The decision regarding notifications to supervisory authorities and the notification of affected individuals lies with the customer, unless in-manas is itself legally obligated to report.
11. Deletion and Return
Upon termination of the data processing services, in-manas will delete, anonymise, or return the personal data processed on behalf of the customer in accordance with the agreement and the customer's instructions, provided there is no legal obligation to retain the data.
Data in backups is deleted in accordance with the defined retention and overwriting cycles. Until final deletion, it remains protected from any further productive processing.
The customer is responsible for requesting or performing necessary data exports in good time before the contract ends.
12. Evidence and Audits
in-manas provides the customer with the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR.
Evidence can be provided in particular through the following documents:
If such documentation is insufficient for an adequate audit, the customer may conduct a supplementary inspection themselves or through an independent auditor bound by confidentiality obligations.
Audits must be announced with reasonable notice, conducted during normal business hours, and carried out in a manner that does not disrupt business operations or compromise the security and confidentiality of other customers.
An auditor may be rejected for legitimate reasons, particularly if they are a competitor of in-manas or if there are concerns regarding their independence or confidentiality.
Reasonable compensation may be agreed upon for audits that exceed the scope of standard, legally required documentation.
13. Sub-processors
The customer grants in-manas general authorisation to engage sub-processors.
The current list of sub-processors used is available on the in-manas website.
in-manas will inform the customer in text form at least 30 calendar days prior to the appointment or replacement of any sub-processor. The customer may object within ten business days for valid data protection reasons.
in-manas contractually obligates sub-processors to data protection requirements that are substantially equivalent to those in this agreement. in-manas remains responsible to the customer for the fulfillment of these obligations.
Currently engaged infrastructure and support provider
nextLayer GmbH
Mariahilfer Gürtel 37/7
1150 Vienna
Austria
Services: Provision and operation of data centre and virtualisation infrastructure, technical infrastructure maintenance, data centre support, and assistance with backup and recovery services.
Processing location: Vienna, Austria.
Access by support personnel is limited to what is necessary for the commissioned technical service.
Additional optional providers, particularly providers of external AI services, are utilised depending on the contractually agreed configuration and the settings chosen by the customer. The provider, processing location, and legal basis for the transfer are specified in the current list of sub-processors and the agreed product information.
14. Processing Locations and Third-Country Transfers
The standard provision and storage of productive SaaS data takes place within the European Union.
Data transfers to a third country or an international organisation only take place:
Where standard contractual clauses or additional safeguards are required, these shall be agreed upon as a supplement.
15. Term and Termination
This agreement remains in effect for the duration of the main contract and terminates once in-manas no longer processes personal data on behalf of the customer.
In the event of a serious or repeated violation of this agreement or the GDPR, the customer may suspend processing or terminate the relevant contract in accordance with legal and contractual provisions.
16. Liability
The liability of the parties for violations of the GDPR is governed in particular by Art. 82 GDPR and other applicable legal provisions.
To the extent that both parties are responsible for any damage, internal compensation shall be made according to their respective share of responsibility.
Supplementary liability provisions in the main contract remain applicable, provided they do not conflict with mandatory data protection regulations.
17. Amendments to this Agreement
in-manas may amend this agreement to reflect changes in the legal situation, the services offered, or the processing operations employed.
Material changes will be communicated to the customer in text form. Changes that expand the customer's obligations, reduce the agreed level of data protection, or involve new sub-processors or third-country processing shall not become binding solely through their publication on the website.
Changes to sub-processors are subject to the procedure outlined in Section 13.
18. Final Provisions
Austrian law applies, excluding the UN Convention on Contracts for the International Sale of Goods, unless mandatory legal provisions dictate otherwise.
The place of jurisdiction shall be determined by the main contract and mandatory legal provisions.
Should any provision of this agreement be invalid or unenforceable, the validity of the remaining provisions shall remain unaffected.
This agreement consists of the following components:
DATA PROTECTION AND INFORMATION SECURITY
in-manas protects customer and personal data through technical and organisational measures that are regularly reviewed and developed on a risk-based approach.
Hosting and physical security
Our productive SaaS infrastructure is operated in an ISO 27001-certified data centre in Vienna. The data centre operator ensures controlled access procedures, technical monitoring, and redundant power and network infrastructure.
The ISO 27001 certification applies to the data centre operator. in-manas itself does not currently hold its own ISO 27001 certification.
Access and authorisation protection
Access to our systems is provided via personalised user accounts and secure connections. Permissions are assigned based on roles and follow the need-to-know and least-privilege principles.
Administrative access to the production environment is restricted to a strictly limited, authorised group of people. Multi-factor authentication is used for central and administrative systems wherever technically supported.
Protection during data transmission
Data transfers between customers and our platform are encrypted. Administrative connections and internal transmission paths are also protected by appropriate technical measures.
Data is only transferred to third parties on a contractual basis, based on customer instructions or configuration, or due to a legal obligation.
Separation of systems and customer data
Production, test, and development environments are operated separately. Developers generally do not have access to actual production data.
We use synthetic or anonymised data for development and testing. Data from different customers is logically separated within the platform and protected by application-level permission checks.
Logging and monitoring
Security and operational events are logged and monitored. Logging supports error analysis, the detection of security events, and the traceability of administrative activities.
Access to log data is restricted to authorised personnel.
Data backup and availability
We create regular, encrypted, and off-site backups. Documented emergency and recovery procedures support the resumption of operations following disruptions.
Systems and applications are maintained regularly. Security-relevant updates are implemented based on risk assessments.
Organisation and security awareness
Responsibilities and escalation paths for information security are defined internally. Employees with potential access to customer or personal data are bound by confidentiality and receive regular training on data protection and information security.
Information security risks are assessed regularly, and derived improvement measures are tracked.
Handling security incidents
We have a documented incident response process for security incidents. This includes detection, analysis, containment, recovery, and post-incident review.
Affected customers and relevant authorities will be notified as required by law or contract.
Further information
We provide our customers with contractual agreements on data processing, a versioned description of our technical and organisational measures, and information regarding sub-processors upon contract conclusion or request.