# Compliance Documents on Demand: DPA, TOMs and Sub-Processors

> The new compliance area provides your data processing agreement, technical and organisational measures and the sub-processor list as ready-to-share PDFs.

> Source: https://www.application-platform.com/en/blog/compliance-documents/

The question comes up in almost every customer project: "Could you send us the data processing agreement and an overview of the services you use?" What follows is a search through old emails and a document from a previous project, with no certainty it is current.

Since 5 August there is a dedicated area for this, generating the paperwork from what is actually configured in your organisation.

## What the compliance area contains

Four documents are available for every organisation, each in German and English:

- **Data processing agreement (DPA)** — the contract between you and the platform as the processor
- **Technical and organisational measures (TOMs)** — the safeguards that apply to access, transmission and availability
- **Privacy policy** — how processing works in the context of the platform
- **Scope statement** — what the platform takes on and where your responsibility begins

On top of that there is a list of sub-processors — exactly the information customers need for their own record of processing activities.

You download each document as a PDF, or as a single ZIP export for a complete handover.

## The documents are generated from your data

The difference: these documents are not static. In your organisation settings you enter the legal details — company name, address, contact person — and those flow automatically into the generated PDFs, so a contract never starts with a placeholder like "Company, Street, City."

A project overview complements this: Firebase in one project, Sentry in another, Mailtrap in a third — all visible in the compliance area instead of collected separately.

{{< visual type="screenshot" screen="08_audit_log" caption="The audit log complements the paperwork with evidence of who changed what and when." >}}

## Where this helps day to day

Three situations come up regularly:

**Customer onboarding.** A new customer asks for data protection paperwork before signing. Instead of several rounds of questions, you send the ZIP export.

**Audits and certifications.** During an ISO 27001 review you are asked to evidence which providers are involved and which contracts exist. The sub-processor list covers exactly that.

**Tenders.** In the public sector and regulated industries, a DPA and TOMs are often part of the required documentation. Supplying them at short notice saves a round trip.

## A note on scope

The platform provides documentation and describes what happens on its side, but it does not replace legal advice. Whether your use case needs additional measures — a data protection impact assessment for sensitive data, say — is a question for your legal counsel. What it automates is current documents, correctly filled in, in both languages, available whenever you need them.

## Alongside operating in the EU

The compliance area complements a property the platform has had from the start: operation and data processing happen inside the EU, on servers you select yourself — often the condition under which projects with public-sector, healthcare or finance customers happen at all. More on this on the page about [GDPR compliant hosting](/en/solutions/dsgvo-hosting/).

