# Compliance Documents on Demand: DPA, TOMs and Sub-Processors

> The new compliance area provides your data processing agreement, technical and organisational measures and the sub-processor list as ready-to-share PDFs.

> Source: https://www.mainpath.ai/en/blog/compliance-documents/

The question comes up in almost every customer project: "Could you send us the data processing agreement and an overview of the services you use?" What follows is a search through old emails and a document from a previous project, with no certainty it is current.

Since 5 August there is a dedicated area for this, generating the paperwork from what is actually configured in your organisation.

## What the compliance area contains

Four documents are available for every organisation, each in German and English:

- **Data processing agreement (DPA)**. The contract between you and MainPath as the processor
- **Technical and organisational measures (TOMs)**. The safeguards that apply to access, transmission and availability
- **Privacy policy**. How processing works in the context of MainPath
- **Scope statement**. What MainPath takes on and where your responsibility begins

On top of that there is a list of sub-processors. Exactly the information customers need for their own record of processing activities.

You download each document as a PDF, or as a single ZIP export for a complete handover.

## The documents are generated from your data

The difference: these documents are not static. In your organisation settings you enter the legal details. Company name, address, contact person. And those flow automatically into the generated PDFs, so a contract never starts with a placeholder like "Company, Street, City."

A project overview complements this: Firebase in one project, Sentry in another, Mailtrap in a third. All visible in the compliance area instead of collected separately.

{{< visual type="screenshot" screen="08_audit_log" caption="The audit log complements the paperwork with evidence of who changed what and when." >}}

## Where this helps day to day

Three situations come up regularly:

**Customer onboarding.** A new customer asks for data protection paperwork before signing. Instead of several rounds of questions, you send the ZIP export.

**Audits and certifications.** During an ISO 27001 review you are asked to evidence which providers are involved and which contracts exist. The sub-processor list covers exactly that.

**Tenders.** In the public sector and regulated industries, a DPA and TOMs are often part of the required documentation. Supplying them at short notice saves a round trip.

## A note on scope

MainPath provides documentation and describes what happens on its side, but it does not replace legal advice. Whether your use case needs additional measures. A data protection impact assessment for sensitive data, say. Is a question for your legal counsel. What it automates is current documents, correctly filled in, in both languages, available whenever you need them.

## Alongside operating in the EU

The compliance area complements a property MainPath has had from the start: operation and data processing happen inside the EU, on servers you select yourself. Often the condition under which projects with public-sector, healthcare or finance customers happen at all. More on this on the page about [GDPR compliant hosting](/en/solutions/dsgvo-hosting/).

