Skip to content

Company master data

Under Settings → Company master data you record how your organisation is named in the contract. These details describe you as the contracting party — they have nothing to do with your domain data and appear neither in the explorer nor in any report.

They are needed in exactly one place: the Contract data table of the data processing agreement. The publicly published version of that agreement reads “as specified in the main contract or the order” throughout. Once you fill these fields in, your organisation can take their place.

Company and address. The company name exactly as entered in the commercial register, including the legal form — so “Muster Handels GmbH”, not “Muster”. Plus the full registered address, the VAT number and, where applicable, the commercial register number with its registry court.

Contract and operating model. The designation and date of your main contract or order, as free text. The operating model says where your Data Nodes run:

  • M1 — fully managed: roleALPHA operates everything.
  • M2 — hybrid: the Data Nodes run on your own infrastructure.
  • M3 — customer cloud: the Data Nodes run at a host you have engaged.

The Core is operated by roleALPHA in all three models. If this says “Not yet specified”, what your main contract agrees applies.

Contacts. The persons authorised to issue instructions are those who may give roleALPHA instructions on data processing — name and function are enough. The data protection contact is the address a notification goes to if there is a personal data breach; roleALPHA reports such a breach within 48 hours.

If these two fields are left empty, the administrators of your tenant and the address recorded there apply. That is a usable fallback but not a good one: in an emergency the notification then lands in a shared mailbox rather than with the person who has to act on it.

The page is reserved for administrators. A tenant administrator maintains the master data of their own tenant; platform administration can maintain it for any tenant.

A newly created tenant has nothing but its name. An empty field does not mean something is missing — it means the detail is in the main contract. You can fill the fields in at any time.

In the same settings, below the master data, you will find Create a data processing agreement. It generates a copy of the agreement in which your organisation is named — instead of the generic wording “as specified in the main contract or the order”.

How it works. You tick which categories of persons and data actually occur in your organisation, confirm acceptance and press Create agreement. Electronic acceptance is sufficient; if you would rather sign, print the PDF and use the signature block at the end of section 9.

What the ticks mean — and what they do not. They are your declaration as controller about which categories occur at your organisation. They do not control what the platform processes: that follows from the modules your organisation has booked and is set out in Annex 1.1 of the agreement. A missing tick therefore switches nothing off.

Empty fields are not an obstacle. Anything you have not recorded in the master data stays in its generic wording in the generated agreement. You can add the details later and create a new agreement; the earlier one is kept.

The archive. Every copy is kept with its version, date, the person who accepted it and a checksum. The checksum evidences that a file presented later is the same one. Download gives it back to you at any time.

Agreements created are deliberately retained when a tenant is deleted — they evidence which version was accepted and when, and are subject to retention under tax law.

See also: Settings at a glance