This English version is a courtesy translation. Only the German version is legally binding.
This Data Processing Agreement ("DPA") applies between the customer as controller or processor engaging a sub-processor and Legado Management UG (haftungsbeschränkt), Hauptstraße 46, 15936 Dahme/Mark, Germany ("Provider"), as processor. It forms part of the contract for the use of GxP-Desk, including the free trial, if incorporated accordingly (§ 1(3)).
§ 1 Subject Matter, Term and Conclusion
(1) This DPA sets out the data protection rights and obligations of the parties regarding the processing of personal data by the Provider on behalf of the customer (Art. 28 GDPR). It is based on the contract for the use of GxP-Desk ("Main Agreement"), consisting of the General Terms and Conditions ("Terms") and, where applicable, a quote or order form. "Customer Data" means all personal data that the Provider processes on behalf of the customer under the Main Agreement.
(2) The customer is the controller within the meaning of Art. 4(7) GDPR; the Provider is the processor within the meaning of Art. 4(8) GDPR. Where the customer itself acts as a processor for a third party, the Provider acts as a sub-processor; the customer ensures that the necessary authorisation has been obtained and that it is entitled to give instructions. This DPA does not cover processing for which the Provider determines the purposes and means as a controller in its own right, in particular contract administration, billing and management of its customer relationship; the Privacy Policy applies to such processing. The classification of account, support and security data depends on the purpose of the particular processing: customer content, audit trail, signature, AI and communication data, and personal data contained in bug reports remain Customer Data to the extent processed on behalf of the customer.
(3) This DPA takes effect upon conclusion of the Main Agreement, including the trial agreement, provided it is incorporated at that time; publication alone does not constitute a contractual agreement. Conclusion in electronic form is sufficient (Art. 28(9) GDPR); no separate signature is required. The version agreed when the contract is concluded applies. On request, the Provider makes that version available to the customer in text form.
(4) The term of this DPA corresponds to the term of the Main Agreement. The obligations under this DPA continue to apply for as long as the Provider processes Customer Data, in particular until return and deletion under § 12 have been completed.
(5) In the event of conflict, this DPA takes precedence over the Terms and the other provisions of the Main Agreement in matters of processing on behalf of the customer. Individually agreed provisions take precedence under Section 305b BGB; a separately negotiated data processing agreement replaces this DPA to the extent agreed. Mandatory statutory rights, in particular those relating to switching providers under Regulation (EU) 2023/2854 (Data Act), remain unaffected.
§ 2 Nature and Purpose of Processing, Types of Data and Data Subjects
(1) The subject matter of the processing is the provision, operation, maintenance and support of GxP-Desk as software-as-a-service. The nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex 1.
(2) The Provider processes Customer Data solely to provide the services under the Main Agreement and not for its own purposes. In particular, it does not use Customer Data to train AI models.
(3) The customer is responsible for the lawfulness of the processing, including the legal basis and informing data subjects (Art. 13, 14 GDPR), and for the content uploaded by it and its users.
(4) The customer informs the Provider without undue delay if, when using the application, it detects errors or irregularities relating to data protection provisions.
§ 3 Instructions
(1) The Provider processes Customer Data only on documented instructions from the customer, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which the Provider is subject. In such a case, the Provider informs the customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28(3)(a) GDPR).
(2) The basic instructions are documented in the Main Agreement and this DPA. The use and configuration of the application by the customer and its authorised users within their authority also constitutes an instruction, for example assigning roles and permissions, setting retention periods, connecting single sign-on, issuing API keys, configuring an AI provider, and exporting or deleting data. The customer gives individual instructions in text form, for example by email to info@gxpdesk.app; the customer confirms oral instructions in text form without undue delay. The Provider documents the instructions received.
(3) On the customer's instructions – given through the respective configuration – the Provider transfers Customer Data in particular:
- to the AI provider configured by the customer with its own API key (e.g. OpenAI, Anthropic, Google or a self-hosted system): inputs (prompts) and the tenant content required for the respective AI function;
- to the identity provider connected by the customer (single sign-on via OIDC or SAML 2.0) in the course of sign-in;
- to API clients that authenticate with API keys issued by the customer;
- by email to users and other recipients designated by the customer in the application for invitations, notifications and reminders.
The customer determines these recipients and is responsible for engaging them and for their processing. The Provider's own obligations remain unaffected (§ 11(4)). These recipients are not Sub-processors of the Provider subject to the conditions in § 6(6). AI functions are optional and become active only when a customer administrator configures them with the customer's own key (BYOK); they may be disabled or restricted to local models. Inputs, context and results are stored in the AI log. Any retention or use for training by an AI provider is governed by the customer's contract with it. AI results are suggestions and require human review and approval.
(4) The administrators of the customer account and the persons who concluded the Main Agreement on behalf of the customer are authorised to give instructions. The customer may designate further authorised persons to the Provider in text form.
(5) If the Provider considers that an instruction infringes the GDPR or other Union or Member State data protection provisions, it informs the customer immediately (Art. 28(3), final subparagraph, GDPR). It may suspend the affected processing pending clarification to the extent necessary to avoid an infringement. Confirmation by the customer does not make an unlawful instruction lawful; the Provider does not execute unlawful instructions. The parties agree on a lawful course of action.
(6) Instructions for additional services outside the contractual and statutory obligations are treated as a change request; their implementation may be made subject to an agreement on reasonable remuneration. Compliance with Art. 28 GDPR and this DPA, in particular necessary assistance, return and deletion, must not be made conditional on an additional fee agreement or delayed for that reason.
§ 4 Confidentiality and Data Protection Organisation
(1) When processing Customer Data, the Provider only uses persons who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality and who have been familiarised with the relevant data protection provisions (Art. 28(3)(b), Art. 29 GDPR). This obligation continues after the end of their engagement.
(2) Persons working for the Provider access Customer Data only to the extent necessary for operation, maintenance, troubleshooting, support or compliance with legal obligations.
(3) The Provider has not currently designated a data protection officer. The contact person for data protection matters is the managing director, Christoph Seydel, reachable at info@gxpdesk.app. The Provider assesses the statutory requirements for designation under Art. 37 GDPR and Section 38 BDSG and designates a data protection officer if required.
(4) The Provider maintains the legally required record of processing activities under Art. 30(2) GDPR and cooperates with the competent supervisory authority on request (Art. 31 GDPR).
§ 5 Technical and Organisational Measures
(1) The Provider implements the technical and organisational measures required under Art. 32 GDPR, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to the rights and freedoms of data subjects. The agreed measures are set out in Annex 2.
(2) The Provider may further develop the measures and replace them with equivalent or better measures, provided the agreed level of protection is not reduced and the requirements of Art. 32 GDPR continue to be met. The Provider documents material changes and notifies the customer in text form in good time before implementation. It may implement urgent security measures immediately and informs the customer without undue delay. Any reduction in the agreed level of protection requires agreement between the parties and must not fall below statutory requirements. Information on the security page does not replace the agreed measures.
(3) The customer is responsible for measures within its own sphere, in particular managing its users, assigning roles and permissions in line with the principle of least privilege, using two-factor authentication or single sign-on, protecting credentials and API keys, selecting and configuring an AI provider, and securing its own devices and networks.
§ 6 Sub-processors
(1) The customer grants the Provider general authorisation to engage other processors ("Sub-processors") (Art. 28(2) GDPR). The Sub-processors listed in Annex 3 are deemed approved upon conclusion of this DPA.
(2) The Provider informs the customer of any intended addition or replacement of a Sub-processor at least four weeks in advance in text form, as a rule by email to the administrators of the customer account. The information includes the name, address, service and location of processing and, where applicable, the safeguards for a third-country transfer.
(3) The customer may object to the change in text form on data protection grounds within four weeks of receiving the complete information and explains those grounds. The parties seek a solution that addresses justified concerns. Until the matter is resolved, the Provider does not use the disputed Sub-processor for this customer's Customer Data. If lawful continuation without that Sub-processor is impossible and no solution is reached, either party may terminate the affected services, or the Main Agreement if those services cannot be separated, with effect no earlier than the planned change date. The Provider refunds any prepaid fees for the period after termination on a pro rata basis; return and deletion obligations remain in force. If no timely objection is made, the Provider may implement the change under the general authorisation; its notice expressly states the deadline and this consequence.
(4) Where an unforeseen urgent need for a change arises, the Provider informs the customer without undue delay and may request express authorisation for an earlier start. Urgency does not replace authorisation or the opportunity to object under Art. 28(2) GDPR. Until use of the Sub-processor is permissible, the Provider safeguards Customer Data and, where necessary, agrees with the customer on a temporary restriction of the affected processing.
(5) The Provider selects Sub-processors carefully and contractually imposes on them the same data protection obligations as set out in this DPA, in particular sufficient guarantees for appropriate technical and organisational measures (Art. 28(4), first sentence, GDPR). Where a Sub-processor fails to fulfil its data protection obligations, the Provider remains liable to the customer for the performance of that Sub-processor's obligations (Art. 28(4), second sentence, GDPR).
(6) The recipients selected by the customer under § 3(3) are not Sub-processors of the Provider to the extent that the customer engages them directly or designates them as recipients and the Provider merely carries out the instructed transfer. In particular, use of an AI API key belonging to the customer does not constitute engagement of the AI provider by the Provider. For other service providers, the actual activity determines the classification: if they process Customer Data on behalf of the Provider, the requirements of this § 6 also apply to ancillary services. Under the agreed scope of processing, Prelumen Analytics is used only for the public website and is not a Sub-processor for Customer Data from the application.
§ 7 Assistance with Data Subject Rights
(1) Taking into account the nature of the processing, the Provider assists the customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the rights of data subjects under Chapter III GDPR (Art. 28(3)(e) GDPR). This is done primarily through functions of the application that the customer uses itself, in particular user and permission management, editing of content, and the export functions (DOCX, PDF, JSON).
(2) If these functions are insufficient in a particular case, the Provider assists the customer on documented instructions with the measures required by Art. 28(3)(e) GDPR and in sufficient time for the customer to meet its statutory deadlines; § 8(3) applies.
(3) If a data subject contacts the Provider directly, the Provider forwards the request to the customer without undue delay, insofar as it can be attributed to the customer. The Provider does not answer the request itself but refers the data subject to the customer.
(4) Audit trail entries can technically only be appended to; electronic signatures support the traceability of GxP records. This does not exclude data subject rights. Taking account of applicable retention obligations and Art. 16 to 19 GDPR, the customer decides on rectification, erasure or restriction. The Provider assists with lawful implementation while preserving data integrity, for example through traceable corrections or access restrictions. It communicates technical limitations without undue delay and agrees suitable alternatives with the customer.
§ 8 Assistance with Obligations under Art. 32 to 36 GDPR
(1) Taking into account the nature of the processing and the information available to it, the Provider assists the customer in ensuring compliance with the obligations under Art. 32 to 36 GDPR (Art. 28(3)(f) GDPR), in particular through:
- information on the security of processing (Art. 32 GDPR), above all through Annex 2;
- notifications and information on personal data breaches under § 9 (Art. 33, 34 GDPR);
- information on the processing and the measures taken that the customer requires for a data protection impact assessment (Art. 35 GDPR);
- cooperation in a prior consultation of the supervisory authority (Art. 36 GDPR).
(2) The Provider informs the customer without undue delay of inspections and measures by a supervisory authority insofar as they concern Customer Data, unless prohibited by law.
(3) The assistance required by Art. 28 GDPR under §§ 7 and 8 is included in the agreed fees; for the free trial it is provided free of charge. Only additional services separately requested beyond that assistance may be charged on a time-spent basis under a prior agreement in text form on their scope and reasonable fees. Statutory assistance must neither be restricted nor delayed as a result. No additional fee is charged for remedying a breach for which the Provider is responsible.
§ 9 Notification of Personal Data Breaches
(1) The Provider notifies the customer of a personal data breach affecting Customer Data without undue delay after becoming aware of it (Art. 33(2) GDPR). It does not wait for the investigation to be completed or for all information to become available. The initial notification is sent by email to the administrators of the customer account and to any contact address designated by the customer for this purpose. The customer keeps these contact details up to date.
(2) The notification contains, insofar as known, the information under Art. 33(3) GDPR:
- a description of the nature of the breach, including, where possible, the categories and approximate number of data subjects and records concerned;
- the name and contact details of a contact person at the Provider;
- a description of the likely consequences of the breach;
- a description of the measures taken or proposed to address the breach and, where appropriate, to mitigate its possible adverse effects.
Where it is not possible to provide the information at the same time, the Provider provides it in phases without undue further delay.
(3) The Provider takes the necessary measures without undue delay to secure Customer Data and to mitigate possible adverse consequences, coordinates these with the customer, and documents the breach including the remedial measures taken.
(4) Notifications to the supervisory authority and communications to data subjects (Art. 33, 34 GDPR) are the customer's responsibility. The Provider makes them on behalf of the customer only on the customer's instructions.
(5) A notification under this § 9 does not constitute an acknowledgement of fault or liability on the part of the Provider.
§ 10 Evidence and Audits
(1) On request, the Provider makes available to the customer all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and in this DPA, and allows for and contributes to audits, including inspections, conducted by the customer or another auditor mandated by the customer (Art. 28(3)(h) GDPR).
(2) Documentation, supplementary written explanations of the technical and organisational measures, and answers to reasonable questionnaires may support an audit. They do not replace the customer's right to audits, including inspections.
(3) The customer may conduct audits, including inspections, itself or through an auditor it appoints. Routine audits should normally be announced in text form 30 days in advance and take place during normal business hours. Their scope and frequency depend on the processing risk and audit needs; an annual routine audit is an organisational guideline, not a limit. Security incidents, concrete indications of breaches or requirements of a supervisory authority permit additional audits and shorter notice periods, or no advance notice where necessary. Audits must not disrupt operations disproportionately. By agreement, they may be conducted remotely or combined with a GxP supplier audit.
(4) The customer and any auditor it appoints protect confidential information. The Provider may reject an auditor only on specifically substantiated confidentiality or conflict-of-interest grounds; in that case, the parties promptly enable an equivalent audit by another suitable auditor. Reasonable safeguards prevent access to other customers' data and risks to the security of the service without frustrating verification of compliance. For Hetzner and other Sub-processors, the Provider supplies appropriate evidence and, where necessary, arranges for the exercise of corresponding contractual audit rights; available documentation does not exhaustively limit its obligation to provide evidence.
(5) Each party bears its own costs of complying with Art. 28(3)(h) GDPR and of the auditors it appoints. Only optional additional services outside those obligations may be charged separately by prior agreement. A necessary audit must not be made conditional on additional payments.
(6) The powers of supervisory authorities are not affected by the restrictions of this § 10.
§ 11 Location of Processing and Third-Country Transfers
(1) The application, including databases, file storage, mail server and backups, is operated in data centres in Germany (Falkenstein and Nuremberg). No US data plane is used. This is distinct from the processing of bug report summaries at GitHub under paragraph 3 and the customer-instructed transfers under § 3(3), which may involve processing outside the EU or EEA depending on the recipient.
(2) Transfers of Customer Data to third countries, including access from a third country, take place only in compliance with Art. 44 et seq. GDPR. For Sub-processors, § 6 must also be followed. The Provider documents the applicable transfer mechanism and, where relying on safeguards under Art. 46 GDPR, assesses the need for supplementary measures. If a valid mechanism ceases to apply, it suspends the affected transfer until a lawful mechanism is established and informs the customer without undue delay.
(3) When a user voluntarily submits a bug report through the application, a summary is transferred as a ticket to a private repository at GitHub, Inc. (USA). It may contain the report ID, severity, URL without parameters, route, app version, window size, user agent, timestamp and free text; screenshots remain on the Provider's own server. Transfers to GitHub rely on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR) or on standard contractual clauses (Art. 46(2)(c) GDPR) with necessary supplementary safeguards. Reliance on the adequacy decision requires it to remain in force and the recipient to hold valid certification covering the particular processing; otherwise, effective appropriate safeguards are required. The Provider verifies these conditions before transferring data and supplies appropriate evidence to the customer on request. The customer instructs its users to exclude unnecessary personal data, in particular data about third parties, from bug reports.
(4) For recipients chosen by the customer under § 3(3), in particular AI providers, the customer determines the recipient and is responsible for engaging it, its processing, and the required transfer mechanism. When executing the instruction, the Provider complies with its own obligations under Art. 28 and Art. 44 et seq. GDPR; an instruction alone does not replace a transfer mechanism. § 3(5) applies accordingly.
§ 12 Return and Deletion
(1) During the term, the customer determines retention periods for Customer Data according to its legal requirements and gives any necessary deletion instructions. The document retention period is configurable per tenant and defaults to 3650 days; this is not a statutory minimum. Audit trail entries and AI logs are retained in accordance with the customer's instructions; the audit trail is not deleted automatically. Exports are available through the provided functions in DOCX, PDF or JSON; their scope and format depend on the particular export function. If the functions are insufficient to implement lawful instructions, the Provider assists the customer under §§ 3 and 7.
(2) After the processing services end, the customer may choose between return and deletion of all Customer Data (Art. 28(3)(g) GDPR). Unless otherwise instructed, Customer Data remains available for export for 30 days after the Main Agreement ends. If the customer chooses return, the Provider supplies Customer Data through the export functions and, where necessary, with supplementary assistance in an agreed commonly used machine-readable format; merely making an export function available does not constitute completed return. It then deletes the remaining copies under paragraph 3. Earlier deletion takes place on documented instructions unless mandatory statutory requirements prevent it. Any right to retain Customer Data as security for claims is excluded.
(3) After the retrieval period expires or upon a lawful instruction for earlier deletion, the Provider deletes Customer Data from its active systems and arranges deletion by its Sub-processors within five working days (Monday to Friday, excluding public holidays at the Provider's registered office). This includes personal Customer Data in documents, audit trails, signatures, AI logs, bug reports and GitHub tickets, and in the MailOutbox, mail server and delivery events. Remaining backup copies are deleted or overwritten no later than 90 days after deletion from active systems. A valid instruction for earlier deletion and mandatory deletion obligations remain applicable. Until then, they are restricted to recovery purposes and remain subject to this DPA; deletion is reapplied if a backup is restored. On request, the Provider confirms completion and any outstanding backup deletion in text form.
(4) An exception to deletion applies only to the extent that Union or Member State law requires the Provider to retain the data concerned. To the extent legally permitted, the Provider informs the customer of the legal basis, scope of data and duration, restricts processing to the statutory retention purpose, and deletes the data once the obligation ends. The Provider's operational retention settings or the customer's GxP obligations do not create such an exception.
(5) The customer determines the retention and archiving requirements applicable to its GxP records. The Provider fulfils the agreed processing, return and assistance obligations; archiving beyond the contract term and applicable retrieval periods requires a separate agreement. The customer plans timely export and continued readable retention of its records, including audit trails and electronic signatures. Necessary assistance with complete return is governed by paragraph 2.
(6) Mandatory switching and data retrieval rights under Regulation (EU) 2023/2854 (Data Act) and any broader provisions of the Main Agreement remain unaffected. Where a switching procedure is ongoing or a longer retrieval period applies, the deletion period under paragraph 3 begins only after that procedure has been duly completed or that period has expired, unless the customer lawfully requests earlier deletion. This DPA does not shorten those rights or periods.
(7) For the trial, the customer may request deletion of its Customer Data at any time. If no paid contract is concluded, the Provider deletes that data from active systems after a reasonable period for the customer to decide whether to continue and to retrieve its data, and no later than six months after the trial ends. After the trial ends, access switches to read-only mode; the Provider informs the customer in good time before the planned deletion of the opportunity to have its data returned. Paragraphs 2 to 4 and 6 apply accordingly; the six-month deadline is not extended by the five-working-day period.
(8) The following retention limits apply during ongoing processing: the Provider deletes bug reports on its own server after 180 days. It retains transactional email content, including in the outgoing queue and mail server, only to the extent necessary and for no more than twelve months. Delivery metadata without content (recipient, time and delivery status), including delivery events, is retained as evidence of dispatch for no more than three years. It deletes server/container logs no later than after 30 days; longer retention applies only for as long as needed to investigate a specific security incident. The Provider ensures deletion in accordance with these limits and documented instructions. Earlier lawful deletion instructions and the deletion periods above, particularly upon termination, take precedence.
§ 13 Liability
(1) The parties are liable for damage suffered by data subjects in accordance with Art. 82 GDPR. Between themselves, the parties bear the damage in proportion to their responsibility for the event giving rise to the damage (Art. 82(2), (4) and (5) GDPR).
(2) Otherwise, the liability provisions validly agreed in the Main Agreement apply between the parties, unless mandatory law provides otherwise. This reference does not limit data subjects' claims, the statutory right of recourse under Art. 82(5) GDPR, or responsibility for Sub-processors under Art. 28(4) GDPR.
§ 14 Final Provisions
(1) Amendments and additions to this DPA are agreed in text form. The precedence of individually agreed provisions under Section 305b BGB remains unaffected. Annex 2 may be updated as permitted by § 5(2), and Annex 3 under § 6; other unilateral changes by publication are excluded.
(2) The annexes form part of this DPA. The order of precedence in relation to the Main Agreement and individually concluded agreements is governed by § 1(5).
(3) If Customer Data held by the Provider is endangered by attachment, seizure, insolvency proceedings or other measures by third parties, the Provider informs the customer without undue delay and notifies the third parties that responsibility for the Customer Data lies with the customer as controller.
(4) The governing law and place of jurisdiction set out in the Terms apply to this DPA. Mandatory provisions of the GDPR remain unaffected.
(5) If a provision is invalid, the consequences are governed by statutory law, in particular Section 306 BGB; an invalid clause is not reduced to the maximum scope that would still be permissible.
Annex 1 – Description of the Processing
1. Subject matter and purpose
Provision of GxP-Desk (https://gxpdesk.app) as software-as-a-service for managing computer system validation, in particular hosting and operating the application, storing Customer Data, sending notifications, executing the integrations configured by the customer (single sign-on, REST API, AI functions), backups, ensuring the security and integrity of processing, maintenance, error analysis and support.
2. Nature of the processing
Collection, recording, organisation, storage, adaptation and alteration, retrieval, consultation, use, disclosure by transmission on the customer's instructions, restriction, erasure.
3. Types of personal data
| Category | Examples |
|---|---|
| User master data | Name, business email address, function or job title, roles and permissions, tenant assignment |
| Authentication data | Password hash, MFA and WebAuthn/passkey data, SSO identifiers, remembered devices, API keys |
| Log data | IP address, user agent, timestamps, audit trail entries, failed re-authentications |
| Electronic signatures | Attribution to the signing user and record, IP address, user agent |
| Training records | Training assignments, completion status, training signatures |
| Business content | System inventory, documents, change requests, risk assessments, supplier evaluations including names and contact details of supplier contact persons, comments, uploaded files |
| Communication data | Email notifications, invitations and reminders (recipient, subject, content), delivery status |
| AI data (only if activated by the customer) | Inputs (prompts), context transmitted, AI results, AI log |
| Bug reports | Free text, optional screenshot, URL without parameters, route, app version, window size, user agent, timestamp |
4. Categories of data subjects
- employees and other agents of the customer, in particular users of the application;
- staff of suppliers, service providers and other business partners of the customer;
- other persons named in content uploaded by the customer.
5. Special categories of personal data
The processing of special categories of personal data (Art. 9 GDPR) and of data relating to criminal convictions and offences (Art. 10 GDPR) is not intended. In particular, the customer does not upload health or patient data, such as data on clinical trial participants, to the application. If this is exceptionally necessary, the parties agree on it in advance in text form and, where appropriate, define additional measures.
6. Duration and location of processing
The duration is governed by § 1(4) and § 12, the location of processing by § 11.
Annex 2 – Technical and Organisational Measures
The following technical measures and functions reflect the agreed scope of processing. The organisational obligations additionally identified must be fulfilled by the Provider under this DPA; they do not represent a statement that assessments have already been performed or that certifications exist. The suitability of the measures must be assessed according to risk under Art. 32 GDPR. Further information is available on the security page.
1. Confidentiality (Art. 32(1)(b) GDPR)
Physical access control: Hosting is provided in data centres operated by Hetzner Online GmbH in Germany. The Provider assesses Hetzner's physical safeguards relevant to the processing, secures them contractually and supplies appropriate evidence to the customer under § 10.
System access control:
- server hardening with a firewall, SSH access by key only, and automatic blocking of suspicious access attempts (fail2ban);
- passwords stored exclusively as Argon2id hashes;
- available two-factor authentication (TOTP, WebAuthn/passkeys) and single sign-on via the customer's identity provider (OIDC, SAML 2.0), subject to customer configuration;
- account lockout after five failed attempts within 15 minutes, and rate limiting;
- sessions limited to a maximum of 24 hours, with sign-out after inactivity;
- API keys for authenticating REST API clients connected by the customer.
Data access control:
- role-based permission concept following the principle of least privilege, configurable by the customer;
- segregation of duties for approvals;
- re-authentication before every electronic signature;
- access to Customer Data by the Provider's personnel only in accordance with § 4(2).
Separation control: Tenant separation through tenant-bound database access; logical separation of the control plane and EU data plane on the same host.
Encryption and pseudonymisation:
- encryption in transit throughout via HTTPS/TLS;
- encrypted storage of secrets such as API and AI keys (AES-256-GCM);
- encrypted backups (AES-256-GCM);
- encrypted tunnel (WireGuard) between the application and the mail server.
Individual GxP records and electronic signatures must remain attributable to individuals. The Provider assesses, according to risk under Art. 32 GDPR, whether pseudonymisation or additional encryption is necessary and appropriate for other data, and agrees any required measures with the customer.
2. Integrity (Art. 32(1)(b) GDPR)
Transfer control: Transmissions between users and the application are always encrypted (HTTPS/TLS). Data is transferred to third parties only to Sub-processors under § 6 and to the recipients configured by the customer under § 3(3). Exports are carried out by signed-in users within the scope of their permissions.
Input control:
- an audit trail that records changes with user, time and content, can only be appended to at database level (append-only) and makes tampering detectable through a hash chain;
- electronic signatures with re-authentication and recording of IP address and user agent;
- logging of inputs, context and results of the AI functions.
3. Availability and Resilience (Art. 32(1)(b) and (c) GDPR)
- encrypted full backups of databases and files with every deployment of a new software version, stored on the same production server in Falkenstein, Germany; retention is set to 30 days and older backups are deleted at the next backup run; no daily backup schedule or off-site copies;
- contractual obligation to ensure timely restoration of availability and access to Customer Data after a physical or technical incident and to test recoverability according to risk; specific recovery times require a separate agreement;
- automated health monitoring with alerting;
- protection against overload and abuse through rate limiting and server hardening.
4. Procedures for Regular Testing, Assessment and Evaluation (Art. 32(1)(d), Art. 25 GDPR)
- automated tests and checks of dependencies for known vulnerabilities before every deployment;
- coordinated vulnerability disclosure policy (/security/disclosure);
- contractual obligation to assess, handle and document security incidents, including notification of the customer under § 9;
- contractual obligation to test, assess and evaluate the effectiveness of the measures regularly according to risk, and additionally upon material changes to the application or infrastructure; results and necessary improvements must be documented;
- data protection by default: AI functions only become active once a customer administrator configures an AI provider with the customer's own key.
5. Processing Control
- processing of Customer Data solely on the customer's instructions (§ 3);
- contractual obligation to bind the persons involved to confidentiality (§ 4);
- contractual obligation to select Sub-processors carefully and conclude agreements under Art. 28(4) GDPR before engaging them (§ 6);
- no processing of Customer Data for the Provider's own purposes, in particular no training of AI models.
Annex 3 – Sub-processors
| Name | Address | Service | Location of processing | Safeguards |
|---|---|---|---|---|
| Hetzner Online GmbH | Industriestr. 25, 91710 Gunzenhausen, Germany | Hosting and data centre operation (application servers, databases, file storage, mail server, backups) | Data centres in Germany (Falkenstein, Nuremberg) | Data protection obligations under Art. 28(4) GDPR; processing within the EU |
| GitHub, Inc. | 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA | Ticket management for bug reports voluntarily submitted by users (summary without screenshots) | USA | Data protection obligations under Art. 28(4) GDPR; EU-US Data Privacy Framework and supplementary standard contractual clauses subject to § 11(2) and (3) |
AI providers that the customer configures with its own API key (e.g. OpenAI, Anthropic, Google or a self-hosted system) are not Sub-processors of the Provider. The customer concludes its own contract with them; the Provider transfers data to them only on the customer's instructions (§ 3(3), § 11(4)).
The Provider ensures the required contractual safeguards and applicable transfer mechanisms are in place before the respective processing begins and supplies evidence to the customer under § 10.
The Provider announces changes to this list in accordance with § 6.