This Auftragsverarbeitungsvertrag (data processing agreement) pursuant to Art. 28(3) GDPR (hereinafter the "AVV") is concluded between you and us upon the registration of an account for the business use of Klate and applies in addition to the Nutzungsbedingungen (terms of use). A separate conclusion is not required. We make available to you, on request at privacy@klate.ai, a copy signed by us.
Contents
- Parties to the contract
- Subject matter, nature and purpose of the processing
- Type of data and categories of data subjects
- Duration of the processing
- The controller's right to issue instructions
- Obligations of the processor
- Confidentiality
- Technical and organisational measures
- Sub-processors
- Transfer to third countries
- Assistance with data subject rights
- Assistance with security, notification obligations and data protection impact assessment
- Inspection and audit rights
- Deletion and return after termination
- Evidence and accountability
- Liability
- Final provisions
Annexes (Anlagen)
- Annex 1: Technical and organisational measures (Art. 32 GDPR)
- Annex 2: Approved sub-processors
- Annex 3: Types of data processed in detail
1. Parties to the contract
Processor (hereinafter "we" or "Klate"):
Klate Technology UG (haftungsbeschränkt) Im Galluspark 4, 60326 Frankfurt am Main, Deutschland Represented by the Geschäftsführer (managing director) Arian Fetahaj Amtsgericht (Local Court) Frankfurt am Main, HRB 145040 E-mail: privacy@klate.ai
Controller (hereinafter "you" or "customer"): the natural or legal person who registers an account for the business use of Klate and has personal data processed in Klate.
You remain the controller within the meaning of Art. 4(7) GDPR for the content you enter. In this respect we act exclusively as processor within the meaning of Art. 4(8) GDPR.
Delimitation. For the data that we process in order to provide and operate our own service, in particular account and profile data of the users, billing data, log and security data as well as consumption data of AI use, we are the controller. That processing is not the subject matter of this AVV but of our privacy notice at https://klate.ai/legal/datenschutz.
2. Subject matter, nature and purpose of the processing
Subject matter. The provision of Klate, a software for designing, reviewing and approving conversation flows for AI assistants ("conversation design"), as software as a service.
Nature of the processing. Collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission within the group of users determined by you, combination, restriction, erasure and destruction.
Purpose. Exclusively the provision of the contractually agreed services, namely:
- storage and editing of the customers, projects and designs created by you, including conversation paths, turns, briefs, guideline cards, tool and widget definitions as well as forms,
- collaboration of several persons on this content, including comments, mentions and notifications,
- versioning and restoration of earlier states,
- approval procedure, including the sending of approval requests to the persons named by you,
- storage of the files uploaded by you,
- execution of the AI functions upon your triggering, including the transmission of the content required for this to the model providers named in Annex 2,
- provision of the programmatic interface (MCP) for the agents connected by you.
No purpose of our own. We do not process the content for any purposes of our own. In particular, we do not evaluate it for analysis or advertising purposes, do not form profiles from it and do not use it to train or improve AI models. A training or evaluation procedure for customer content does not exist in our system.
3. Type of data and categories of data subjects
Type of personal data. The scope is determined solely by you, since the content is predominantly free text. The data typically processed are:
- contact and identification data of the persons acting for you (name, e-mail address, profile picture, role, voluntary profile details),
- content and communication data in designs, briefs, guidelines, comments and forms,
- e-mail addresses of the persons invited by you and of the persons whom you ask for approval,
- content of uploaded files,
- usage and log data, to the extent that it is assigned to your users.
Annex 3 contains a detailed listing.
Special categories of personal data. Klate is not intended for the processing of special categories of personal data under Art. 9 GDPR or of data on criminal convictions under Art. 10 GDPR. You undertake not to enter such data into Klate unless this has previously been separately agreed in writing.
Recommendation on data minimisation. Klate is designed for drafting conversation flows with invented example data. We expressly recommend that real personal data of third parties be entered only to the extent that this is necessary for the design purpose.
Categories of data subjects.
- your employees and other persons acting for you who use Klate,
- external persons invited by you (for instance persons on the customer's side),
- persons whom you ask to approve a draft,
- persons whose data appears in the content entered by you.
4. Duration of the processing
The processing begins with the registration and runs for an indefinite period until the underlying user relationship ends. You may end the user relationship, and with it this AVV, at any time by deleting your account. Clause 14 governs what happens to the data thereafter.
5. The controller's right to issue instructions
- We process personal data exclusively on your documented instructions, including with regard to a transfer to a third country, unless we are required to do so by Union or Member State law. In such a case we shall inform you of the legal requirements before the processing, unless the law in question prohibits this on important grounds of public interest.
- Your instructions arise in the first instance from this AVV and from the operation of the service: every function that you execute in Klate is an instruction to us. You issue supplementary instructions in Textform (text form) to
privacy@klate.ai. - We shall inform you without undue delay if we are of the opinion that an instruction infringes the GDPR or other data protection provisions. We are entitled to suspend the execution of such an instruction until it is confirmed or amended.
- The persons entitled to issue instructions on your side are those to whom you have assigned the role "Administrator" in your workspace.
6. Obligations of the processor
We undertake:
- to carry out the processing exclusively within the framework of this AVV and of your instructions (Clause 5);
- to keep the data logically separated from the data of other customers. Every access is checked server-side against the actual authorisation; if the authorisation is absent, the response does not even reveal whether the requested content exists (Annex 1);
- to place the persons authorised to process the data under an obligation of confidentiality (Clause 7);
- to take and maintain the measures under Art. 32 GDPR (Clause 8 and Annex 1);
- to comply with the conditions for engaging further processors (Clause 9);
- to assist you in fulfilling the rights of data subjects (Clause 11);
- to assist you in complying with Art. 32 to 36 GDPR (Clause 12);
- to delete or return the data after termination (Clause 14);
- to make available to you all information necessary to demonstrate compliance with these obligations and to allow for reviews (Clause 13);
- to maintain a record of all categories of processing activities under Art. 30(2) GDPR.
7. Confidentiality
We ensure that the persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation continues to exist after the end of their activity.
The group of persons who can access customer content is limited to those for whom this is necessary in order to provide the service. At present this is exclusively the Geschäftsführer (managing director). Access takes place only to the extent that it is necessary in order to handle a support request, to remedy a malfunction or to fulfil a legal obligation.
8. Technical and organisational measures
- We take the technical and organisational measures described in Annex 1 under Art. 32 GDPR and maintain them for the term of the contract.
- The measures are subject to technical progress. We may adapt them as long as the agreed level of protection is not reduced. We document material changes and communicate them to you on request.
- You have satisfied yourself of the adequacy of the measures before the start of the processing.
9. Sub-processors
- You hereby grant your general authorisation under Art. 28(2) sentence 2 GDPR for the engagement of the sub-processors listed in Annex 2.
- We shall inform you of the intended engagement or replacement of a sub-processor at least 30 days in advance in Textform to the e-mail address you have provided, and by updating the list at
https://klate.ai/legal/dpa. - You may object to the change in Textform within 30 days of receipt of the information, on an important ground relating to data protection law. If we cannot accommodate your objection, you are entitled to terminate the user relationship for cause (außerordentliche Kündigung) with effect as of the time of the changeover; we shall reimburse fees already paid in advance on a pro rata basis.
- We conclude with every sub-processor engaged directly by us a contract that imposes on it substantially the same data protection obligations as those to which we are subject under this AVV. If a sub-processor is in turn engaged by one of our sub-processors (Annex 2, for example a model provider engaged via Vercel Inc.), this obligation is incumbent on the engaging sub-processor. In both cases we remain responsible to you for compliance.
- Services that you yourself connect to Klate are not sub-processors in this sense, in particular an AI agent connected by you via the MCP interface. You are yourself responsible for those services and for the further processing that takes place there.
10. Transfer to third countries
- The permanent storage of the content takes place within the European Union: database and accounts in Frankfurt am Main, execution of the application in Frankfurt am Main. For the uploaded files we have specified Western Europe as the preferred storage location with the object storage provider; according to the provider's information this is an optimisation specification and not an assurance of a guaranteed storage location. Storage outside the European Economic Area is permissible only under the safeguards set out in paragraphs 3 and 4.
- A transfer to the United States takes place to the extent that you use AI functions: the content required for the request is transmitted via the AI gateway to the model providers named in Annex 2, whose programming interfaces are operated from the United States. We do not technically specify a routing region to the AI gateway, so that processing at another location of the respective provider cannot be ruled out; the safeguards set out in paragraphs 3 and 4 apply irrespective of the place of processing. Further transfers follow from Annex 2.
- Contractual partners in the Union. To the extent that we engage the model providers directly, our contractual partners are established in the Union (OpenAI Ireland Limited, Anthropic Ireland, Limited); the same applies to the payment service provider (Stripe Payments Europe, Ltd.). The path of the data to these contractual partners is therefore not itself a third-country transfer. To the extent that the AI request is executed via the operator of our AI gateway, that operator is our contractual partner and the model providers are its sub-processors. In both cases the processing takes place in the United States; the safeguards under Art. 46 GDPR, as a rule the standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914), form part of the contractual chain applicable in each case.
- For recipients with whom we contract directly in a third country, in particular Vercel Inc. for hosting, the AI gateway and performance measurement, we base the transfer on the standard contractual clauses under Art. 46(2)(c) GDPR, which form part of the respective data processing agreement, to the extent that no adequacy decision applies.
- On request at
privacy@klate.aiwe shall inform you which safeguards the respective recipient uses and where you can inspect them. - By concluding this AVV and using the AI functions you instruct us to carry out these transfers.
- You can prevent the transfer to the model providers at any time by not using the AI functions. All other functions of Klate remain unaffected by this.
11. Assistance with data subject rights
- If a data subject addresses a request under Art. 15 to 22 GDPR directly to us even though the request concerns your processing, we forward it to you without undue delay and do not answer it ourselves.
- We assist you by appropriate technical and organisational measures in complying with your obligation to respond. You can at any time inspect, rectify and delete the content of your workspace yourself, except for as long as we have suspended your account or your workspace under Clause 21 of the Nutzungsbedingungen; for that period we carry out your instruction to inspect, rectify or delete (Clause 5 No. 2) on request at
privacy@klate.ai. The owner and the administrators of a workspace can in addition extract its content themselves at any time through the export function in the application, in a structured, commonly used and machine-readable format (JSON together with the uploaded files in the form in which they are stored with us; without content marked as deleted; without a file we have blocked under Clause 21 of the Nutzungsbedingungen, for as long as the block lasts; of the conversations with the AI assistant, only those of the exporting person; Terms of Use, section "Data Export and Deletion after the End of the Contract"). This also applies during such a suspension: during a suspension of the workspace for its owner and administrators, during a suspension of an account for that account's personal workspace and for workspaces of which it is the owner. Beyond that we make a structured extraction available to you on request atprivacy@klate.ai, as well as assistance going beyond that. - Assistance that goes beyond the provision of the product functions and causes considerable effort may be charged by us on a time and materials basis if we have notified you of this beforehand.
12. Assistance with security, notification obligations and data protection impact assessment
- Taking into account the nature of the processing and the information available to us, we assist you in complying with Art. 32 to 36 GDPR.
- Personal data breach. If we become aware of a personal data breach affecting the data for which you are responsible, we shall report this to you without undue delay, at the latest within 48 hours of becoming aware of it, in Textform. The report contains, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences as well as the remedial measures taken or proposed. If not all the information is immediately available, we first report what is known and supplement it without undue delay.
- The notification to the supervisory authority under Art. 33 GDPR and the communication to the data subjects under Art. 34 GDPR are incumbent on you. We do not make them on your behalf.
- On request we assist you with a data protection impact assessment under Art. 35 GDPR and a prior consultation under Art. 36 GDPR, to the extent that the necessary information is available exclusively to us.
13. Inspection and audit rights
- You have the right to review compliance with this AVV.
- We demonstrate compliance primarily by: the documentation of the technical and organisational measures (Annex 1), our published security and data protection statements as well as written answers to your specific questions.
- If this evidence is not sufficient in an individual case, you may, after reasonable advance notice of at least 30 days, during our usual business hours, at most once per calendar year and without disrupting the course of business, carry out a review, or have it carried out by an auditor engaged by you who is bound to secrecy and who is not in a competitive relationship with us. Where there is a specific cause, in particular following a personal data breach or upon the order of a supervisory authority, the restrictions on frequency and on the period of advance notice do not apply.
- You bear the effort arising from a review, unless the review uncovers an infringement for which we are responsible.
- We are obliged to provide information to a competent supervisory authority as well, to the extent that it addresses us directly; we shall inform you of this without undue delay, to the extent that this is legally permissible.
14. Deletion and return after termination
- After the end of the user relationship we delete the personal data contained in your workspace or, at your choice, return it to you, unless there is an obligation to store it under Union or Member State law.
- Before the deletion you can extract your content yourself at any time through the export function in the application (Clause 11 No. 2); on request we additionally make a structured extraction of your content available to you.
- Course of the deletion. If you delete a customer, a project or a design during the term, it is first marked as deleted together with all content it contains and, after 30 days, finally removed from the database by a nightly run, unless a retention order ("legal hold", No. 6) is in place for the workspace; this period serves solely to enable an inadvertent deletion to be reversed. At your request we delete earlier. For the duration of a retention order the daily clean-up runs for the content of that workspace are suspended, but not the deletion of notifications to individual persons, which may contain excerpts from comments and are deleted 30 days after they arise in that case as well. Tools, tool providers, widgets, forms, guideline cards, subagents as well as individually deleted conversation paths, turns, version states and comments are deleted immediately and finally upon deletion; restoration by us is not possible. The content of an individually deleted conversation path or turn remains contained in earlier version states of the design until those are deleted. The deletion of your account, by contrast, is immediate and final on every path - whether you delete it yourself in the settings, notify us of the termination in text form or we terminate the contract: with it, in the case of a termination in text form after the end of the access period, the content of your personal workspace and of the team workspaces of which you are the only member is removed from the database without first being marked as deleted; a restoration is not possible thereafter. Where a retention order covers content of the account, we do not carry out the deletion automatically but handle it separately. Independently of the termination, conversations with the AI assistant are finally removed by the same daily run 30 days after the last use (last message or last change to the conversation). Attached images are thereafter no longer retrievable through the application, since no signed retrieval link is generated any more; the stored file itself is treated in accordance with No. 4. The person who started a conversation can delete it themselves at any time beforehand; during a suspension under Clause 11 No. 2 we delete it on request at
privacy@klate.ai. An export file from the export function and the associated job entry are deleted by the same daily run once 7 days have passed since the export was completed, and an export that was not completed is deleted at the latest by the first daily run that takes place more than 7 days after it was started; if a newer export by the same person for the same workspace is completed before then, we delete the older one, outside a retention order, as a rule at that point and at the latest by the next daily run. - Stored files. The objects of uploaded files are removed from the object storage in the course of the termination in a separate, manually executed step; an active automated deletion run does not currently exist for this. In the case of an account deletion we record the storage locations of the files still to be removed in a list until that step. The application contains a daily run that would remove files with no use whatsoever in the workspace, together with their directory entry, after 30 days; it operates exclusively in dry-run mode, that is, it identifies and logs but marks and deletes nothing. Before any activation we will amend this clause and the privacy notice. As soon as the directory entry is deleted, the files are no longer retrievable via the application, since no signed retrieval link is generated any more. We furnish you with evidence of the execution on request.
- Backup copies. Deleted data may still be contained in backup copies for a limited transitional period. These serve exclusively for restoration following an outage, are not evaluated for other purposes and expire automatically at the end of their retention period.
- Exceptions. Entries that are subject to statutory retention obligations, in particular billing-relevant documents under § 147 AO, § 257 HGB and § 14b UStG, are not deleted but anonymised or, as the case may be, retained for the statutory period. The history entries on approvals which serve as evidence exist for as long as the associated content and are deleted with it; if the account of the acting person is erased while the content remains, we remove that person's attribution. The audit log of operations relevant to security and to proof is retained by us for 90 days from the time the respective entry arises; thereafter the daily clean-up run deletes it. For workspaces for which a retention order ("legal hold") is in place, because of a legal dispute, an enquiry by an authority, a security investigation or the review of a file blocked under Clause 21 of the Nutzungsbedingungen, we suspend this deletion for the duration of the order. If the account of the acting person is erased, we remove that person's attribution to the entries still in existence beforehand; the entries themselves lapse with the period.
- We document the deletion on request.
15. Evidence and accountability
On request we make available to you the information that you need in order to fulfil your accountability obligation under Art. 5(2) GDPR and to maintain your record of processing activities under Art. 30(1) GDPR.
16. Liability
The provisions of the underlying Nutzungsvertrag (usage contract) apply to liability. Art. 82 GDPR remains unaffected.
17. Final provisions
- Precedence. In the event of contradictions between this AVV and the underlying Nutzungsvertrag, this AVV takes precedence in matters of data protection law. In the event of contradictions between this AVV and the standard contractual clauses, the standard contractual clauses take precedence.
- Amendments. We may adapt this AVV to the extent that this is necessary in order to adapt to a changed legal situation, to case law or to requirements of a supervisory authority. We shall inform you at least 30 days before the amendment takes effect; Clause 9(3) applies accordingly.
- Textform. Amendments and supplements require Textform. This also applies to the waiver of this formal requirement.
- Severability clause. Should a provision be invalid, the validity of the remaining provisions remains unaffected.
- Law and place of jurisdiction. The law of the Federal Republic of Germany applies, to the exclusion of the UN Convention on Contracts for the International Sale of Goods. The place of jurisdiction is Frankfurt am Main, to the extent that you are a merchant (Kaufmann), a legal person under public law or a special fund under public law.
Annex 1: Technical and organisational measures (Art. 32 GDPR)
The measures set out below are implemented. Measures that are merely planned we deliberately do not list here.
1. Confidentiality
Physical access control (Zutrittskontrolle). We do not operate our own data centres. Physical security is incumbent on the providers named in Annex 2, which hold recognised certifications for this purpose.
System access control (Zugangskontrolle).
- Sign-in exclusively via the authentication service; passwords are stored exclusively as a cryptographic hash value.
- Confirmation of the e-mail address upon registration.
- On a password change, all other sessions are signed out.
- Limitation of sign-in and registration attempts per source.
- Rejection of registrations using disposable e-mail domains.
- Access tokens of the programmatic interface are stored exclusively as a SHA-256 hash value.
Data access control (Zugriffskontrolle).
- Role-based permission model with the roles viewer, editor and administrator; the ranking is checked server-side on every request.
- Tenant separation: every request is checked against the actual membership of the workspace. If the authorisation is absent, the system responds in such a way that it does not emerge whether the requested content exists.
- Sharing links (Freigabelinks) authorise reading only and, once redeemed, are permanently bound to the redeeming account; anonymous access is thereby excluded.
- Uploaded files are held in object storage that is not publicly accessible and are retrievable exclusively via short-lived, signed retrieval links following a prior authorisation check.
- Feedback from the application is held in a separate database schema, separated from the product data.
- Administrative access to customer content is currently held exclusively by the Geschäftsführer (managing director). Further persons acting for us are given access only to the extent necessary and are placed under an obligation of confidentiality beforehand.
2. Integrity
Transmission control (Weitergabekontrolle).
- All connections exclusively via TLS; browsers are instructed by the
Strict-Transport-Securityheader to access the offerings only in encrypted form. - Content Security Policy and further security headers against the execution of foreign code in the browser.
- Encrypted connections to all sub-processors.
Input control (Eingabekontrolle).
- All writing interfaces validate their inputs against a fixed schema.
- Audit log of security- and evidence-relevant operations: permission changes, invitations and their acceptance, approvals, role changes, billing events and accesses by automated agents, in each case with the acting person, the object and the time. Entries cannot be changed.
- Versioning of the content with an indication of who created a version and when.
3. Availability and resilience
- Operation on a managed, multiply redundant platform.
- Regular backup of the database by the database provider with the possibility of restoration to a point in time.
- External availability monitoring at short intervals as well as monitoring of the scheduled maintenance tasks by dead man's signals; alerting in the event of a malfunction.
- Server-side error monitoring; the error events are held in a project in the EU region (Frankfurt am Main). For the provider's administrative data see Annex 2.
- Limitation of the request load at network and application level in order to repel overload and abuse attacks.
- Public status page.
4. Procedure for regular review, assessment and evaluation
- Automated checks on every code change (type checking, linting, test run) before it is taken over into the main branch.
- Automated monitoring of the dependencies for known vulnerabilities.
- Secrets exclusively in the platform's secret management, never in the source code.
- Data processing agreements with the sub-processors under Annex 2 (Clause 9(4)); with Functional Software, Inc. ("Sentry") by accepting the provider's data processing addendum (version 5.1.0) on 5 September 2026. Where a model provider is engaged via Vercel Inc., the contractual chain in this respect runs via Vercel Inc.
- Data protection by design and by default (Art. 25 GDPR), in particular: the AI memory is switched off by default, the transmission of technical details with a feedback submission is deselected by default, the raw IP address is discarded for feedback and for performance measurement, and sharing links authorise reading only.
Annex 2: Approved sub-processors
As at 24 September 2026. The version applicable at any given time is available at https://klate.ai/legal/dpa. We announce changes in accordance with Clause 9 with a period of 30 days.
| Sub-processor | Service | Data processed | Place of processing |
|---|---|---|---|
| Vercel Inc., USA | Hosting, execution of the application, scheduled tasks, network protection | All content during the processing of a request; server log files | Execution of the application: Frankfurt am Main (fra1); storage location of the server log files not currently confirmed; network protection global |
| Vercel Inc., USA | AI gateway: forwarding of the AI requests | Content of the AI request | USA |
| Vercel Inc., USA | Measurement of loading performance (Speed Insights) | Technical measurements, no content | USA |
| Databricks, Inc., USA (parent company of Neon, LLC; "Neon") | Database (leading system) and authentication service | All permanently stored data including accounts and sessions | Frankfurt am Main (aws-eu-central-1) |
| Cloudflare, Inc., USA | Object storage for uploaded files; name resolution; bot check at registration ("Turnstile", on the registration page only) | Uploaded files; connection data; for the bot check the IP address, TLS fingerprint, browser identifier and widget identifier of the registering person as well as the one-time check token. No customer content and nothing from the registration form. | Object storage Western Europe; network global; bot check not fixed to a region by the provider (possible processing in the USA) |
| Plus Five Five, Inc. ("Resend"), USA | Dispatch of transactional e-mails | Recipient address, name, content of the respective message. No design content. | Dispatch EU (Ireland); account data, delivery logs and metadata USA |
| Stripe Payments Europe, Ltd., Ireland | Payment processing, invoices, subscriptions | Billing and invoice data | EU (Ireland), with transfer to Stripe, Inc. or Stripe, LLC (USA) |
| OpenAI Ireland Limited, Ireland | AI inference; engaged directly by us or via Vercel Inc. | Content of the AI request | Processing at affiliated companies in the USA |
| Anthropic Ireland, Limited, Ireland | AI inference; engaged directly by us or via Vercel Inc. | Content of the AI request | Processing at affiliated companies in the USA |
| Functional Software, Inc. ("Sentry"), USA | Server-side error diagnostics | Error message, stack trace, request identifier and route. No customer content, no IP addresses, no cookies, no request content. In rare cases the error message of a third-party program library may contain a fragment of processed content; every error message is limited to 250 characters, e-mail addresses are removed before transmission. | Error events EU region (Frankfurt am Main); account, organisation and administrative data as well as support requests USA |
| Better Stack, Czech Republic | Availability monitoring, status page | No customer content and no personal data of the users | EU, or as stated by the provider |
| Google Ireland Limited, Ireland | E-mail mailboxes at @klate.ai | Content of the e-mails addressed to us | EU, with the possibility of access by Google LLC (USA) |
Execution of the AI requests. With every request our application requires the AI gateway to have it executed exclusively by the model providers OpenAI and Anthropic themselves. Until 6 September 2026 this requirement was not in place for every request; during that period the AI gateway could also have a model executed at an operator engaged by Vercel Inc., in particular at Microsoft Corporation, Amazon Web Services, Inc. or Google LLC (each USA). Earlier versions of this Annex therefore listed those operators.
Not sub-processors are services that you yourself connect to Klate, in particular an AI agent connected by you via the MCP interface (Clause 9(5)), and likewise the providers that are queried directly by your browser when third-party image addresses are displayed.
Likewise not a sub-processor is Mintlify, Inc. (USA), which operates our internal documentation domain docs.klate.ai. No customer content and no data of the users from the application is processed there, but exclusively the connection data of the calls to this domain as well as the sign-in and session data of the only person on our side authorised to access it. This processing takes place under our own responsibility; it is described in our privacy notice and is not the subject matter of this contract.
Annex 3: Types of data processed in detail
| Category | Individual data |
|---|---|
| Account and profile of the users | Name, e-mail address, confirmation status, profile picture, role in the workspace, voluntary details on role, company and short description, time and version of the accepted Nutzungsbedingungen, time of the last use of the account (a single value, overwritten at most once a day) |
| Session data | Session identifier, expiry time, IP address and browser identifier of the session |
| Content | Customer and project details, designs with conversation paths and turns, briefs, guideline cards, tool and provider definitions, widgets, forms as well as all version states |
| Collaboration | Comments, mentions, notifications, presence details, editing locks |
| Permissions | Assignment of persons to workspaces and content, roles, invitations with e-mail address and status, sharing links |
| Approval procedure | E-mail address of the approving person, note text, token of the approval link, decision and time |
| Files | Uploaded files including the images attached to AI conversations |
| AI use | Conversations with the assistant including inputs, outputs and tool calls; memory entries stored on request; per request the time, model, token count and cost |
| Programmatic access | Details of the connected application, released workspaces, access token as hash value |
| Logs | Audit log of security- and evidence-relevant operations; history entries on approvals |
As at: 8 October 2026 · Version 1.10
