Data Processing Agreement
Last updated: 2 September 2026 · Version 2.6 · pursuant to Art. 28 GDPR · The German version is legally binding.
This agreement is concluded between the customer (the “Controller”) and Beyondles UG (haftungsbeschränkt), Bahnhofstraße 44, 14612 Falkensee, Germany, Amtsgericht Potsdam HRB 42428 P (the “Processor”). It forms part of the General Terms and Conditions and is concluded upon their acceptance. On request the Processor provides a separately signed copy.
1. Subject matter, nature and purpose of processing
1.1 The Processor provides the Controller with a platform to make knowledge accessible, handle workflows and have tasks executed by AI-supported agents. In the course of this use, the Processor processes personal data on behalf of the Controller.
1.2 Processing comprises collection, recording, organisation, storage, adaptation, retrieval, querying, use, transmission to the sub-processors listed in Annex 1, restriction and erasure.
1.3 The sole purpose is the provision of the contractually agreed services. There is no processing for the Processor's own purposes, in particular no use for training or fine-tuning its own models, no advertising and no analysis beyond the assignment. Embeddings and derived indices are created and used exclusively to provide the services for the respective Controller. The analysis of anonymised, aggregated usage data without personal reference remains permitted to ensure operations, for billing and to improve the service. For the model providers used, Annex 1 applies; it states per provider whether training on your data is excluded.
1.4 This agreement applies for as long as the Processor processes personal data on behalf of the Controller and ends with its complete erasure or return.
2. Types of data and categories of data subjects
2.1 The nature and scope of the data is determined solely by the Controller through its use. Typically affected are: master data, contact data, contract and billing data, content and communication data, documents and files, usage and log data, and data from connected third-party systems. This also includes inputs to AI models, their outputs, and task and conversation histories; they are stored like other content data for the duration of the contract and are subject to section 9.
2.2 Categories of data subjects: employees, customers, prospects, suppliers and other business partners of the Controller, as well as further individuals named in the content provided.
2.3 Special categories of personal data under Art. 9 GDPR may only be introduced following prior agreement in text form.
3. Instructions
3.1 The Processor processes personal data exclusively on documented instructions from the Controller, including with regard to transfers to third countries — unless required to process by Union or Member State law. In that case the Processor informs the Controller of the legal requirement before processing, unless that law prohibits it.
3.2 The provisions of this agreement and the settings made by the Controller within the platform constitute instructions — in particular the selection of permitted model providers and the activation of providers in third countries.
3.3 If the Processor considers an instruction to be unlawful, it informs the Controller without delay and may suspend execution until confirmation.
3.4 Instructions outside the platform require text form and are given via designated contacts: the Controller designates the persons authorised to issue instructions; the Processor receives instructions at [email protected]. Instructions given orally must be confirmed in text form without delay.
4. Obligations of the Processor
4.1 Confidentiality. The Processor binds all persons granted access to personal data to confidentiality before access is granted, unless they are already subject to a statutory duty of confidentiality. The obligation continues beyond the end of their activity.
4.2 Security. The Processor implements the technical and organisational measures described in Annex 2 pursuant to Art. 32 GDPR and maintains them at a level corresponding to the state of the art. Measures may be adapted provided the level of protection is not reduced.
4.3 Assistance. The Processor assists the Controller by appropriate measures in fulfilling data subject rights under Art. 15 to 22 GDPR and the obligations under Art. 32 to 36 GDPR, including data protection impact assessment and prior consultation.
4.4 Data subject requests. If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without delay and does not respond to it itself.
4.5 Evidence. The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR.
5. Personal data breaches
The Processor notifies the Controller of any personal data breach that comes to its attention without undue delay, at the latest within 24 hours of becoming aware. The notification states the nature of the breach, the categories of data affected and, where known, the approximate number of data subjects, the likely consequences, and the measures taken or proposed.
6. Sub-processors
6.1 The Controller hereby grants general authorisation for the engagement of the sub-processors listed in Annex 1.
6.2 The Processor gives at least 30 days' prior notice in text form of the addition or replacement of a sub-processor. Within that period the Controller may object for good cause on data protection grounds. If no mutually acceptable solution is found, the Controller may terminate the affected part of the service for cause.
6.3 The Processor imposes on every sub-processor the same data protection obligations to which it is itself subject and remains liable to the Controller for their conduct. Excepted are the model providers expressly marked as such in Annex 1, with which no data processing agreement is in place. The Processor discloses them by name in Annex 1 so that the Controller can deselect them in its organisation's settings. If it does not deselect them, use occurs on its instruction.
6.4 Providers without an adequacy decision. Model providers established in a third country without an adequacy decision of the European Commission are not activated by default. Processing by them occurs only where the Controller explicitly activates them in its organisation's settings. Such activation constitutes an instruction within the meaning of section 3 and is recorded with time and acting person. The Controller may withdraw it at any time with future effect.
7. Transfers to third countries
7.1 Where personal data is processed outside the European Economic Area, the Processor ensures appropriate safeguards under Chapter V GDPR — as a rule the Standard Contractual Clauses pursuant to Implementing Decision (EU) 2021/914 and, where the provider is certified, additionally the EU-US Data Privacy Framework.
7.2 For providers where such safeguards do not exist, section 6.4 applies. In that case the Controller is informed that no adequacy decision exists for the country concerned and that no data processing agreement with the respective provider is in place.
8. Obligations of the Controller
8.1 The Controller is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects.
8.2 It names a contact for data protection matters and notifies changes to the processing insofar as these are material for the Processor.
8.3 It is responsible for the settings within its organisation, in particular the selection of permitted model providers, the assignment of permissions to its own staff, and the configuration of approval steps for autonomously executed tasks.
9. Erasure and return
9.1 After the end of the provision of services the Processor makes the data available for export in a common, machine-readable format for 30 days.
9.2 It then erases the data from the main databases. Copies in the knowledge and vector store and in the knowledge graph database are removed as part of regular clean-up, at the latest within 90 days after termination.
9.3 Backup copies expire after no more than 30 days and are not separately purged; until then they remain blocked and are used exclusively for restoration.
9.4 Retention beyond this occurs only where required by Union or Member State law. The Processor discloses this on request.
9.5 If the Controller deletes individual content during the term, or if a data subject legitimately requests its erasure, the Processor also removes the associated entries in the knowledge and vector store and in the knowledge graph database. Full effect occurs at the latest when the backup copies expire pursuant to section 9.3.
10. Evidence and audits
10.1 On request the Processor demonstrates compliance with this agreement by suitable documentation, in particular the description of technical and organisational measures and the current list of sub-processors.
10.2 Where such evidence is insufficient, the Processor enables an audit by the Controller or by an auditor mandated by it and bound to confidentiality. Audits take place after announcement with reasonable notice, during normal business hours and without disrupting operations, as a rule once per calendar year. Further audits for specific cause remain possible.
11. Liability
Art. 82 GDPR applies. Otherwise the liability provisions of the General Terms and Conditions apply; they do not limit liability towards data subjects and supervisory authorities.
12. Final provisions
12.1 In the event of conflict between this agreement and the General Terms and Conditions, this agreement prevails.
12.2 Amendments require text form. Should a provision be invalid, the validity of the remaining provisions remains unaffected.
12.3 German law applies. The place of jurisdiction is Potsdam, Germany.
Annex 1 — Sub-processors
This list is identical to the one in the Privacy Policy and is maintained together with it.
1.1 AI model providers
| Provider | Place of processing | Use of your data for training | Data processing agreement |
|---|---|---|---|
| Anthropic PBC | USA | excluded | yes, part of the commercial terms |
| OpenAI | USA | excluded | yes, part of the commercial terms |
| Google (Gemini API) | EU and USA | excluded | yes, part of the paid services terms |
| Mistral AI SAS | France (EU) | excluded | yes, part of the commercial terms |
| Microsoft Ireland Operations Ltd. (Microsoft Foundry, for DeepSeek models) | European Union (storage) and USA (processing) | excluded | yes, part of the Microsoft Product Terms |
Anthropic, OpenAI, Google, Mistral and Microsoft are used via their paid business interfaces. Microsoft provides the models of the developer DeepSeek via Microsoft Foundry (storage in the EU, processing in the EU and the USA); no content is transmitted to DeepSeek itself. For all five, the use of transmitted content for training is excluded by the terms of paid usage, and a data processing agreement is in place with all five as part of the respective commercial terms.
Providers without a data processing agreement (section 6.3): currently none. Every provider listed in this Annex excludes the use of transmitted content for training, and a data processing agreement is in place with each of them. The activation under section 6.4 therefore currently has no application. Should this change, the provider concerned will first be added here and the Controller informed under section 6.2.
1.2 Further sub-processors
| Provider | Purpose | Place of processing | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Servers, databases, knowledge and vector stores, backups | Germany (Nuremberg) | — |
| Cloudflare, Inc. | Website delivery, attack mitigation, access protection | EU and USA | Standard Contractual Clauses |
| Resend, Inc. | Delivery of system and notification emails | USA | Standard Contractual Clauses |
| Stripe | Payment processing and billing | EU and USA | Standard Contractual Clauses |
| Slack Technologies | internal incident notifications to our team | USA | Standard Contractual Clauses |
| Microsoft Ireland Operations Ltd. | business email communication and document storage | European Union | — |
| External development contractors (individuals) | Maintenance, debugging and development; read access to operational logs | Türkiye, Pakistan and India | Data processing agreement with Standard Contractual Clauses |
The external development contractors have no access to the production databases and no access to credentials. For debugging purposes they can view operational logs of the running system, which may contain personal data. They are independent individuals, each bound separately. The Processor discloses their names and addresses on request.
Annex 2 — Technical and organisational measures
Measures pursuant to Art. 32 GDPR, as at 2 September 2026:
Confidentiality (physical access, system access, data access, separation)
- Operation in ISO 27001-certified data centres of Hetzner Online GmbH in Nuremberg; physical access lies exclusively with the data centre operator.
- Access to production systems only via personal, attributable accounts with key-based authentication and only to the extent required.
- Two-factor authentication for user accounts; mandatory for accounts with administrative rights in the organisation.
- Access protection for administrative interfaces via an upstream identity check.
- Network filtering; databases are not reachable from the public internet.
- Separate database roles for application, schema change and maintenance; the application holds no rights to alter structures.
- Encrypted storage of credentials for connected third-party systems; keys are never stored in plain text.
- Separation of data per customer via separate database schemas or separate holdings in the relational database, the knowledge and vector store, and the knowledge graph database.
- Separate database instances for production and development environments with distinct credentials.
Integrity (transfer and input control)
- Encryption of all transmissions over public networks (TLS).
- Inspection rules to detect impermissible inputs and outputs in AI-supported workflows.
- Continuous audit trail of the agents’ significant actions; approval steps before actions classified as significant.
- Logging of security-relevant events.
Availability and resilience
- Daily encrypted backups of all data holdings; access restricted to system administration; retention no more than 30 days.
- Tested restoration; target values: restoration within 24 hours, data loss no more than 24 hours.
- Regular server images for disaster recovery.
- Automated monitoring with incident notification to the operations team.
Procedures for regular review (Art. 32(1)(d) GDPR)
- Automatic installation of operating system security updates.
- Security and quality checks in the development process before every release.
- Annual review and adaptation of these measures; ad hoc review upon material changes.
Sub-processor control
- Sub-processors are engaged only in accordance with Art. 28 GDPR and are disclosed in Annex 1.
- Confidentiality obligations for all staff and contractors before access is granted.
- Defined procedure for withdrawing all access upon the end of a working relationship.
No separate execution environment isolated from the rest of the system is promised for self-generated program code. Where the Controller uses features that execute program code, this must be taken into account when assessing risk.
