Data Processing.
Agreement on data processing pursuant to Art. 28 of Regulation (EU) 2016/679 (GDPR) for the Eigenwelt Plus service.
This is the current version published at eigenweltlabs.com/de/eigenwelt-plus/avv (§ 12). The German version is legally binding; the English translation is provided for convenience only. The version signed by both parties is the agreed basis.
Parties
between
[Name of the firm / company]
[Represented by]
[Street, number]
[Postcode, city]
– hereinafter the “Controller” –
and
Poensgen Technology UG (haftungsbeschränkt)
Wiclefstr. 45, 10551 Berlin
Local court Berlin (Charlottenburg), HRB 226111 B
represented by its managing director
– hereinafter “Eigenwelt” or the “Processor” –
§ 1 Subject matter and term
(1) The Controller uses the “Eigenwelt Plus” service (hosted model inference, team and organisation administration, and Knowledge Hub, available at platform.eigenweltlabs.com) on the basis of the Terms and Conditions for Eigenwelt Plus (the “Main Agreement”). In providing the service, Eigenwelt processes personal data on behalf of and on the instructions of the Controller. This agreement sets out the parties’ data-protection obligations in detail.
(2) The subject matter, nature, and purpose of the processing, the type of personal data, and the categories of data subjects are set out in Annex 1.
(3) The term of this agreement corresponds to the term of the Main Agreement. It ends automatically upon the latter’s termination; surviving obligations (in particular §§ 11 and 13) remain unaffected.
§ 2 Zero data retention for inference content
(1) Eigenwelt’s gateway does not store any prompt or output content of paid inference and retains only content-free billing and usage metadata (in particular user, model, token count, cost, status, and timestamp).
(2) The subprocessor used for model inference (Scaleway SAS) applies zero data retention (“ZDR”) by default. Under its published policy, temporary access and retention for up to two weeks are permitted only to investigate abnormal errors or suspected malicious activity; aggregated, anonymised usage data may be retained for up to six months.
(3) Paid inference content is not used to train shared or public models.
(4) ZDR does not apply to account, billing, security, and usage data, nor to Knowledge Hub content that the Controller deliberately stores in the platform.
§ 3 Instructions
(1) Eigenwelt processes personal data only on the documented instructions of the Controller, unless processing is required by Union or Member State law; in such a case, Eigenwelt informs the Controller of that legal requirement before processing, unless the law in question prohibits such notification.
(2) Instructions are initially the Main Agreement, this agreement, and the use of the platform’s features by the Controller and its users. Supplementary instructions require text form.
(3) Eigenwelt informs the Controller without undue delay if it considers that an instruction infringes the GDPR or other data-protection provisions (Art. 28(3) subpara. 2 GDPR). Eigenwelt is entitled to suspend performance of the instruction concerned until it is confirmed.
§ 4 Confidentiality
(1) Eigenwelt ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR). The confidentiality obligations continue after the activity ends.
(2) Any confidentiality agreement concluded between the parties under § 43e BRAO and § 203 StGB remains unaffected and applies alongside this agreement.
§ 5 Technical and organisational measures
(1) Eigenwelt implements the technical and organisational measures described in Annex 2 pursuant to Art. 32 GDPR and maintains them for the term.
(2) The measures may be adapted to technical and organisational developments, provided that the agreed level of protection is not reduced. Material changes are documented.
§ 6 Subprocessors
(1) The Controller authorises the subprocessors listed in Annex 3 (general written authorisation within the meaning of Art. 28(2) GDPR).
(2) Eigenwelt informs the Controller at least 30 days before the intended addition or replacement of a subprocessor, in text form (e.g. by email or via the platform). The Controller may object to the change on important data-protection grounds. If no mutual solution is reached, the Controller may terminate the Main Agreement extraordinarily with effect from the time of the change.
(3) By contract, Eigenwelt imposes on each subprocessor the same data-protection obligations set out in this agreement, in particular sufficient guarantees of appropriate technical and organisational measures. Where a subprocessor fails to meet its obligations, Eigenwelt remains liable to the Controller for the performance of that subprocessor’s obligations (Art. 28(4) GDPR).
(4) Paid inference content is transmitted only to model infrastructure within the European Union.
§ 7 Assistance to the Controller; data-subject rights
(1) Eigenwelt assists the Controller, by appropriate technical and organisational measures, in responding to data-subject requests under Chapter III GDPR. Requests from data subjects received by Eigenwelt that evidently concern the Controller are forwarded to the Controller without undue delay.
(2) Taking into account the nature of the processing and the information available to it, Eigenwelt assists the Controller in complying with the obligations under Art. 32 to 36 GDPR (security of processing, breach notification, data-protection impact assessment, prior consultation).
§ 8 Notification of personal-data breaches
(1) Eigenwelt notifies the Controller of any personal-data breach affecting data processed on its behalf without undue delay after becoming aware of it.
(2) The notification contains, where available, the information required under Art. 33(3) GDPR; information not immediately available is supplied without undue further delay.
§ 9 Place of processing; transfers to third countries
(1) Core platform data and paid inference content are processed in the European Union (Annex 3).
(2) Where a subprocessor’s limited support access constitutes, in an individual case, a transfer to a third country, that transfer takes place only on the basis of an adequacy decision or appropriate safeguards within the meaning of Chapter V GDPR (in particular EU Standard Contractual Clauses). Otherwise, no transfer of personal data to third countries takes place, and none is carried out without the Controller’s prior documented instruction.
§ 10 Evidence and audits
(1) Eigenwelt makes available to the Controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR. This is provided primarily through documentation, in particular the documentation of technical and organisational measures (Annex 2), existing certificates and attestations (in particular ISO/IEC 27001 and BSI C5), and audit reports of the subprocessors used, supplemented by responses to a reasonable written questionnaire no more than once per calendar year.
(2) The Controller may request an on-site review (inspection) only where (a) the evidence provided under paragraph 1 is demonstrably insufficient to establish compliance in the individual case, (b) a competent supervisory authority bindingly orders this in respect of the Controller, or (c) there is a documented personal-data breach affecting the Controller’s data.
(3) Inspections are limited to at most one per calendar year (except in the cases of paragraph 2(b) and (c)), to be announced at least 30 days in advance in text form, limited to ordinary business hours, and carried out without disrupting operations and while preserving the confidentiality and rights of other customers. Any auditor engaged must be independent and bound to secrecy and must not be a competitor of Eigenwelt; Eigenwelt may reject an auditor for good cause. The Controller bears the cost of the inspection, including Eigenwelt’s reasonable effort.
§ 11 Deletion and return
(1) For prompt and output content of paid inference, § 2 applies: it is not stored, so no separate deletion is required in that respect.
(2) After termination of the Main Agreement, Eigenwelt deletes or anonymises the remaining personal data processed on the Controller’s behalf within a reasonable operational period or, at the Controller’s request, returns it in a common format where technically possible. The Controller exports needed Knowledge Hub content before the contract ends; Eigenwelt assists to a reasonable extent.
(3) Statutory retention obligations and data in backups with defined deletion cycles remain unaffected; the protection obligations of this agreement continue to apply to such data.
§ 12 Updates and versioning
(1) This agreement bears a version number and a date. The current version is published at eigenweltlabs.com/de/eigenwelt-plus/avv. The version signed by both parties is the agreed basis; updates take effect in accordance with this section.
(2) Changes to the technical and organisational measures (Annex 2) are governed by § 5(2) and must not fall below the agreed level of protection. Changes to the subprocessors (Annex 3) are governed by § 6. Such updates to the annexes take effect without renewed signature; the Controller’s rights under § 6(2) (objection and extraordinary termination) remain unaffected.
(3) Eigenwelt notifies the Controller of changes to the main body of this agreement at least 30 days before they take effect, in text form (e.g. by email or via the platform). If the Controller does not object within 30 days of receipt, the new version is deemed accepted. Material changes disadvantaging the Controller require its consent in text form. If no agreement is reached, the most recently agreed version continues to apply; the right to terminate the Main Agreement remains unaffected.
(4) Changes required by mandatory legal provisions, by an order or recommendation of a supervisory authority, or by a change in the case law of the highest courts, Eigenwelt may implement with effect from the required time; Eigenwelt informs the Controller of this without undue delay.
(5) Either party may at any time request a copy of the current version countersigned by both parties. Eigenwelt keeps a traceable record of the versions of this agreement (change history).
§ 13 Liability and final provisions
(1) The parties’ liability is governed by the provisions of the Main Agreement and by Art. 82 GDPR.
(2) In the event of conflict between this agreement and the Main Agreement, this agreement prevails on data-protection matters.
(3) Supplementary amendments and side agreements require text form; § 12 remains unaffected. German law applies; the exclusive place of jurisdiction, to the extent legally permissible, is Berlin.
(4) Should individual provisions of this agreement be invalid, the validity of the remaining provisions remains unaffected; the invalid provision is replaced by a provision that comes closest to the purpose of Art. 28 GDPR.
Place, date — For the Controller — [Name in block letters]
Place, date — For Poensgen Technology UG (haftungsbeschränkt) — Managing director, [Name in block letters]
Annex 1 – Subject matter of the processing
1. Processing operations
- Hosted model inference: processing of prompts, inputs, documents or document excerpts, and generated output to provide the AI features. Processing takes place transiently in memory; content is not stored, in accordance with § 2 of the agreement (zero data retention).
- Knowledge Hub: storage and provision of content that the Controller deliberately stores (e.g. workflows, integrations, plugins, MCP server definitions, presets, permissions, version history).
- Team and organisation administration: management of members, roles, invitations, and organisation-wide settings.
- Content-free usage and billing metadata: user, model, token count, cost, status, timestamp.
2. Purpose of the processing
Provision, security, billing, and support of the Eigenwelt Plus service in accordance with the Main Agreement.
3. Type of personal data
- All personal data contained in content submitted by the Controller or its users, in particular master data, contact data, contract, case, and matter data, and communication content.
- This may include special categories of personal data (Art. 9 GDPR) and data relating to criminal convictions and offences (Art. 10 GDPR), where these are the subject of the content processed by the Controller.
- Platform user data: name, email address, organisation membership, role.
4. Categories of data subjects
- the Controller’s clients and their staff or officers,
- opposing parties, participants in proceedings, and other third parties whose data is contained in processed content,
- the Controller’s staff and users.
Annex 2 – Technical and organisational measures (Art. 32 GDPR)
As of July 2026. The measures are continuously adapted to the state of the art; the level of protection is not reduced in doing so.
1. Location and physical-access control
- Processing exclusively in data centres within the European Union: Google Cloud region europe-west3 (Frankfurt am Main) for platform, gateway, and databases; Scaleway (Paris, region fr-par) for model inference. For the Google Cloud services used (including Cloud Run, Cloud SQL, Memorystore), storage of data at rest is restricted to the selected region.
- Certifications of the providers used: Scaleway S.A.S. is certified to ISO/IEC 27001:2022 (BSI, certificate IS 787020, for the technical infrastructure platform of the public-cloud products). Google Cloud is certified to ISO/IEC 27001:2022 and holds a BSI C5:2020 attestation. No physical access by Eigenwelt personnel.
2. Access and authorisation control
- Role-based access concepts following the least-privilege principle; personalised accounts, multi-factor authentication for administrative access.
- Authentication of API use via organisation-specific keys or token-based sign-in; authorisation checks at organisation level.
- Management of secrets (credentials, keys) in dedicated secret management.
3. Transmission and disclosure control
- Transport encryption of all connections (TLS); encryption of stored platform data to provider standard (encryption at rest).
- Technical prevention of logging of inference content at the gateway: content is redacted from logs and downstream systems; client-side disabling of this redaction is technically excluded.
4. Separation and input control
- Logical tenant separation at organisation level; separate environments for the paid service (zero data retention) and the separate evaluation gateway for free models.
- Traceability of administrative operations and security-relevant events through content-free logs.
5. Data minimisation and zero data retention
- No storage of prompt and output content of paid inference; retention of content-free billing metadata only.
- Automated checks (including continuous tests) that the zero-data-retention configuration is effective.
6. Availability and resilience control
- Managed, redundant database and infrastructure services; regular backups of platform data with defined deletion cycles; monitoring and alerting.
7. Commissioned-processing control and organisation
- Data-processing agreements with all subprocessors; selection by suitability and certification status; regular review.
- Internal process for security incidents (detection, assessment, notification, follow-up); regular review and evaluation of the effectiveness of the measures (Art. 32(1)(d) GDPR).
Annex 3 – Authorised subprocessors
As of July 2026. Changes to this list are governed by § 6 (30-day advance notice, right of objection and extraordinary termination) and § 12.
| Subprocessor | Registered office | Processing location | Service |
|---|---|---|---|
| Google Cloud EMEA Limited (Google Cloud Platform), 70 Sir John Rogerson’s Quay, Dublin 2 | Dublin, Ireland | Frankfurt am Main, Germany (region europe-west3) | Application, gateway, databases, caches, Knowledge Hub data, operational metadata |
| Scaleway S.A.S., 8 rue de la Ville l’Evêque, 75008 Paris (RCS Paris 433 115 904) | Paris, France | Paris, France (region fr-par) | Model inference (zero data retention) |
Note 1: Paid inference content is transmitted only to model infrastructure within the European Union. Where, in an individual case, a subprocessor’s limited support access originates from outside the EU, it is contractually limited to what is necessary and safeguarded by the guarantees set out in § 9 (in particular EU Standard Contractual Clauses under Chapter V GDPR).
Note 2: Payment processing for fees is carried out by a payment service provider in relation to Eigenwelt as the data controller and is not the subject of this commissioned processing. Details are set out in the Eigenwelt Plus Privacy Notice.
Questions about data processing, or to request a countersigned copy: chris@eigenweltlabs.com.