Legal register
Data Processing Agreement (DPA) Art. 28 GDPR — English courtesy translation
Englishavv-en
under Article 28(3) and (4) GDPR · Annex A to the AUVY Business GTC
Version: 1.10 · Last updated: 2026-08-10
Governing law: Federal Republic of Germany · GDPR · BDSG
Form: Written form including electronic form (Article 28(9) GDPR)
English courtesy translation. The binding German standard agreement is AUVY_AVV_DE.md / AVV Art. 28 GDPR. This translation is provided for review and does not override the German text. Public version history: trust.auvy.ai/changelog Change v1.10: Subprocessor register v3.1 — optional Firecrawl (SideGuide Technologies) and E2B (FoundryLabs) paths removed from the baseline; product web_search / web_read remains Linkup (EU); Annexes 1 and 4 cleaned accordingly.
Parties
Processor (“AUVY” / “Processor”)
AUVY GmbH
Am Haag 8, 82166 Gräfelfing, Germany
Munich Local Court · HRB 311039 · VAT ID DE461400892
Represented by managing directors Patrick Schröppel and Achim Ströbel, each individually authorised to represent
Privacy: privacy@auvy.ai · Security: security@auvy.ai · Legal: legal@auvy.ai
External data protection officer: not currently appointed
Controller (“Customer” / “Controller”)
The organisation identified in the order form, pilot agreement, self-serve checkout, or signature page that uses AUVY workspaces and determines the purposes and means of processing Customer Data.
This DPA is Annex A to the AUVY Business GTC. Acceptance of the Business GTC at B2B self-serve checkout simultaneously concludes this standard DPA electronically; separate countersignature is not required (Article 28(9) GDPR). Enterprise customers may negotiate changes in an order form, MSA, or DPA addendum; only those negotiated changes may require countersignature. For personal-data protection matters, this DPA prevails over conflicting terms of the main agreement.
§ 1 Subject and scope
(1) AUVY processes personal data on the Customer's behalf solely to provide AUVY and related support and operations.
(2) This DPA does not apply where AUVY acts as controller, including for account master data, authentication, billing, platform-security logs, and aggregated telemetry. The Product Privacy Notice applies to those activities.
(3) There is no processor relationship for B2C consumer contracts; AUVY is controller for that consumer context.
(4) Annexes 1–4 form an integral part of this DPA.
§ 2 Roles, instructions, and purpose limitation
(1) The Customer is controller under Articles 4(7) and 24 GDPR; AUVY is processor under Articles 4(8) and 28 GDPR.
(2) AUVY processes personal data only on the Customer's documented instructions unless Union or Member State law requires processing. Where permitted, AUVY informs the Customer before legally required processing.
(3) Documented instructions include product configuration, workspace settings, support tickets, order forms, pilot agreements, API metadata, and written instructions to privacy@auvy.ai or security@auvy.ai.
(4) AUVY informs the Customer without undue delay if it considers an instruction to infringe the GDPR or other applicable Union or Member State data-protection law.
(5) AUVY does not use Customer Data to train or fine-tune its own or third-party AI models. Anonymous aggregate statistics without personal data remain permitted.
(6) Article 50 EU AI Act has applied since 2 August 2026. AUVY addresses covered provider duties for its direct-interaction AI systems; the Customer retains its deployment-specific provider or deployer duties. Machine-readable provenance may be removed or degraded downstream and does not establish accuracy or authorship. Each party takes role-appropriate AI-literacy measures for its personnel. This role allocation is not a blanket compliance assurance for the Customer's deployment.
§ 3 Description of processing
The subject, duration, nature, purposes, data types, and categories of data subjects are set out in Annex 1. An individually agreed scope annex may narrow that scope but does not expand AUVY's rights.
§ 4 Confidentiality
(1) AUVY ensures that persons authorised to process personal data are bound by confidentiality or an appropriate statutory duty.
(2) AUVY personnel and contractors receive access to Customer Data only where strictly required for contractual performance, operations, support, or security under need-to-know and least-privilege principles.
§ 5 Technical and organisational measures
(1) AUVY maintains at least the measures in Annex 2 under Article 32 GDPR, taking account of the state of the art, implementation costs, processing context, and risk to natural persons.
(2) AUVY may update the measures provided the protection level is not reduced. Material reductions are communicated to the Customer.
§ 6 Sub-processors
(1) The Customer gives AUVY general written authorisation under Article 28(2) GDPR to use the sub-processors in Annex 3 and the live register at trust.auvy.ai/subprocessors (register v3.1, 2026-08-10).
(2) AUVY provides at least 30 days' prior notice in text form of intended additions or replacements so the Customer may object.
(3) If the Customer objects within that period for an important data-protection reason and no reasonable solution is available, the Customer may terminate the affected part of the service for cause.
(4) AUVY imposes substantially the same data-protection obligations on sub-processors and remains responsible to the Customer for their performance.
(5) Customer-selected integrations and destinations are not AUVY sub-processing where the connected service acts as an independent recipient at the Customer's direction.
§ 7 Assistance
(1) Taking account of the nature of processing, AUVY assists the Customer with appropriate measures to answer data-subject requests under Articles 12–22 GDPR.
(2) AUVY forwards recognisable Customer-related requests without undue delay and does not answer them unless instructed.
(3) AUVY assists with obligations under Articles 32–36 GDPR to the extent permitted by the nature of processing and information available to AUVY.
§ 8 Personal-data breaches
(1) AUVY notifies the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, using the Customer's recorded security/privacy contact.
(2) The notice contains the information required for Articles 33 and 34 GDPR where available. Missing initial information is supplemented.
§ 9 Evidence and audits
(1) AUVY makes available information necessary to demonstrate compliance with Article 28 GDPR and this DPA.
(2) AUVY permits audits, including inspections, by the Customer or an independent auditor. Audits occur at reasonable intervals, generally with at least 20 business days' notice except for substantiated suspicion or authority order, during business hours, and without disrupting other customers.
(3) Existing assurance material may be considered. The Customer bears audit costs unless a material breach by AUVY is established.
§ 10 International transfers
(1) AUVY transfers personal data to third countries only on documented instructions, where law requires it, and in accordance with Chapter V GDPR.
(2) Relevant mechanisms may include an adequacy decision, the EU-US Data Privacy Framework where the recipient is certified, the 2021/914 Standard Contractual Clauses (Modules 2 and/or 3), and supplementary measures such as encryption, access restriction, minimisation, and EU-region pinning where offered.
(3) Annex 4 describes transfer paths. Copies of applicable safeguards are available from privacy@auvy.ai.
§ 11 Return and deletion
(1) The Customer may export Customer Data during the contract.
(2) At the end of processing, AUVY returns available export data and deletes it, or deletes it directly at the Customer's choice, including copies within 30 days, unless Union or Member State law requires retention. AUVY's controller records may remain under category-specific statutory retention; Customer Data remains only where law specifically requires AUVY to retain it.
(3) This DPA continues until return or deletion. Data in routinely rotating backups remains protected and is not used for another purpose until overwritten.
(4) AUVY confirms deletion in text form on request.
§ 12 Professional secrecy (§ 203 StGB)
(1) Processing secrets entrusted to professional secret-holders under § 203 StGB is permitted only after bilateral activation in text form: Customer notice of the intended processing and AUVY counter-confirmation that the required commitments are in place.
(2) Without activation, such data must not be entered. There is no technical product unlock; permission is contractual.
(3) Activation requires confidentiality commitments for relevant AUVY personnel, use of a § 203-compatible subprocessor subset or equivalent safeguards, and documented additional access, logging, and purpose-limitation measures. Web search may be disabled.
(4) Activation is available only on the B2B Enterprise path. B2C workspaces may not use § 203 workflows.
§ 13 Term
This DPA applies for the duration of the main agreement while AUVY processes Customer Data. Statutory and contractual rights to suspend or terminate for cause remain unaffected.
§ 14 Liability
Data-protection liability is governed by Article 82 GDPR and § 14 of the Business GTC. Mandatory claims and fines are not limited where law prohibits limitation.
§ 15 Final provisions
(1) German law applies, subject to mandatory GDPR rules and incorporated unalterable standard clauses.
(2) Munich is the place of jurisdiction where the Customer is a merchant, public-law entity, or public-law special fund.
(3) Changes require text form unless the main agreement's annex-change mechanism applies and mandatory standard clauses prevent modification.
(4) Invalidity of one provision does not affect the remainder.
(5) Contacts: privacy@auvy.ai · security@auvy.ai · legal@auvy.ai.
Annex 1 — Description of processing
| Field | Description |
|---|---|
| Subject | Hosting, storage, display, search, AI inference, product web search/read, transcription where enabled, export/deletion, and support for Customer Data |
| Nature | Collection through Customer input, storage, retrieval, organisation, adaptation, inference, transmission to approved sub-processors when the relevant path is invoked, restriction, and deletion |
| Purposes | Providing AUVY as a Project OS / verified AI workspace, including collaboration, engagement context, audit traces, document-supported research, and agreed support |
| Duration | Contract term plus the § 11 deletion period, generally 30 days, and any mandatory retention |
| Data subjects | Customer personnel and contractors; third parties named in workspace content; meeting participants where transcription is used; persons named on public pages where web tools are used |
| Personal data | Workspace content, documents, notes, prompts, AI output, files, meeting audio/transcripts, search queries and URLs, connected integration content, workspace/user assignment metadata |
| Article 9 data | Not intended by default; permitted only with a valid basis, prior notice to AUVY, compliance with the AUP, and agreed additional measures |
| § 203 secrets | Only after § 12 activation |
Annex 2 — Technical and organisational measures
Measures current as of 2026-08-10:
A. Confidentiality
- TLS 1.2+ in transit and AES-256 or equivalent at rest where supported by storage services.
- Logical workspace isolation, server-authoritative workspace binding, RBAC, least privilege, Better Auth session controls, and MFA/WebAuthn where enabled.
- AUVY-operated identity storage in Helsinki; EU-region infrastructure for core hosting and standard AI/voice paths.
- AUVY-operated OpenPulse internal EU infrastructure for realtime communication; Linkup as the default EU web-search path.
B. Integrity
- Code review, controlled deployments, patch management, hardened operating standards, authenticated APIs, and server-side authority over workspace scope.
C. Availability and resilience
- Encrypted backups of the document/trace plane, separately operated identity/database backup, recovery processes, monitoring, alerting, and queue/worker operations.
D. Evaluation
- Security and audit logging, documented incident response, security reviews, and tenant-isolation testing. No issued certification is implied.
E. Minimisation and deletion
- Feature-based activation of optional processors, pseudonymous/aggregate telemetry, no Customer Data model training, product export, workspace deletion, and § 11 timelines.
F. Controller assistance
- Export/deletion functions and assistance with data-subject requests and DPIAs on documented instruction.
Annex 3 — Sub-processors
Authorisation: General authorisation · Notice: 30 days
Live register: https://trust.auvy.ai/subprocessors
Snapshot: v3.1 · 2026-08-10
| Provider | Purpose | Data | Hosting | Optional |
|---|---|---|---|---|
| Hetzner Online GmbH | Primary product hosting and AUVY-operated stores | Account/session data, workspace content/files, operational data | EU (Helsinki) | no |
| Amazon Web Services EMEA SARL | EU cloud infrastructure and AI model access | Workspace content, prompts, files, service logs | EU (Frankfurt) | no |
| Microsoft Ireland Operations Ltd. | AI model services where configured and voice transcription | Workspace content, prompts, files, audio/transcripts, logs | EU (Frankfurt, Sweden) | no |
| Linkup SAS | Default product web search and public-page retrieval | Queries, URLs, returned public results/page text | EU (Azure EU) | no |
| Vercel Inc. | Web application hosting and delivery | Request and delivery metadata | EU (Frankfurt); edge metadata may be global | no |
| Stripe Payments Europe, Ltd. | Billing and payments, primarily controller data | Billing details and payment method held by Stripe | EU (Ireland) | no |
| Resend Inc. | Transactional email | Recipient, message content, delivery metadata | EU send (Ireland); account metadata in US under safeguards | no |
| PostHog Inc. | Product analytics and feature flags when enabled | Pseudonymous IDs, events, workspace metadata | EU (Frankfurt) | yes |
“Optional” means data is sent only when the configured path is invoked. OpenPulse is operated by AUVY on internal EU infrastructure and is not listed as a separate third-party subprocessor because no separate contracting legal entity is verified. Customer-selected integrations and destinations are separate recipients under the Customer's control.
Annex 4 — Third-country transfers
(1) Core workspace and account storage is EU-based.
(2) Limited third-country processing may also include Resend account metadata and Vercel edge request metadata.
(3) Applicable mechanisms are adequacy decisions where available, DPF certification where applicable, SCC 2021/914 Modules 2/3, and supplementary measures.
(4) Completed formal SCC modules are available with Enterprise documentation where required. Self-serve processing relies on this DPA together with processor DPAs/SCCs.
Signature page
The standard self-serve DPA binds electronically without separate signature. The fields below are available for negotiated Enterprise changes.
| Controller (Customer) | Processor (AUVY GmbH) | |
|---|---|---|
| Company | AUVY GmbH | |
| Name / role | ||
| Place / date | ||
| Signature / eSign |
Optional § 12 activation: ☐ requested by Customer on ________ ☐ AUVY counter-confirmation on ________
Structural Article 28 mapping
| Article 28(3) element | Location |
|---|---|
| Subject and duration | § 3 / Annex 1 |
| Nature, purpose, data, data subjects | § 3 / Annex 1 |
| Documented instructions | § 2 |
| Confidentiality | § 4 |
| Article 32 measures | § 5 / Annex 2 |
| Sub-processors | § 6 / Annex 3 |
| Data-subject assistance | § 7 |
| Articles 32–36 assistance / breach notice | §§ 7–8 |
| Return and deletion | § 11 |
| Evidence and audits | § 9 |
| International transfers | § 10 / Annex 4 |
| Electronic form | Header / parties / signature page |