Legal register
Data Processing Overview
Englishdpa
Version: 1.6 · Last updated: 2026-08-10
This document summarizes GDPR Article 28 roles when AUVY GmbH receives instructions from organisational controllers using AUVY.
Binding contract text
The full German-law Data Processing Agreement (AVV) — Annex A to the AUVY B2B GTC, Article 28-complete including TOMs, sub-processors, transfer rules, and § 203 StGB activation — is:
→ AVV Art. 28 GDPR (DE) · file AUVY_AVV_DE.md · Version 1.10 (2026-08-10) · live subprocessor register v3.1
The published standard AVV is binding when a B2B customer accepts the AUVY Business GTC at self-serve checkout; electronic form satisfies Art. 28 (9) GDPR and no separate countersignature is required. Enterprise customers may negotiate amendments in an order form, MSA, or DPA addendum; only those negotiated changes may require countersignature. The German text is the controlling contract under German law. A full English courtesy translation is public for review and does not override the German text. Public version history: trust.auvy.ai/changelog.
Controller vs processor
- The organisation that invites users into a B2B AUVY workspace is typically the GDPR controller for workspace content.
- AUVY GmbH processes Customer Data on documented instructions pursuant to Articles 28, 29 and 32 GDPR.
- AUVY remains controller for account, authentication, billing, and platform-security processing described in the Product Privacy Notice. For B2C consumer workspaces, AUVY is controller for the consumer context and the AVV does not apply.
- Individuals always retain GDPR rights — escalate through their organisation first, otherwise privacy@auvy.ai / security@auvy.ai.
Documented instructions & transfers
Instructions arrive via onboarding, workspace settings, ticketing, API metadata, order form / pilot agreement and written instructions. Third-country transfers: AVV § 10 / Annex 4 (SCCs 2021/914 and adequacy decisions where applicable). Linkup provides the default EU web-search path. Limited third-country processing for Resend account metadata and Vercel edge metadata remains documented in the AVV. Customer-selected destinations remain separate recipients under the customer's control.
Sub-processors transparency
Live register: trust.auvy.ai/subprocessors (register v3.1, 2026-08-10). OpenPulse is an AUVY-operated service on internal EU infrastructure, not a separately verified contracting subprocessor.
AI responsibilities
Article 50 EU AI Act has applied since 2 August 2026. Provider and deployer duties remain role-specific: AUVY addresses covered provider duties for AUVY direct-interaction systems, while customers retain deployment-specific transparency and AI-literacy obligations. Machine-readable provenance can be removed or degraded downstream and is not a guarantee of origin, authorship, or accuracy. Prohibited uses and non-approved high-risk uses remain governed by the AUP.
Assurance artefacts
Trust Center artefacts (trust.auvy.ai), pentest excerpts, questionnaires and DPIA aides are exchanged under confidentiality obligations.