Data Processing Agreement
Last updated: 25 September 2026 · Version 2026-09-25
Agreement on the Processing of Personal Data on Behalf of the Controller
Data processing under Art. 28 GDPR · Version 2026-09-25
The German version is binding; this English version is provided for information only.
between the customer using Klickdemo (Controller) and
Droidtech e.K., owner Michael Rauen, Auf der Eichelsbach 19, 54533 Hasborn, Germany, commercial register HRA 41160 Amtsgericht Wittlich, VAT ID DE306856290, e-mail mail@klickdemo.com (Processor).
Preamble
The Controller uses the Processor’s software Klickdemo to have explainer and demo videos of its web applications, websites and spreadsheet files produced, stored and embedded on its websites. In doing so the Processor processes personal data, the scope of which the Controller determines, exclusively on behalf of and on the instructions of the Controller. This agreement specifies the rights and obligations under Art. 28(3) GDPR. It applies in addition to the Processor’s terms of service and prevails over them in data protection matters.
1. Subject matter, duration and termination
(1) The subject matter of the engagement is the processing of personal data in the course of providing and operating Klickdemo as an internet-based application: exploring and recording the sources named by the Controller, producing, storing and delivering videos and companion files, and delivering embedded videos to visitors of the Controller’s websites.
(2) The agreement begins with its acceptance by the Controller in the application and runs for an indefinite period. It ends with the end of the underlying usage agreement; no separate termination is required.
(3) The Controller may terminate this agreement for cause if the Processor breaches material obligations under this agreement or data protection law and does not remedy the breach within a reasonable period. Without this agreement the application cannot be used for projects containing personal data.
(4) The Processor may amend the wording of this agreement where necessary to adapt to changes in law, case law or regulatory requirements or to include new features. A new version is displayed to the Controller in the account; the Controller has 30 days from display to accept it. Versions carry their date; the accepted version remains available in the account.
2. Nature and purpose of processing
(1) Processing serves solely to provide the contractually owed services to the Controller: automated exploration and recording of its sources, drafting and translating scripts, producing videos with synthetic speech, captions and companion files, storing, updating and delivering them, and counting views of embedded videos.
(2) Processing comprises collecting, recording, storing, retrieving, consulting, using, transmitting to the sub-processors named in Annex 1, restricting, erasing and destroying the data.
(3) Machine processing by AI services. Page texts, page structures, screenshots, file contents, the content of additional knowledge sources (fetched websites, documents, notes) and texts of the Controller are transmitted to the language-model and speech-synthesis services named in Annex 1 and analysed there to produce the knowledge base, script, translation and narrator voice. Credentials never reach these services. In page texts and page structures the application replaces credentials and typical sensitive patterns (e-mail addresses, IBANs, card numbers) with placeholders before transmission; in screenshots it blacks out these places before transmission. Of spreadsheet files, structure, formulas and texts are transmitted, with numbers, dates and boolean values replaced by their kind; of documents only the extracted text, never the file. Redaction rules defined by the Controller for its account or a project are applied by the application before every transmission to the language models (replacement in page texts, page structures, texts of spreadsheet files and additional knowledge sources; blacking out the matched places in screenshots), and what they match is made unrecognisable in the video recording. Processing takes place only at the Controller’s initiative (creating a project or a source, starting a run).
(4) No automated decision-making within the meaning of Art. 22 GDPR takes place. Scripts are presented to the Controller for approval and are recorded only afterwards.
(5) The Processor does not use the Controller’s data for its own purposes, in particular not for advertising and not to train artificial-intelligence models. It ensures by agreement that the service providers named in Annex 1 do not use the content for such purposes either. Statistical evaluations for operations, capacity planning, cost control and troubleshooting use only data without personal reference.
3. Types of data and categories of data subjects
(1) The following types of personal data are processed insofar as the Controller enters them into the application or its sources contain them: credentials of demo accounts (username, password, TOTP secret, API token); content of the explored software or website as it appears in page structures, screenshots and recordings (such as names, e-mail addresses, contact details, transaction data); content of uploaded spreadsheet files and documents; content of public websites that the Controller names as an additional knowledge source; content of e-mails to the project mail address (sign-in codes, invitations); texts of the Controller in the project description, notes, notes for revising the script, brand rules and pronunciation dictionary; usage data of the application (acting user, time, action); and connection data of viewers of embedded videos (IP address and browser identifier only transiently to form a daily changing hash, origin of the embedding page, playback events), of which only daily totals are stored.
(2) Special categories of personal data (Art. 9 GDPR) are not part of the engagement. The Controller ensures that demo accounts and files contain no such data; otherwise it redacts them with the application’s redaction rules before exploration.
(3) Data subjects are: users of the Controller who operate the application; persons whose data appears in the demo account, the explored source, additional knowledge sources or uploaded files (such as employees, customers or test records of the Controller); visitors of the Controller’s websites who play embedded videos.
(4) The Controller ensures that demo accounts and files contain only the data required for the video. The Processor recommends test accounts without real personal data of third parties.
4. Obligations of the Processor
(1) Instructions. The Processor processes the data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do so by Union or Member State law; in that case the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28(3)(a) GDPR). This agreement, the project settings (allowed actions, redaction rules, languages, embed domains) and every run started by the Controller constitute instructions. Further instructions are given by the Controller in text form to mail@klickdemo.com.
(2) If the Processor considers an instruction to be unlawful, it informs the Controller without delay (Art. 28(3) sentence 3 GDPR). It may suspend execution until the instruction is confirmed or changed.
(3) Confidentiality. The Processor uses only persons who have committed themselves to confidentiality and makes them familiar with the relevant data protection requirements (Art. 28(3)(b) GDPR). Access to production data is currently held by the owner and one further person with administrator rights who has committed to confidentiality in text form (confirmed electronically); further persons are engaged only after such a commitment in text form.
(4) Technical and organisational measures. The Processor implements the measures required under Art. 32 GDPR; their current state is described in Annex 2. The Processor may develop them further as long as the level of protection is not reduced; material changes are reflected in Annex 2.
(5) Notification of personal data breaches. The Processor notifies the Controller of any personal data breach it becomes aware of without undue delay and at the latest within 24 hours of becoming aware (Art. 33(2) GDPR), in text form to the owner’s address stored in the account. The notification contains, as far as known, the nature and scope of the incident, the data types and categories of persons concerned, the likely consequences and the measures taken and proposed. The Processor assists the Controller with its notification and communication obligations under Art. 33 and 34 GDPR.
(6) Assistance. The Processor assists the Controller with appropriate measures in fulfilling data subjects’ rights (Art. 12 to 23 GDPR) and with data protection impact assessments and prior consultations (Art. 35 and 36 GDPR), taking into account the nature of processing and the information available to it (Art. 28(3)(e) and (f) GDPR). If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without delay and does not answer it itself. The Controller can largely handle access, rectification, erasure and export for the data stored in the application itself (delete project, delete source, delete video, export); these functions count as assistance within the meaning of this paragraph.
(7) Evidence and audits. The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for and contributes to audits, including inspections (Art. 28(3)(h) GDPR). Evidence is provided primarily by information in text form and by presenting Annex 2 in its current version. An on-site audit takes place with reasonable advance notice, during normal business hours, without disrupting operations and while protecting third parties’ confidentiality interests; the Processor may charge for the effort where the audit goes beyond one audit per year and is not prompted by a specific incident.
(8) Records and contact. The Processor keeps records of all categories of processing activities under Art. 30(2) GDPR. No data protection officer has been appointed; the requirements of Section 38 BDSG are not met. The contact for data protection matters is the owner, reachable at mail@klickdemo.com.
5. Sub-processors
(1) The Controller grants the Processor general authorisation to engage further processors (Art. 28(2) sentence 2 GDPR). The sub-processors engaged at the time of acceptance of this agreement are named in Annex 1 with legal entity, purpose, processing location and basis; Annex 1 carries its own version date, which is recorded with the acceptance.
(2) If the Processor intends to engage a further sub-processor or replace an existing one, it announces this at least 30 days in advance: by updating the publicly available list at klickdemo.com/en/subprocessors, by a notice in the account and by e-mail to the owner’s stored address.
(3) The Controller may object to a change within the notice period in text form for an important, data-protection-related reason. If the reason cannot be resolved and the service cannot be provided without the sub-processor concerned, either party may terminate the usage agreement for cause with effect from the planned date of the change; fees paid in advance are refunded pro rata.
(4) The Processor selects sub-processors carefully and binds them contractually to data protection obligations equivalent to those of this agreement (Art. 28(4) GDPR). Where a sub-processor fails to fulfil its obligations, the Processor remains liable to the Controller for compliance.
(5) Ancillary services without access to the Controller’s personal data (such as telecommunications, maintenance without data access) do not count as sub-processing. The Processor’s payment provider processes only the Controller’s own contract and payment data and no project data; it is named in Annex 1 for completeness.
(6) Castfold and YouTube. Castfold is a product of the Processor itself and not a sub-processor. If the Controller instructs the publication of a video on YouTube, the Processor transmits the video file, title, description and chapters to the YouTube channel the Controller has connected in Castfold. From the transfer onwards Google (YouTube) processes the data under its own responsibility on the basis of the contract between the Controller and Google; this transfer is an instruction of the Controller.
6. Processing in third countries
(1) The application and database run in Germany; recording and video generation run in regions of the European Union; videos and files are stored in data centres in the European Union (Annex 1). AI processing by language models currently takes place entirely through Anthropic’s Claude API with processing by Anthropic, PBC in the United States (paragraph 3), because the quota requested for Google Cloud Vertex AI has not been approved yet; after approval it takes place primarily in regions of the European Union through Vertex AI and through Anthropic only as a fallback. Google Cloud Text-to-Speech is called through the service’s EU endpoint; according to Google, storage and processing stay within Europe.
(2) For the services of the Google, Cloudflare and Stripe groups named in Annex 1, access from the United States, for example by support or security functions, cannot be fully excluded. The contracting parties are the legal entities named in Annex 1; the basis for any transfer is the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR), under which Google LLC, Cloudflare, Inc. and Stripe, Inc. are certified, and additionally the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).
(3) Anthropic Ireland, Limited with processing by Anthropic, PBC (United States). While the quota requested for Vertex AI has not been approved (currently), and afterwards as a fallback when Vertex AI is unavailable, the Processor transmits the data named in section 2(3) (page texts and page structures with placeholders, screenshots, project description, notes, notes for revising the script, script, brand rules, pronunciation dictionary, structure, formulas and texts of spreadsheet files, texts of additional knowledge sources) directly to Anthropic’s Claude API for processing by the Claude models. The contracting party is Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland; processing is carried out by its affiliate Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA, in the United States. The basis is the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR), which form part of the Data Processing Addendum incorporated into Anthropic’s Commercial Terms. This transfer does not rely on the adequacy decision for the EU-US Data Privacy Framework. Under the Commercial Terms, Anthropic may not train models on content from the use of its services. Anthropic retains inputs and outputs for up to 30 days for abuse and safety review and deletes them afterwards. Excepted are inputs and outputs that Anthropic’s automated systems flag as violating its Usage Policy: they are retained for up to two years and the classification scores for up to seven years. Anthropic also retains data where required by law. Credentials never reach Anthropic. By accepting this agreement the Controller gives the documented instruction for this transfer (Art. 28(3)(a) GDPR).
(4) Embedded videos are delivered to viewers through Cloudflare’s global network; the location closest to the viewer processes the viewer’s IP address for delivery. Storage remains in the European Union.
(5) No transfer to third countries beyond those named in paragraphs 2 to 4 takes place. Should it become necessary in future, the procedure under section 5(2) and (3) applies accordingly.
7. Rights and obligations of the Controller
(1) The Controller is solely responsible for the lawfulness of processing and for safeguarding data subjects’ rights (Art. 24 GDPR). It determines the purposes and means of processing within the functions offered by the application.
(2) It ensures that there is a legal basis for the data in demo accounts, explored sources and uploaded files, that it is entitled to have the source explored and recorded, and that data subjects have been informed under Art. 13 and 14 GDPR.
(3) It informs the visitors of its websites about the embed player in its privacy policy and names the Processor as a recipient; consent is not required for the player because it stores nothing on and reads nothing from the device.
(4) It defines the agent’s allowed actions and the redaction rules per project and checks scripts, screenshots and videos before approval and publication for personal data that must not appear.
(5) It manages its users’ access and access keys itself and revokes them without delay when the authorisation ends. In case of doubt the owner stored in the account is the contact for data protection matters.
(6) It informs the Processor without delay if it identifies errors or irregularities regarding data protection provisions.
8. Erasure and return of data
(1) The Controller can download videos, companion files, scripts and the knowledge base itself at any time and export its account data. Export is the primary means of return within the meaning of Art. 28(3)(g) GDPR.
(2) Within the application the following periods apply: demo-account credentials are deleted as soon as the Controller deletes the source or the project; messages to the project mail address 30 days after receipt, at the latest with the project; intermediate files and audit screenshots of individual actions no later than 30 days after the run; the raw take of a video version (silent picture track, narration track, action log) together with that version; additional knowledge sources (documents, fetched website texts, notes) with their entries in the knowledge base as soon as the Controller deletes the source or the project; older versions of a video (beyond the current and the previous one per language) 30 days after two newer versions replaced them; operational job logs without content after 90 days; the account activity log after twelve months; teaser files and videos 48 hours after being made available. Knowledge-base screenshots remain until a new exploration replaces them or the project is deleted.
(3) After the end of a paid plan, videos remain fully usable for 90 days; afterwards embeds and share links are no longer available, and after a further 90 days the Processor deletes projects, videos, recordings, knowledge bases and access data; the Controller is informed by e-mail at the end and 30 and 7 days before the deletion. In free accounts without a plan, videos are deleted 90 days after the last sign-in, with notice 30 and 7 days before. If storage credits for storage above the allowance remain unpaid, the Processor may, no earlier than 90 days after the first notice, delete the oldest videos above the allowance that have not been viewed for twelve months, with notice 30 and 7 days before. If the Controller deletes its account, projects, credentials, knowledge bases and videos are deleted without undue delay. On request in text form the Processor deletes earlier.
(4) Erasure does not take place to the extent and as long as a retention obligation under Union or Member State law exists (Art. 28(3)(g) GDPR). This concerns invoices, credit bookings and usage data without content (Sections 147 AO, 257 HGB, 14b UStG), not the content of projects.
(5) Backup copies are overwritten in the normal backup cycle when the retention period stated in Annex 2 expires; targeted deletion of individual records from existing backups does not take place.
9. Liability, precedence and final provisions
(1) Liability is governed by Art. 82 GDPR. Otherwise the liability provisions of the terms of service apply; this does not limit liability towards data subjects or supervisory authorities.
(2) In case of conflict between this agreement and the terms of service, this agreement prevails in data protection matters. Instructions of the Controller prevail over this agreement insofar as they are compatible with it.
(3) The Controller concludes this agreement in text form under Art. 28(9) GDPR; acceptance in the account and storage of the resulting document including time, accepting person, IP address, version and checksum suffice. A handwritten signature is not required. The document remains available as a PDF in the account.
(4) Should any provision of this agreement be or become invalid, the validity of the remaining provisions remains unaffected.
(5) The law of the Federal Republic of Germany applies. The place of jurisdiction is, where permissible, the Processor’s registered office.
(6) Annex 1 (sub-processors) and Annex 2 (technical and organisational measures) form part of this agreement.
Annex 1: Sub-processors
Version 2026-09-25. The following sub-processors are generally authorised under section 5. The list is available at any time at klickdemo.com/en/subprocessors; changes are announced at least 30 days in advance. The machine-readable version is legal/subprocessors.json.
| Legal entity | Purpose | Processing location | Basis | Since |
|---|---|---|---|---|
| Host Europe GmbH, Hansestraße 111, 51149 Cologne, Germany | Operation of the server for application, API, database and website; data-centre services, connectivity, backups. Affects all customers. | Germany | Data processing agreement under Art. 28 GDPR | 2026 |
| Neue Medien Münnich, owner René Münnich (ALL-INKL.COM), Hauptstraße 68, 02742 Friedersdorf, Germany | Sending the application’s e-mails (sign-in codes, invitations, confirmations, notifications). | Germany | Data processing agreement under Art. 28 GDPR | 2026 |
| Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland | Vertex AI (primary route of AI processing once the quota is approved, currently not in use): language models of the Claude model family (Anthropic) for exploration, script, translation, summarising knowledge sources and review; Cloud Text-to-Speech: narrator voices (only the texts to be spoken are transmitted); Cloud Run: execution of recording and rendering jobs; Secret Manager and Artifact Registry for operating the jobs. Inputs and outputs are not used for training and are not stored permanently after processing; when used through Vertex AI, Anthropic, PBC has no access under Google’s commitments. Affects every project in which a run is started. | Vertex AI and Cloud Run: regions in the European Union; Text-to-Speech: EU endpoint (storage and processing within Europe according to Google) | Google Cloud Data Processing Addendum (Art. 28 GDPR); for possible access from the USA, standard contractual clauses (Art. 46(2)(c) GDPR) and certification of Google LLC under the EU-US Data Privacy Framework (Art. 45 GDPR) | 2026 |
| Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland (contracting party), with processing by Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA | Claude API (currently the only route, while the quota for Vertex AI has not been approved; afterwards as a fallback when Vertex AI is unavailable): language models of the Claude model family for exploration from screenshots and page structure, summarising knowledge sources, drafting scripts and plans, translation and text checks. Anthropic may not train models on content from the use of its services; inputs and outputs are retained at Anthropic for up to 30 days for abuse and safety review and deleted afterwards. Excepted are inputs and outputs that Anthropic’s automated systems flag as violating its Usage Policy: they are retained for up to two years and the classification scores for up to seven years. Anthropic also retains data where required by law. Credentials never reach the service; in page texts, sensitive patterns are replaced with placeholders before transmission (section 2(3)). Affects every project in which a run is processed through this route (section 6(3)). | United States (third country; processing by Anthropic, PBC) | Anthropic Commercial Terms with the incorporated Data Processing Addendum (Art. 28 GDPR); standard contractual clauses from the Data Processing Addendum (Art. 46(2)(c) GDPR); no EU-US Data Privacy Framework | 2026-09-24 |
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (Cloudflare Germany GmbH, Rosental 7, 80331 Munich, as European contact) | Object storage R2 for videos, screenshots, audio files, uploaded files and documents (“EU” jurisdiction, storage in the EU only); delivery of released videos and the embed player through the Cloudflare network; Turnstile to protect the teaser form; DNS of the domains klickdemo.com and klickdemo-mail.com; Email Routing: receipt of e-mails to the project mail addresses (sign-in codes and invitations from the recorded software), immediate forwarding to the application server, no storage of the content at Cloudflare. Affects all customers. | Storage: European Union; delivery and mail receipt: Cloudflare network | Cloudflare Data Processing Addendum (Art. 28 GDPR); standard contractual clauses (Art. 46(2)(c) GDPR) and certification of Cloudflare, Inc. under the EU-US Data Privacy Framework (Art. 45 GDPR) | 2026 |
| Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Dublin 2, Ireland | Payment processing, invoicing, tax calculation, customer portal, partner payouts. Affects only the Controller’s own contract and payment data (name, company, billing address, e-mail address, VAT ID), no project data. For payment processing Stripe acts as an independent controller, for invoicing as a processor. | Ireland; transfer to Stripe, Inc. (USA) possible | Stripe Data Processing Agreement (Art. 28 GDPR); standard contractual clauses (Art. 46(2)(c) GDPR) and certification of Stripe, Inc. under the EU-US Data Privacy Framework (Art. 45 GDPR) | 2026 |
Not part of this agreement (delimitation): Google Ireland Limited and Google LLC for Google Tag Manager, Google Analytics 4 and Google Ads run exclusively on the public website pages after the respective visitor’s consent and process no data from the Controller’s account or projects. Castfold is a product of the Processor itself (section 5(6)). YouTube (Google) receives data only on the Controller’s instruction and processes it under its own responsibility.
Change log: 2026-09-25 Initial version.
Annex 2: Technical and organisational measures
The following measures describe the actual state of implementation under Art. 32 GDPR. They expressly name what is currently not implemented. On this basis the Controller assesses whether the level of protection is adequate for its processing.
1. Confidentiality: physical access control
- The application and database run on a server in a data centre of Host Europe GmbH in Germany. Physical access, video surveillance, fire protection, power supply and air conditioning are the responsibility of the data-centre operator; its measures are subject to the data processing agreement concluded with it.
- Recording and rendering jobs run in Google Cloud data centres in the European Union; videos and files are stored in Cloudflare data centres in the European Union. The physical security of these data centres is the responsibility of the operators under their data processing agreements.
- The Processor operates no server rooms of its own. Workstations are located in lockable rooms.
2. Confidentiality: system access control
- Access to the application only through personal accounts. There are no passwords: sign-in uses a one-time code sent to the user’s e-mail address, valid for a few minutes and for one use only, with failed attempts limited. Account protection therefore depends on the protection of the mailbox; the Controller takes this into account.
- Additional two-factor authentication is currently not offered, including for the Processor’s administrators.
- Sessions are based on a random token stored only as a hash; users can see and end their sessions in the account.
- Administrative access to the server is via SSH with key pair and via the Plesk server administration; access is restricted to the owner. Access to Google Cloud and Cloudflare is via personal accounts with the respective provider’s two-factor authentication.
- The recording worker receives a short-lived access token (JSON Web Token) per job, restricted to that job and invalid after the job ends.
3. Confidentiality: data access control
- Role model per account: Owner, Admin, Editor, Reviewer. Changes to projects, credentials, settings, members and billing are bound to the role and checked server-side.
- Demo-account credentials are stored exclusively encrypted (AES-256-GCM with a unique random nonce per record and a versioned key). The key is kept in the application configuration, separate from the database. Decryption happens only into the job record for the recording worker; there the credentials exist only in memory for the duration of the job. The AI model never receives credentials; it works with placeholders substituted only when typing. Castfold access keys are encrypted the same way.
- No encryption of data at rest by the application beyond the credentials and keys mentioned: the database on the application server is not encrypted by the application. The object storage (Cloudflare R2) encrypts stored objects at rest by default.
- The object storage is not public. Application and worker access it only via short-lived signed URLs; released videos are delivered via dedicated, unguessable addresses.
- The Processor’s platform administrators may access account data for troubleshooting; such access is restricted to two named persons.
- Separation of production and development environments; development works against its own databases, mailboxes and storage.
4. Confidentiality: separation control
- Tenant separation is logical: every record carries its account identifier, and every query is restricted to the signed-in account by global query filters in the data access layer. There is no physical separation into separate databases per customer.
- The separation is safeguarded by automated tests that explicitly check access across account boundaries.
- Each recording job runs in its own container without persistent storage, discarded after the job; the job’s browser may only open the addresses allowed in the project.
5. Integrity: transfer control
- All connections to website, application, API, player and object storage run exclusively over HTTPS (TLS); HTTP requests are redirected. Certificates are renewed automatically.
- Connections of the worker to the application, Google Cloud, Anthropic, the object storage and the mailbox are secured with TLS. Calls to Google Cloud Vertex AI go to endpoints pinned to regions in the European Union; calls to Google Cloud Text-to-Speech go to its EU endpoint; calls to Anthropic’s Claude API (currently for all language-model requests, Annex 1) go to its endpoint in the United States.
- E-mails are sent over a TLS-secured connection. End-to-end encryption of e-mails is not offered; messages therefore contain no project content, only notices and links.
- Before transmission to AI services the software replaces credentials and typical sensitive patterns (e-mail addresses, IBANs, card numbers) with placeholders in page texts and page structures and blacks out these places in screenshots; if it cannot determine the places in a screenshot, the screenshot is not transmitted. Of spreadsheet files, structure, formulas and shortened texts go to the model, with numbers, dates and boolean values replaced by their kind; of documents only the extracted text. The Controller’s redaction rules (account and project) are applied by the software before transmission as well, and additionally in the recording.
- Page content, screenshots and e-mails are handed to the model marked as untrusted data; the model cannot open arbitrary addresses or read files outside the job.
6. Integrity: input control
- Who created a project, changed credentials, approved a script, started a run or invited members, and when, is logged with time and acting user and is visible in the account; the activity log is kept for twelve months.
- Each run stores the rates, settings and results used so that it is reproducible; every action of the agent is recorded with time, target and result in the action log.
- Actions the Controller has not allowed (create, change, delete) are refused by the software; the refusal is logged. Created objects are registered and removed after the run where possible.
- Changes to prices, rates and accounts by administrators are recorded in an audit log.
7. Availability and resilience
- Daily backup of the database on the server in Germany (access only for the application’s system account, retained for 14 days, then deleted).
- In addition, the backup is transferred daily over a secured connection (SSH) to a separate, access-restricted storage location outside the server environment. It is located in Germany, in lockable business premises of the Processor; only the owner has access. This annex deliberately does not name the exact location. Backups are kept there only in encrypted form (file level, AES-256 via GnuPG); the key is kept separately from the backups, not at the storage location itself. An unencrypted version exists only for the duration of the integrity check directly after retrieval and is deleted afterwards. Retention 30 days, then deleted.
- There is no formal procedure for regular restore testing; restorability is tested when there is a specific reason.
- Videos and files are held in the storage provider’s object storage, which keeps the data redundantly within the European Union. There is no additional separate backup of video files; the Controller downloads delivered videos.
- Jobs run with a time limit, progress reporting and automatic retry on transient errors; aborted jobs are detected and re-queued.
- Application logging for troubleshooting; logs contain no credentials, no access tokens and no page content. Retention 90 days.
- Availability is owed as an endeavour; there is no availability guarantee.
8. Organisation, key and secret management
- Access to production data is held by the owner and one further person with administrator rights who has committed to confidentiality in text form (confirmed electronically). Records of processing categories under Art. 30(2) GDPR are kept.
- Operational credentials and keys (database, encryption key for credentials, payment service, object storage, SMTP, Google Cloud, Anthropic API key) are kept in the application configuration on the server and in an access-restricted private source-code repository; on Google Cloud in Secret Manager. No dedicated secret store is used for the application server; this is a deliberate decision of the owner and is stated here.
- Updates of the operating system, runtimes and dependencies are applied as the need arises.
- There is no certification under ISO 27001, BSI IT-Grundschutz or comparable standards.
- No data protection officer has been appointed; the requirements of Section 38 BDSG are not met.
9. Data protection by design and by default
- Default “show only”: without explicit permission the agent creates nothing and deletes nothing.
- Free accounts (teaser) do not accept credentials.
- When a source is created, the application recommends a test account without real personal data and offers redaction rules.
- The embed player sets no cookies and stores nothing in the viewer’s browser; IP addresses are not stored but only processed transiently into a hash with a daily changing key that is deleted with the day; only totals per video and day are stored.
- AI processing only at the Controller’s explicit initiative, currently through Anthropic’s Claude API (Anthropic Ireland, Limited, processing by Anthropic, PBC in the United States) and, once the quota is approved, primarily in regions of the European Union (Google Cloud Vertex AI) (Annex 1); on both routes the content is contractually not used for training. Documents are handed to the model only after the displayed page count and estimate have been confirmed.
- Reach measurement on the website only after consent; none in the signed-in area.
- Credentials are deleted with the source, intermediate files after 30 days at the latest, raw takes with their video version, teaser data after 48 hours.