This English translation is provided for convenience only. The legally binding version of this document is the German original. In case of any discrepancy, the German version prevails.
Data Processing Agreement (Auftragsverarbeitungsvertrag – AVV) pursuant to Art. 28 GDPR
Last updated: 04.09.2026
between
the customer (hereinafter the "Client" or the "Controller")
– controller within the meaning of Art. 4(7) GDPR –
and
Kipti GmbH Hermann-Glüsenkamp-Straße 5 49086 Osnabrück Managing Director: Björn Schriewer Register court: Amtsgericht Osnabrück (Osnabrück Local Court), HRB 222888
(hereinafter the "Contractor" or the "Processor")
– processor within the meaning of Art. 4(8) GDPR –
– the Controller and the Processor hereinafter jointly referred to as the "Parties" –
Preamble
The Controller uses the cloud-based, AI-supported documentation and communication platform "Kipti" (hereinafter the "Platform") of the Processor on the basis of the Processor's GTC (Allgemeine Geschäftsbedingungen – general terms and conditions; hereinafter the "Main Agreement"). In the course of using the Platform, the Processor processes personal data on behalf of the Controller.
This data processing agreement (hereinafter the "DPA") specifies the data protection rights and obligations of the Parties in connection with processing on behalf of a controller pursuant to Art. 28 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter the "GDPR").
The Controller within the meaning of this DPA is:
a) in the case of an organisation customer (§ 1(2)(a) GTC): the organisation itself, represented by the administrator who accepts the DPA as part of the organisation registration.
b) in the case of an individual customer (§ 1(2)(b) GTC): the individual customer themselves, who accepts the DPA in person as the controller within the meaning of Art. 4(7) GDPR.
§ 1 Subject Matter and Duration of the Processing
(1) The subject matter of this DPA is the processing of personal data by the Processor on behalf of the Controller in the context of the provision and use of the Platform in accordance with the Main Agreement.
(2) The duration of the processing corresponds to the term of the Main Agreement. This DPA ends automatically upon termination of the Main Agreement, without prejudice to the obligations to erase and return data pursuant to § 12.
(3) This DPA forms part of the Main Agreement. In the event of any conflict between the provisions of this DPA and the Main Agreement, the provisions of this DPA shall prevail with regard to data protection matters.
(4) The processing of telemetry data relating to staff Platform-user accounts – namely consent-based product analytics and error monitoring – is carried out by the Processor as an independent controller and does not form part of this DPA. Data of documented persons is excluded from this processing. Product analytics is described in section 8 of the Privacy Policy; error-monitoring information is set out in section 9. Operational usage data of Platform users pursuant to § 3(1) remains part of the processing carried out on behalf of the Controller where it is processed to provide and operate the Platform. PostHog and Sentry are listed in Annex 2 for reasons of transparency.
§ 2 Nature and Purpose of the Processing
(1) The processing is carried out for the purpose of providing the Platform and the functionalities it contains to the Controller, in particular:
a) hosting and storage of documentation data (notes, observations, reports, profiles) on the Platform;
b) provision of the AI-supported chat function for structuring and preparing stored information;
c) AI-supported creation of summaries, reports and documentation drafts;
d) provision of communication functions between authorised Platform users;
e) technical support and maintenance of the Platform (security and availability);
f) user administration and access control (detection of use contrary to the GTC);
g) provision of product, onboarding and documentation videos.
(2) The nature of the processing comprises, in particular, the collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission (within the Platform), alignment, combination, restriction, erasure and destruction of personal data.
(3) Processing in the context of the AI features comprises the transmission of data to AI models which are obtained exclusively from providers established in the European Economic Area (EEA) that carry out the processing within the European Union, or which are hosted by the Processor itself within its own European infrastructure. No transmission to, or processing by, model or platform providers established outside the EEA takes place. The use of customer data to train or improve AI models is contractually excluded.
(4) The Platform is not intended for automated decision-making within the meaning of Art. 22 GDPR or profiling within the meaning of Art. 4(4) GDPR. The Processor has implemented technical and organisational measures designed to prevent such use, in particular by limiting the AI features to supporting documentation activities of a purely suggestive nature (human-in-the-loop principle). Within the scope of its own responsibility, the Controller shall ensure that the Platform is not used by its users for profiling or automated decision-making.
§ 3 Types of Personal Data
(1) The following types of personal data are the subject of the processing:
Data of documented persons:
a) master data (e.g. surname, first name, date of birth, class/group, gender);
b) pedagogical documentation data (e.g. observations, notes, descriptions of learning progress, development records, reports, draft assessments);
c) communication data (e.g. records of conversations, minutes of parent meetings, exchanges between professionals);
d) where applicable, special categories of personal data within the meaning of Art. 9(1) GDPR, in particular health data, insofar as entered into the Platform by the Controller in the course of the intended use.
Data of Platform users (end users and individual customers):
a) registration data (e.g. name, email address, function/role);
b) usage data (e.g. login times, activity logs, settings);
c) content data (e.g. notes, entries and chat histories with the AI function created by users);
d) technical video retrieval data when Kipti product, onboarding or documentation videos are played (e.g. IP address, user agent, rough location, time of retrieval, delivery logs).
(2) The decision on the nature and scope of the personal data processed lies solely with the Controller. The Processor has no influence over which personal data is processed via the Platform.
§ 4 Categories of Data Subjects
The persons affected by the processing comprise:
a) documented persons about whom the Controller or its users record information in the Platform (e.g. pupils, children, clients, persons cared for or supported), including minors;
b) persons with parental responsibility and relatives of the documented persons;
c) Platform users (e.g. professionals, employees, administrative staff or private users);
d) other persons whose data is entered into the Platform by the Controller.
§ 5 Processing on Documented Instructions
(1) The Processor shall process personal data solely on documented instructions from the Controller (Art. 28(3)(a) GDPR), unless it is required to process the data by Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
(2) The Controller's instructions are generally issued through the use and configuration of the Platform. This DPA, the Main Agreement and the Controller's configuration of the Platform shall be deemed documented instructions.
(3) The Processor shall inform the Controller without undue delay if, in its opinion, an instruction from the Controller infringes data protection law. The Processor is entitled to suspend the execution of the instruction concerned until the Controller confirms or amends it.
(4) Instructions that go beyond the contractually agreed services require a separate written agreement, including an agreement on any additional remuneration.
(5) The Processor expressly reaffirms that it processes all personal data processed on behalf of the Controller – including data of documented persons (e.g. pupils and students) and the contact, master and content data pursuant to § 3 – solely on the documented instructions of the Controller and solely for the performance of this engagement. The Processor does not process this data for its own purposes, in particular for advertising or training purposes.
§ 6 Confidentiality
(1) The Processor shall ensure that the persons entrusted with the processing of personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR).
(2) The Processor warrants that all persons who have access to the Controller's personal data process such data exclusively in accordance with the Controller's instructions, unless they are required to process it by law.
§ 7 Technical and Organisational Measures
(1) Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, the Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Art. 32 GDPR).
(2) The technical and organisational measures implemented at the time of conclusion of the contract are described in Annex 1 to this DPA.
(3) The Processor is entitled to amend the technical and organisational measures during the term of the contract, provided that the contractually agreed level of protection is not undercut. The Processor shall notify the Controller of material changes in text form.
§ 8 Sub-processing
(1) The Controller grants the Processor general written authorisation to engage sub-processors for the performance of its contractual obligations (Art. 28(2) GDPR).
(2) The sub-processors engaged at the time of conclusion of the contract are listed in Annex 2 to this DPA. The Controller authorises the engagement of the sub-processors named there.
(3) The Processor shall inform the Controller in text form at least fourteen (14) days in advance of any intended addition or replacement of a sub-processor. The Controller has the right to object to the change in text form within that period on legitimate data protection grounds.
(4) If the Controller objects in due time and with reasons, the Processor shall use its best efforts to find an alternative solution that addresses the Controller's concerns. If no mutually agreeable solution can be found, the Controller and the Processor shall each have the right to terminate the Main Agreement and this DPA extraordinarily with three (3) months' notice to the end of a month.
(5) The Processor shall ensure by contract that the provisions of this DPA also apply vis-à-vis the sub-processors. In particular, the Processor shall impose on the sub-processors data protection obligations at least equivalent to those agreed in this DPA (Art. 28(4) GDPR).
(6) The Processor shall be liable to the Controller for the sub-processors it engages complying with data protection obligations as it is for its own conduct.
§ 9 Assistance with Data Subject Rights
(1) Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR (Art. 28(3)(e) GDPR).
(2) If a data subject contacts the Processor directly in order to exercise their rights, the Processor shall forward the request to the Controller without undue delay. The Processor shall not answer the request itself unless the Controller has expressly instructed it to do so.
(3) The Processor shall make available to the Controller, via the Platform, the technical means to fulfil data subject requests, in particular for the provision of information, rectification, erasure, restriction of processing and data portability.
§ 10 Notification Obligations in the Event of Personal Data Breaches
(1) The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach (Art. 33(2) GDPR). The notification shall be made in text form to the contact address specified by the Controller for this purpose.
(2) The notification shall contain at least the following information, insofar as known to the Processor:
a) a description of the nature of the personal data breach, where possible including the categories and approximate number of data subjects and records concerned;
b) the name and contact details of the contact person at the Processor from whom further information can be obtained;
c) a description of the likely consequences of the breach;
d) a description of the measures taken or proposed by the Processor to address the breach and, where appropriate, to mitigate its possible adverse effects.
(3) The Processor shall take the necessary measures without undue delay to secure the data and to mitigate possible adverse consequences for the data subjects, and shall cooperate with the Controller in doing so.
(4) The Controller's obligation to notify a personal data breach to the competent supervisory authority (Art. 33 GDPR) and, where applicable, to the data subjects (Art. 34 GDPR) remains unaffected by this DPA. The Processor shall assist the Controller in fulfilling these obligations.
§ 11 Assistance with Data Protection Impact Assessments
(1) Taking into account the nature of the processing and the information available to the Processor, the Processor shall assist the Controller in ensuring compliance with the obligations in connection with carrying out a data protection impact assessment (Art. 35 GDPR) and any prior consultation of the supervisory authority (Art. 36 GDPR) (Art. 28(3)(f) GDPR).
(2) Such assistance shall be provided in particular by making available information on:
a) the nature of the processing and the technical and organisational measures applied;
b) the sub-processors engaged and their locations;
c) the certifications and audit reports of the infrastructure service providers engaged (in particular the hosting service provider pursuant to Annex 2);
d) the architecture of the AI features and the measures for the protection of personal data in the context of AI processing.
§ 12 Erasure and Return of Data
(1) After termination of the Main Agreement, the Processor shall erase all personal data processed on behalf of the Controller, unless there is an obligation to store the data under Union or Member State law (Art. 28(3)(g) GDPR).
(2) Prior to erasure, the Processor shall provide the Controller, for a period of thirty (30) days after termination of the Main Agreement, with the opportunity to export the personal data in a commonly used, structured and machine-readable format.
(3) After expiry of the period referred to in paragraph 2, and in any event no later than ninety (90) days after termination of the Main Agreement, the Processor shall irreversibly erase all personal data of the Controller, including all existing copies, unless statutory retention obligations preclude this.
(4) At the Controller's request, the Processor shall confirm the complete erasure of the data in text form.
(5) Existing statutory retention obligations remain unaffected by the erasure obligation. In such a case, the Processor shall restrict the processing to the extent required by law and shall erase the data without undue delay once the reason for retention ceases to apply.
§ 13 Audit and Inspection
(1) The Processor shall make available to the Controller the information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller (Art. 28(3)(h) GDPR).
(2) The Controller is entitled to carry out inspections, or have them carried out by a qualified third party bound to secrecy, following reasonable prior notice (as a rule at least four (4) weeks) and during normal business hours. The frequency of inspections is limited to once per calendar year, unless there is a justified suspicion of a data protection infringement.
(3) As a measure equivalent to an on-site inspection, the Processor may make the following evidence available to the Controller on request:
a) current certifications (e.g. ISO 27001, ISO 27701, C5) or equivalent certifications;
b) audit reports of independent third parties (e.g. SOC 2 Type II);
c) an up-to-date summary of the technical and organisational measures.
(4) The costs of audits shall in principle be borne by the Controller, unless the audit reveals a material breach by the Processor of the provisions of this DPA. In that case the Processor shall bear the costs.
§ 14 Data Processing in Third Countries
(1) The Processor processes the Controller's personal data exclusively within the European Union or the European Economic Area (EU/EEA).
(2) No transfer of personal data to a third country (i.e. outside the EU/EEA) takes place unless one of the following conditions is met:
a) an adequacy decision of the European Commission pursuant to Art. 45 GDPR;
b) appropriate safeguards pursuant to Art. 46 GDPR, in particular the European Commission's standard contractual clauses; or
c) the express, documented instruction of the Controller.
(3) The Processor warrants that the sub-processors engaged likewise process personal data exclusively within the EU/EEA, unless the conditions of paragraph 2 are met.
(4) The Processor operates the infrastructure used for the processing of personal data of documented persons exclusively with providers whose place of establishment and place of processing are within the EU or the EEA. For primary data hosting (including the databases), the Processor uses cloud infrastructure of a European provider operated in Germany and certified in accordance with the BSI C5 criteria catalogue. Backups are held exclusively with European providers with a storage location within the EU. For these parts of the infrastructure it is ensured that they are operated exclusively from the EU and that access to personal data of documented persons takes place exclusively from the EU. No technical means exist for accessing this data from outside the EU. The technical provision of the AI features (model inference) takes place, at the Processor's discretion, either via self-hosted AI models within the aforementioned infrastructure, via a European AI platform provider, or additionally via direct API access to the respective European model provider. No transmission of personal data of documented persons to, or processing by, non-European model or platform providers takes place. Other customer data (e.g. contact, master and usage data of Platform users) may also be processed by service providers established outside the EEA, provided that a data processing agreement pursuant to Art. 28 GDPR is in place with them, that they act in compliance with the GDPR and, where applicable, the AI Act, and that appropriate safeguards pursuant to Art. 46 GDPR (standard contractual clauses) have been agreed for transfers to third countries.
§ 15 Liability
(1) The liability provisions of the Main Agreement shall apply to the Processor's liability under this DPA, unless otherwise provided in this DPA.
(2) The liability of the Processor and of the Controller towards data subjects for damage caused by processing which infringes the GDPR is governed by Art. 82 GDPR.
(3) The Controller shall indemnify the Processor against claims by third parties (including data subjects and supervisory authorities) that are based on unlawful data processing by the Controller, on an inadmissible instruction from the Controller, or on a breach by the Controller of its obligations under this DPA. This shall not apply insofar as the Processor has (co-)caused the damage through a breach of its obligations under this DPA.
§ 16 Data Protection Officer
The Processor has appointed a data protection officer. The data protection officer can be reached at:
Email: datenschutz@kipti.app Address: Kipti GmbH, attn. Data Protection Officer, Hermann-Glüsenkamp-Straße 5, 49086 Osnabrück
§ 17 Final Provisions
(1) Amendments and supplements to this DPA must be made in text form. This also applies to any waiver of this text form requirement.
(2) Should individual provisions of this DPA be or become invalid or unenforceable, the validity of the remaining provisions shall remain unaffected.
(3) The law of the Federal Republic of Germany shall apply.
(4) The choice of venue agreed in the Main Agreement shall apply to disputes arising out of or in connection with this DPA.
(5) In the event of any conflict between this DPA and the Main Agreement, the provisions of this DPA shall prevail with regard to data protection matters.
(6) This DPA forms part of the Main Agreement and becomes effective upon its conclusion. It ends automatically upon termination of the Main Agreement, without prejudice to the surviving obligations pursuant to § 12.
Annex 1: Technical and Organisational Measures (TOMs)
The Processor implements the following technical and organisational measures pursuant to Art. 32 GDPR for the protection of the personal data processed on behalf of the Controller:
1. Confidentiality (Art. 32(1)(b) GDPR)
1.1 Physical access control (Zutrittskontrolle)
The Platform is operated on servers in the EU. The physical security of the data centres is ensured by the hosting service provider in accordance with its security standards, including:
- multi-level physical access controls;
- 24/7 monitoring of the data centres;
- biometric access controls and visitor logging.
1.2 System access control (Zugangskontrolle)
- encrypted transmission of all data using TLS 1.2 or higher;
- access to the Platform exclusively via authenticated user accounts with secure passwords;
- multi-factor authentication for administrative access;
- regular review and updating of access authorisations.
1.3 Data access control (Zugriffskontrolle)
- role-based authorisation concept (role-based access control, RBAC);
- access to personal data on a need-to-know basis (least privilege);
- logical tenant separation to ensure data isolation between different customers;
- granular access control within the Platform (user- and role-based visibility of records);
1.4 Separation control (Trennungskontrolle)
- logical tenant separation at database level;
- separation of production, test and development environments;
- use of separate database schemas or row-level security for data isolation.
2. Integrity (Art. 32(1)(b) GDPR)
2.1 Transfer control (Weitergabekontrolle)
- encryption of all data in transit (TLS 1.2+);
- encryption of data at rest (AES-256 or equivalent);
- secure API communication between Platform components;
- no unencrypted transmission of personal data.
2.2 Input control (Eingabekontrolle)
- logging of data entries and changes;
- ability to trace who entered or changed which data and when;
- versioning of changes to records, insofar as technically possible and appropriate.
3. Availability and Resilience (Art. 32(1)(b), (c) GDPR)
- use of high-availability hosting infrastructure of a European provider in the EU;
- regular automated backups;
- ability to restore systems and data following a physical or technical incident;
- use of monitoring and alerting systems;
- emergency management and documented restoration procedures.
4. Procedure for Regular Testing, Assessment and Evaluation (Art. 32(1)(d) GDPR)
- regular review of the technical and organisational measures;
- vulnerability analyses and penetration tests;
- training of employees on data protection and information security;
- documented data protection management system;
- regular review of the sub-processors engaged.
5. Certifications of the Hosting Infrastructure
Our hosting service provider maintains at least the following recognised certifications and audit reports:
- ISO/IEC 27001 (information security management system);
- BSI C5 Type 2 (Cloud Computing Compliance Criteria Catalogue).
Current certificates and audit reports will be made available to the Controller on request in accordance with § 13(3).
Note: The above measures are continuously developed further by the Processor and adapted to the state of the art. Detailed technical documentation can be provided on request.
Annex 2: List of Sub-processors
At the time of conclusion of the contract, the Processor engages the following sub-processors. All sub-processors that process personal data of documented persons are established in the European Economic Area (EEA) and process such data exclusively within the European Union. Data processing agreements pursuant to Art. 28 GDPR are in place with all sub-processors; they undertake to comply with the GDPR and, where applicable, the AI Act. Where transfers to third countries take place, a permissible basis under Chapter V GDPR exists, in particular an adequacy decision pursuant to Art. 45 GDPR or appropriate safeguards pursuant to Art. 46 GDPR, in particular standard contractual clauses.
| Sub-processor | Place of establishment | Purpose of processing | Place of processing |
|---|---|---|---|
| Hetzner Online GmbH | Germany | Primary hosting of the Platform and databases (storage of customer data and personal data of documented persons) | EU (Germany: Falkenstein/Nuremberg) |
| Scaleway S.A.S. | France | (i) provision of AI models for model inference (open-source/open-weight models); (ii) encrypted backups; (iii) transactional email dispatch to Platform users (e.g. registration, authentication, system notifications); (iv) object storage for content-free log data of the AI features (technical metrics, evaluation results and pseudonymous identifiers for quality assurance; no inputs, answers or note content) | EU (France: Paris) |
| Inceptron AB | Sweden | Provision of further AI models of European providers by way of direct API access (open-source/open-weight models) | EU (Sweden) |
| Lyceum Technology Germany GmbH | Germany | Provision of further AI models for model inference (open-source/open-weight models) on the provider's own infrastructure in data centres within the EEA; inputs and outputs are processed exclusively to generate the respective answer | EU/EEA (Finland) |
| Stripe Payments Europe, Limited (including affiliated companies of the Stripe group) | Ireland | Payment processing and billing of the chargeable use of the Platform (contract, invoice and payment data of the Controller or of Platform users); no personal data of documented persons | EU (Ireland); and possible processing in third countries, in particular the USA |
| Attio Limited | United Kingdom | CRM for the administration of business and sales contacts (master and contact data of prospective and existing customers); no personal data of documented persons | United Kingdom; and possible processing in third countries |
| Mux, Inc. | USA | Video hosting, adaptive playback and delivery; technical video retrieval data; no Mux Data tracking; no data of documented persons | Worldwide via delivery networks |
| PostHog, Inc. | USA | Product analytics (usage, behavioural and master data of Platform users); no personal data of documented persons | EU region of the provider |
| Functional Software, Inc. (Sentry) | USA | Error monitoring (technical data and identifiers of Platform users); no personal data of documented persons | EU region of the provider |
| Cloudflare, Inc. | USA | Authoritative DNS and DNS-01 validation of TLS certificates; no personal data of documented persons | Worldwide |
Notes on data processing:
Payment processing (Stripe): Stripe processes exclusively contract, invoice and payment data of the Controller or of Platform users and receives no access to personal data of documented persons. The Processor's contractual partners are Stripe Payments Europe, Limited and Stripe Technology Europe, Limited, both established in Ireland; since 3 January 2026, the main establishment of the Stripe group in Europe for data protection purposes has been Stripe Technology Company Limited, Ireland. A data processing agreement pursuant to Art. 28 GDPR is in place with Stripe Payments Europe, Limited. Insofar as Stripe processes personal data for fraud prevention, for compliance with its own regulatory, financial and anti-money-laundering obligations, and for the security and further development of its own services, Stripe is itself a controller in that respect; such processing takes place outside the processing carried out on behalf of the Processor. The Processor processes billing data as a controller in its own right in relation to the Controller; Stripe is listed here for reasons of transparency. Transfers to affiliated companies of Stripe in third countries, in particular to Stripe, LLC (USA), take place primarily on the basis of the EU-U.S. Data Privacy Framework pursuant to Art. 45 GDPR and additionally on the basis of the standard contractual clauses pursuant to Art. 46 GDPR.
AI inference (Scaleway, Inceptron, Lyceum): Inputs and outputs of the AI features are processed by these providers exclusively to generate the respective answer, are not used for training purposes and are not stored beyond what is necessary for operation, security and error analysis. At Lyceum, only models operated on infrastructure within the EEA are used; models the provider operates outside the EEA are technically excluded.
Ancillary services (PostHog, Sentry, Attio): These services process exclusively data of Platform users or business contacts (master, usage and technical data as well as system-related email content) and receive no access to personal data of documented persons. Data processing agreements pursuant to Art. 28 GDPR are in place with all providers. In the case of Attio, processing takes place primarily in the United Kingdom on the basis of the adequacy decision of the European Commission pursuant to Art. 45 GDPR; supplementary transfers by Attio to further third countries take place on the basis of appropriate safeguards pursuant to Art. 46 GDPR. In the case of PostHog and Sentry (US companies with processing in EU regions), standard contractual clauses pursuant to Art. 46 GDPR have been agreed.
Video delivery (Mux): Mux processes technical retrieval and delivery data (e.g. IP address, user agent, roughly derived location data, times of retrieval) for the purposes of provision, security and error analysis. Kipti uses Mux without Mux Data tracking, without Mux cookies and without personal user, organisation, role or email metadata. Transfers to third countries take place on the basis of the transfer mechanisms provided by Mux, in particular the EU-U.S. Data Privacy Framework or standard contractual clauses, where applicable.
Changes to the list of sub-processors will be notified to the Controller at least fourteen (14) days in advance in accordance with § 8(3) of this DPA.