Data Processing Agreement

This is an English courtesy translation. The German version is the legally binding original (see Section 14).

Under Art. 28 GDPR, between Güclü Holding UG (haftungsbeschränkt), Ilexweg 35, 50769 Cologne, Germany, Amtsgericht Köln HRB 127145 — trading as Compliverse — as processor, and the customer as controller.

1. Subject matter and duration

This agreement specifies the parties' obligations under Art. 28 GDPR in connection with the processing of personal data by Güclü Holding UG (haftungsbeschränkt), trading as Compliverse, as processor on behalf of the customer as controller. It becomes part of the main contract (our Terms & Conditions) as soon as and to the extent that the customer enters personal data while using the Compliverse platform that we process on its behalf.

The term of this agreement corresponds to the term of the main contract. It ends automatically upon termination of the main contract, without prejudice to the continuing effect of the deletion and return obligations under Section 12.

2. Type and purpose of processing, categories of data, data subjects

The purpose of the processing is to provide the Compliverse platform for implementing the customer's compliance obligations: managing user accounts, assigning and evidencing mandatory training, maintaining inventories (e.g. IT systems, AI applications, vendors), and generating documents and evidence packages.

We process in particular: master data of users set up by the customer (name, business email address, role), usage and progress data within the platform (e.g. training completions, timestamps), and business information entered by the customer to the extent it is personal data (e.g. named contacts at vendors).

Data subjects are the customer's employees who use the platform, as well as contacts at the customer's vendors and service providers named by the customer.

The customer decides which personal data it enters into the platform. Special categories of personal data (Art. 9 GDPR) are not intended for use of the platform; the customer does not enter such data.

3. Rights and obligations of the controller

The customer remains responsible, as controller within the meaning of Art. 4(7) GDPR, for the lawfulness of collecting and entering the data and for safeguarding data subjects' rights. It instructs us within the scope of the platform's intended functionality; further instructions are given under Section 5.

4. Obligations of the processor

We process the customer's personal data solely on documented instructions, unless we are required to do otherwise by law; in that case, we inform the customer of those legal requirements before processing, unless the law prohibits doing so. We ensure that persons authorised to process the data have committed themselves to confidentiality (Section 6), implement the technical and organisational measures under Section 7, support the customer under Sections 9 and 11, delete or return data under Section 12, and demonstrate compliance with these obligations under Section 10.

5. Right to issue instructions

Instructions initially follow from the intended use of the platform's functionality. Further instructions are given by the customer in text form (e.g. email); instructions given verbally are confirmed by the customer in text form without delay. If we believe an instruction violates the GDPR or other data protection provisions, we notify the customer and are entitled to suspend execution until the instruction is confirmed or amended.

6. Confidentiality

Persons we entrust with processing are bound to confidentiality or are subject to an appropriate statutory duty of secrecy.

7. Technical and organisational measures (Art. 32 GDPR)

We take, in particular, the following measures:

  • Hosting exclusively in Germany: Hetzner Online GmbH, Falkenstein data centre.
  • Encrypted transmission: TLS encryption with automatically renewed certificates.
  • Access control: individual user accounts, tenant-separated data storage (multi-tenant architecture), two-factor authentication (TOTP with backup codes) available for platform access.
  • Data backup: daily server snapshots plus a daily database backup, retained for 14 days.
  • Logging: security-relevant events are logged server-side.

8. Sub-processors

The customer generally approves engaging the following sub-processors:

  • Hetzner Online GmbH (Gunzenhausen, Germany) — hosting infrastructure, Falkenstein data centre.
  • united-domains AG (Starnberg, Germany) — sending transactional emails (e.g. invitations, password resets) via their mail servers.

Our payment service provider is deliberately not part of this list: it processes none of the data the customer entrusts to us under this agreement, only the payment data from the purchase itself. How that is governed is set out in our privacy policy under “Payment processing”.

We announce the engagement of further or different sub-processors at least four weeks in advance, in text form. The customer may object to the engagement within this period for good cause related to data protection; if no agreement is reached, either party may terminate the main contract for cause.

9. Assisting the controller

We assist the customer with appropriate technical and organisational measures in fulfilling requests from data subjects (access, rectification, erasure, restriction, data portability) and with data protection impact assessments and prior consultation of supervisory authorities, to the extent this concerns data we process and the customer does not already have this information available through the platform itself.

10. Rights of inspection

The customer may satisfy itself of compliance with the measures named in Section 7, in particular by reviewing suitable evidence. The customer announces any further on-site inspections with reasonable advance notice; they take place during usual business hours and with due regard for trade secrets and the security and confidentiality of other customers' data.

11. Reporting data protection breaches

If we identify a breach of the protection of personal data affecting the customer's data, we inform the customer without delay and provide the information known to us at that time that is required for a notification under Art. 33(3) GDPR.

12. Deletion and return after termination

After termination of the main contract, we delete or, at the customer's choice, return all personal data processed on its behalf, unless a statutory retention obligation applies. If the customer does not make a choice within 30 days of termination, we delete the data.

13. Liability

Liability between the parties is governed by the liability provisions of the main contract (Section 10 of the Terms & Conditions), to the extent legally permissible. The statutory liability rules toward data subjects and supervisory authorities (Art. 82, 83 GDPR) remain unaffected.

14. Governing language, final provisions

This English version is a courtesy translation of our German Auftragsverarbeitungsvertrag. In the event of any conflict or inconsistency between the two versions, the German version governs.

In the event of any conflict between this agreement and the Terms & Conditions, this agreement prevails on data protection matters. Amendments and additions require text form. In all other respects, the final provisions of the Terms & Conditions (Section 13) apply accordingly, in particular regarding governing law and jurisdiction. For customers who need a separately signed agreement, we provide one as a document on request.

As of: 18 August 2026