KI-Denkraum
Data processing agreement
Annex to the terms: how we process data on your company's behalf, such as the accounts of a team.
Version of 9 October 2026 · identifier denkraum-avv-2026-10-09 · Download as PDF
This English text is a translation for information purposes. Only the German version is authoritative: Auftragsverarbeitungsvertrag.
between the Customer who takes out a subscription to the KI-Denkraum or concludes an individual contract for a team (controller) and lennartgehl.com GmbH, Hans-Henny-Jahnn-Weg 53, 22085 Hamburg, Local Court (Amtsgericht) Hamburg HRB 173152, represented by the managing director Lennart Maximilian Gehl (provider, processor).
§ 1 Conclusion of the contract and scope
(1) This agreement is an annex to the Terms of the KI-Denkraum. The Customer and the provider agree to it when a subscription or an individual contract for a team under the Terms, such as a pilot, is concluded, without a separate declaration being required. The version valid at the conclusion of the contract is authoritative; the provider stores which version applied, and for an individual contract, the contract names it.
(2) The agreement applies to the extent that the provider processes personal data of Users on behalf of the Customer. That is the case as soon as the Customer creates a team in the KI-Denkraum or the provider creates it for the Customer under an individual contract, and for as long as the team exists. Users are the natural persons to whom the Customer gives a seat through the team, including the persons with the role of owner or admin.
(3) The agreement is available in each version at kidenkraum.com as a page and as a PDF and can be saved and printed (electronic form under Art. 28(9) GDPR); the same applies to every version of its annexes.
(4) For processing on behalf of the Customer, this agreement takes precedence over the Terms. In all other respects, the definitions of the Terms apply.
§ 2 Subject matter, nature, purpose and duration
(1) The subject matter is the provision of the Platform to the Users authorised by the Customer within the scope of a team’s subscription or individual contract, with the functions the Platform offers from time to time. This includes in particular:
- invitations to the business email addresses that owners or admins enter and, for a team under an individual contract, to the addresses that the Customer names to the provider;
- team management: membership, roles (owner, admin, member), seats, invitation status and the log of these operations;
- the accounts of the invited Users, to the extent they serve team access, including sign-in, downloading their own data and deleting the account;
- the associated emails;
- the functions a User uses in their account, such as saving and rating Content, the search and services the User connects to their account themselves.
(2) Nature of the processing: collecting, storing, organising, matching, displaying to the User and to owners and admins, sending by email, deleting.
(3) The data serve exclusively the services under paragraph 1. If the provider uses an AI model, it does so via a sub-processor with processing in the EU (Annex 2) that does not store the inputs. An AI model receives at most the entered search term without reference to the account and, for support and operations in a separate working session set up for that purpose, the information needed for the case. The provider does not use the data for training AI models or for advertising.
(4) The processing lasts as long as the team’s subscription or individual contract; § 10 applies beyond that.
§ 3 Data subjects and types of data
(1) The data subjects are employees of the Customer and other persons authorised by the Customer, in particular freelancers working for it, as well as persons the Customer invites, even before acceptance of the invitation.
(2) The following are processed:
- account data: name, business email address, name of the business, language, login data including the identifiers of a chosen sign-in service or of an identity provider of the Customer;
- team data: membership of the team, role, time of joining;
- invitation data: invited address, intended role, inviting person and the times of the invitation;
- log data of team management and of sign-in: operations with their time and the acting person, times of registration and sign-ins, IP address, browser identifier;
- communication data: emails with recipient address, name, content and delivery status;
- settings and saved entries of the User in their account, such as saved Content and ratings with their time and services the User connects to their account;
- inputs for carrying out a function, such as search terms, only for the duration of the processing; Annex 1 states how long technical logs contain them.
(3) Special categories of personal data (Art. 9 and 10 GDPR) are not covered. The Customer also does not enter such data in free-text fields, such as the name of the team.
(4) Reading behaviour is not covered: the provider does not analyse on a user-related basis which Content a User accesses, searches for or downloads, and shows owners and admins none of it. Such accesses appear only in the technical logs of the hosting. Saved entries and ratings (paragraph 2 no. 6) are visible only to the User themselves, never to owners or admins. Aggregated analyses with which the provider improves the selection and presentation of the Content are carried out under its own responsibility (§ 4(1) no. 7).
§ 4 Distinction from the provider’s own responsibility
(1) This agreement does not cover processing for which the provider itself is responsible:
- performance of the contract and billing with the Customer, including checkout, payment, invoices and the number of seats booked;
- the account of the person who orders the subscription for the Customer or whom the Customer names as the contact person for an individual contract, to the extent it serves the performance of the contract;
- records of the confirmation of business status (Unternehmereigenschaft) and of the acceptance of the Terms and this agreement;
- the security of the Platform as a whole and the prevention of abuse, such as analysing technical logs to detect attacks and blocking abusive access;
- the fulfilment of legal obligations, such as retention obligations;
- the trial and accounts outside a team, such as an account that already existed before the invitation and an account after the end of team membership (§ 10(3));
- aggregating saved entries and ratings into totals without reference to individual persons, never per team or Customer and only across at least ten Users; the totals contain no personal data.
(2) This distinction does not narrow the processing on behalf of the Customer. Invitations, team management and the Users’ accounts remain processing on behalf of the Customer, to the extent they serve team access, even if the provider needs information from them for a purpose under paragraph 1. In that case it uses only what is necessary for that purpose; the payment service provider, for example, receives from team management only the number of seats, no names or addresses, and nothing at all from a team under an individual contract. The measures under Annex 1 remain an obligation under this agreement.
(3) The privacy policy of the KI-Denkraum applies to the processing under paragraph 1.
§ 5 Instructions
(1) The provider processes the data only on documented instructions from the Customer, including with regard to a transfer to a third country. If the law of the European Union or of Germany requires it to process the data otherwise, it informs the Customer of that requirement beforehand, unless the law prohibits such information.
(2) The Customer’s instructions are the Terms, this agreement and the settings and entries that Users, owners and admins make in the functions of the Platform, in particular in team management: inviting, resending or withdrawing invitations, changing roles, removing members. This includes a User connecting a service to their account themselves; the provider transmits to the service only what the User releases for it. Such services are not sub-processors of the provider; the Customer or the service itself is responsible for them. For a team under an individual contract, instructions also include the individual contract with its amendments, the addresses and roles that the Customer names to the provider for invitations and a change of owner that it requests in text form. The Customer also instructs the provider to enable every User to download their data and delete their account in their account.
(3) Further instructions are issued by the Customer’s legal representatives or the owner of the team in text form (Textform, e.g. by email) to hallo@kidenkraum.com. The provider documents them. An instruction that goes beyond the agreed scope of services it treats as a request for an amendment of the contract.
(4) If the provider considers an instruction to be unlawful, it points this out to the Customer without undue delay. It may suspend execution until the Customer confirms or changes the instruction.
§ 6 Confidentiality and security
(1) The provider uses only persons who have committed themselves to confidentiality or are subject to a statutory obligation of confidentiality, and gives them only the access their task requires. The obligation continues after the end of the contract.
(2) The provider implements the technical and organisational measures under Art. 32 GDPR described in Annex 1 in the version published from time to time; authoritative at the conclusion of the contract is the version last published before it, and earlier versions remain available. It may develop them further as long as the level of protection of that version does not decrease, and communicates material changes in text form.
(3) The contact for data protection is the management at hallo@kidenkraum.com. The provider has not designated a data protection officer because there is no obligation to do so (Art. 37 GDPR, § 38 of the German Federal Data Protection Act (BDSG)).
§ 7 Sub-processors
(1) The Customer grants general authorisation to engage sub-processors (Art. 28(2) GDPR). The sub-processors engaged are listed in Annex 2; authorised are the sub-processors of the version last published before the conclusion of the contract, and earlier versions remain available. The provider announces every later version that adds or replaces a sub-processor in accordance with paragraph 2; the Customer may object in accordance with paragraph 3.
(2) Before the provider engages or replaces a sub-processor, it informs the Customer at least 30 days in advance in text form, by email to the owner of the team.
(3) The Customer may object to the change in text form on objective grounds under data protection law within 14 days of receipt of the information. The parties then seek a solution. If that fails, the Customer may end the team’s subscription or individual contract by extraordinary termination (außerordentliche Kündigung), effective at the time the change takes effect; the provider refunds fees paid in advance pro rata in accordance with the rule of the Terms on refunds when a contract ends early.
(4) The provider binds each sub-processor by contract to the data protection obligations of this agreement, to the extent they apply to that sub-processor’s service, as a rule through that sub-processor’s data processing agreement. The provider is liable to the Customer for the performance of those obligations (Art. 28(4) GDPR).
§ 8 Transfers to third countries
(1) If a sub-processor processes data outside the EU and the EEA or accesses them from there, this happens only under the conditions of Art. 44 to 49 GDPR: on the basis of the adequacy decision for the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795) for certified recipients, or of standard contractual clauses (Implementing Decision (EU) 2021/914). Annex 2 states the basis for each service.
(2) If a basis ceases to apply, the provider switches the transfer to another safeguard or ends it, and informs the Customer.
§ 9 Assistance and personal data breaches
(1) The provider assists the Customer with appropriate technical and organisational measures in relation to the rights of data subjects (Art. 12 to 22 GDPR). Owners and admins can remove members and withdraw invitations; every User can download their data and delete their account. If a User asks the provider for an export or the deletion of their account, the provider does so in accordance with § 5(2). Other requests concerning team management it forwards to the Customer without undue delay.
(2) With the obligations under Art. 32 to 36 GDPR, the provider assists the Customer with the information available to it.
(3) The provider notifies the Customer of a personal data breach affecting data processed on behalf of the Customer without undue delay after becoming aware of it, where possible within 48 hours. The notification is sent by email to the owner of the team and contains, as far as known, the information under Art. 33(3) GDPR; missing information the provider supplies subsequently. It takes measures without undue delay to remedy the breach and mitigate its effects. The Customer notifies the supervisory authority and the data subjects; the provider does so only on instruction or on the basis of its own legal obligation.
(4) For assistance that goes beyond the functions of the Platform and a minor effort, the provider may demand reasonable remuneration, unless the assistance is due to a breach of its own obligations.
§ 10 Deletion and return
(1) During the term, the provider deletes a member’s team membership as soon as owners or admins remove the member, and an invitation 30 days after its acceptance, withdrawal or expiry; the Terms govern when an invitation expires. Entries in the team management log it deletes twelve months after they are created. It deletes saved entries and ratings as soon as the User removes them or deletes their account.
(2) After the end of the team’s subscription or individual contract, the provider deletes the team data, the invitations and the team management log within 30 days. If the Customer requests their return in text form before the end, the provider first hands over a list of the members and invitations in a common machine-readable format. Copies in backups are overwritten in the regular cycle. Data the provider must retain by law it blocks until the retention period expires. On request it confirms the deletion in text form.
(3) The provider does not delete the Users’ accounts when team membership ends. When it ends, by removal from the team or with the end of the team’s subscription or individual contract, the account continues to exist with access to the preview until the User deletes it (rules of the Terms on the end of the contract). From then on, the provider processes the account data as well as saved entries and ratings under its own responsibility, as with any account outside a team; the privacy policy provides information about this.
§ 11 Evidence and audits
(1) On request, the provider makes available to the Customer the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR, primarily by way of documents: this agreement with its annexes, written information such as answers to questionnaires, and the contracts, certificates and audit reports of the sub-processors, to the extent they make them available for passing on.
(2) If the documents are insufficient in an individual case, the Customer may audit the provider on site, itself or through an auditor bound to confidentiality who is not a competitor of the provider. The Customer announces the audit at least 30 days in advance in text form. It takes place during normal business hours and at most once per calendar year, except where there is a specific reason such as a personal data breach, and must not disrupt operations disproportionately. The Customer bears the costs, including, to the extent reasonable, the provider’s effort; this does not apply if the audit reveals a material breach by the provider.
(3) The provider does not operate its own servers. The Customer assesses the data centres on the basis of the sub-processors’ certificates and audit reports.
(4) The powers of the supervisory authorities remain unaffected.
§ 12 Obligations of the Customer
(1) The Customer is responsible for the lawfulness of the processing, in particular for being permitted to invite Users and to provide their data to the provider. It informs the Users about the processing (Art. 13 and 14 GDPR). The provider supports it in that every email to Users refers to the privacy policy of the KI-Denkraum.
(2) The Customer invites only business addresses and removes Users who are no longer to have access, for example after they leave. It ensures that its Users connect to their accounts only services it permits.
(3) If the Customer discovers errors or irregularities in the processing, it informs the provider without undue delay.
(4) The Customer’s contact person is the owner of the team, unless the Customer names another person in text form.
§ 13 Liability
(1) Towards data subjects, the parties are liable under Art. 82 GDPR.
(2) As between the Customer and the provider, the liability rules of the Terms also apply to claims under this agreement. Art. 82 GDPR remains unaffected.
§ 14 Term, amendments, final provisions
(1) This agreement applies for the term of the subscription or individual contract and ends with it, without any notice of cancellation being required. § 6(1) and § 10 continue to apply beyond the end.
(2) The parties agree amendments to this agreement in text form or under the amendment procedure of the Terms. § 6(2) and § 7 apply to the annexes.
(3) The German version is authoritative; the English version is a translation.
(4) In all other respects, the final provisions of the Terms apply, in particular on applicable law and place of jurisdiction.
Annex 1: Technical and organisational measures
The measures are set out in a separate document at kidenkraum.com/en/tom, in the version published from time to time with its date; earlier versions remain available there (§ 6(2)).
Annex 2: Sub-processors
The sub-processors are listed in part A of the list of service providers at kidenkraum.com/en/dienstleister, in the version published from time to time with its date; earlier versions remain available there (§ 7).