Legal

Data Processing Agreement

Last updated · 21 September 2026

Data processing agreement under Article 28 GDPR, Annex 4 to the terms and conditions for the elunos.ai platform, including the list of sub-processors (Annex 4-C) and the technical and organisational measures (Annex 4-D).

Convenience translation. Only the German version is legally binding; in the event of any discrepancy the German text prevails.

Data Processing Agreement pursuant to Art. 28 GDPR
Annex 4 to the General Terms and Conditions (GTC) for the elunos.ai platform

elunos.ai Labs UG (haftungsbeschränkt), Neue Mainzer Straße 31, 60311 Frankfurt am Main
Standard document, hub generation, version 1.0, status: 19.08.2026 · version 2026-09, published on 21.09.2026

Scope

This Data Processing Agreement (hereinafter “DPA”) applies between the company designated in the customer account upon placing the order (hereinafter “Controller”) and elunos.ai Labs UG (haftungsbeschränkt), Neue Mainzer Straße 31, 60311 Frankfurt am Main (hereinafter “Processor”). The Controller and the Processor are jointly referred to as the “Parties”. This DPA is Annex 4 to the General Terms and Conditions (GTC) for the elunos.ai platform. The Controller offers to conclude it by placing its order (Clauses 10.3 and 10.6 of the GTC); it is concluded upon receipt of the order confirmation, simultaneously with the Main Agreement (Clause 10.4 of the GTC). “Main Agreement” means the software-as-a-service agreement pursuant to Parts B and C of the GTC; references to Clauses with the addition “of the GTC” refer to the GTC, references without this addition refer to this Agreement.

Preamble

This Agreement specifies the obligations of the Parties arising from the software-as-a-service agreement concluded between them (Main Agreement) with regard to data protection and data security. It governs the processing of personal data by the Processor on behalf of the Controller and applies to all activities in the course of which employees of the Processor or subcontractors engaged by the Processor may come into contact with personal data of the Controller.

In the event of contradictions between the Main Agreement and this Agreement, the provisions of this Agreement shall prevail in matters of data protection law.

Section 1 Subject matter and term of the Agreement

(1) The subject matter of the assignment is the provision of the Software “elunos.ai” as software as a service, including the storage and processing of personal data required for this purpose, in accordance with the provisions of the Main Agreement.

(2) The Processor processes personal data for the Controller within the meaning of Art. 4 no. 2 and Art. 28 GDPR on the basis of this contract.

(3) The contractually agreed service is rendered primarily in a Member State of the European Union or in a contracting state of the Agreement on the European Economic Area. Processing in third countries shall take place only by the subcontractors approved in Annex 4-C or with the prior consent of the Controller in text form, and only if the special requirements of Art. 44 et seq. GDPR are met, in particular if an adequacy decision of the Commission or valid standard contractual clauses (Implementing Decision (EU) 2021/914), where necessary with supplementary measures, are in place.

(4) This Agreement enters into force upon the conclusion of the contract pursuant to Clause 10.4 of the GTC (receipt of the order confirmation by the Controller) and ends automatically upon termination of the Main Agreement. An ordinary termination of this Agreement alone is excluded; the right to terminate without notice pursuant to para. 5 remains unaffected.

(5) The Controller may terminate this Agreement at any time without notice if there is a serious breach by the Processor of data protection provisions or of provisions of this Agreement, if the Processor is unable or unwilling to carry out an instruction of the Controller, or if the Processor refuses the Controller's rights of control in breach of contract. The termination of this Agreement entitles the Controller to extraordinary termination of the Main Agreement as well.

Section 2 Nature and purpose of the processing, type of personal data, categories of data subjects

(1) Nature of the processing: The processing comprises all processing activities within the meaning of Art. 4 no. 2 GDPR that are necessary for rendering the contractually agreed service, in particular:

  • collection, recording and organisation of personal data;
  • storage in the infrastructure operated by the Processor;
  • adaptation, alteration, retrieval and consultation;
  • transmission within the scope of the use initiated by the Controller;
  • erasure and destruction in accordance with this Agreement.

(2) Purpose of the processing: Provision of the contractually agreed software-as-a-service offering, including support, maintenance and the functions initiated by the Controller. Processing for other purposes, in particular for profiling, for the Processor's own advertising purposes or for the training of artificial intelligence models, is excluded.

(3) Type of personal data: In the course of the performance of the assignment, the following categories of data in particular may be processed:

  • master data of the Users of the Controller (surname, first name, business contact details, function, user ID);
  • communication and connection data (e-mail address, IP address, telephone numbers of the callers and connected telephone numbers of the Controller, timestamps, log data);
  • content data which the Controller or its Users enter into the Software;
  • customer data and business partner data of the Controller, to the extent these are processed in the Software;
  • audio and voice data, any call recordings, transcripts and call metadata from telephone calls and chat conversations conducted via the agents of the Controller;

(4) Special categories of personal data within the meaning of Art. 9 GDPR are processed to the extent that the Controller enters such data into the Software or to the extent that they arise in the course of use in accordance with the contract. In particular, information provided by callers in the context of pharmacies, medical practices or other healthcare professions may constitute data concerning health within the meaning of Art. 9 para. 1 GDPR, even if the connection to health only results from a mental association or deduction (CJEU, Case C-21/23, Lindenapotheke). The Controller shall ensure on its own responsibility that the requirements for lawful processing under Art. 9 para. 2 GDPR (in particular lit. h in conjunction with Section 22 of the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG)) are met. The Processor shall treat these data in accordance with the technical and organisational measures (Annex 4-D) and, to the extent it applies to the Controller (Clause 24.4 of the GTC), the Undertaking to maintain professional secrecy (Section 203 of the German Criminal Code (Strafgesetzbuch, StGB), Annex 5).

(5) Categories of data subjects:

  • employees of the Controller who use the Software;
  • customers and potential customers of the Controller;
  • suppliers and business partners of the Controller;
  • callers and chat users who interact with the agents via the communication channels of the Controller;
  • other persons whose data the Controller enters into the Software.

Section 3 Rights and obligations as well as authority of the Controller to issue instructions

(1) The Controller alone is responsible for assessing the lawfulness of the processing pursuant to Art. 6 para. 1 GDPR and for safeguarding the rights of the data subjects under Art. 12 to 22 GDPR. The Processor is obliged to forward to the Controller without undue delay all requests that are recognisably addressed to the Controller.

(2) The Controller shall, as a rule, issue all assignments, partial assignments and instructions in text form. Oral instructions shall be confirmed in text form without undue delay.

(3) Changes to the subject matter of the processing and changes of procedure shall be coordinated between the Parties and documented in text form.

(4) The Controller is entitled, before the start of the processing and regularly thereafter, to satisfy itself in an appropriate manner of compliance with the technical and organisational measures of the Processor and with the obligations laid down in this Agreement. The modalities are governed by Section 7 of this Agreement.

(5) The Controller shall inform the Processor without undue delay if it identifies errors or irregularities when examining the results of the assignment.

(6) The Controller is obliged to treat as confidential all knowledge of trade secrets and data security measures of the Processor obtained in the course of the contractual relationship. This obligation continues to apply after the termination of this Agreement.

Section 4 Obligations of the Processor

(1) The Processor processes personal data exclusively within the scope of the agreements made and in accordance with the instructions of the Controller, unless it is required to carry out other processing by Union or Member State law. In such a case, the Processor shall inform the Controller of the legal requirements before the processing, unless that law prohibits such information on important grounds of public interest (Art. 28 para. 3 sentence 2 lit. a GDPR).

(2) The Processor shall not use the personal data provided to it for any other purposes, in particular not for its own purposes. Copies or duplicates shall not be made without the knowledge of the Controller. This does not apply to technically necessary backup copies, to the extent they are required to ensure proper data processing, or to data that are required for compliance with statutory retention obligations.

(3) The Processor warrants the performance in accordance with the contract of all agreed measures in the area of the processing of personal data in accordance with the assignment. It shall ensure that the data processed for the Controller are strictly separated from other data holdings (tenant separation).

(4) The Processor shall support the Controller to the necessary extent in fulfilling the rights of the data subjects under Art. 12 to 22 GDPR, in preparing the records of processing activities and in any required data protection impact assessments (Art. 28 para. 3 sentence 2 lit. e and f GDPR).

(5) The Processor shall draw the Controller's attention without undue delay to any instruction issued by the Controller which, in the Processor's opinion, infringes statutory provisions (Art. 28 para. 3 sentence 3 GDPR). The Processor is entitled to suspend the execution of the relevant instruction until it has been confirmed or amended by the Controller following a review.

(6) The Processor shall rectify, erase or restrict the processing of personal data from the processing relationship if the Controller so requires by way of an instruction.

(7) The Processor may provide information about personal data from the processing relationship to third parties or to the data subject only following prior instruction or consent by the Controller.

(8) The Processor shall commit all employees involved in the data processing to confidentiality before they take up their activity, in accordance with Art. 28 para. 3 sentence 2 lit. b and Art. 29 GDPR. This obligation continues to apply after the termination of the respective employment relationship. The Processor shall familiarise the employees in a suitable manner with the data protection provisions relevant to them.

(9) The Processor monitors compliance with the data protection provisions in its business.

(10) The following person has been appointed as data protection officer at the Processor: Felix Reuter, felix@elunos.ai. Any change shall be notified to the Controller without undue delay. To the extent that a data protection officer has not been appointed at the Processor because the statutory requirements for this are not met, the Processor shall inform the Controller thereof.

(11) The Processor shall ensure that it complies with its obligations under Art. 32 para. 1 lit. d) GDPR to implement a process for regularly reviewing the effectiveness of the technical and organisational measures for ensuring the security of the processing.

Section 5 Notification obligations in the event of personal data breaches

(1) The Processor shall notify the Controller in text form without undue delay, but no later than within 24 hours of becoming aware thereof, of disruptions, breaches of data protection provisions or of the stipulations made in the assignment, as well as of any suspicion of data protection breaches or irregularities in the processing of personal data.

(2) The notification shall contain at least the information specified in Art. 33 para. 3 GDPR, to the extent this is known to the Processor or can be determined with reasonable effort. If not all information is available at the time of the initial notification, it shall be provided subsequently without undue delay.

(3) The Processor shall support the Controller appropriately in fulfilling its obligations under Art. 33 and Art. 34 GDPR (Art. 28 para. 3 sentence 2 lit. f GDPR).

(4) The Processor may carry out notifications to supervisory authorities under Art. 33 GDPR or communications to data subjects under Art. 34 GDPR on behalf of the Controller only following prior instruction of the Controller in text form.

Section 6 Subcontracting

(1) The engagement of subcontractors for the processing of personal data of the Controller requires the prior authorisation of the Controller pursuant to Art. 28 para. 2 GDPR.

(2) By concluding this agreement, the Controller consents to the engagement of the subcontractors listed by name in Annex 4-C, together with their address and a description of their activities (Clauses 10.4 and 10.6 of the GTC); no signature is required.

(3) The Processor shall inform the Controller in text form of any intended change concerning the addition of new subcontractors or the replacement of existing subcontractors at least 30 days in advance. The Controller has the right to object to such changes in text form within 14 days of receipt of the information (Art. 28 para. 2 sentence 2 GDPR).

(4) In the event of a justified objection by the Controller, the Processor shall not use the subcontractor concerned for the processing of personal data of the Controller. If the Parties are unable to reach agreement within 30 days of receipt of the objection, either Party is entitled to terminate the Main Agreement extraordinarily with a notice period of two months to the end of a calendar month.

(5) Subcontractors in third countries may only be engaged if the special requirements of Art. 44 et seq. GDPR are met, in particular if there is an adequacy decision of the Commission, valid standard contractual clauses (Implementing Decision EU 2021/914) with supplementary measures, or approved codes of conduct. The Processor shall document the measures taken and submit them to the Controller on request.

(6) The Processor shall ensure by contract that the provisions agreed between the Parties to this agreement, in particular those on technical and organisational measures, rights of control and notification obligations, also apply vis-à-vis subcontractors. The contract with the subcontractor shall be drawn up in writing, for which an electronic format is sufficient (Art. 28 para. 9 GDPR).

(7) The Processor shall select the subcontractor carefully, having particular regard to the suitability of the technical and organisational measures taken by that subcontractor. The audit documentation shall be made available to the Controller on request.

(8) The Processor shall review the subcontractor's compliance with its data protection obligations regularly, but at least annually. The result shall be documented and made accessible to the Controller on demand.

(9) The Processor is liable to the Controller for the subcontractor's compliance with the data protection obligations imposed on it in accordance with this Section 6 (Art. 28 para. 4 GDPR).

(10) If the Controller connects its own third-party systems, services or endpoints via the interfaces of the platform using its own access credentials (e.g. its own webhooks, its own automation or workflow services, its own CRM), these are not subcontractors of the Processor within the meaning of this Section 6. The Processor transmits personal data to such systems exclusively on the documented instruction of the Controller, which consists in the configuration made by the Controller. The Controller itself is responsible for the lawfulness, the security and the data protection of these systems and for the conclusion of any data processing agreements that may be required with their providers. If the Controller causes transmissions to recipients or endpoints outside the EU or the EEA, it is responsible for the safeguards required for this under Chapter V GDPR; the EU data storage of the platform does not extend to such transmissions caused by the Controller.

Section 7 Rights of control of the Controller

(1) The Controller is entitled to monitor, itself or through third parties commissioned by it, compliance with the provisions on data protection and data security and with the contractual agreements to the appropriate and necessary extent (Art. 28 para. 3 sentence 2 lit. h GDPR).

(2) The control may be carried out in particular by obtaining information, inspecting stored data and data processing programs, and by means of on-site reviews and inspections.

(3) On-site controls shall be announced with a lead time of at least 14 days, unless a control at short notice is required on account of a specific data protection incident. They shall be carried out in coordination with the business hours of the Processor and arranged in such a way that business operations are not unreasonably impaired.

(4) If the Controller commissions a third party to carry out the control, the third party shall provide an Undertaking of confidentiality. The Processor may object to the selection of the third party if that third party is a direct competitor of the Processor.

(5) Proof of compliance may also be provided by means of current certifications, audit reports or reports of independent bodies (for instance in accordance with ISO 27001, BSI C5, SOC 2 Type II), to the extent that these cover the relevant requirements.

(6) The Processor shall support the Controller in the controls. Remuneration for the Processor's effort for controls going beyond one standard control agreed per year may be agreed separately.

Section 8 Technical and organisational measures pursuant to Art. 32 GDPR

(1) The Processor shall take the technical and organisational measures required under Art. 32 GDPR for the security of processing (Art. 28 para. 3 sentence 2 lit. c GDPR). The measures are guided by the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the varying likelihood and severity of the risk to the rights and freedoms of natural persons.

(2) The specific technical and organisational measures are described in Annex 4-D to this agreement. They comprise at least measures to ensure:

  • confidentiality (physical access control, system access control, data access control, separation control, pseudonymisation);
  • integrity (transfer control, input control);
  • availability and resilience (availability control, rapid recoverability);
  • procedures for regularly testing, assessing and evaluating effectiveness (Art. 32 para. 1 lit. d GDPR).

(3) The Processor shall carry out a review of the effectiveness of the measures at least once a year and shall communicate the result to the Controller on request in the form of a summary report.

(4) In the course of the processing relationship, the measures may be adapted to technical and organisational developments, but must not fall below the agreed standards. The Processor shall document material changes and notify the Controller of them in text form.

(5) If the measures do not meet the requirements of the Controller, the Processor shall notify the Controller without undue delay.

Section 9 Obligations after termination of the processing

(1) After completion of the contractual work or earlier at the request of the Controller, but at the latest in accordance with paragraph 2 and Clause 23 of the GTC, the Processor shall hand over to the Controller all personal data, data carriers and processing results that have come into its possession or have reached subcontractors and that are connected with the processing relationship, or shall, at the choice of the Controller, erase them in a manner compliant with data protection law (Art. 28 para. 3 sentence 2 lit. g GDPR).

(2) If the Controller does not make a choice, the Processor shall first make the data available for download for three weeks in accordance with Clause 23.1 of the GTC and shall then erase them in accordance with Clause 23.2 of the GTC within one week after the download has taken place, but at the latest three months after termination of the Main Agreement.

(3) The erasure or destruction shall be confirmed to the Controller in text form, stating the date.

(4) Where statutory retention obligations exist, the obligation to erase remains unaffected in all other respects. The Processor shall technically secure the data concerned against further processing and shall erase them after expiry of the statutory retention period.

Section 10 Liability

(1) The liability of the Parties towards data subjects is governed by Art. 82 GDPR.

(2) As between the Parties (internal relationship), each Party is liable for damage caused by its own breaches of duty. The liability provisions and limitations of liability of the GTC (Clause 25) apply in addition, unless paragraph 4 provides otherwise.

(3) If a fine is imposed on a Party by the supervisory authority or if a claim for damages is asserted against a Party by a data subject, the other Party shall indemnify it against such claim to the extent that corresponds to the other Party's share of fault.

(4) For contractual claims of the Controller against the Processor arising out of or in connection with the processing of personal data under this agreement, including the indemnification under paragraph 3, a separate liability cap applies in place of the liability cap under Clause 25.4 of the GTC. In this respect, the liability of the Processor is limited per calendar year to the higher of the two values of (a) twice the annual contract value within the meaning of Clause 25.4 of the GTC and (b) the sum insured under the cyber and financial loss liability insurance maintained by the Processor in the amount of EUR 500,000. Liability for intent and gross negligence, for damage arising from injury to life, body or health, and any other mandatory statutory liability remain unaffected and unlimited in amount; direct claims of data subjects under Art. 82 GDPR are governed exclusively by paragraph 1.

Section 11 Final provisions

(1) Amendments and supplements to this agreement require text form. This also applies to the waiver of this text form requirement.

(2) The defence of the right of retention under Section 273 BGB is excluded with regard to the data processed for the Controller and the associated data carriers.

(3) Agreements on the technical and organisational measures as well as control and audit documentation shall be retained by both Parties for the term of this agreement and thereafter for three full calendar years.

(4) The law of the Federal Republic of Germany applies.

(5) Should individual provisions of this agreement be or become invalid or unenforceable, the validity of the remaining provisions remains unaffected. The Parties shall replace the invalid or unenforceable provision with a valid provision that comes closest to the economic purpose of the invalid provision.

List of annexes to the DPA

  • Annex 4-C: List of approved subcontractors (name, address, activity, data categories, place of processing, transfer basis)
  • Annex 4-D: Technical and organisational measures (TOMs) pursuant to Art. 32 GDPR

Conclusion of this agreement

This Data Processing Agreement is concluded without a handwritten signature: the Controller offers its conclusion by placing its order; acceptance is effected by the Processor's order confirmation at the same time as the Main Agreement (Clauses 10.4 and 10.6 of the GTC). Conclusion in electronic format is sufficient (Art. 28 para. 9 GDPR). The Controller's confirmation under Clause 10.6 of the GTC, the accepted version of this agreement and the times of the order and of the acceptance are logged in the customer account in a manner suitable as evidence and are confirmed to the Controller in text form.

Annex 4-C: Approved subcontractors

The following subcontractors are approved by the Controller upon conclusion of this agreement:

Subcontractor (name, registered office) Activity and data categories Place of processing Transfer basis (Chapter V GDPR)
elunos GmbH, Neue Mainzer Straße 31, 60311 Frankfurt am Main Operation, set-up and support of the platform by the personnel deployed by it, and procurement of the upstream services of the subcontractors listed below for as long as their contracts are in the name of elunos GmbH; all data categories specified in Section 2 Frankfurt am Main; access exclusively from within the European Union EU processing, no third country transfer; processing on behalf pursuant to Art. 28 para. 4 GDPR; commitment to professional secrecy given at supplier level, to the extent that the Undertaking under Annex 5 applies to the Controller (Clause 24.4 of the GTC)
ElevenLabs Inc., New York, USA Speech synthesis (TTS/STT) and conversational AI platform; audio data, transcripts, call metadata EU Data Residency (isolated EU environment); zero retention mode can be activated per agent, and is permanently activated for all agents in the case of Professional Secrecy Holders (Annex 5) (Annex 4-D Clause 5); residual processing in the USA possible (support, content moderation) EU-US Data Privacy Framework (actively certified), additionally SCCs 2021/914 in the DPA; Section 203 commitment at supplier level, to the extent that the Undertaking under Annex 5 applies to the Controller (Clause 24.4 of the GTC)
LLM models (including Anthropic Claude and Google Gemini via Google Vertex AI, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; OpenAI GPT; models hosted by ElevenLabs itself such as Qwen), provided as an integrated component of the ElevenLabs platform. Where zero retention mode is activated (mandatory for the processing of Art. 9 data or professional secrets under Section 203 StGB), only Claude and Gemini models are available — for information purposes: sub-sub-processors of ElevenLabs, approval via the ElevenLabs row and its DPA/SCC chain LLM inference for conducting the conversation; transcripts EU environment of the ElevenLabs platform; EU location commitment for the Vertex inference confirmed in writing by ElevenLabs (e-mail dated 16.06.2026): Google Cloud Platform, region Belgium; under zero retention mode exclusively Vertex AI in Belgium, no routing of inputs and outputs out of the EU. Covered by the DPA and the SCC chain of ElevenLabs (see note on sub-sub-processors)
Functional Software, Inc. (Sentry), San Francisco, USA Error monitoring; technical log data (with PII scrubbing) Event data: EU region Frankfurt; account data: USA EU region for event data; otherwise EU-US Data Privacy Framework (actively certified) and SCCs
Amazon Web Services EMEA SARL, Luxembourg Hosting of the platform infrastructure; all data categories specified in Section 2 Frankfurt (eu-central-1) EU processing; SCCs in the AWS DPA as a fallback
Cloudflare, Inc., San Francisco, USA Content delivery network, reverse proxy and DDoS protection of the platform (TLS termination); IP addresses, connection data, content data in transit passed through EU edge locations prioritised; processing in the USA possible EU-US Data Privacy Framework (actively certified), additionally SCCs

Note: For subcontractors with processing outside the EU/EEA, the legal basis under Chapter V GDPR must be stated (SCCs, adequacy decision, additional measures). Sub-processors of the above subcontractors (for instance the sub-processors engaged by ElevenLabs) are set out in the respective Data Processing Agreements and sub-processor lists of the providers and are not repeated here; the Processor shall provide the Controller with a consolidated overview on request. The row relating to elunos GmbH concerns the transitional phase until the contracts for the upstream services of the other listed subcontractors have been transferred to the Processor. Its removal without replacement shortens the processing chain, is neither an addition nor a replacement of a subcontractor within the meaning of Section 6 para. 3 of this agreement and therefore requires no approval; the Processor shall notify the Controller of it in text form.

Annex 4-D: Technical and organisational measures (TOMs)

This Annex describes the technical and organisational measures taken by the Processor pursuant to Art. 32 GDPR.

1. Confidentiality (Art. 32 para. 1 lit. b GDPR)

Physical access control: Processing takes place exclusively in data centres of the hosting providers used (in particular AWS, region Frankfurt eu-central-1); the Processor does not operate any data processing facilities of its own containing personal data. Physical access control (electronic access controls, security personnel, video surveillance, visitor management) is ensured by the hosting providers and is evidenced by their certifications (including ISO 27001).

System access control: Access to IT systems is granted exclusively after authentication via individual user accounts with strong passwords and multi-factor authentication. There is no standing external administrative access: operation is containerised without permanent remote administrative access (no standing SSH access); privileged access is granted exclusively for a limited time and expires automatically (just-in-time), with multi-factor authentication, and is logged without gaps. Inactive sessions are terminated automatically after 15 minutes.

Data access control: Authorisation concept based on the principle of least privilege (need-to-know). Access to personal data is logged. Authorisations are reviewed regularly, at least annually.

Separation control: Tenant separation is effected logically by means of unique tenant IDs and by organisationally separate databases or database schemas. A commingling of data of different controllers is technically excluded.

Pseudonymisation: To the extent not required for the purpose of the processing, personal data are processed in pseudonymised form.

2. Integrity (Art. 32 para. 1 lit. b GDPR)

Transfer control: Personal data are transmitted exclusively via encrypted connections (TLS 1.2 or higher). Data carriers are encrypted before dispatch. Data at rest (object storage, databases, volumes) are encrypted with a key of the hosting provider's key management service that is managed by the Processor. Control over the key lies with the Processor; the operations and deploy role has no decryption right, and the key policy protects the key against deletion. The hosting provider is therefore unable to obtain knowledge of content at rest. A key held or controlled by the Controller itself is not part of the service.

Input control: Changes to personal data are logged (who changed what and when?). The logs are retained for at least 12 months.

3. Availability and resilience (Art. 32 para. 1 lit. b and c GDPR)

Availability control: Redundant design of the essential infrastructure components, regular backups on a daily basis, retention of the backups for 30 days. Uninterruptible power supply (UPS) and emergency power supply are ensured by the data centres of the hosting providers.

Rapid recoverability: Emergency plans with defined recovery time objectives (RTO) and recovery point objectives (RPO). The recovery procedures are reviewed regularly.

4. Procedures for regular review (Art. 32 para. 1 lit. d GDPR)

Data protection management: Appointment of an internal or external data protection officer. Regular training of employees on data protection. Record of processing activities pursuant to Art. 30 GDPR.

Incident response management: Established processes for the detection, assessment and notification of personal data breaches. Notification to the Controller within 24 hours of becoming aware.

Order control: Written instructions are documented. Subcontractors are reviewed for compliance with the data protection requirements before being engaged.

External audits/certifications: The Processor currently holds no certifications of its own; the material sub-processors are externally audited (Amazon Web Services, among others, in accordance with ISO 27001, ElevenLabs with an annual independent audit in accordance with SOC 2 Type II pursuant to Services Agreement clause 1.8).

5. Special measures for the voice AI service

Zero retention mode: On the speech synthesis and conversational AI platform (ElevenLabs), zero retention mode can be activated per agent; it is activated to the extent that special categories of personal data (Art. 9 GDPR) or professional secrets (Section 203 StGB) are processed. If the Controller is a Professional Secrecy Holder and the Undertaking under Annex 5 applies to it (Clause 24.4 of the GTC), zero retention mode is permanently and unconditionally activated for all agents of the Controller; in this case, deactivation requires the prior consent of the Controller in text form. Where zero retention mode is activated, conversation content (inputs and outputs) is neither stored nor logged at ElevenLabs and is not passed on to its sub-processors; the sole exception is transient processing for the purpose of handling the respective request; this comprises the hosting service providers of ElevenLabs and the LLM inference pursuant to Annex 4-C. The LLM inference is thus part of the permitted transient processing and not an exception to the commitment of non-storage. If the Processor finds that an activated zero retention mode is not effective or not fully effective, it shall inform the Controller without undue delay in text form. Liability is governed by Section 10 of this agreement.

Distinction from storage in the Processor's infrastructure (customer portal): The storage of call recordings (audio), transcripts and call metadata intended for the customer portal (Annex 1 Clause 2, Annex 3 Clause 2) takes place exclusively in the infrastructure operated by the Processor in the AWS region Frankfurt (eu-central-1), encrypted in accordance with Clause 2 of this Annex. The basis for this is the automated handover of the call data, including the audio recording, to this infrastructure immediately after the end of the call. The audio recording and the transcript are conversation content; the same storage period applies to them as to the call metadata. To the extent that zero retention mode is activated, it concerns solely the storage at ElevenLabs and its sub-processors; in that case, no retention at ElevenLabs going beyond the handling of the request takes place. To the extent that the platform does not technically provide the handover of individual conversation content, only call metadata are available in the customer portal for the calls concerned; the Processor shall inform the Controller of this without undue delay in text form and shall work towards restoring the handover. A restriction of the portal resulting from this does not constitute a defect of the service.

Consent to recording: To the extent that calls are recorded, the agent identifies itself as an AI system at the beginning of the call, points out the recording and asks the caller for his or her consent. If the caller does not expressly declare his or her consent, the call is not continued as a recorded call; the agent switches over to the alternative agreed with the Controller. Call data without declared consent are discarded upon receipt by the Processor and are not transferred to the customer portal. The time and result of the declaration as well as the version of the notice text used are logged separately from the call data and retained for five years (proof under Art. 7 para. 1 GDPR); this log contains no conversation content and no telephone numbers.

Configuration protection: Zero retention mode does not cover the permanently stored agent configuration (system prompts, knowledge bases, sample dialogues). Therefore, no identifying data of data subjects and no special categories of personal data (Art. 9 GDPR) are entered into the agent configuration. Compliance is ensured by internal work instructions and the Undertaking of the employees; if the Controller carries out configurations itself, its duty to cooperate under Annex 1 Clause 6 applies.

EU data storage: For the conversational AI platform, EU Data Residency (isolated EU environment) is activated; the platform is hosted in the AWS region Frankfurt (eu-central-1). Error monitoring uses the EU region of the provider with PII scrubbing activated.

Erasure concept: Erasure and retention periods are documented in an erasure concept based on DIN 66398. Call recordings, transcripts and call metadata are erased automatically after expiry of the agreed storage period; billing-relevant metadata only after expiry of statutory retention obligations (Section 257 of the German Commercial Code (Handelsgesetzbuch, HGB), Section 147 of the German Fiscal Code (Abgabenordnung, AO)). Only the time and duration of the call, the consumption in credits, the agent used and the connected telephone number of the Controller, as well as the invoices created from these, are billing-relevant. The caller's telephone number is not among them; it is erased together with the other call metadata after expiry of the agreed storage period. Conversation content, transcripts and audio recordings are not billing-relevant.

Master data of the Users of the Controller (Section 2 para. 3 of this agreement) are processed for the duration of the contractual relationship because they underpin access to the customer portal; the storage period for call recordings, transcripts and call metadata does not apply to them. After termination of the Main Agreement, they are handed over or erased in accordance with Section 9 of this agreement. If the Controller deletes a User beforehand, that User's account ceases to exist upon the deletion; entries relevant for billing and logging purposes remain in place in accordance with the statutory periods.

Chain of confidentiality under Section 203 StGB (to the extent that the Controller is a Professional Secrecy Holder and the Undertaking under Annex 5 applies to it, Clause 24.4 of the GTC): Subcontractors that have plain-text access to Protected Data for the purpose of providing the services (elunos GmbH as the operating company and ElevenLabs as the speech and conversational AI platform) are formally bound to secrecy as Further Assisting Persons (supplier level; in the case of elunos GmbH by a separate Undertaking under Section 203 para. 4 sentence 2 no. 2 StGB, which in turn includes the commitment of the personnel deployed by it at the internal level; in the case of ElevenLabs via Order Form 5.H/Professional Secrecy in conjunction with the zero retention mode permanently activated for Professional Secrecy Holders). Where zero retention mode is activated, no stored conversation content arises at ElevenLabs of which its sub-processors could obtain knowledge. Subcontractors without the possibility of obtaining knowledge of protected content (in particular the hosting provider Amazon Web Services and the CDN and reverse proxy service Cloudflare) are not assisting persons relevant for disclosure purposes: data at rest are encrypted in accordance with Clause 2 of this Annex and are without standing access by the hosting provider; the web and portal traffic runs via Cloudflare, not the speech processing (the latter takes place via ElevenLabs). A separate Section 203 commitment of these providers is not required for lack of the possibility of obtaining knowledge. All employees are bound to data secrecy and, where applicable, to professional secrecy (internal level).

The measures described here constitute the minimum standard and may be further developed by the Processor in line with the state of the art, provided that the agreed level of protection is not undercut.