DATA PROCESSING AGREEMENT
When your company uses AI Safety Check, you decide who takes the training and we store the resulting records. That makes your company the controller and Aisthetic Lab the processor under Article 28 GDPR. This page sets out the terms of that processing. It is a template prepared for signature — request the signable version and we will send it to you. It is not legal advice.
Controller: your company (as registered in the service). Processor: Aisthetic Lab, Walther-Rathenau-Straße 1, 63486 Bruchköbel, Germany.
Provision of an online AI-safety training, testing and documentation service: hosting the modules, recording who passed each module and with which score, issuing completion records with record IDs, and storing the tool registry, incident log and audit package that the company maintains in the service.
Employee name, work email address, role in the service (owner/admin), training progress, module test scores, attempts, timestamps, completion records and completion record identifiers. Optionally, names or departments entered as incident reporters, where the company chooses not to report anonymously.
Employees, contractors and interns of the controller who are invited to use the training or who are recorded in the registry and incident log.
For the term of the service agreement and until deletion of the records in line with section 8 below.
Data is stored in the European Union on the processor's hosting platform; access is protected by password hashing and session authentication; employee accounts are scoped to their own company, so one company cannot see another's training records, tools or incidents.
Sub-processors: (a) Higgsfield — the platform on which the service runs, our contractual counterparty for hosting and database (Cloudflare Workers with D1, EU region), with Cloudflare as its infrastructure provider; (b) Amazon Web Services — CloudFront content delivery for media and images; (c) Namecheap Private Email — the mailbox service hosting the contact address, which processes correspondence sent to us. The service currently sends no automated emails to invited employees; if a transactional email service is added, it will be listed here as a sub-processor before it goes live. Our own agreements with each upstream provider are in place and copies are available on request. The controller may object to changes to sub-processors. On termination, the controller may export its records (audit package, completion records) and request deletion of its company data.
The controller may request information necessary to demonstrate compliance and, where required, conduct an audit during business hours with reasonable notice. German law applies; the mandatory provisions of the GDPR and the place-of-jurisdiction clause in the AGB apply.
This AVV/DPA is concluded electronically when a company registers: the registration form contains an explicit acceptance step, the data processing agreement is thereby agreed between the controller and the processor, and the acceptance is recorded with a timestamp in the service (Art. 28(9) GDPR permits electronic form). There is therefore no period in which employee data is processed without an agreement. A signable PDF version remains available on request — write to the contact in the Impressum.
STATUS: TEMPLATE FOR SIGNATURE · LAST UPDATED 2026-09-29