← AI Safety Check

DATA PROCESSING AGREEMENT

Auftragsverarbeitungsvertrag (AVV / DPA)

When your company uses AI Safety Check, you decide who takes the training and we store the resulting records. That makes your company the controller and Aisthetic Lab the processor under Article 28 GDPR. This page sets out the terms of that processing. It is a template prepared for signature — request the signable version and we will send it to you. It is not legal advice.

1. Parties

Controller: your company (as registered in the service). Processor: Aisthetic Lab, Walther-Rathenau-Straße 1, 63486 Bruchköbel, Germany.

2. Subject matter, nature and purpose

Provision of an online AI-safety training, testing and documentation service: hosting the modules, recording who passed each module and with which score, issuing completion records with record IDs, and storing the tool registry, incident log and audit package that the company maintains in the service.

3. Categories of personal data

Employee name, work email address, role in the service (owner/admin), training progress, module test scores, attempts, timestamps, completion records and completion record identifiers. Optionally, names or departments entered as incident reporters, where the company chooses not to report anonymously.

4. Categories of data subjects

Employees, contractors and interns of the controller who are invited to use the training or who are recorded in the registry and incident log.

5. Duration

For the term of the service agreement and until deletion of the records in line with section 8 below.

6. Processor obligations

  • • Process personal data only on the controller's documented instructions, including for transfers to third countries.
  • • Ensure that persons authorised to process the data are bound to confidentiality.
  • • Implement appropriate technical and organisational measures (section 7).
  • • Assist the controller in responding to data subject requests and in meeting its GDPR obligations.
  • • Notify the controller without undue delay after becoming aware of a personal data breach.
  • • Delete or return personal data at the end of the provision of services, subject to legal retention duties.

7. Technical and organisational measures

Data is stored in the European Union on the processor's hosting platform; access is protected by password hashing and session authentication; employee accounts are scoped to their own company, so one company cannot see another's training records, tools or incidents.

8. Sub-processors and deletion

Sub-processors: (a) Higgsfield — the platform on which the service runs, our contractual counterparty for hosting and database (Cloudflare Workers with D1, EU region), with Cloudflare as its infrastructure provider; (b) Amazon Web Services — CloudFront content delivery for media and images; (c) Namecheap Private Email — the mailbox service hosting the contact address, which processes correspondence sent to us. The service currently sends no automated emails to invited employees; if a transactional email service is added, it will be listed here as a sub-processor before it goes live. Our own agreements with each upstream provider are in place and copies are available on request. The controller may object to changes to sub-processors. On termination, the controller may export its records (audit package, completion records) and request deletion of its company data.

9. Audit rights and controlling law

The controller may request information necessary to demonstrate compliance and, where required, conduct an audit during business hours with reasonable notice. German law applies; the mandatory provisions of the GDPR and the place-of-jurisdiction clause in the AGB apply.

10. How to conclude it

This AVV/DPA is concluded electronically when a company registers: the registration form contains an explicit acceptance step, the data processing agreement is thereby agreed between the controller and the processor, and the acceptance is recorded with a timestamp in the service (Art. 28(9) GDPR permits electronic form). There is therefore no period in which employee data is processed without an agreement. A signable PDF version remains available on request — write to the contact in the Impressum.

STATUS: TEMPLATE FOR SIGNATURE · LAST UPDATED 2026-09-29