Legal
Data Processing Agreement (Art. 28 GDPR)
under Article 28 of the General Data Protection Regulation (GDPR)
Where the Free Pilot Addendum applies, the Customer accepts this agreement in text form (for example by email) instead of in the dashboard. Acceptance takes effect when we confirm the account in text form, and we record date, accepting person and version. The dashboard acceptance described below applies to future paid accounts.
Version 1.1 · Last updated: 29 September 2026
Between the customer that accepts this agreement in the System1 Models dashboard or, for a free named pilot account under the Free Pilot Addendum, in text form ("Controller" or "Customer")
and productivity-boost.com Betriebs UG (haftungsbeschränkt) & Co. KG, Reichenberger Str. 2, 94036 Passau, Germany, Amtsgericht Passau HRA 12725, represented by its general partner productivity-boost.com UG (haftungsbeschränkt), itself represented by its managing director Florian Standhartinger ("Processor" or "we").
The Customer accepts this agreement electronically in the dashboard; acceptance is recorded with date, version and the accepting user. For a free named pilot account under the Free Pilot Addendum, the Customer instead accepts this agreement in text form (for example by email), in the version we name in our request for acceptance; acceptance takes effect when we confirm the account in text form, and we record the date, the accepting person and the version. Acceptance in electronic or text form satisfies Art. 28(9) GDPR. A signed PDF copy is available on request. A German version exists; if the two versions differ, the German version prevails.
1. Subject matter, scope and duration
1.1 This agreement governs the processing of personal data by the Processor on behalf of the Controller in connection with the System1 Models Service, in both the EU tier and the Global tier, under the Terms of Service ("Main Contract").
1.2 It does not apply to account, billing and usage data that the Processor processes as a controller for its own purposes (see the Privacy Policy).
1.3 The subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
1.4 This agreement runs for as long as the Processor processes personal data for the Controller under the Main Contract. It ends automatically when the Main Contract ends and all personal data have been deleted in accordance with section 11.
2. Instructions
2.1 The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by Union or Member State law; in that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest (Art. 28(3)(a) GDPR).
2.2 The Main Contract, this agreement and the Controller's use and configuration of the Service (for example, choice of tier, model and retention setting through the API or dashboard) constitute the Controller's complete documented instructions at the time of conclusion. Further instructions must be given in text form to info@productivity-boost.com. Instructions that go beyond the agreed scope of the Service are handled as a change request; the Processor may charge reasonable additional costs agreed in advance.
2.3 The Processor informs the Controller without undue delay if it believes that an instruction infringes the GDPR or other Union or Member State data protection provisions. The Processor may suspend carrying out the instruction until the Controller confirms or changes it.
3. Obligations of the Controller
3.1 The Controller is responsible for the lawfulness of the processing, including the legal basis, the information of data subjects and the assessment of whether its use case requires a data protection impact assessment or falls under Art. 22 GDPR or the EU AI Act.
3.2 The Controller sends personal data only to the extent necessary for its purpose. Special categories of personal data (Art. 9 GDPR) and data relating to criminal convictions (Art. 10 GDPR) may only be sent if the Controller has a legal basis for it and has assessed that the measures in Annex 2 are appropriate.
3.3 The Controller informs the Processor without undue delay if it finds errors or irregularities in the processing.
4. Confidentiality
The Processor ensures that all persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR), and that they process the data only on the Controller's instructions.
5. Security of processing
5.1 The Processor takes all measures required under Art. 32 GDPR. The technical and organisational measures (TOMs) in effect are described in Annex 2.
5.2 The TOMs are subject to technical progress. The Processor may implement alternative adequate measures, provided the level of security is not reduced. Material changes are documented and announced on the Security page.
6. Sub-processors
6.1 The Controller gives the Processor general written authorisation to engage sub-processors (Art. 28(2) GDPR). The sub-processors engaged when this agreement is concluded are listed in Annex 3 and at /legal/subprocessors; the Controller approves them.
6.2 The Processor informs the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance by email to the account's email address and by updating /legal/subprocessors. The Controller may object in text form within this period for reasonable data protection grounds. If the Processor cannot reasonably accommodate the objection, either party may terminate the affected part of the Main Contract with effect from the date of the change; unused prepaid credit is refunded. In urgent cases (for example, the sudden failure of a sub-processor), the notice period may be shortened; the objection right remains.
6.3 The Processor imposes on each sub-processor, by contract, the same data protection obligations as set out in this agreement, in particular sufficient guarantees for appropriate technical and organisational measures (Art. 28(4) GDPR). The Processor remains fully liable to the Controller for the performance of the sub-processor's obligations.
6.4 The Processor engages only sub-processors that process the personal data within the European Union, for both tiers. Processing of a Global-tier API key's data outside the European Union requires, in addition to the notice under section 6.2, the Controller's explicit opt-in for that key and compliance with section 7.
6.5 Ancillary services that do not involve access to the Controller's personal data (for example telecommunications, postal services, or the maintenance of hardware without data access) are not sub-processing.
7. Transfers to third countries
The Processor processes the Controller's personal data only within the European Union. A transfer to a third country requires a prior documented instruction from the Controller (for the Global tier: the explicit opt-in under section 6.4) and compliance with Chapter V GDPR.
8. Support with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR (Art. 28(3)(e) GDPR). Because content is not stored (Annex 1, section 5), there is normally no stored content to access, correct or delete. If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay and does not answer it itself, unless instructed.
9. Support with Articles 32 to 36 GDPR; personal data breaches
9.1 The Processor assists the Controller in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to it (Art. 28(3)(f) GDPR). This includes providing information needed for a data protection impact assessment and prior consultation.
9.2 The Processor notifies the Controller without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach affecting the Controller's data. The notification contains, as far as available: a description of the nature of the breach including the categories and approximate number of data subjects and records concerned; the name and contact details of a contact point; the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects. Information that is not yet available is provided in phases without undue further delay.
9.3 The Processor takes the necessary measures to secure the data and mitigate possible adverse consequences and documents the breach.
9.4 The Processor may charge reasonable costs for support under sections 8 and 9.1 only if the support goes beyond what is needed to meet its own obligations and the need for it was not caused by a breach on the Processor's part.
10. Audits and information
10.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller (Art. 28(3)(h) GDPR).
10.2 The Processor may first provide current documentation, including this agreement, the TOMs, the sub-processor list and, where available, certificates or audit reports of its sub-processors (for example ISO/IEC 27001 certificates of the data centre operators). If this documentation is not sufficient to demonstrate compliance, the Controller may carry out inspections, including on-site. The Controller announces inspections with reasonable notice, normally 14 days, or without delay where there is a specific cause such as a personal data breach or an inquiry by a supervisory authority. Inspections take place during normal business hours and avoid unnecessary disruption of operations. The Controller's auditors must be bound to confidentiality; the Processor may object to an auditor who is its direct competitor, in which case the Controller appoints another auditor. The Processor may charge reasonable, proven costs for its support with on-site inspections if the Controller conducts more than one per calendar year without specific cause, unless an inspection reveals a material breach by the Processor.
10.3 Rights of supervisory authorities remain unaffected.
11. Deletion and return at the end of processing
11.1 Content sent to the Service is deleted as soon as the response has been returned (Annex 1, section 5). Idempotency records (Annex 1, section 5) are deleted automatically after 24 hours. No content therefore remains to be returned or deleted at the end of the Main Contract.
11.2 Deletion is confirmed in text form on request.
12. Liability
Liability towards data subjects is governed by Art. 82 GDPR. In the relationship between the parties, the liability provisions of the Main Contract apply, unless mandatory law provides otherwise.
13. Final provisions
13.1 In the event of any conflict, this agreement takes precedence over the Main Contract as regards the processing of personal data.
13.2 Changes to this agreement are made in the same way as changes to the Terms of Service (section 14 of the Terms). Changes to the sub-processor list follow section 6.2. Changes to the TOMs follow section 5.2.
13.3 If a provision of this agreement is invalid, the rest remains valid. German law applies. The place of jurisdiction is determined by the Main Contract.
Annex 1 — Details of the processing
1. Subject matter and purpose: typed-decision inference: the Controller sends a state (text and, where supported, images) and questions to the Service (EU tier or Global tier); a machine-learning model computes probabilities for the answer options and returns them to the Controller. The purpose is solely to provide this result to the Controller.
2. Nature of processing: receipt over an encrypted connection, temporary storage in the working memory of the API gateway and GPU servers, computation by the model, return of the result, deletion. Collection of metadata without content for billing and security (see the Privacy Policy).
3. Types of personal data: determined by the Controller. Typically: any personal data contained in the texts or images the Controller submits, for example names, contact details, contents of messages, tickets, documents or transactions, descriptions of behaviour or preferences, and images that may show people. Special categories of personal data only under section 3.2 of this agreement.
4. Categories of data subjects: determined by the Controller. Typically: the Controller's customers, users, prospects, employees, contractors and business partners, and other people mentioned in the submitted content.
5. Retention of content: content (states, questions, images) and results are not written to logs, databases, disk or any other persistent storage (zero data retention). They are held in volatile working memory while the request is processed. For performance, the inference server may keep intermediate values of recent requests in GPU memory (prefix cache) until they are overwritten by later requests, and at the latest until the server process restarts; this cache is never persisted, is isolated per model instance and cannot be read through the API. If the Controller sends an optional Idempotency-Key, the Processor keeps for 24 hours a keyed (HMAC) digest of the request body, the request ID, the processing status and the usage receipt, without content, to prevent duplicate processing and charging. Metadata without content (request ID, time, key ID, model, tier, token count, number of decisions, latency, status) is processed by the Processor as a controller for billing and security.
6. Place of processing: exclusively within the European Union, for both tiers: API gateway on EU-hosted infrastructure (Hetzner); GPU inference in Finland (Verda).
7. Contact for data protection: info@productivity-boost.com.
8. Duration of the processing: for the duration of the Main Contract, until deletion under section 11 (see section 1.4).
Annex 2 — Technical and organisational measures (Art. 32 GDPR)
The measures below apply to both tiers. They are also published on the Security page.
2.1 Pseudonymisation and encryption (Art. 32(1)(a))
- All connections to the API, dashboard and MCP server use TLS 1.2 or higher; plain HTTP is redirected or refused. HSTS is enabled.
- Connections between the API gateway and GPU servers are encrypted (TLS or WireGuard tunnel) and authenticated.
- API keys are stored only as salted cryptographic hashes; the full key is shown once.
- Database backups are encrypted.
- Content is not stored, so there is no stored content to pseudonymise; usage records carry only IDs, never content.
2.2 Confidentiality (Art. 32(1)(b))
- Physical access control: servers run in ISO/IEC 27001-certified data centres of Hetzner and Verda with access control, video surveillance and security staff. We operate no own server rooms.
- System access control: administrative access only through SSH with public keys or through the provider's console with two-factor authentication; no password logins; firewalls allow only the required ports.
- Data access control: role-based access; production access is limited to the managing director and named administrators on a need-to-know basis; every customer's requests are isolated by API key and account; no shared state between requests other than the model weights.
- Separation: EU-tier requests have priority on the inference servers; Global-tier requests share the same EU infrastructure at lower priority and may briefly occupy at most one slot of the contracted base capacity while no EU-tier request is waiting, with at least one slot kept reserved for EU-tier traffic; customer data is logically separated by account ID and API key; development and test systems use no customer data.
- Minimal logging: logs record only IDs, sizes, latency, model, tier and status — never request or response content.
2.3 Integrity (Art. 32(1)(b))
- Transfer control: encryption in transit (see 2.1); no removable media.
- Input control: administrative actions and changes to deployments are logged; deployments are made from version-controlled, reviewed code.
- Container images are pinned by digest and model weights by revision and SHA-256 checksum.
2.4 Availability and resilience (Art. 32(1)(b) and (c))
- A permanently running base GPU node in the EU.
- Health checks and automatic restart of failed services.
- Daily encrypted database backups (account and usage data; no content), stored in the EU.
- Uninterruptible power supply, redundant network and fire protection in the data centres of our providers.
- Rate limits and abuse protection per API key.
2.5 Regular testing and evaluation (Art. 32(1)(d))
- Security review of our own code before each major release; dependency and image vulnerability scanning.
- Review of these measures at least once a year and after every security incident.
- Documented incident process: detection, containment, assessment, notification of affected controllers within 48 hours (section 9.2 of the DPA), follow-up.
2.6 Organisational measures
- Everyone with access is bound to confidentiality and instructed in data protection.
- We require Art. 28 GDPR agreements with sub-processors before opening customer-data processing.
- Secrets are kept in protected configuration stores, never in source code or logs.
Annex 3 — Approved sub-processors (both tiers)
| Sub-processor | Service | Location of processing | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Hosting of the websites (including the dashboard), API gateway and database | EU | Provider's standard Art. 28 GDPR agreement, required before customer-data processing |
| DataCrunch Oy (trading as Verda), Helsinki, Finland | GPU servers for model inference | Finland (EU) | Data processing terms under Art. 28 GDPR |
The following providers do not process API content but process account-related data that we handle as a controller (see the Privacy Policy): Stripe Payments Europe, Ltd. (payments), Scaleway SAS (service emails). No other provider processes API content. Any future processing of Global-tier traffic outside the EU requires an update of this Annex under section 6.2 and the Controller's opt-in under section 6.4.