KlarComply provides the Customer with the services described in the subscription agreement (compliance dashboard, online training, evidence management under Regulation (EU) 2024/1689). In doing so, KlarComply processes personal data on behalf of the Customer. This agreement applies for the duration of the subscription and ends upon its termination; clause 7 (deletion) remains unaffected.
Storage, organisation and evaluation of data of the Customer's employees for the purposes of training management, certificate management, evidence management (AI inventory, policy details, acknowledgment logs) and access management. Details: Annex 1.
KlarComply processes the data exclusively on the Customer's documented instructions (Art. 28(3)(a) GDPR); the Customer's use of the platform features constitutes an instruction. If KlarComply considers an instruction unlawful, it shall inform the Customer without undue delay and may suspend execution.
The Customer grants general authorisation for the use of the sub-processors listed in Annex 3. KlarComply gives notice of intended changes; the Customer may object within 14 days on substantial data-protection grounds. Agreements pursuant to Art. 28 GDPR are in place with all sub-processors.
KlarComply assists the Customer, to the extent reasonable, in responding to data-subject requests (Art. 12–23), in securing the processing, in data protection impact assessments and in notification duties (Art. 32–36). KlarComply notifies the Customer of personal data breaches affecting data processed on the Customer's behalf without undue delay, at the latest within 24 hours of becoming aware. The notification contains the information required by Art. 33(3) GDPR as far as it is available; where it is not available in full, it may be provided in phases pursuant to Art. 33(4) GDPR. The notification serves to support the Customer in its own notification duty and does not constitute an admission of fault.
After termination of the subscription, KlarComply deletes all personal data processed on behalf of the Customer within 30 days, unless a statutory retention duty applies. The Customer may back up its data beforehand via the dashboard's export/print functions. Issued certificates remain stored for public verification (legitimate interest of the certificate holders); the Customer may request their deletion.
KlarComply provides the Customer with the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and enables audits — upon notice and at most once per year, except where there is specific cause. Evidence may be provided through current attestations/certifications of the sub-processors (e.g. SOC 2, ISO 27001).
Processing takes place in data centres in the EU (Frankfurt region, Germany). Where sub-processors established outside the EU are used (Annex 3), any transfer is based on EU standard contractual clauses or an adequacy decision (e.g. the EU-US Data Privacy Framework).
The law applicable to the subscription agreement also applies here. In case of conflict, this agreement prevails in data-protection matters. Should any provision be invalid, the remaining provisions remain in force.
| Data subjects | Employees, contact persons and, where applicable, external staff of the Customer |
|---|---|
| Data categories | Name, business email address, role; training progress and results (per cent); certificate data (name, company, date, check-ID); acknowledgment logs (who, what, when); details maintained by the Customer (AI inventory, contact person, rules) |
| No processing of | special categories under Art. 9 GDPR; such data must not be entered into the platform |
| Nature of processing | Collection, storage, organisation, evaluation and deletion in the course of operating the platform. Additionally, on the Customer's separate request: manual review and expert assessment of the compliance documentation maintained by the Customer, carried out by trained KlarComply staff (“expert check”). |
This processing takes place only if the Customer expressly requests it in its dashboard. The request is stored with its time and the requesting person and constitutes a documented instruction within the meaning of Art. 29 GDPR. Without such a request, no manual inspection takes place.
| Subject of the review | Exclusively company-related information: AI inventory (tools, providers, purposes of use, risk classes including reasoning), internal AI policy, labelling rule under Art. 50, blocked uses, details of the contact person and the question submitted by the Customer |
|---|---|
| Expressly not covered | Employee lists, training status and examination results of individual persons, certificate data, acknowledgment logs, billing and payment data |
| Purpose | Expert feedback to the Customer in the form of a written report with prioritised recommended measures, and answering follow-up questions on it for 30 days |
| Persons carrying out the review | KlarComply staff who have previously completed the internal specialist training and signed a confidentiality undertaking pursuant to Art. 28(3)(b) GDPR. No sub-processors are used for this. |
| Logging | Every read access in the course of a review order is logged with person, time and the Customer concerned (accountability under Art. 5(2) GDPR). The Customer can view the review orders stored for it in its dashboard. |
| Retention | Review order and report are stored for the duration of the contractual relationship and thereafter handled in accordance with the deletion clause (clause 7). Access logs are retained for 24 months. |
| Provider | Purpose | Registered office / region |
|---|---|---|
| Supabase Inc. | Database, authentication, server functions | USA · data stored in the EU (AWS Frankfurt) · SCC/DPF |
| Cloudflare Inc. | Website hosting, CDN, security | USA · EU delivery · SCC/DPF |
| Google Ireland Ltd. | Google Workspace — sending and receiving emails to users (sign-in links, course and certificate notifications, cancellation confirmations) | Ireland (EU) · parent company USA · SCC/DPF |
| MailerLite (UAB) | Newsletter delivery to prospects (contact email only) — not currently in use | Lithuania (EU) |
Note: payment data is processed by Stripe Payments Europe Ltd. as an independent controller — it is not covered by this data processing agreement.
| Version | As of | Change |
|---|---|---|
| 1.3 | September 2026 | Designation of the processor: “Patrick de Kathen (KlarComply)” instead of “(sole proprietorship)” — the legal form will only be stated once registration is complete. No substantive change to the obligations. |
| 1.2 | August 2026 | Clause 6: fixed notification period of 24 hours for the initial notification of a personal data breach, with express provision for phased information pursuant to Art. 33(4) GDPR. Previously it only said “without undue delay” without a figure. |
| 1.1 | August 2026 | Annex 3: Google Ireland Ltd. (Google Workspace) added as a sub-processor for email delivery — it was in use but not listed. MailerLite marked as not currently in use. |
| 1.0 | July 2026 | Initial version. |
Existing customers are informed of changes to the sub-processors in accordance with clause 5; the right to object is 14 days. The version accepted at the time of contract conclusion remains authoritative until the Customer accepts a new one.
This agreement is concluded electronically (Art. 28(9) GDPR). Acceptance takes place in the KlarComply dashboard by the Customer's authorised signatory; time, name and contract version are logged verifiably. The binding text is the German version 1.3 (see klarcomply.com/avv).
This document forms part of the subscription agreement.