KlarComply
KlarComply
Quick check
DEENNL
KlarComply
German version (binding) Nederlands

Data Processing Agreement

pursuant to Art. 28 Regulation (EU) 2016/679 (GDPR) · version 1.3 · as of September 2026
English translation for information purposes. Legally binding is the German version 1.3 published at klarcomply.com/avv, which is accepted electronically when the company account is created.
Controller (“Customer”)
[Company name — added when the subscription is taken out]
represented by the authorised signatory
Processor (“KlarComply”)
Patrick de Kathen (KlarComply)
10 Xagħra Heights, Xagħra, Gozo, Malta (EU)
kontakt@klarcomply.com

1. Subject matter and duration

KlarComply provides the Customer with the services described in the subscription agreement (compliance dashboard, online training, evidence management under Regulation (EU) 2024/1689). In doing so, KlarComply processes personal data on behalf of the Customer. This agreement applies for the duration of the subscription and ends upon its termination; clause 7 (deletion) remains unaffected.

2. Nature, purpose and scope of processing

Storage, organisation and evaluation of data of the Customer's employees for the purposes of training management, certificate management, evidence management (AI inventory, policy details, acknowledgment logs) and access management. Details: Annex 1.

3. Right of instruction

KlarComply processes the data exclusively on the Customer's documented instructions (Art. 28(3)(a) GDPR); the Customer's use of the platform features constitutes an instruction. If KlarComply considers an instruction unlawful, it shall inform the Customer without undue delay and may suspend execution.

4. Confidentiality and security

  1. Persons authorised to process the data are committed to confidentiality (Art. 28(3)(b)).
  2. KlarComply implements the technical and organisational measures set out in Annex 2 (Art. 32 GDPR) and adapts them to the state of the art without lowering the level of protection.

5. Sub-processors

The Customer grants general authorisation for the use of the sub-processors listed in Annex 3. KlarComply gives notice of intended changes; the Customer may object within 14 days on substantial data-protection grounds. Agreements pursuant to Art. 28 GDPR are in place with all sub-processors.

6. Duties of assistance

KlarComply assists the Customer, to the extent reasonable, in responding to data-subject requests (Art. 12–23), in securing the processing, in data protection impact assessments and in notification duties (Art. 32–36). KlarComply notifies the Customer of personal data breaches affecting data processed on the Customer's behalf without undue delay, at the latest within 24 hours of becoming aware. The notification contains the information required by Art. 33(3) GDPR as far as it is available; where it is not available in full, it may be provided in phases pursuant to Art. 33(4) GDPR. The notification serves to support the Customer in its own notification duty and does not constitute an admission of fault.

7. Deletion and return

After termination of the subscription, KlarComply deletes all personal data processed on behalf of the Customer within 30 days, unless a statutory retention duty applies. The Customer may back up its data beforehand via the dashboard's export/print functions. Issued certificates remain stored for public verification (legitimate interest of the certificate holders); the Customer may request their deletion.

8. Evidence and audits

KlarComply provides the Customer with the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and enables audits — upon notice and at most once per year, except where there is specific cause. Evidence may be provided through current attestations/certifications of the sub-processors (e.g. SOC 2, ISO 27001).

9. Third-country transfers

Processing takes place in data centres in the EU (Frankfurt region, Germany). Where sub-processors established outside the EU are used (Annex 3), any transfer is based on EU standard contractual clauses or an adequacy decision (e.g. the EU-US Data Privacy Framework).

10. Final provisions

The law applicable to the subscription agreement also applies here. In case of conflict, this agreement prevails in data-protection matters. Should any provision be invalid, the remaining provisions remain in force.

Annex 1 — Data and data subjects

Data subjectsEmployees, contact persons and, where applicable, external staff of the Customer
Data categoriesName, business email address, role; training progress and results (per cent); certificate data (name, company, date, check-ID); acknowledgment logs (who, what, when); details maintained by the Customer (AI inventory, contact person, rules)
No processing ofspecial categories under Art. 9 GDPR; such data must not be entered into the platform
Nature of processingCollection, storage, organisation, evaluation and deletion in the course of operating the platform. Additionally, on the Customer's separate request: manual review and expert assessment of the compliance documentation maintained by the Customer, carried out by trained KlarComply staff (“expert check”).

Annex 1a — Expert check (manual review on request)

This processing takes place only if the Customer expressly requests it in its dashboard. The request is stored with its time and the requesting person and constitutes a documented instruction within the meaning of Art. 29 GDPR. Without such a request, no manual inspection takes place.

Subject of the reviewExclusively company-related information: AI inventory (tools, providers, purposes of use, risk classes including reasoning), internal AI policy, labelling rule under Art. 50, blocked uses, details of the contact person and the question submitted by the Customer
Expressly not coveredEmployee lists, training status and examination results of individual persons, certificate data, acknowledgment logs, billing and payment data
PurposeExpert feedback to the Customer in the form of a written report with prioritised recommended measures, and answering follow-up questions on it for 30 days
Persons carrying out the reviewKlarComply staff who have previously completed the internal specialist training and signed a confidentiality undertaking pursuant to Art. 28(3)(b) GDPR. No sub-processors are used for this.
LoggingEvery read access in the course of a review order is logged with person, time and the Customer concerned (accountability under Art. 5(2) GDPR). The Customer can view the review orders stored for it in its dashboard.
RetentionReview order and report are stored for the duration of the contractual relationship and thereafter handled in accordance with the deletion clause (clause 7). Access logs are retained for 24 months.

Annex 2 — Technical and organisational measures (Art. 32)

Annex 3 — Sub-processors

ProviderPurposeRegistered office / region
Supabase Inc.Database, authentication, server functionsUSA · data stored in the EU (AWS Frankfurt) · SCC/DPF
Cloudflare Inc.Website hosting, CDN, securityUSA · EU delivery · SCC/DPF
Google Ireland Ltd.Google Workspace — sending and receiving emails to users (sign-in links, course and certificate notifications, cancellation confirmations)Ireland (EU) · parent company USA · SCC/DPF
MailerLite (UAB)Newsletter delivery to prospects (contact email only) — not currently in useLithuania (EU)

Note: payment data is processed by Stripe Payments Europe Ltd. as an independent controller — it is not covered by this data processing agreement.

Annex 4 — Change history

VersionAs ofChange
1.3September 2026Designation of the processor: “Patrick de Kathen (KlarComply)” instead of “(sole proprietorship)” — the legal form will only be stated once registration is complete. No substantive change to the obligations.
1.2August 2026Clause 6: fixed notification period of 24 hours for the initial notification of a personal data breach, with express provision for phased information pursuant to Art. 33(4) GDPR. Previously it only said “without undue delay” without a figure.
1.1August 2026Annex 3: Google Ireland Ltd. (Google Workspace) added as a sub-processor for email delivery — it was in use but not listed. MailerLite marked as not currently in use.
1.0July 2026Initial version.

Existing customers are informed of changes to the sub-processors in accordance with clause 5; the right to object is 14 days. The version accepted at the time of contract conclusion remains authoritative until the Customer accepts a new one.

Acceptance

This agreement is concluded electronically (Art. 28(9) GDPR). Acceptance takes place in the KlarComply dashboard by the Customer's authorised signatory; time, name and contract version are logged verifiably. The binding text is the German version 1.3 (see klarcomply.com/avv).

This document forms part of the subscription agreement.