Privacy Policy

1. Data Protection at a Glance

General information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. For detailed information on the subject of data protection, please refer to our data protection declaration listed below this text.

Data collection on this website

Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the "Information on the controller" section of this privacy policy.

How do we collect your data?
On the one hand, your data is collected when you provide it to us. This may, for example, be data that you enter in a contact form; other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or time of page view). This data is collected automatically as soon as you enter this website.

What do we use your data for?
Some of the data is collected to ensure that the website is provided without errors. Other data may be used to analyse your user behaviour.

What rights do you have regarding your data?
You have the right to receive information about the origin, recipient and purpose of your stored personal data free of charge at any time. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data.

Application procedure

In the course of handling application procedures in our company, we work together with the application platform of the service provider Workwise GmbH, Imprint (https://www.workwise.io/impressum). Recruitment on behalf of job seekers or employers is not order processing, but the use of a third-party specialist service provided by an independent controller (LDA-Bayern, FAQ list dated 20 July 2018). Further information on the data protection of the service provider Workwise GmbH can be found in the privacy policy (https://www.workwise.io/datenschutz).

Analysis tools and tools from third-party providers

When you visit this website, your surfing behaviour may be statistically analysed. This is mainly done using so-called analysis programmes, detailed information on these analysis programmes can be found in the following privacy policy.

Copyright

The content and works created by the site operators on these pages are subject to German copyright law. Duplication, processing, distribution and any form of commercialisation of such material beyond the scope of the copyright law shall require the prior written consent of its respective author or creator. Downloads and copies of this site are only permitted for private, non-commercial use and, insofar as the content on this site was not created by the operator, the copyrights of third parties are respected. In particular, third-party content is labelled as such. Should you nevertheless become aware of a copyright infringement, please inform us accordingly. If we become aware of any infringements, we will remove such content immediately.

2. Hosting and content delivery networks (CDN)

External hosting

This website is hosted by an external service provider (hoster). The personal data collected on this website is stored on the hoster's servers. This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses and other data generated via a website. the hoster is used for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f GDPR) Our hoster will only process your data to the extent necessary to fulfil its performance obligations and follow our instructions with regard to this data.

We use the following hoster:

Webflow, Inc.
398 11th Street, 2nd Floor
San Francisco, CA 94103

Conclusion of an order processing contract

In order to ensure data protection-compliant processing, we have concluded an order processing contract with our hoster.

3. General notes and mandatory information

Data protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this data protection declaration. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done and points out that data transmission over the Internet (e.g. when communicating by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.

Note on the responsible body

The controller responsible for data processing on this website is

doinstruct Software GmbH

Prenzlauer Allee 242

Haus 6

10405 Berlin

Phone: +49 5419 3935391

E-mail: post@doinstruct.com

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses, etc.).

Storage period

Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the deletion will take place after these reasons no longer apply.

Note on data transfer to the USA and other third countries

Among other things, we use tools from companies based in the USA or other third countries that are not secure under data protection law. If these tools are active, your personal data may be transferred to these third countries and processed there. We would like to point out that a level of data protection comparable to that in the EU cannot be guaranteed in these countries. For example, US companies are obliged to hand over personal data to security authorities without you as the data subject being able to take legal action against this. It can therefore not be ruled out that US authorities (e.g. secret services) may process, analyse and permanently store your data on US servers for surveillance purposes. We have no influence on these processing activities.

Revocation of your consent to data processing

Many data processing operations are only possible with your express consent. You can withdraw your consent at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to object to data collection in special cases and to direct advertising (Art. 21 GDPR)

IF THE DATA PROCESSING IS BASED ON ART. 6 ABS. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR). IF YOUR PERSONAL DATA ARE PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING, WHICH INCLUDES PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING.

Right to lodge a complaint with the competent supervisory authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged violation. The right to lodge a complaint is without prejudice to any other administrative or judicial remedy.

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place if it is technically feasible.

SSL or TLS encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Information, erasure and rectification

Within the framework of the applicable legal provisions, you have the right at any time to request information free of charge.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time to do this. The right to restriction of processing exists in the following cases:

- If you dispute the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the review, you have the right to request that the processing of your personal data be restricted.

- If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of erasure.

- If we no longer need your personal data, but you need it for the exercise, defence or assertion of legal claims, you have the right to request the restriction of the processing of your personal data instead of its erasure.

- If you have lodged an objection in accordance with Art. 21 para. 1 GDPR, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data - apart from its storage - may only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.

4. Data collection on this website

Cookies

Our Internet pages use so-called "cookies". Cookies are small text files and do not cause any damage to your end device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your end device until you delete them yourself or they are automatically deleted by your web browser.

In some cases, cookies from third-party companies may also be stored on your device when you visit our website (third-party cookies). These enable us or you to use certain services of the third-party company (e.g. cookies for processing payment services).

Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping basket function or the display of videos). Other cookies are used to evaluate user behaviour or display advertising.

Cookies that are required to carry out the electronic communication process (necessary cookies) or to provide certain functions that you have requested (functional cookies, e.g. for the shopping basket function) or to optimise the website (e.g. cookies to measure the web audience) are stored on the basis of Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in the storage of cookies for the technically error-free and optimised provision of its services. If consent to the storage of cookies has been requested, the cookies in question are stored exclusively on the basis of this consent (Art. 6 para. 1 lit. a GDPR); consent can be revoked at any time.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.

If cookies are used by third-party companies or for analysis purposes, we will inform you about this separately in this privacy policy and, if necessary, request your consent.

This website uses cookies. We use cookies to optimise content and advertisements.

By law, we can store cookies on your device if they are absolutely necessary for the operation of this site. We need your permission for all other types of cookies.

This site uses different types of cookies. Some cookies are placed by third parties that appear on our pages.

You can change or withdraw your consent at any time from the cookie statement on our website.

Find out more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please provide your consent ID and date if you wish to contact us regarding your consent.

Cookie consent with Usercentrics

This website uses Usercentrics' cookie consent technology to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies and to document this in compliance with data protection regulations. The provider of this technology is Usercentrics GmbH, Rosental 4, 80331 Munich, Germany, website: https://usercentrics.com/de/ (hereinafter referred to as "Usercentrics").

When you visit our website, the following personal data is transmitted to Usercentrics:

- Your consent(s) or the revocation of your consent(s)

- your IP address

- Information about your browser

- Information about your end device

- Time of your visit to the website

In addition, Usercentrics stores a cookie in your browser in order to be able to assign the consents given or their revocation to you. The data collected in this way is stored until you ask us to delete it, delete the Usercentrics cookie yourself or the purpose for storing the data no longer applies. Mandatory statutory retention obligations remain unaffected.

Usercentrics is used to obtain the legally required consent for the use of certain technologies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.

Contract on order processing

We have concluded an order processing contract with Usercentrics. This is a contract required by data protection law, which ensures that Usercentrics processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Contact form

If you send us enquiries via the contact form, your details from the enquiry form, including the contact details you provide there, will be stored by us for the purpose of processing the enquiry and in the event of follow-up questions. We will not pass on this data without your consent.

This data is processed on the basis of Art. 6 para. 1 lit. b GDPR if your enquiry is related to the fulfilment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the enquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested.

We will retain the data you provide on the contact form until you request its deletion, revoke your consent for its storage, or the purpose for its storage no longer pertains (e.g. after fulfilling your request). Mandatory statutory provisions - in particular retention periods - remain unaffected.

Enquiry by e-mail, telephone or fax

If you contact us by e-mail, telephone or fax, your enquiry including all personal data (name, enquiry) will be stored and processed by us for the purpose of processing your request. We will not pass on this data without your consent.

This data is processed on the basis of Art. 6 para. 1 lit. b GDPR if your enquiry is related to the fulfilment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the enquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested.

The data you send to us via contact requests will remain with us until you ask us to delete it, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions - in particular statutory retention periods - remain unaffected.

5. Analysis tools and advertising

Google Analytics

This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables the website operator to analyse the behaviour of website visitors. In doing so, the website operator receives various usage data, such as page views, length of visit, operating systems used and origin of the user. This data may be summarised by Google in a profile that is assigned to the respective user or their end device.

We can also use Google Analytics to record your mouse and scroll movements and clicks, among other things. Google Analytics also uses various modelling approaches to supplement the data records collected and uses machine learning technologies for data analysis.

Google Analytics uses technologies that enable the recognition of the user for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is generally transmitted to a Google server in the USA and stored there.

The use of this analysis tool is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analysing user behaviour in order to optimise both its website and its advertising. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent can be revoked at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://privacy.google.com/businesses/controllerterms/mccs/.

IP anonymisation

We have activated the IP anonymisation function on this website. This means that your IP address will be truncated by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to analyse your use of the website, to compile reports on website activity and to provide the website operator with other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

Browser plugin

You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de. You can find more information on how Google Analytics handles user data in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.

Order processing

We have concluded an order processing contract with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.

Storage duration

Data stored by Google at user and event level that is linked to cookies, user IDs or advertising IDs (e.g. DoubleClick cookies, Android advertising ID) is anonymised or deleted after 2 months. For details, please see the following link: https://support.google.com/analytics/answer/7667196?hl=de

6. Plugins and tools

Adobe Fonts

This website uses web fonts from Adobe for the standardised display of certain fonts. The provider is Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA (Adobe).

When you access this website, your browser loads the required fonts directly from Adobe in order to display them correctly on your device. In doing so, your browser establishes a connection to Adobe's servers in the USA. This gives Adobe knowledge that this website has been accessed via your IP address. According to Adobe, no cookies are stored when the fonts are provided.

The data is stored and analysed on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the uniform presentation of the typeface on its website. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent can be revoked at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Details can be found here: https://www.adobe.com/de/privacy/eudatatransfers.html

You can find more information about Adobe Fonts at: https://www.adobe.com/de/privacy/policies/adobe-fonts.html

You can find Adobe's privacy policy at: https://www.adobe.com/de/privacy/policy.html

Data Processing Agreement

Version 1.2 – Last updated: 26.08.2026

The following Data Processing Agreement pursuant to Art. 28 of the General Data Protection Regulation (“GDPR”) is concluded between the customer (as controller, hereinafter the “Controller”) and doinstruct Software GmbH, Prenzlauer Allee 242, Haus 6, 10405 Berlin (as processor, hereinafter the “Data Processor”; the Controller and the Data Processor hereinafter each also a “PARTY” and together the “PARTIES”).

Preamble

A) The Data Processor offers a video-based, digital platform for the onboarding and training of the Controller’s employees, which enables the Controller to access and complete topic-related content and tests via a web app over the internet, internet-enabled televisions, computers, smartphones and other devices (the “Main Contract/GTC”).

B) In the course of the performance of the Main Contract, personal data within the meaning of the General Data Protection Regulation (“GDPR”) is processed. For this reason, and following negotiation, the Parties enter into the following agreement on the processing of personal data on behalf of a controller pursuant to Art. 28 GDPR in order to comply with the requirements of the GDPR.

1. General provisions

1.1 The cooperation of the Parties under the Main Contract entails that the Data Processor obtains access to personal data of the Controller, in particular of the Controller’s employees, and processes such data exclusively on behalf of and in accordance with the instructions of the Controller within the meaning of Art. 4 (8) and Art. 28 GDPR.

1.2 Under this Agreement, the Controller shall be solely responsible within the meaning of Art. 4 (7) GDPR for compliance with the statutory provisions on data protection, in particular for the lawfulness of the disclosure of data to the Data Processor and for the lawfulness of the data processing.

1.3 For the terms used in this Agreement for which Art. 4 GDPR provides a definition, that statutory definition shall apply in the version in force at the time of conclusion of the contract.

2. Subject matter/scope of the commissioned processing

2.1 The subject matter of the processing, the nature and purpose of the processing, the type of personal data and the categories of Data Subjects are set out in the Main Contract and in Annex 1.

2.2 In case of doubt, the provisions of this Agreement shall take precedence over the provisions of the Main Contract.

2.3 The term of this Agreement shall correspond to the term of the Main Contract, unless the following provisions give rise to obligations extending beyond the term of the Main Contract. In case of doubt, termination of the Main Contract shall also be deemed termination of this Agreement.

2.4 This Agreement shall remain valid beyond the end of the Main Contract for as long as the Data Processor has personal data at its disposal which have been forwarded to it by the Controller or which it has collected for the Controller.

2.5 The processing of the data processed on behalf of the Controller shall take place exclusively within the territory of the Federal Republic of Germany, in a Member State of the European Union or in another state party to the Agreement on the European Economic Area. In the event of processing of the data processed on behalf of the Controller in a third country, the Data Processor shall ensure, in a manner reasonable for it, that an adequate level of data protection is guaranteed (e.g. by concluding an agreement based on the EU standard data protection clauses).

3. Right of instruction of the Controller

3.1 The Data Processor shall process the data processed on behalf of the Controller only within the scope of the commissioned processing and exclusively on behalf of and in accordance with the documented instructions of the Controller within the meaning of Art. 28 GDPR. This shall also apply with regard to the transfer of personal data to a third country or an international organization, unless the Data Processor is required to do so by the law of the Union or of the Member States to which it is subject. In such a case, the Data Processor shall notify the Controller of these legal requirements prior to the processing, unless the relevant law prohibits such notification on important grounds of public interest.

3.2 Instructions shall as a rule be issued by the Controller in writing or in an electronic format (“text form”); instructions given verbally shall be confirmed in writing without undue delay.

3.3 If the Data Processor is of the opinion that an instruction of the Controller violates data protection provisions, it shall notify the Controller thereof without undue delay. The Data Processor shall be entitled to suspend the implementation of the relevant instruction until it is confirmed or amended by the Controller.

4. Obligations

4.1 The Data Processor shall be obliged to observe the statutory provisions on data protection and not to disclose information obtained from the Controller’s domain to third parties or expose it to their access. Documents and data shall be secured against disclosure to unauthorized persons, taking into account the state of the art.

4.2 Furthermore, the Data Processor shall oblige all persons entrusted by it with the processing and the performance of this Agreement to maintain confidentiality in written form and shall ensure compliance with this obligation with due care.

4.3 The Data Processor shall organize its internal organization in such a way that it meets the special requirements of data protection. It undertakes to take all appropriate technical and organizational measures for the adequate protection of the data processed on behalf of the Controller pursuant to Art. 32 GDPR, in particular the measures set out in Annex 2 and 3 to this Agreement, and to maintain them for the duration of the processing of the data processed on behalf of the Controller. The Controller is aware of these technical and organizational measures and is responsible for ensuring that they provide an adequate level of protection for the risks of the data to be processed.

4.4 The Data Processor reserves the right to change the technical and organizational measures set out in Annex 2 and 3, whereby it must be ensured that the contractually agreed level of protection is not undercut.

4.5 The categories of personal data listed in Annex 1 do not include opt-in data and consents for text messages (SMS/RCS); this information is not disclosed to third parties, with the exception of aggregators and providers of the text messaging services.

4.6 The Data Processor has appointed an external data protection officer. The Data Processor’s data protection officer is heyData GmbH, Schützenstraße 5, 10117 Berlin, datenschutz@heydata.eu, www.heydata.eu.

5. Information and support obligations

5.1 The Data Processor shall support the Controller, within the scope of its possibilities, in fulfilling the requests and claims of Data Subjects pursuant to Chapter III GDPR and in complying with the obligations set out in Art. 32 to 36 GDPR.

5.2 The Data Processor shall inform the Controller without undue delay if it becomes aware of any breaches of the protection of the Controller’s personal data. The Data Processor shall take the necessary measures to secure the data and to mitigate any possible adverse consequences for the Data Subjects and shall coordinate with the Controller in this regard without undue delay.

5.3 The Controller shall inform the Data Processor without undue delay and in full if it discovers errors or irregularities in the processing results with regard to data protection provisions.

5.4 In the event that a Data Subject asserts claims against the Controller pursuant to Art. 82 GDPR, the Data Processor undertakes to support the Controller in defending against such claim within the scope of its possibilities. The same shall apply to the Controller in the event that a Data Subject asserts claims against the Data Processor.

6. Other obligations of the Data Processor

Should the data processed on behalf of the Controller be endangered at the Data Processor by seizure or confiscation, by insolvency or composition proceedings or by other events or measures of third parties, the Data Processor shall inform the Controller thereof without undue delay, unless it is prohibited from doing so by a court or official order. In this context, the Data Processor shall inform all competent bodies without undue delay that the authority to decide on the data lies exclusively with the Controller as controller within the meaning of the GDPR.

7. Sub-processor relationships (further processors)

7.1 The Data Processor engages the sub-processors listed in Annex 4. In all other respects, the engagement of further sub-processors requires the written consent of the Controller. The Controller may not refuse its consent without an important reason under data protection law. The Data Processor shall ensure that the provisions agreed in this Agreement also apply vis-à-vis the sub-processors engaged by it, whereby the Controller shall be granted all control rights vis-à-vis the sub-processor pursuant to Section 8 of this Agreement below. The engagement of sub-processors in third countries outside the European Union and the European Economic Area is subject to compliance with Art. 44 et seq. GDPR.

7.2 A sub-processor relationship within the meaning of these provisions does not exist if the Data Processor commissions third parties with services that are to be regarded as purely ancillary services. These include, for example, postal, transport and shipping services, cleaning services, guarding services, telecommunications services without any specific reference to services provided by the Data Processor for the Controller, as well as other measures to ensure the confidentiality, availability, integrity and resilience of the hardware and software of data processing systems. The Data Processor’s obligation to ensure compliance with data protection and data security in these cases as well shall remain unaffected.

8. Control rights

8.1 The Data Processor shall demonstrate to the Controller by appropriate means its compliance with the obligations set out in this Agreement.

8.2 Should inspections by the Controller or an auditor commissioned by it be necessary in individual cases, these shall be carried out during normal business hours, without disrupting operations, following prior notice and with due regard to a reasonable lead time. The Data Processor may make the inspection conditional upon the signing of a confidentiality undertaking with regard to the data of other customers and the technical and organizational measures implemented. Should the auditor commissioned by the Controller be in a competitive relationship with the Data Processor, the Data Processor shall have a right to object to that auditor. The Data Processor may charge a reasonable fee for its support in carrying out an inspection.

8.3 Should a data protection supervisory authority or another public supervisory authority of the Controller carry out an inspection, Section 8.2 shall apply accordingly in principle. The signing of a confidentiality undertaking shall not be required if that supervisory authority is subject to professional or statutory confidentiality obligations the breach of which is punishable under the German Criminal Code.

9. Rights of Data Subjects

9.1 The Data Processor shall support the Controller, within the scope of its possibilities and on instruction, with suitable technical and organizational measures in fulfilling the Controller’s obligations pursuant to Art. 12 to 22 and Art. 32 to 36 GDPR.

9.2 If a Data Subject asserts its rights pursuant to Art. 16 to 18 GDPR, the Data Processor shall be obliged to rectify, erase or restrict the data processed on behalf of the Controller without undue delay upon written instruction of the Controller.

9.3 If a Data Subject asserts its rights, such as the right of access, rectification or erasure with regard to its data, directly against the Data Processor, the Data Processor shall forward this request to the Controller without undue delay and shall await the Controller’s written instructions. Without a corresponding written individual instruction, the Data Processor shall not contact the Data Subject.

9.4 The Data Processor shall not be liable if the Data Subject’s request is not answered by the Controller, or is answered incorrectly or not within the applicable time limit.

10. Deletion and return after the end of the contract

10.1 Following termination of the Main Contract, the Data Processor shall, at the Controller’s choice, return to the Controller all documents, data and data carriers provided to it or, unless a statutory retention obligation exists, delete them completely and irretrievably. This shall also apply to reproductions of the data processed on behalf of the Controller held by the Data Processor, such as data backups, but not to documentation which serves as evidence of the processing of the data processed on behalf of the Controller in accordance with the commissioned processing and in due order.

10.2 If deletion in compliance with data protection law or a corresponding restriction of the data processing is not possible, the Data Processor shall carry out the destruction of data carriers and other materials in compliance with data protection law on the basis of an individual commission by the Controller, or shall return such data carriers to the Controller, unless otherwise agreed in this Agreement. The costs arising therefrom shall be borne by the Controller.

11. Final provisions

11.1 Should any provision of this Agreement be or become wholly or partially null and void, invalid or unenforceable, the validity and enforceability of all remaining provisions shall not be affected thereby. To the extent legally permissible, the null and void, invalid or unenforceable provision shall be deemed replaced by the valid and enforceable provision that comes closest, in terms of subject matter, measure, time, place and scope of application, to the economic purpose pursued by the null and void, invalid or unenforceable provision. The same shall apply to the filling of any gaps in this Agreement. The Parties are aware of the judgment of the German Federal Court of Justice of 14 September 2002 (case no. KZR 10/01). It is nevertheless the intention of the Parties that this severability clause shall not substantially bring about a reversal of the burden of proof, but that Section 139 of the German Civil Code (BGB) shall be excluded in its entirety, to the extent legally possible.

11.2 There are no verbal or written collateral agreements to this Agreement. Amendments to this Agreement and its annexes must be made in writing.

11.3 This Agreement is subject to German law.

Annexes:

Annex 1 – Subject matter of the processing, nature and purpose of the processing, type of personal data and categories of Data Subjects

1. Subject matter and purpose of the processing

The Controller’s commission to the Data Processor comprises the following work and/or services:

Collection of information (e.g. clothing sizes) from employees in the course of digital training in our web app. For the provision of the digital training, the Controller provides the following data:

- First name, last name

- Phone number

- E-mail address

- Status

- Date of first working day

- Cost center

- Language

- Employee number, from the Controller’s system

2. Type(s) of personal data

The following types of data are regularly subject to processing:

- First name, last name

- Phone number

- E-mail address

- Status

- Date of first working day

- Cost center

- Language

- Employee number, from the Controller’s system

3. Categories of Data Subjects

Group of persons affected by the data processing:

Employees of the Controller or other users.

Annex 2 – Appropriate technical and organizational measures

Entry control

  • Entry control system: entry to the office premises only with an access chip
  • Chip allocation is centrally and organizationally clearly regulated: the employee receives a chip, issuance is documented in the office
  • Clear assignment of authorizations:
    • Management: all rooms (office premises + network distribution rooms)
    • Employees: all office premises
  • Locking of cabinets and offices when unoccupied: cabinets containing sensitive data are locked

Admission control

  • Dedicated password procedure for login, clear password rules (specified length, combination of letters and numbers, no trivial passwords). Preset passwords must be changed immediately.

Access control

  • Differentiated authorizations (profiles, roles)
    • Authorizations are assigned
  • Differentiated folder concept (all files are to be named uniformly and traceably and stored in such a way that they can be retrieved without difficulty).

Separation control

  • Separation of the data of different controllers

Transfer control

  • Encryption
  • Requirements for employees regarding the printing of confidential documents (ensuring that no one else obtains access to printouts).
    • Do not leave printouts freely accessible in the printer; collect them immediately
  • Rules on the use of USB sticks and CD-ROMs
  • No external data carriers containing confidential/sensitive material, e.g. DVDs, external hard drives, USB sticks, etc., are used in data processing.

Input control

  • Logging and log evaluation systems are used or are applicable as parts of existing software applications
  • Access to data processing systems is only possible after login
  • No disclosure of passwords
  • Locking: manual log-off when leaving the office

Order control

  • Delineation of competences and obligations between the Data Processor and the Controller
  • Ensuring the destruction of data after the end of the commissioned processing

Availability control

  • Regular backup procedures are ensured; the software is backed up with every release
  • Virus protection/firewall in accordance with the current state of the art
  • An emergency plan is in place

Other

  • Checklist for the onboarding/offboarding of employees (authorizations, keys, instruction)
  • Home office agreement

Annex 3 – Platform-related technical and organizational measures

  • Hosting and data location. The processing of personal data takes place exclusively in data centers within the EU or the EEA.
  • Encryption. AES-256 at rest, TLS 1.2 or higher in transit, with managed cryptographic keys and regular key rotation.
  • Certifications of the infrastructure. The infrastructure providers used hold independent certifications under recognized standards (ISO/IEC 27001, SOC 2 Type II or comparable).
  • Tenant separation. Multi-tenant architecture with logical tenant separation and customer-specific isolation through authentication and access controls.
  • Business continuity and disaster recovery. A Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP) are in place with defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets; the plans are tested at least annually.
  • Log data. Log data is subject to masking and redaction procedures in order to minimize the exposure of personal data. The measures described in this Annex are reviewed regularly for their effectiveness and adapted to the respective state of the art. Material changes that are liable to impair the agreed level of data protection will be communicated to the Controller in text form pursuant to Section 11.4 of the DPA.
  • Certification of doinstruct. doinstruct Software GmbH itself holds an ISO/IEC 27001 certification; the current certificate will be provided on request.
  • Technical vulnerabilities are identified, assessed and remediated on a risk basis in accordance with a documented process.
  • Administrative access to systems processing customer data is restricted to authorised roles, attributable to individual users, and logged as part of doinstruct’s logging and monitoring process.

Annex 4 – Current Sub-processors

Amazon Web Services EMEA SARL

38 Avenue John F. Kennedy, L-1855 Luxembourg, Luxembourg

Backend infrastructure and databases

EU

SCCs have been concluded (EU Standard Contractual Clauses pursuant to Art. 46 (2) lit. c GDPR), DPF certificate is available.

Datadog, Inc.

620 8th Avenue, 45th Floor, New York, NY 10018, USA

Application monitoring, error tracking

EU

SCCs have been concluded (EU Standard Contractual Clauses pursuant to Art. 46 (2) lit. c GDPR), DPF certificate is available.

Mixpanel, Inc.

Pier 1, Bay 2, The Embarcadero, San Francisco, CA 94111, USA

Product and user analytics

EU

SCCs have been concluded (EU Standard Contractual Clauses pursuant to Art. 46 (2) lit. c GDPR), DPF certificate is available.

OpenAI Ireland Limited

1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland

AI Services

EU

SCCs have been concluded (EU Standard Contractual Clauses pursuant to Art. 46 (2) lit. c GDPR).

Twilio, Inc. (Sendgrid)

101 Spear Street, Fifth Floor, San Francisco, CA 94105, USA

Sending emails

EU

SCCs have been concluded (EU Standard Contractual Clauses pursuant to Art. 46 (2) lit. c GDPR), DPF certificate is available.