Data processing agreement
Vereinbarung nach Art. 28 DSGVO und Art. 9 des Schweizer Datenschutzgesetzes für OUHUD Search Intelligence.
This is a convenience translation. The legally binding version of this document is the German one.
This page is not yet ready for publication.
The following mandatory details or checks are still open: Production hosting provider, location and contracting entity · Binding maximum backup and deletion cycle · Complete tenant export and tested restore · Final operational TOM including backup concept. The affected legal page stays excluded from search engines until it is complete.
Processor
Contractual basis
Document version
1. Parties and incorporation
Customer is the organisation designated in the main contract, order form or administration account. Depending on the processing, it acts as controller or as processor for a further controller. Company name, address, authorised representative, data protection contact, role and date of accession follow from the contract documents.
Processor ist Ouhud GmbH, Kaiserswerther Straße 135, 40474 Düsseldorf, Deutschland, E-Mail: info@ouhud.com. Ouhud Digital GmbH (in formation) is not a party to this agreement before its registration and an express accession to the contract.
Handelt der Kunde selbst als Auftragsverarbeiter, gilt er für diese Vereinbarung als weiterer Auftragsverarbeiter und Ouhud GmbH als Unterauftragsverarbeiter. Der Kunde bestätigt, zur Beauftragung von Ouhud GmbHund zur Erteilung der Weisungen durch den jeweiligen Verantwortlichen befugt zu sein.
2. Subject matter, scope and duration
Gegenstand ist die Verarbeitung personenbezogener Daten zur Bereitstellung von OUHUD Search Intelligence im Umfang des Hauptvertrags. Dazu können je nach gebuchten und aktivierten Modulen Website-Analyse und Crawling, Wissensverarbeitung, Themenrecherche, Content-Erstellung und Qualitätsprüfung, Messung von Such- und KI-Sichtbarkeit, Berichte, Integrationen sowie eine vom Kunden ausgelöste Veröffentlichung gehören.
Diese Vereinbarung gilt ab ihrer wirksamen Einbeziehung für die Dauer des Hauptvertrags und darüber hinaus, solange Ouhud GmbH Auftragsdaten für den Kunden verarbeitet. Art, Zweck, Datenkategorien, betroffene Personen und Frequenz sind in Anlage B konkretisiert. Verarbeitungen, bei denen Ouhud GmbH eigene Zwecke festlegt, fallen ausschließlich unter Ziffer 13.
3. Documented instructions and customer obligations
The main contract, the service description, this agreement as well as the settings made and functions triggered by the customer in the platform constitute the documented instructions. Further instructions are issued by the customer via the product functions provided for this purpose or in text form to the data protection contact. Oral instructions in an urgent exceptional case must be confirmed in text form without delay.
Ouhud GmbH informiert den Kunden unverzüglich, wenn eine Weisung nach ihrer Auffassung gegen anwendbares Datenschutzrecht verstößt, und darf die betroffene Verarbeitung bis zur Klärung aussetzen. Muss Ouhud GmbH aufgrund von Unionsrecht oder mitgliedstaatlichem Recht ohne Weisung verarbeiten, wird der Kunde vorab über diese Pflicht informiert, soweit das Recht eine Mitteilung nicht aus wichtigen Gründen des öffentlichen Interesses verbietet.
Der Kunde bleibt insbesondere verantwortlich für Rechtsgrundlage, Transparenz, Datenminimierung, Richtigkeit, Speicherfristen, die Erfüllung von Betroffenenrechten und die Zulässigkeit seiner Weisungen. Er übermittelt nur Daten, die Ouhud GmbH nach seiner Weisung verarbeiten darf, und informiert vorab über besondere Schutzbedarfe, Berufsgeheimnisse oder gesetzliche Geheimhaltungspflichten.
4. Obligations of Ouhud GmbH
Ouhud GmbH verpflichtet sich,
- to process processed data exclusively in accordance with documented instructions and only for the agreed purposes, including instructions on international transfers,
- to grant access only to authorised persons who, before access, are bound to confidentiality or subject to an appropriate statutory duty of secrecy,
- to instruct these persons appropriately and to limit their access rights to what is necessary for their task,
- to comply with the requirements for sub-processors set out in section 9,
- to support the customer in fulfilling its data protection obligations in accordance with this agreement,
- to maintain the required records and evidence and to cooperate with the competent supervisory authorities.
Ouhud GmbH verwendet Auftragsdaten nicht für Werbung, den Verkauf von Daten oder das Training beziehungsweise die Verbesserung eigener oder fremder KI-Modelle. Das gilt auch für eingesetzte Unterauftragsverarbeiter. Eine abweichende Nutzung setzt eine ausdrücklich gesondert dokumentierte Weisung des Kunden, eine zulässige datenschutzrechtliche Rollenverteilung und alle erforderlichen Rechtsgrundlagen voraus. Die bloße Aktivierung einer KI-Funktion ist keine solche Weisung zum Modelltraining.
5. Security of processing
Ouhud GmbH trifft unter Berücksichtigung des Stands der Technik, der Implementierungskosten sowie Art, Umfang, Umständen, Zwecken und Risiken der Verarbeitung angemessene technische und organisatorische Maßnahmen nach Art. 32 DSGVO. Anlage C unterscheidet den nachweisbaren Entwicklungsstand von den dort ausdrücklich als vor Produktivbetrieb abzuschließen gekennzeichneten Betriebsmaßnahmen. Solange diese offenen Maßnahmen nicht umgesetzt und dokumentiert sind, ist diese Fassung nicht zur Einbeziehung in einen Produktivvertrag freigegeben.
The measures may be adapted to technical developments provided that the agreed level of protection is not reduced overall. Materially disadvantageous changes are documented and communicated to the customer on request or, if they concern a significant risk, actively. Absolute security is not promised.
6. Support with data subject rights
Unter Berücksichtigung der Art der Verarbeitung unterstützt Ouhud GmbH den Kunden mit geeigneten technischen und organisatorischen Maßnahmen bei Anträgen nach Art. 12 bis 22 DSGVO sowie den entsprechenden Rechten nach Schweizer DSG. Dies umfasst, soweit technisch verfügbar und vom Kunden angewiesen, Suche, Auskunft, Berichtigung, Export, Einschränkung und Löschung von Auftragsdaten.
Unmittelbar bei Ouhud GmbH eingehende Anfragen, die Auftragsdaten betreffen, werden unverzüglich an den Kunden weitergeleitet. Ouhud GmbH beantwortet sie nur auf dokumentierte Weisung oder aufgrund einer eigenen zwingenden gesetzlichen Pflicht. Der Kunde bleibt für die inhaltliche Prüfung und fristgerechte Antwort verantwortlich.
7. Further support and authorities
Unter Berücksichtigung von Art der Verarbeitung und verfügbaren Informationen unterstützt Ouhud GmbH den Kunden bei seinen Pflichten aus Art. 32 bis 36 DSGVO, insbesondere bei Risikobewertungen, Datenschutz-Folgenabschätzungen, Vorabkonsultationen sowie Anfragen oder Prüfungen einer Aufsichtsbehörde. Die für Ouhud GmbH als Auftragsverarbeiter erforderlichen Verzeichnisse werden nach Art. 30 Abs. 2 DSGVO geführt; der Kunde wird bei seinen eigenen Dokumentationspflichten im erforderlichen Umfang unterstützt.
Unterstützung, die wegen eines Verstoßes von Ouhud GmbH erforderlich wird, ist mit der vereinbarten Vergütung abgegolten. Sonstige außergewöhnliche, kundenspezifische Zusatzleistungen können nach vorheriger Abstimmung zu den vereinbarten oder üblichen Sätzen berechnet werden.
8. Verletzungen des Schutzes personenbezogener Daten
Ouhud GmbH meldet dem Kunden eine Verletzung des Schutzes von Auftragsdaten unverzüglich nach Bekanntwerden. Die Erstmeldung enthält, soweit verfügbar, die Art der Verletzung, Kategorien und ungefähre Zahl betroffener Personen und Datensätze, eine Kontaktstelle, wahrscheinliche Folgen sowie bereits ergriffene oder geplante Abhilfemaßnahmen. Fehlende Angaben werden ohne unangemessene Verzögerung schrittweise nachgereicht.
Ouhud GmbH ergreift angemessene Maßnahmen zur Eindämmung, Beweissicherung, Ursachenanalyse und Vermeidung einer Wiederholung und unterstützt den Kunden bei Meldungen nach Art. 33 und 34 DSGVO sowie Art. 24 DSG. Eine Meldung an Betroffene oder Behörden im Namen des Kunden erfolgt nur auf dokumentierte Weisung oder aufgrund einer eigenen gesetzlichen Pflicht. Die Meldung an den Kunden ist kein Anerkenntnis eines Rechtsverstoßes oder einer Haftung.
9. Unterauftragsverarbeiter
Der Kunde erteilt eine allgemeine Genehmigung ausschließlich für Anbieter, die bei Vertragsschluss in der Liste service providers and data recipients are marked with the status “in use” and the role “processor”. Planned, not yet selected or customer-activated recipients are not covered by this authorisation.
Ouhud GmbH informiert die im Kundenkonto hinterlegte Administratoradresse mindestens 30 Tage vor der Hinzufügung oder Ersetzung eines Unterauftragsverarbeiters aktiv in Textform. Die Mitteilung nennt Anbieter, Aufgabe, Datenkategorien, Verarbeitungsorte und gegebenenfalls die Transfergrundlage. Der Kunde kann innerhalb dieser Frist aus nachvollziehbaren datenschutzrechtlichen Gründen widersprechen.
Bei einem berechtigten Widerspruch suchen die Parteien eine zumutbare Lösung. Ist keine Lösung möglich, darf Ouhud GmbH die betroffene Funktion nicht über den beanstandeten Anbieter erbringen; der Kunde kann den betroffenen Leistungsteil zum Änderungstermin ohne zusätzliche Kosten kündigen. Ouhud GmbH auferlegt dem Unterauftragsverarbeiter vertraglich dieselben Datenschutzpflichten, die fürOuhud GmbH aus dieser Vereinbarung gelten, bleibt für deren Einhaltung und Pflichtverletzungen verantwortlich und stellt dem Kunden auf Anfrage eine erforderlichenfalls zum Schutz von Geschäftsgeheimnissen geschwärzte Vertragskopie bereit.
10. Transfers to third countries
Transfers to third countries or to international organisations take place only on documented instructions and in compliance with Chapter V GDPR and, where applicable, Art. 16 to 18 FADP. This agreement alone is not a transfer instrument.
Soweit kein anwendbarer Angemessenheitsbeschluss besteht, verwendet Ouhud GmbHinsbesondere die Standardvertragsklauseln nach Durchführungsbeschluss (EU) 2021/914 im jeweils passenden Modul, führt die erforderliche Transferprüfung durch und ergreift erforderliche ergänzende Maßnahmen. Eine Zertifizierung nach einem Datenschutzrahmen wird nur herangezogen, wenn der konkrete Empfänger und die konkrete Datenkategorie aktuell von ihr umfasst sind.
For data from Switzerland, recognised standard data protection clauses with the Swiss adaptations required by the FDPIC are used. The specific transfer basis of each authorised provider is set out in the service provider list.
11. Return and deletion
Nach Beendigung der Auftragsverarbeitung löscht Ouhud GmbH nach Wahl des Kunden sämtliche Auftragsdaten und bestätigt die Löschung oder gibt die Daten in einem verfügbaren, gängigen Format zurück und löscht anschließend bestehende Kopien. Der Kunde teilt seine Wahl spätestens zum Vertragsende mit. Ohne rechtzeitige Weisung werden aktive Auftragsdaten nach Ablauf einer 30-tägigen Abholfrist gelöscht.
Data subject to statutory retention is separated, blocked for other purposes and processed only for the duration and purpose of the statutory obligation. Backup copies, insofar as they are kept in production, are blocked against regular reprocessing and deleted at the end of the maximum backup cycle to be determined bindingly before production operation. In the event of a restore, due deletion orders are applied again.
12. Information, evidence and audits
Ouhud GmbH stellt dem Kunden alle Informationen bereit, die zum Nachweis der Pflichten aus Art. 28 DSGVO erforderlich sind. Aktuelle Zertifikate, Prüfberichte, TOM-Dokumentation und standardisierte Fragebögen können vorrangig zur Nachweisführung verwendet werden.
The customer or an independent auditor commissioned by it and bound to confidentiality may audit the processing covered by the contract at reasonable intervals and, in addition, where there are concrete indications of a breach or after a relevant incident. Necessary inspections take place with reasonable prior notice during usual business hours, unless urgency or an official order requires otherwise, and without unnecessary interference with operations or the rights of other customers.
Die Parteien stimmen Umfang, Sicherheitsvorkehrungen und Zeitplan vorab ab. Der Kunde trägt angemessene Kosten einer von ihm veranlassten Sonderprüfung, es sei denn, die Prüfung weist einen wesentlichen Verstoß von Ouhud GmbH nach. Gesetzliche Prüf- und Zugriffsrechte von Aufsichtsbehörden bleiben unberührt.
13. Verarbeitungen in eigener Verantwortlichkeit
Nicht Gegenstand dieser AVV sind Verarbeitungen, bei denen Ouhud GmbH eigene Zwecke und wesentliche Mittel festlegt. Dazu gehören insbesondere Vertragsanbahnung und -verwaltung, Abrechnung und Steuern, Verwaltung eigener Geschäftskontakte, Nachweis rechtlicher Erklärungen, Sicherheit eigener Konten und Infrastruktur sowie die Erfüllung eigener gesetzlicher Pflichten. Sicherheitsmaßnahmen, Protokolle und Prüfungen, die der geschuldeten Verarbeitung von Auftragsdaten dienen, bleiben dagegen Teil dieser AVV. Für die eigenen Verarbeitungen gilt die privacy policy.
14. Suspension and termination in the event of data protection breaches
Kann Ouhud GmbH diese Vereinbarung aus rechtlichen oder tatsächlichen Gründen nicht mehr einhalten, informiert sie den Kunden unverzüglich und setzt die betroffene Verarbeitung aus, soweit dies zum Schutz der Daten erforderlich ist. Behebt Ouhud GmbH einen wesentlichen Verstoß nicht innerhalb einer angemessenen Frist, darf der Kunde den betroffenen Leistungsteil oder, wenn eine Fortsetzung unzumutbar ist, den Hauptvertrag außerordentlich kündigen.
Entsprechendes gilt zugunsten von Ouhud GmbH, wenn eine rechtswidrige Weisung oder ein erheblicher Verstoß des Kunden trotz Hinweis und angemessener Frist fortbesteht. Zwingende Rechte von Betroffenen und Aufsichtsbehörden bleiben unberührt.
15. Supplementary provisions for Switzerland
Insofar as the Swiss Data Protection Act applies, the terms of this agreement also cover “personal data”, “controller” and “processor” under Swiss law. Art. 9 FADP, the requirements on data security, the prior authorisation of further processors, the support with notifications under Art. 24 FADP as well as Art. 16 to 18 FADP apply in addition.
Data security breaches are reported as quickly as possible. In the event of conflicts, the mandatory provision that affords data subjects stronger protection prevails. Ouhud Digital GmbH (in formation) becomes a party to this agreement only after entry in the commercial register, determination of its role and express accession to the contract.
16. Order of precedence, liability and final provisions
In the event of conflicts with other parts of the contract, this agreement prevails for the processing of processed data. For international transfers, mandatory provisions of effectively incorporated standard contractual clauses prevail over conflicting contractual rules. In all other respects, the liability provisions of the main contract apply, without limiting statutory rights of data subjects or mandatory data protection liability.
Amendments and additions require a documented electronic form or text form, unless data protection law requires a stricter form. The choice of law and the place of jurisdiction of the main contract apply. The invalidity of one provision does not affect the rest of the agreement; the statutory rule takes its place.
Annex A – Parties and accession
Customer
Processor
Annex B – Description of the processing
Subject matter, purpose, nature and frequency
Continuous or customer-triggered provision of the platform: collecting, recording, organising, structuring, storing, reading, querying, matching, analysing, indexing, converting, generating, transmitting, making available, publishing, restricting and erasing. Processing takes place when the platform is used, during scheduled background jobs and following specific customer instructions for the duration of the main contract.
Categories of data
- contact data and profile data of its users, roles and team assignments managed by the customer
- organisation, project, domain, website and configuration data
- publicly accessible URLs, website content, technical crawl and SEO data
- uploaded documents, extracted texts, chunks, sources, facts, entities and — where activated — embeddings
- topics, keywords, search intents, prompts, briefs, drafts, AI outputs, quality findings and approvals
- integration settings, encrypted OAuth or CMS credentials and transfers triggered by the customer
- search, analytics, visibility, publishing, usage, error and audit data, insofar as it is processed on behalf
- other personal data that the customer lawfully includes in content or documents
Categories of data subjects
- employees, freelancers and other authorised users of the customer
- customers, prospects, suppliers and business contacts of the customer
- authors, website visitors and persons appearing in publicly accessible website content
- persons named in uploaded documents, operational knowledge, reviews, drafts or published content
Specially protected data
Data under Art. 9 or 10 GDPR and particularly sensitive personal data under the Swiss FADP are not envisaged for the regular service. Their processing requires prior documented instructions, a sound legal basis and expressly agreed additional protective measures. Without these conditions, the customer must not transmit such data.
Annex C – Technical and organisational measures
1. Organisation and access control
- role-based authorisation concept and personal user accounts based on the need-to-know principle
- passwords are stored as irreversible Argon2id hashes
- privileged system tasks are separated from normal tenant processes and user roles
- access by authorised persons is limited to operations, security and authorised support
2. Tenant separation and authorisations
- tenant-related tables are protected by PostgreSQL row level security and a transaction-bound organisation context
- the regular application connects with a non-privileged database role; narrowly limited system tasks use a separate path
- automated isolation tests check access between different customer organisations
3. Transmission, secrets and keys
- external production access is transmitted in encrypted form; secure cookies and HTTPS are provided for the production configuration
- OAuth tokens, CMS credentials, MFA secrets and comparable integration secrets are stored encrypted at application level
- service, database and object storage access is separated by role and not embedded in source code
4. Upload and processing security
- file type, size, page count and archive limits reduce abuse and resource risks
- uploads are scanned for malware before parsing; in the intended production operation, processing fails closed if there is no unambiguous clearance
- the document parser is designed as an isolated service without direct database, object storage or AI provider access
5. Logging and traceability
- security-relevant account, role, approval, integration and system operations are logged traceably
- technical connection metadata and audit records are subject to documented, separate retention rules
- background jobs use unique job identifiers, retry limits and traceable status transitions
6. Integrity, availability and recovery
- idempotent processing, transactions, outbox and retry mechanisms reduce duplicate processing and lost jobs
- deletion orders for object storage are tracked via persistent tombstones
- production backups, restore tests and their maximum deletion cycle are laid down bindingly in the operating concept before production release
7. Review and improvement
- changes are versioned, reviewed and subjected to automated type, security and isolation tests before release
- security incidents are contained, documented, analysed and translated into improvement measures
- sub-processors are reviewed before release with regard to contract, role, location, security and transfer basis
Anlage D – Genehmigte Unterauftragsverarbeiter
Genehmigt sind ausschließlich Anbieter, die in der aktuellen service provider list expressly bear the status “in use” and the role “processor”. According to the development status documented at present, no external provider has yet been confirmed as in productive use. Planned candidates and customer-activated recipients are not authorised sub-processors.
Before the first production operation, provider, contracting entity, address, service, data categories, processing locations, start and transfer basis are added bindingly. Subsequent changes are governed by section 9 of this agreement.
This text is a draft and does not replace legal advice. Before publication it should be reviewed by a lawyer specialising in IT and data protection law — in particular the liability rules and the statements on data processing.