Earlyswell

Data Processing Agreement (Annex 1 to the Terms and Conditions)

Convenience translation. Only the German version is legally binding: Auftragsverarbeitungsvertrag

Version 1 of 29 September 2026. The version applicable at the time of booking is authoritative; its version number is stated in the booking confirmation. We will send earlier versions on request.

between the Customer (controller) and Atlaxis Digital Services GmbH, Hintere Grabenstraße 25, 72070 Tübingen (processor, “Atlaxis”). This agreement is an annex to the Terms and Conditions for Earlyswell and is concluded upon booking a plan or upon the start of the trial.

1. Subject matter and delimitation

1.1 Atlaxis processes, on behalf of the Customer, personal data that the Customer enters into Earlyswell: details of invited members (name, email address, role), topics and search terms created by the Customer, and notes. The Customer determines the purposes of this processing.

1.2 Atlaxis does not process on behalf of the Customer:

1.3 Duration: for the term of the contract for Earlyswell, including the read-only period after the end of the contract (Terms and Conditions, clause 15).

2. Type of data, data subjects, purpose

Types of dataName, email address, role in the organisation, times of sign-in and invitation; topics, search terms, exclusions, notes of the Customer
Data subjectsEmployees, members and agents of the Customer whom the Customer invites; where applicable, persons to whom search terms relate (only public officials and public figures in their public role, Terms and Conditions, clause 10.2)
PurposeProvision of Earlyswell to the Customer: accounts and roles, analysis of topics, reports and notifications
LocationAtlaxis servers in Germany

3. Obligations of Atlaxis

3.1 Atlaxis processes the data only on documented instructions from the Customer; the instructions are conclusively laid down in the Terms and Conditions, this agreement and the functions of Earlyswell. The Customer issues further instructions in text form. If Atlaxis considers an instruction to be unlawful, it informs the Customer accordingly.

3.2 Persons who have access to the data are bound to confidentiality.

3.3 Atlaxis implements the technical and organisational measures pursuant to clause 7 and adapts them to the state of the art without lowering the level of protection.

3.4 Atlaxis assists the Customer with requests from data subjects (Art. 12–22 GDPR) and with its obligations under Art. 32–36 GDPR. The Customer can export and delete the data of an account itself at any time.

3.5 Atlaxis notifies the Customer of a breach of the protection of the commissioned data without undue delay, where possible within 48 hours of becoming aware of it, with the information pursuant to Art. 33(3) GDPR, insofar as known.

3.6 After the end of the contract and expiry of the read-only period, Atlaxis deletes the commissioned data; backup copies are overwritten after eight weeks at the latest. Statutory retention obligations remain unaffected.

3.7 Atlaxis makes available the information necessary to demonstrate compliance with these obligations and allows for audits by the Customer or by an auditor mandated by the Customer who is bound to confidentiality, as a rule by means of written information; on-site audits by arrangement with reasonable advance notice.

4. Sub-processors

4.1 The Customer consents to the following sub-processors:

CompanyServiceLocationBasis for third country
Cloudflare, Inc., San Francisco, USADelivery of the application (encrypted connection, protection against attacks)worldwideEU Standard Contractual Clauses
Proton AG, Plan-les-Ouates, SwitzerlandSending of emails (sign-in links, invitations, reports)SwitzerlandAdequacy decision

4.2 Atlaxis informs the Customer in text form at least four weeks in advance of any new or replacement sub-processors. The Customer may object for good cause under data protection law; if no agreement is reached, the Customer may terminate the contract with effect from the date of the change.

4.3 Stripe (payment processing) is not a sub-processor but is independently responsible for its processing.

5. Rights and obligations of the Customer

The Customer is responsible for the lawfulness of the processing of the data it enters, in particular for not creating any topics about individual private persons (Terms and Conditions, clause 10.2).

6. Liability

Art. 82 GDPR applies and, in all other respects, the liability provisions of the Terms and Conditions (clause 12).

7. Technical and organisational measures (Art. 32 GDPR)

Reviewed on 29 September 2026: