Data Processing Agreement (Annex 1 to the Terms and Conditions)
Convenience translation. Only the German version is legally binding: Auftragsverarbeitungsvertrag
Version 1 of 29 September 2026. The version applicable at the time of booking is authoritative; its version number is stated in the booking confirmation. We will send earlier versions on request.
between the Customer (controller) and Atlaxis Digital Services GmbH, Hintere Grabenstraße 25, 72070 Tübingen (processor, “Atlaxis”). This agreement is an annex to the Terms and Conditions for Earlyswell and is concluded upon booking a plan or upon the start of the trial.
1. Subject matter and delimitation
1.1 Atlaxis processes, on behalf of the Customer, personal data that the Customer enters into Earlyswell: details of invited members (name, email address, role), topics and search terms created by the Customer, and notes. The Customer determines the purposes of this processing.
1.2 Atlaxis does not process on behalf of the Customer:
- the Customer’s contract and invoice data (Atlaxis is itself the controller);
- the personal data in the analysed public sources (parliamentary documents, research, media, social networks); Atlaxis processes these under its own responsibility, as described in the Privacy Policy. A search term of the Customer is customer data processed on its behalf; the source data counted for it is data of Atlaxis.
1.3 Duration: for the term of the contract for Earlyswell, including the read-only period after the end of the contract (Terms and Conditions, clause 15).
2. Type of data, data subjects, purpose
| Types of data | Name, email address, role in the organisation, times of sign-in and invitation; topics, search terms, exclusions, notes of the Customer |
|---|---|
| Data subjects | Employees, members and agents of the Customer whom the Customer invites; where applicable, persons to whom search terms relate (only public officials and public figures in their public role, Terms and Conditions, clause 10.2) |
| Purpose | Provision of Earlyswell to the Customer: accounts and roles, analysis of topics, reports and notifications |
| Location | Atlaxis servers in Germany |
3. Obligations of Atlaxis
3.1 Atlaxis processes the data only on documented instructions from the Customer; the instructions are conclusively laid down in the Terms and Conditions, this agreement and the functions of Earlyswell. The Customer issues further instructions in text form. If Atlaxis considers an instruction to be unlawful, it informs the Customer accordingly.
3.2 Persons who have access to the data are bound to confidentiality.
3.3 Atlaxis implements the technical and organisational measures pursuant to clause 7 and adapts them to the state of the art without lowering the level of protection.
3.4 Atlaxis assists the Customer with requests from data subjects (Art. 12–22 GDPR) and with its obligations under Art. 32–36 GDPR. The Customer can export and delete the data of an account itself at any time.
3.5 Atlaxis notifies the Customer of a breach of the protection of the commissioned data without undue delay, where possible within 48 hours of becoming aware of it, with the information pursuant to Art. 33(3) GDPR, insofar as known.
3.6 After the end of the contract and expiry of the read-only period, Atlaxis deletes the commissioned data; backup copies are overwritten after eight weeks at the latest. Statutory retention obligations remain unaffected.
3.7 Atlaxis makes available the information necessary to demonstrate compliance with these obligations and allows for audits by the Customer or by an auditor mandated by the Customer who is bound to confidentiality, as a rule by means of written information; on-site audits by arrangement with reasonable advance notice.
4. Sub-processors
4.1 The Customer consents to the following sub-processors:
| Company | Service | Location | Basis for third country |
|---|---|---|---|
| Cloudflare, Inc., San Francisco, USA | Delivery of the application (encrypted connection, protection against attacks) | worldwide | EU Standard Contractual Clauses |
| Proton AG, Plan-les-Ouates, Switzerland | Sending of emails (sign-in links, invitations, reports) | Switzerland | Adequacy decision |
4.2 Atlaxis informs the Customer in text form at least four weeks in advance of any new or replacement sub-processors. The Customer may object for good cause under data protection law; if no agreement is reached, the Customer may terminate the contract with effect from the date of the change.
4.3 Stripe (payment processing) is not a sub-processor but is independently responsible for its processing.
5. Rights and obligations of the Customer
The Customer is responsible for the lawfulness of the processing of the data it enters, in particular for not creating any topics about individual private persons (Terms and Conditions, clause 10.2).
6. Liability
Art. 82 GDPR applies and, in all other respects, the liability provisions of the Terms and Conditions (clause 12).
7. Technical and organisational measures (Art. 32 GDPR)
Reviewed on 29 September 2026:
- Encrypted transmission (HTTPS/TLS via Cloudflare); application reachable only via the Cloudflare tunnel, database not reachable from the network (bound locally only).
- Sign-in via one-time links valid for 20 minutes, optionally with a password (stored only as a scrypt hash, lock after 5 failed attempts, notification on change); session cookie over HTTPS only, not readable by scripts; protection against requests from third-party sites (custom request header).
- Limitation of sign-in links per address and connection (protection against misuse); IP addresses only as an encrypted fingerprint, 24 hours.
- Roles in the organisation (Owner, Edit, Read); tenant separation in the application (every query restricted to the user’s own organisation).
- Daily backup of the database to a separate storage medium; restore successfully tested on 29 September 2026.
- No third-party AI services; no tracking or analytics tools.
- Location: Atlaxis’s own server in premises in Germany that are not publicly accessible (not a data centre); access for the management only. Backups on Atlaxis’s own storage devices at the same location.
- The storage media of the server and of the backups are currently not encrypted; protection is based on the access restriction. Encryption is planned; we will announce it as soon as it has been implemented.
- Administrative access to the server only via SSH with a key (no password login); two-factor authentication for all administrative accounts (hosting, payment, email and code services).
- The application does not write access logs; operating logs contain no IP addresses and are limited in size.