DATA PROCESSING AGREEMENT

pursuant to Art. 28 GDPR – SOF AI
Version as of: 10 August 2026 · Version 1

1. Subject Matter, Roles and Scope

This Data Processing Agreement (“DPA”) supplements the agreement governing the use of SOF AI (“Main Agreement”). It applies to the extent that Robert Kraft, trading under “SOF Solutions Hub” and “SOF AI” (“SOF AI”), processes personal data on behalf of the Customer.

For a particular processing operation, the Customer may be a controller or itself a processor. Where the Customer is a processor, it confirms that the relevant controller has authorized the engagement of SOF AI as a further processor and has authorized the instructions and subprocessors provided for in this DPA.

For processing operations in which SOF AI determines its own purposes and means – in particular account administration, its own contract and billing administration, IT security, support, abuse prevention and legal obligations – SOF AI acts as an independent controller. Those processing operations are not subject to this DPA.

2. Parties

Customer / instructing party: the business customer identified in the Main Agreement or in the SOF AI customer account.

Processor: Robert Kraft, trading under “SOF Solutions Hub” and “SOF AI”, Schönefelder Chaussee 221, 12524 Berlin, Germany; email: contact@sofsolutionshub.com; telephone: +49 160 6119180.

3. Subject Matter and Duration of Processing

The subject matter of the processing is the provision of the cloud-based SOF AI platform and the functions selected by the Customer. Details are determined by the Main Agreement, the functions used by the Customer and Annex 1 to this DPA.

Processing on behalf of the Customer begins when a SOF AI function is used in which personal data is processed on behalf of the Customer and generally continues for the term of the Main Agreement or until the relevant processed data is deleted or returned in accordance with this DPA.

4. Nature and Purpose of Processing

SOF AI processes Customer Content to provide the Services selected by the Customer. This may include, in particular, storing and organizing projects and workspaces, processing keywords, URLs, texts and files, research, analysis, content planning, text and metadata generation, quality review, internal linking, and the provision and delivery of results.

Not every request is transmitted to every external AI or research service. The processing steps performed depend on the function, configuration and documented instruction selected by the Customer.

5. Customer Instructions

Within the scope of this DPA, SOF AI processes personal data only on documented instructions from the Customer, including with regard to transfers to a third country or an international organization, unless SOF AI is required to process the data differently by applicable Union law or the law of a Member State.

Use of the functions and settings provided for in the Main Agreement, dashboard or an agreed technical interface constitutes documented instructions. Additional instructions may be given in text form to the extent that they relate to the agreed scope of Services and are technically feasible.

Where SOF AI is legally required to carry out processing that deviates from a Customer instruction, SOF AI will inform the Customer of that legal requirement before processing, unless the relevant law prohibits such information on important grounds of public interest.

If SOF AI considers that an instruction infringes the GDPR or other applicable data protection provisions, SOF AI will inform the Customer without undue delay. Execution of the relevant instruction may be suspended until the matter is clarified.

6. Confidentiality

SOF AI ensures that persons authorized to process personal data have committed themselves to confidentiality or are subject to an appropriate statutory duty of confidentiality and are granted access only to the extent necessary.

7. Technical and Organizational Measures

Taking into account the nature, scope, context and purposes of processing and the risks involved, SOF AI implements appropriate technical and organizational measures pursuant to Art. 32 GDPR. The core measures currently underlying this DPA are described in Annex 2.

SOF AI may further develop the technical and organizational measures provided that the agreed level of protection is not reduced.

8. Assistance with Data Subject Rights

Taking into account the nature of the processing, SOF AI assists the Customer through appropriate technical and organizational measures in responding to requests by data subjects to exercise their rights under Chapter III GDPR, to the extent possible and necessary for the processing carried out by SOF AI on behalf of the Customer.

If SOF AI receives a data subject request that clearly relates to data processed on behalf of the Customer, SOF AI will forward the request to the Customer unless there is a legal obligation to handle it directly.

9. Assistance pursuant to Arts. 32 to 36 GDPR

Taking into account the nature of processing and the information available to SOF AI, SOF AI provides reasonable assistance to the Customer in complying with its obligations concerning security of processing, notifications and communications of personal data breaches, data protection impact assessments and, where required, prior consultations with supervisory authorities.

10. Personal Data Breaches

SOF AI will inform the Customer without undue delay as soon as SOF AI becomes aware of a personal data breach affecting data processed on behalf of the Customer.

The notification will include the information available to SOF AI concerning the nature and scope of the incident, affected data or groups of persons, possible consequences, countermeasures already taken or planned, and a contact for follow-up questions, to the extent such information is available at the time of notification. Missing information may be provided subsequently.

11. Subprocessors

The Customer grants SOF AI general written authorization to engage the subprocessors listed in Annex 3.

SOF AI will inform the Customer within a reasonable period before the intended engagement or replacement of a subprocessor, in particular by email or through a contract/account notice accessible to the Customer, and will give the Customer an opportunity to object on objectively justified data protection grounds. If advance notice is exceptionally not possible for compelling security, legal or emergency reasons, the information will be provided without undue delay as soon as this is permissible and practicable.

SOF AI binds each subprocessor by contract or another permissible legal act to data protection obligations that ensure, with regard to the processing delegated to it, a level of protection corresponding to the requirements of this DPA and Art. 28 GDPR.

If a subprocessor fails to comply with its data protection obligations, SOF AI remains fully liable to the Customer for performance of that subprocessor’s obligations to the extent provided by law.

If a justified objection cannot be resolved through a reasonable alternative, the parties may disable the affected function or – where the affected processing is material to performance of the contract – terminate the Main Agreement in accordance with the rules applicable to such termination.

12. Transfers to Third Countries

Where personal data is processed outside the European Economic Area within the scope of this DPA and no adequacy decision applies, SOF AI ensures that a transfer mechanism permitted under Chapter V GDPR is used.

Where SOF AI itself acts as processor and a further processor is used in a third country, the Standard Contractual Clauses intended for processor-to-processor transfers or another permissible transfer mechanism are used, where required.

13. Deletion and Return

After processing on behalf of the Customer ends, SOF AI will, at the Customer’s choice, delete all personal data processed on behalf of the Customer or return it to the Customer and then delete existing copies, unless Union law or the law of a Member State requires further storage.

Data is returned in an electronic format available or reasonably available for the relevant SOF AI function. Where the Customer has export or download functions during the term of the contract, it may use those functions to retrieve the data.

Data deleted from active systems may temporarily remain in automated backups. Regular system backups are currently subject to a rotating Restic retention schedule of 7 daily, 4 weekly and 12 monthly backup snapshots. Expired backup snapshots are removed as part of regular repository cleanup and are not available for regular production access.

Where data may not be deleted because of a statutory retention obligation, it will thereafter be processed only for the purpose required by law.

14. Evidence and Audits

SOF AI makes available to the Customer all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and permits audits, including inspections, by the Customer or an independent auditor mandated by the Customer, and contributes to such audits as required.

Existing security, contractual and compliance documentation and suitable technical evidence should be used as a priority. Further audits must be conducted with reasonable advance notice unless a data protection incident, a regulatory order or a comparable urgent reason requires an audit on shorter notice. The security interests of other customers, trade secrets and the integrity of the systems must be appropriately protected.

15. Customer Obligations

The Customer is responsible for the lawfulness of the collection, use and transmission of the personal data it provides and for the permissibility of its instructions. In particular, it ensures that required information obligations are fulfilled and appropriate legal bases are available.

SOF AI is not designed as intended for processing special categories of personal data under Art. 9 GDPR or data relating to criminal convictions and offences. The Customer should provide such data only where this is necessary for an appropriate and legally permissible use case and the additional safeguards required for that purpose are satisfied.

16. Precedence, Entry into Effect and Electronic Form

In the event of conflicts between this DPA and the Main Agreement, the provisions of this DPA prevail with respect to processing personal data on behalf of the Customer.

This DPA becomes effective as soon as it is accepted by the Customer in text form or electronically, or is otherwise agreed between the parties. An electronic agreement satisfies the form requirement of Art. 28 GDPR.

Where accepted electronically, at least the relevant customer/contract identifier, the applicable version or version date of this DPA and the time of acceptance must be documented in a manner that allows the acceptance to be verified later.

In all other respects, the provisions of the Main Agreement apply. Amendments to this DPA require at least text form unless a stricter form is prescribed by law.

ANNEX 1 – Details of the Processing on Behalf of the Customer

CharacteristicDescription
Subject matterProvision of the cloud-based SOF AI platform and the functions selected by the Customer.
DurationFor the duration of the Main Agreement or until the relevant data processed on behalf of the Customer is deleted or returned; backups follow the documented backup lifecycle.
Nature of processingCollection through Customer input, storage, organization, retrieval, analysis, transmission to authorized subprocessors, generation, linking, provision, return and deletion.
PurposesProject and workspace management, research, analysis, content planning, text/metadata generation, QA, internal linking and provision of results.
Data subjectsEmployees, contact persons, customers, prospects, authors, website users or other persons whose personal data the business Customer provides in Customer Content.
Categories of dataMaster and contact data, professional information, online/identification data, URLs, texts, files, communication content, project and research information, and other personal data provided by the Customer.
Special categories / criminal dataNot intended as part of the standard use. Processing only where the Customer lawfully provides such data for an appropriate use case and the required additional conditions are satisfied.
Customer rights and obligationsTo the extent that it is the controller, the Customer determines the purpose and permissible instructions for processing on its behalf and exercises in particular its rights to issue instructions, receive information, carry out controls, request deletion/return and object under this DPA.

ANNEX 2 – Technical and Organizational Measures (TOMs)

MeasureImplementation
Authentication and sessionsBackend-managed authentication and sessions; technically necessary session/CSRF protection mechanisms. The login tunnel does not store passwords, session tokens or CSRF tokens in localStorage or sessionStorage.
Separation of permissions and functionsSeparate Customer and admin areas and protected admin functions; access to protected functions only in an authenticated context.
CSRF protectionCredentialed requests and CSRF cookie/header binding for write operations and protected dashboard functions, where provided for the relevant route.
HostingVPS infrastructure of IONOS SE; the VPS used is assigned to the Europe data center region.
Backups and recoveryDaily Restic backups, regular verification and restore tests; rotating retention of 7 daily / 4 weekly / 12 monthly snapshots with repository pruning.
Logging and security analysisTechnical login/security and comparable log data generally for up to 90 days; longer retention only where required for a specific security incident, abuse prevention, legal defense or a statutory obligation.
Data minimization for external servicesTransmission only of Inputs, project information, research contexts and technical instructions required for the respective processing step; not every request is sent to every provider.
Change and recovery securityControlled changes with baseline checks, BEFORE/AFTER backups and verifiable rollback/restore procedures for material production changes.

ANNEX 3 – Approved Subprocessors

This Annex concerns only providers that may process Customer Content as part of processing on behalf of the Customer. Paddle is not listed as a subprocessor for Customer Content because Paddle processes payment and buyer data as Merchant of Record under its own responsibility as controller.

ProviderLocationPurposeContractual safeguard
IONOS SEGermany / EuropeVPS hosting, storage and technical infrastructureIONOS DPA; for new contracts since 19 July 2022, part of the IONOS terms and conditions.
OpenAI Ireland Ltd.Ireland; additional processing locations in accordance with the provider DPAOpenAI API for generative AI, analysis and inferenceOpenAI Data Processing Addendum; for EEA/Switzerland customers, the contracting party is OpenAI Ireland Ltd.; transfer mechanisms in accordance with the DPA.
Anthropic Ireland, LimitedIreland; additional processing locations in accordance with the provider DPAAnthropic API / Claude for generative AI and analysisThe Anthropic Data Processing Addendum is incorporated into the Commercial Terms; for EEA/Switzerland/UK customers, the contracting party is Anthropic Ireland, Limited.
Google Cloud EMEA LimitedIreland; additional processing locations in accordance with the Google DPAGemini API Paid Services for generative AI and analysisGemini API Paid Services; processing of prompts/responses under Google’s Data Processing Addendum for Products where Google is a Data Processor; EMEA contracting party in accordance with Google’s entity rules.
Perplexity AI, Inc.USA; additional processing locations in accordance with the provider DPAPerplexity Sonar API for web-assisted research and answersThe Perplexity API Terms incorporate the DPA; processor-to-processor SCCs or other transfer mechanisms under the DPA, where required.

Electronic Acceptance / Contractual Evidence

Where this DPA is accepted electronically, the acceptance must be documented in a verifiable manner with the customer/contract identifier, version/version date and time of acceptance.