Binding language version
Only the German version of this data processing agreement (Auftragsverarbeitungsvertrag) is legally binding and is the version that is concluded. This English text is a non-binding convenience translation provided for information purposes only. In the event of any discrepancy or conflict between the German and the English version, the German version prevails.
Data Processing Agreement
pursuant to Art. 28 GDPR
between
Example Company Ltd.
Example Street 123, 12345 Example City
– hereinafter referred to as the “Controller” –
and
neuland.ai AG
Konrad-Adenauer-Ufer 83, 50668 Cologne, Germany
– hereinafter referred to as the “Processor” –
Binding language version
Only the German version of this data processing agreement (Auftragsverarbeitungsvertrag) is legally binding and is the version that is concluded. This English text is a non-binding convenience translation provided for information purposes only. In the event of any discrepancy or conflict between the German and the English version, the German version prevails.
I. Subject matter of the processing
Subject matter and purposes of the processing
The services covered by this agreement are as follows:
Development and adaptation of AI models
Data is processed exclusively on behalf of the Controller in order to test and evaluate AI algorithms.
The aim is to improve the performance of the AI algorithms for the Controller by enabling them to recognise patterns, make predictions and take decisions in an automated manner on the basis of the data provided. This also includes the continuous adaptation and optimisation of the models in order to adjust them to changing requirements or new data sets.
Note on the use of data in AI systems
The Processor warrants that all data processed within this contractual relationship is used exclusively to perform the contractually agreed services for the Controller. In particular, it is excluded that data collected, transmitted or generated in connection with this agreement — in whatever form — is used for the (further) development, optimisation or training of AI-supported systems or products outside this specific contractual relationship.
Any use of the data, or of insights derived from it, to improve other products, services or models of the Processor or of third parties — including use for the purposes of machine learning, fine-tuning, cross-domain learning or other forms of system optimisation — is expressly excluded.
By means of technical and organisational measures, the Processor ensures that all of the Controller's data is processed in isolation and at no time flows into shared or centralised training data pools, model architectures or databases.
This obligation continues to apply after the end of the contractual relationship.
Amendments
Amendments to the subject matter of the processing shall be agreed jointly between the Controller and the Processor and set down in writing or in a documented electronic format.
II. Place of processing
The contractually agreed service is provided exclusively in a Member State of the European Union or in a state party to the Agreement on the European Economic Area .
Any relocation of the service or of parts of the work to a third country requires the prior consent (in writing or by email) of the Controller and may only take place if the specific requirements of Art. 44 et seq. GDPR are met (e. g. an adequacy decision of the Commission, standard data protection clauses and, where applicable, additional safeguards, approved codes of conduct).
III. Duration of the processing
General
The duration of this agreement corresponds to the term of the respective main agreement.
Special provision
Notwithstanding the preceding paragraph, this agreement applies for as long as the Processor processes personal data of the Controller (including backups).
Extraordinary right of termination
The Controller may terminate this agreement at any time without notice if there is a serious breach by the Processor of data protection provisions or of the terms of this agreement, if the Processor cannot or will not carry out an instruction of the Controller, or if the Processor refuses the Controller's audit rights in breach of this agreement.
In particular, failure to comply with the obligations agreed in this agreement and derived from Art. 28 GDPR constitutes a serious breach.
IV. Nature of the processing
The nature of the processing may comprise any one or all of the following processing operations:
- collection and recording
- organisation and structuring
- storage, adaptation or alteration
- retrieval and consultation
- disclosure by transmission, dissemination or otherwise making available
- alignment or combination
- restriction, erasure or destruction
V. Categories of data subjects
Personal data of the following categories of data subjects is processed:
VI. Types of personal data
The following personal data is processed:
VII. Obligations and rights of the Controller
General
The Controller alone is responsible for assessing the lawfulness of the processing pursuant to Art. 6(1) GDPR and for safeguarding the rights of data subjects under Art. 12 to 22 GDPR.
Notification obligations
The Controller is obliged to inform the Processor without undue delay and in full if errors, disruptions or other irregularities in relation to the processing are identified with regard to data protection provisions.
VIII. Controller's right to issue instructions
General
The Controller has the right to issue instructions to the Processor regarding the nature, scope and procedure of the data processing. The Controller decides alone and exclusively on the purposes and means of processing the commissioned data. The Processor may process the commissioned data only on documented instructions from the Controller, unless the Processor is legally obliged to process such data. In such a case, the Processor shall inform the Controller of those legal requirements before processing, unless the law in question prohibits such notification on important grounds of public interest.
Instructions shall be retained for the period of their validity and thereafter for three full calendar years following the end of the calendar year.
Persons authorised to issue and to receive instructions
The persons authorised to issue instructions on behalf of the Controller and the recipients of instructions at the Processor are listed in the annex “Persons authorised to issue and receive instructions” to this agreement.
In the event of a change of contact person or a prolonged absence, the successors or deputies shall be notified to the contracting partner without undue delay and generally in writing or electronically.
Specificity and form of instructions
Instructions shall be issued in specific terms (requirement of clarity of instructions). Instructions may be issued in writing, in text form or, in urgent cases, orally.
The Controller must confirm oral instructions without undue delay in writing or in text form.
Notification in the event of unlawfulness
The Processor shall inform the Controller without undue delay if it considers an instruction to be unlawful. This duty to give notice does not entail a comprehensive legal review. The Processor is entitled to suspend the execution of the instruction in question until it is confirmed or amended by the Controller.
Instructions outside the scope of the engagement
The Processor decides on the execution of instructions from the Controller that go beyond the subject matter governed by this agreement. In such a case the Processor may, subject to prior consultation and prior consent of the Controller, claim separate remuneration.
Recourse
If, as a result of implementing an unlawful instruction, the Processor is exposed to a justified liability claim, it may seek indemnification from the Controller to that extent.
Changes to procedures
Changes to procedures shall be agreed jointly between the Controller and the Processor and set down in writing or in a documented electronic format.
IX. Ensuring the obligation of confidentiality
Data secrecy and telecommunications secrecy
Every person under the Processor's authority who has access to commissioned data is bound to confidentiality, in particular pursuant to Art. 5(1)(f), Art. 28(3)(b), Art. 29 and Art. 32(4) GDPR and Section 3 TDDDG.
The obligation of confidentiality continues to apply after the end of this agreement.
Instruction of personnel
By means of appropriate measures, in particular regular data protection training, the Processor ensures that the persons under its authority who are authorised to process commissioned data are familiar with the relevant provisions on data secrecy and telecommunications secrecy.
X. Technical and organisational measures
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, the Processor implements appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
The agreed technical and organisational measures are subject to technical progress and further development. The Processor is therefore permitted to implement alternative, adequate measures in future. In doing so, the security level of the specified measures must not be reduced. The Controller shall be informed without undue delay of any material changes, which must be documented by the Processor.
The overview of the material technical and organisational measures is maintained separately.
XI. Conditions for engaging further processors
Definition of subprocessor
Subprocessing relationships within the meaning of this provision are those services that relate directly to the provision of the main service. This does not include ancillary services used by the Processor, provided and to the extent that access to personal data covered by this agreement is excluded. Likewise, basic telecommunications services, postal and transport services do not constitute processing or subprocessing. However, in order to ensure the protection and security of the Controller's data, the Processor is obliged to put in place appropriate and legally compliant contractual arrangements and control measures for outsourced ancillary services as well.
Conditions for the admissibility of the engagement
The Controller hereby grants the Processor general authorisation to engage subprocessors. The Processor is obliged to inform the Controller of any intended change concerning the addition or replacement of other processors, giving one (1) month's notice. The Controller must raise any objection to the change with the Processor within one (1) month of receiving the information about the change. In the event of an objection, the Processor may, at its own discretion, provide the service without the intended change or — if providing the service without the Processor's intended change is unreasonable — terminate the service affected by the change vis-à-vis the Controller within one (1) month of receipt of the objection.
Level of data protection at the subprocessor
Before processing activities begin, every subprocessor is obliged to undertake to comply with the same data protection obligations as agreed in this agreement, unless expressly agreed otherwise. The subprocessing agreement must at least ensure the level of data protection required under this agreement. In particular, every subprocessor must undertake to comply with the agreed technical and organisational security measures pursuant to Art. 32 GDPR and to provide the Processor with a list of the technical and organisational measures implemented, which is made available to the Controller on request. The subprocessor's measures may deviate from those agreed between the Controller and the Processor, but must not fall below the level of data protection ensured by the Processor's measures. If a subprocessor refuses to submit to the same data protection obligations as set out in this agreement, engaging that subprocessor requires the Controller's consent, which must not be unreasonably withheld. If the subprocessor fails to meet its data protection obligations, the Processor is liable to the Controller for the subprocessor's compliance with its obligations pursuant to Art. 28(4) GDPR. In such a case, at the Controller's request, the Processor must terminate the engagement of the subprocessor in whole or in part, or dissolve the contractual relationship with the subprocessor, if and to the extent that this is not disproportionate.
Level of data protection at the subprocessor
In the event that a subprocessor is established in a third country that does not provide an adequate level of data protection pursuant to Art. 45 GDPR, the Processor will take sufficient account of this circumstance. The Processor will conclude appropriate standard data protection clauses for the third-country transfer with that subprocessor (COMMISSION IMPLEMENTING DECISION (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council). In this context, the effects of the CJEU's Schrems II ruling must be taken into account and, where necessary, additional safeguards for securing the data must be implemented by the Processor or agreed with the subcontractor.
The current list of engaged subprocessors is maintained separately.
XII. Assistance with data subject requests
General
Within its area of responsibility and as far as possible, the Processor assists the Controller by appropriate technical and organisational measures in responding to and implementing requests from data subjects regarding their data protection rights.
Documentation
The Processor may not provide information about, port, rectify, erase or restrict the processing of the data processed on behalf of the Controller on its own initiative, but only on documented instructions from the Controller.
Duty to inform
Where a data subject contacts the Processor directly in this regard, the Processor will forward that request to the Controller without undue delay.
Handling of data subject rights by the Processor
The rights of access, rectification, restriction of processing, erasure and data portability may be ensured directly by the Processor on documented instructions from the Controller. Where the associated measures exceed the reasonable assistance owed by the Processor, the Processor may, subject to prior consultation and prior consent of the Controller, claim separate remuneration.
XIII. Assistance to the Controller in complying with the obligations under Art. 32-36 GDPR
Compliance with the obligations under Art. 32 GDPR (technical and organisational measures)
The Processor assists the Controller in ensuring an appropriate level of protection through technical and organisational measures that take into account the circumstances and purposes of the processing as well as the projected likelihood and severity of a possible infringement of rights due to security vulnerabilities, and that in particular ensure protection against accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored or otherwise processed.
Compliance with the obligations under Art. 33 GDPR (notification of a personal data breach to the supervisory authority)
The Processor assists the Controller in notifying personal data breaches to the competent supervisory authority. The Processor notifies the Controller of a personal data breach without undue delay and, where possible, within 24 hours of becoming aware of the breach, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.
Compliance with the obligations under Art. 34 GDPR (communication of a personal data breach to the data subject)
The Processor assists the Controller in communicating a personal data breach to the data subject where that breach is likely to result in a high risk to the personal rights and freedoms of natural persons.
Compliance with the obligations under Art. 35 GDPR (data protection impact assessment)
The Processor assists the Controller in carrying out a data protection impact assessment and in the prior consultation of the supervisory authority where processing would result in a high risk to the rights and freedoms of natural persons.
Compliance with the obligations under Art. 36 GDPR (prior consultation)
The Processor assists the Controller in the prior consultation of the supervisory authority where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the Controller to mitigate the risk.
XIV. Erasure and return of the data
Erasure after the end of the agreement
After the end of the provision of the processing services, the Processor erases all personal data and existing copies, unless storage of the personal data is required under Union law or the law of the Member States.
Return on instruction
On documented instructions from the Controller, the Processor returns all personal data or erases it and destroys existing copies, unless storage is required under Union law or the law of the Member States.
Evidence of erasure
The Processor provides the Controller with evidence of the proper erasure or return of the data.
XV. Controller's audit rights
General right of audit
The Controller has the right to verify the Processor's compliance with data protection provisions by appropriate means. This includes in particular obtaining information and evidence, inspecting the data processing systems used and carrying out other on-site checks.
Right to information
On request, the Processor provides the Controller with all necessary information and demonstrates in particular the implementation of the technical and organisational measures.
Inspections and audits
The Processor allows for and contributes to inspections — including audits — conducted by the Controller. This also includes inspections by another auditor mandated by the Controller.
XVI. Notification obligations
Disruptions and data protection breaches
The Processor notifies without undue delay any disruptions that may have a significant impact on the processing of the Controller's personal data. This applies in particular to personal data breaches.
Measures taken by authorities
The Processor informs the Controller without undue delay of inspections by the supervisory authority or other third parties, in so far as they relate to the engagement.
Suspected data protection breaches
If breaches of data protection provisions in connection with the commissioned data are suspected, the Processor informs the Controller without undue delay.
XVII. Liability and damages
Liability under the GDPR
Any party that has suffered damage as a result of processing is entitled to compensation from the Controller or from the Processor for the damage suffered pursuant to Art. 82 GDPR.
Joint and several liability
Where both a controller and a processor are involved in the same processing and are responsible for damage caused by the processing pursuant to paragraphs 2 and 4 of Art. 82 GDPR, each of them is liable for the entire damage in order to ensure effective compensation of the data subject.
Recourse
Where a controller or processor has, pursuant to paragraph 5 of Art. 82 GDPR, paid full compensation for the damage suffered, that party is entitled to claim back from the other controllers or processors involved in the same processing that part of the compensation corresponding to their part of responsibility for the damage, in accordance with the conditions set out in paragraph 2 of Art. 82 GDPR.
Signatures
Controller:
Processor:
Annex
Supplementary agreement BRAO: confidentiality undertaking and instruction
to the data processing agreement
1. Scope
This supplementary agreement applies to customers who fall within the scope of the German Federal Lawyers' Act (BRAO), in respect of the dedicated instance provided by neuland.ai AG. neuland.ai AG makes no assurances in respect of the "neuland.ai HUB" in this regard and this supplementary agreement does not apply to it.
2. Confidentiality
neuland.ai AG hereby undertakes towards the Customer to keep all confidential information obtained strictly secret and to protect it against access by third parties.
3. Obligation of staff
neuland.ai AG ensures that all employees involved in the processing, as well as other persons acting for neuland.ai AG (e. g. subprocessors) who may gain access to confidential information, are bound to confidentiality in text form and instructed about the criminal consequences of a breach of duty.
4. Obtaining knowledge
neuland.ai AG may obtain knowledge of confidential information only in so far as this is necessary for the obligations set out in the main agreement. neuland.ai AG is entitled to engage subprocessors to perform the agreement, provided that they are carefully selected, bound to secrecy in text form and instructed about the criminal consequences of a breach of duty. Subprocessors abroad may only be engaged if the protection of secrets existing there is comparable to the protection within Germany.
5. Instruction on criminal liability
The Customer hereby instructs neuland.ai AG that a breach of confidentiality or the exploitation of another party's secrets by neuland.ai AG is a criminal offence for the persons involved (Sections 203(1), 203(4) sentence 1 StGB, Section 204 StGB) and may be punished by imprisonment of up to one year, in the case of Section 204 StGB by imprisonment of up to two years, or by a fine. The penalty increases to imprisonment of up to two years or a fine where the person concerned acts with the intention of obtaining a benefit, even if for the benefit of a third party, or with the intention of harming another person by the act.
6. Engagement of further persons
As a precaution, the Customer instructs neuland.ai AG that persons involved commit a criminal offence punishable by imprisonment of up to one year or a fine where further persons are engaged, if such further person breaches confidentiality and the person involved has at the same time failed to ensure that the former was bound to confidentiality (Sections 203(1), 203(4) sentence 2 no. 2 StGB). The penalty increases to imprisonment of up to two years or a fine where the offender acts with the intention of obtaining a benefit, even if for the benefit of a third party, or with the intention of harming another person by the act. This obligation applies to all further subcontracting.
7. Statutory annexes
This instruction also includes the wording of the relevant statutes, attached as an annex in their current version — in particular Section 43e BRAO, Section 203 StGB and Sections 53a and 97 StPO.
8. Protective measures
neuland.ai AG will maintain appropriate organisational and technical measures to protect the confidentiality of the confidential information and undertakes to protect confidential information appropriately in accordance with accepted security standards reflecting the state of the art. The level of security applied must not be lower than that applied to its own confidential information.
9. Duration
The confidentiality undertaking under this agreement applies without any time limit.
10. Procedural protection (StPO)
The Customer informs neuland.ai AG that the processing may also involve data subject to a lawyer's professional secrecy within the meaning of the BRAO and Section 203 StGB.
Right to refuse to give evidence (Section 53a StPO)
Data processed by neuland.ai AG on behalf of a professional bound by professional secrecy may be subject to the right of the persons involved to refuse to give evidence (Section 53a of the German Code of Criminal Procedure, StPO). The professional bound by professional secrecy, as the Customer, decides whether that right is exercised.
If neuland.ai AG is required by law enforcement or other authorities to disclose information or give evidence that may be subject to professional secrecy, neuland.ai AG will object with reference to Section 53a StPO and inform the Customer without undue delay so that the Customer can decide whether to invoke the right to refuse to give evidence.
Protection against seizure (Section 97 StPO)
Data protected by professional secrecy that is in the custody of neuland.ai AG may be subject to the prohibition of seizure under Section 97 StPO, in particular in so far as the right of the persons involved to refuse to give evidence under Section 53a StPO applies.
neuland.ai AG does not release such data without the consent of the Customer (the professional bound by professional secrecy). In the event of a seizure or comparable access by authorities, neuland.ai AG will object to that measure and inform the Customer without undue delay.
Subprocessing
The obligations regarding the right to refuse to give evidence and protection against seizure apply accordingly to all subprocessors that may gain access to data protected by professional secrecy in the course of performing the agreement. neuland.ai AG ensures that subprocessors are informed of these rights and obligations.
Professional-law basis — lawyers
Section 43e Federal Lawyers' Act (BRAO) and Section 203 Criminal Code (StGB)
Bundesrechtsanwaltsordnung (BRAO)
§ 43e Inanspruchnahme von Dienstleistungen
The provision is reproduced below in its binding German wording. The German Federal Ministry of Justice publishes an official English translation, which — like this Trust Center's English pages — is a convenience translation without legal force. Only the German wording is legally binding.
Full text of the provision: gesetze-im-internet.de (German)
Official English translation: Section 43e – Availment of services
Binding German wording
(1) Der Rechtsanwalt darf Dienstleistern den Zugang zu Tatsachen eröffnen, auf die sich die Verpflichtung zur Verschwiegenheit gemäß § 43a Absatz 2 Satz 1 bezieht, soweit dies für die Inanspruchnahme der Dienstleistung erforderlich ist. Dienstleister ist eine andere Person oder Stelle, die vom Rechtsanwalt im Rahmen seiner Berufsausübung mit Dienstleistungen beauftragt wird.
(2) Der Rechtsanwalt ist verpflichtet, den Dienstleister sorgfältig auszuwählen. Er hat die Zusammenarbeit unverzüglich zu beenden, wenn die Einhaltung der dem Dienstleister gemäß Absatz 3 zu machenden Vorgaben nicht gewährleistet ist.
(3) Der Vertrag mit dem Dienstleister bedarf der Textform. In ihm ist
- der Dienstleister unter Belehrung über die strafrechtlichen Folgen einer Pflichtverletzung zur Verschwiegenheit zu verpflichten,
- der Dienstleister zu verpflichten, sich nur insoweit Kenntnis von fremden Geheimnissen zu verschaffen, als dies zur Vertragserfüllung erforderlich ist, und
- festzulegen, ob der Dienstleister befugt ist, weitere Personen zur Erfüllung des Vertrags heranzuziehen; für diesen Fall ist dem Dienstleister aufzuerlegen, diese Personen in Textform zur Verschwiegenheit zu verpflichten.
(4) Bei der Inanspruchnahme von Dienstleistungen, die im Ausland erbracht werden, darf der Rechtsanwalt dem Dienstleister den Zugang zu fremden Geheimnissen unbeschadet der übrigen Voraussetzungen dieser Vorschrift nur dann eröffnen, wenn der dort bestehende Schutz der Geheimnisse dem Schutz im Inland vergleichbar ist, es sei denn, dass der Schutz der Geheimnisse dies nicht gebietet.
(5) Bei der Inanspruchnahme von Dienstleistungen, die unmittelbar einem einzelnen Mandat dienen, darf der Rechtsanwalt dem Dienstleister den Zugang zu fremden Geheimnissen nur dann eröffnen, wenn der Mandant darin eingewilligt hat.
(6) Die Absätze 2 und 3 gelten auch im Fall der Inanspruchnahme von Dienstleistungen, in die der Mandant eingewilligt hat, sofern der Mandant nicht ausdrücklich auf die Einhaltung der in den Absätzen 2 und 3 genannten Anforderungen verzichtet hat.
(7) Die Absätze 1 bis 6 gelten nicht, soweit Dienstleistungen auf Grund besonderer gesetzlicher Vorschriften in Anspruch genommen werden. Absatz 3 Satz 2 gilt nicht, soweit der Dienstleister hinsichtlich der zu erbringenden Dienstleistung gesetzlich zur Verschwiegenheit verpflichtet ist.
(8) Die Vorschriften zum Schutz personenbezogener Daten bleiben unberührt.
Strafgesetzbuch (StGB)
§ 203 Verletzung von Privatgeheimnissen
The provision is reproduced below in its binding German wording. The German Federal Ministry of Justice publishes an official English translation, which — like this Trust Center's English pages — is a convenience translation without legal force. Only the German wording is legally binding.
Full text of the provision: gesetze-im-internet.de (German)
Official English translation: Section 203 – Violation of private secrets
Binding German wording
(1) Wer unbefugt ein fremdes Geheimnis, namentlich ein zum persönlichen Lebensbereich gehörendes Geheimnis oder ein Betriebs- oder Geschäftsgeheimnis, offenbart, das ihm als
- Arzt, Zahnarzt, Tierarzt, Apotheker oder Angehörigen eines anderen Heilberufs, der für die Berufsausübung oder die Führung der Berufsbezeichnung eine staatlich geregelte Ausbildung erfordert,
- Berufspsychologen mit staatlich anerkannter wissenschaftlicher Abschlußprüfung,
- Rechtsanwalt, Kammerrechtsbeistand, Patentanwalt, Notar, Verteidiger in einem gesetzlich geordneten Verfahren, Wirtschaftsprüfer, vereidigtem Buchprüfer, Steuerberater, Steuerbevollmächtigten,
- Organ oder Mitglied eines Organs einer Wirtschaftsprüfungs-, Buchprüfungs- oder einer Berufsausübungsgesellschaft von Steuerberatern und Steuerbevollmächtigten, einer Berufsausübungsgesellschaft von Rechtsanwälten oder europäischen niedergelassenen Rechtsanwälten oder einer Berufsausübungsgesellschaft von Patentanwälten oder niedergelassenen europäischen Patentanwälten im Zusammenhang mit der Beratung und Vertretung der Wirtschaftsprüfungs-, Buchprüfungs- oder Berufsausübungsgesellschaft im Bereich der Wirtschaftsprüfung, Buchprüfung oder Hilfeleistung in Steuersachen oder ihrer rechtsanwaltlichen oder patentanwaltlichen Tätigkeit,
- Ehe-, Familien-, Erziehungs- oder Jugendberater sowie Berater für Suchtfragen in einer Beratungsstelle, die von einer Behörde oder Körperschaft, Anstalt oder Stiftung des öffentlichen Rechts anerkannt ist,
- Mitglied oder Beauftragten einer anerkannten Beratungsstelle nach den §§ 3 und 8 Absatz 1 des Schwangerschaftskonfliktgesetzes,
- staatlich anerkanntem Sozialarbeiter oder staatlich anerkanntem Sozialpädagogen oder
- Angehörigen eines Unternehmens der privaten Kranken-, Unfall- oder Lebensversicherung oder einer privatärztlichen, steuerberaterlichen oder anwaltlichen Verrechnungsstelle
anvertraut worden oder sonst bekanntgeworden ist, wird mit Freiheitsstrafe bis zu einem Jahr oder mit Geldstrafe bestraft.
(2) Ebenso wird bestraft, wer unbefugt ein fremdes Geheimnis, namentlich ein zum persönlichen Lebensbereich gehörendes Geheimnis oder ein Betriebs- oder Geschäftsgeheimnis, offenbart, das ihm als
- Amtsträger oder Europäischer Amtsträger,
- für den öffentlichen Dienst besonders Verpflichteten,
- Person, die Aufgaben oder Befugnisse nach dem Personalvertretungsrecht wahrnimmt,
- Mitglied eines für ein Gesetzgebungsorgan des Bundes oder eines Landes tätigen Untersuchungsausschusses, sonstigen Ausschusses oder Rates, das nicht selbst Mitglied des Gesetzgebungsorgans ist, oder als Hilfskraft eines solchen Ausschusses oder Rates,
- öffentlich bestelltem Sachverständigen, der auf die gewissenhafte Erfüllung seiner Obliegenheiten auf Grund eines Gesetzes förmlich verpflichtet worden ist, oder
- Person, die auf die gewissenhafte Erfüllung ihrer Geheimhaltungspflicht bei der Durchführung wissenschaftlicher Forschungsvorhaben auf Grund eines Gesetzes förmlich verpflichtet worden ist,
anvertraut worden oder sonst bekanntgeworden ist. Einem Geheimnis im Sinne des Satzes 1 stehen Einzelangaben über persönliche oder sachliche Verhältnisse eines anderen gleich, die für Aufgaben der öffentlichen Verwaltung erfaßt worden sind; Satz 1 ist jedoch nicht anzuwenden, soweit solche Einzelangaben anderen Behörden oder sonstigen Stellen für Aufgaben der öffentlichen Verwaltung bekanntgegeben werden und das Gesetz dies nicht untersagt.
(3) Kein Offenbaren im Sinne dieser Vorschrift liegt vor, wenn die in den Absätzen 1 und 2 genannten Personen Geheimnisse den bei ihnen berufsmäßig tätigen Gehilfen oder den bei ihnen zur Vorbereitung auf den Beruf tätigen Personen zugänglich machen. Die in den Absätzen 1 und 2 Genannten dürfen fremde Geheimnisse gegenüber sonstigen Personen offenbaren, die an ihrer beruflichen oder dienstlichen Tätigkeit mitwirken, soweit dies für die Inanspruchnahme der Tätigkeit der sonstigen mitwirkenden Personen erforderlich ist; das Gleiche gilt für sonstige mitwirkende Personen, wenn diese sich weiterer Personen bedienen, die an der beruflichen oder dienstlichen Tätigkeit der in den Absätzen 1 und 2 Genannten mitwirken.
(4) Mit Freiheitsstrafe bis zu einem Jahr oder mit Geldstrafe wird bestraft, wer unbefugt ein fremdes Geheimnis offenbart, das ihm bei der Ausübung oder bei Gelegenheit seiner Tätigkeit als mitwirkende Person oder als bei den in den Absätzen 1 und 2 genannten Personen tätiger Datenschutzbeauftragter bekannt geworden ist. Ebenso wird bestraft, wer
- als in den Absätzen 1 und 2 genannte Person nicht dafür Sorge getragen hat, dass eine sonstige mitwirkende Person, die unbefugt ein fremdes, ihr bei der Ausübung oder bei Gelegenheit ihrer Tätigkeit bekannt gewordenes Geheimnis offenbart, zur Geheimhaltung verpflichtet wurde; dies gilt nicht für sonstige mitwirkende Personen, die selbst eine in den Absätzen 1 oder 2 genannte Person sind,
- als im Absatz 3 genannte mitwirkende Person sich einer weiteren mitwirkenden Person, die unbefugt ein fremdes, ihr bei der Ausübung oder bei Gelegenheit ihrer Tätigkeit bekannt gewordenes Geheimnis offenbart, bedient und nicht dafür Sorge getragen hat, dass diese zur Geheimhaltung verpflichtet wurde; dies gilt nicht für sonstige mitwirkende Personen, die selbst eine in den Absätzen 1 oder 2 genannte Person sind, oder
- nach dem Tod der nach Satz 1 oder nach den Absätzen 1 oder 2 verpflichteten Person ein fremdes Geheimnis unbefugt offenbart, das er von dem Verstorbenen erfahren oder aus dessen Nachlass erlangt hat.
(5) Die Absätze 1 bis 4 sind auch anzuwenden, wenn der Täter das fremde Geheimnis nach dem Tod des Betroffenen unbefugt offenbart.
(6) Handelt der Täter gegen Entgelt oder in der Absicht, sich oder einen anderen zu bereichern oder einen anderen zu schädigen, so ist die Strafe Freiheitsstrafe bis zu zwei Jahren oder Geldstrafe.
Annex
Supplementary agreement StBerG: confidentiality undertaking and instruction
to the data processing agreement
1. Scope
This supplementary agreement applies to customers who are tax advisors or tax agents within the meaning of the German Tax Advisory Act (StBerG), in respect of the dedicated instance provided by neuland.ai AG. neuland.ai AG makes no assurances in respect of the "neuland.ai HUB" in this regard and this supplementary agreement does not apply to it.
2. Confidentiality
neuland.ai AG hereby undertakes towards the Customer to keep all confidential information obtained strictly secret and to protect it against access by third parties.
3. Obligation of staff
neuland.ai AG ensures that all employees involved in the processing, as well as other persons acting for neuland.ai AG (e. g. subprocessors) who may gain access to confidential information, are bound to confidentiality in text form and instructed about the criminal consequences of a breach of duty.
4. Obtaining knowledge
neuland.ai AG may obtain knowledge of confidential information only in so far as this is necessary for the obligations set out in the main agreement. neuland.ai AG is entitled to engage subprocessors to perform the agreement, provided that they are carefully selected, bound to secrecy in text form and instructed about the criminal consequences of a breach of duty. Subprocessors abroad may only be engaged if the protection of secrets existing there is comparable to the protection within Germany.
5. Instruction on criminal liability
The Customer hereby instructs neuland.ai AG that a breach of confidentiality or the exploitation of another party's secrets by neuland.ai AG is a criminal offence for the persons involved (Sections 203(1), 203(4) sentence 1 StGB, Section 204 StGB) and may be punished by imprisonment of up to one year, in the case of Section 204 StGB by imprisonment of up to two years, or by a fine. The penalty increases to imprisonment of up to two years or a fine where the person concerned acts with the intention of obtaining a benefit, even if for the benefit of a third party, or with the intention of harming another person by the act.
6. Engagement of further persons
As a precaution, the Customer instructs neuland.ai AG that persons involved commit a criminal offence punishable by imprisonment of up to one year or a fine where further persons are engaged, if such further person breaches confidentiality and the person involved has at the same time failed to ensure that the former was bound to confidentiality (Sections 203(1), 203(4) sentence 2 no. 2 StGB). The penalty increases to imprisonment of up to two years or a fine where the offender acts with the intention of obtaining a benefit, even if for the benefit of a third party, or with the intention of harming another person by the act. This obligation applies to all further subcontracting.
7. Statutory annexes
This instruction also includes the wording of the relevant statutes, attached as an annex in their current version — in particular Section 62a StBerG, Section 203 StGB and Sections 53a and 97 StPO.
8. Protective measures
neuland.ai AG will maintain appropriate organisational and technical measures to protect the confidentiality of the confidential information and undertakes to protect confidential information appropriately in accordance with accepted security standards reflecting the state of the art. The level of security applied must not be lower than that applied to its own confidential information.
9. Duration
The confidentiality undertaking under this agreement applies without any time limit.
10. Procedural protection (StPO)
The Customer informs neuland.ai AG that the processing may also involve data subject to a tax advisor's professional secrecy within the meaning of the StBerG and Section 203 StGB.
Right to refuse to give evidence (Section 53a StPO)
Data processed by neuland.ai AG on behalf of a professional bound by professional secrecy may be subject to the right of the persons involved to refuse to give evidence (Section 53a of the German Code of Criminal Procedure, StPO). The professional bound by professional secrecy, as the Customer, decides whether that right is exercised.
If neuland.ai AG is required by law enforcement or other authorities to disclose information or give evidence that may be subject to professional secrecy, neuland.ai AG will object with reference to Section 53a StPO and inform the Customer without undue delay so that the Customer can decide whether to invoke the right to refuse to give evidence.
Protection against seizure (Section 97 StPO)
Data protected by professional secrecy that is in the custody of neuland.ai AG may be subject to the prohibition of seizure under Section 97 StPO, in particular in so far as the right of the persons involved to refuse to give evidence under Section 53a StPO applies.
neuland.ai AG does not release such data without the consent of the Customer (the professional bound by professional secrecy). In the event of a seizure or comparable access by authorities, neuland.ai AG will object to that measure and inform the Customer without undue delay.
Subprocessing
The obligations regarding the right to refuse to give evidence and protection against seizure apply accordingly to all subprocessors that may gain access to data protected by professional secrecy in the course of performing the agreement. neuland.ai AG ensures that subprocessors are informed of these rights and obligations.
Professional-law basis — tax advisors
Section 62a Tax Advisory Act (StBerG) and Section 203 Criminal Code (StGB)
Steuerberatungsgesetz (StBerG)
§ 62a Inanspruchnahme von Dienstleistungen
There is no official English translation of the Tax Consultancy Act (Steuerberatungsgesetz). The English text below was translated by neuland.ai for information purposes only and has no legal force; only the German wording is legally binding.
Full text of the provision: gesetze-im-internet.de (German)
Non-official English translation
(1) Tax advisors and tax agents may give service providers access to facts to which the obligation of confidentiality in accordance with section 57 (1) applies to the extent that this is necessary to be able to avail themselves of such services. Service providers are other persons or agencies commissioned by the tax advisor or tax agent with rendering services in the exercise of their profession.
(2) Tax advisors and tax agents are obliged to carefully select their service providers. Cooperation must be immediately terminated where it can no longer be guaranteed that the service provider will be able to fulfil the requirements set out in subsection (3).
(3) Contracts with service providers must be made in text form. Such contracts must
- oblige the service provider to maintain confidentiality and advise of the consequences under criminal law of any violation of that obligation,
- oblige the service provider to obtain knowledge of others’ secrets only insofar as this is necessary in the fulfilment of the contract and
- stipulate whether the service provider is authorised to involve other persons in the fulfilment of the contract; where this is the case, the service provider must be required to oblige, in text form, those persons to maintain confidentiality.
(4) When availing themselves of services which are provided abroad, tax advisors and tax agents may only give the service provider access to others’ secrets, notwithstanding the other conditions set out in this provision, if the level of protection of secrets in the other country is comparable to that in Germany, unless this is not a requirement of the protection of secrets.
(5) Where tax advisors and tax agents avail themselves of services which directly serve an individual client, they may only grant service providers access to others’ secrets if the client has consented thereto.
(6) Subsections (2) and (3) also apply where tax advisors and tax agents avail themselves of services to which the client has consented, unless the client has expressly waived the need to observe the requirements set out in subsections (2) and (3).
(7) Subsections (1) to (6) do not apply where tax advisors and tax agents avail themselves of services on the basis of special statutory provisions. Subsection (3) sentence 2 does not apply if the service provider is bound by law to maintain confidentiality regarding the service to be rendered.
(8) Provisions concerning the protection of personal data remain unaffected.
Binding German wording
(1) Steuerberater und Steuerbevollmächtigte dürfen Dienstleistern den Zugang zu Tatsachen eröffnen, auf die sich die Verpflichtung zur Verschwiegenheit gemäß § 57 Absatz 1 bezieht, soweit dies für die Inanspruchnahme der Dienstleistung erforderlich ist. Dienstleister ist eine andere Person oder Stelle, die vom Steuerberater oder vom Steuerbevollmächtigten im Rahmen seiner Berufsausübung mit Dienstleistungen beauftragt wird.
(2) Steuerberater und Steuerbevollmächtigte sind verpflichtet, den Dienstleister sorgfältig auszuwählen. Die Zusammenarbeit muss unverzüglich beendet werden, wenn die Einhaltung der dem Dienstleister gemäß Absatz 3 zu machenden Vorgaben nicht gewährleistet ist.
(3) Der Vertrag mit dem Dienstleister bedarf der Textform. In ihm ist
- der Dienstleister unter Belehrung über die strafrechtlichen Folgen einer Pflichtverletzung zur Verschwiegenheit zu verpflichten,
- der Dienstleister zu verpflichten, sich nur insoweit Kenntnis von fremden Geheimnissen zu verschaffen, als dies zur Vertragserfüllung erforderlich ist, und
- festzulegen, ob der Dienstleister befugt ist, weitere Personen zur Erfüllung des Vertrags heranzuziehen; für diesen Fall ist dem Dienstleister aufzuerlegen, diese Personen in Textform zur Verschwiegenheit zu verpflichten.
(4) Bei der Inanspruchnahme von Dienstleistungen, die im Ausland erbracht werden, darf der Steuerberater und der Steuerbevollmächtigte dem Dienstleister den Zugang zu fremden Geheimnissen unbeschadet der übrigen Voraussetzungen dieser Vorschrift nur dann eröffnen, wenn der dort bestehende Schutz der Geheimnisse dem Schutz im Inland vergleichbar ist, es sei denn, dass der Schutz der Geheimnisse dies nicht gebietet.
(5) Bei der Inanspruchnahme von Dienstleistungen, die unmittelbar einem einzelnen Mandat dienen, darf der Steuerberater und der Steuerbevollmächtigte dem Dienstleister den Zugang zu fremden Geheimnissen nur dann eröffnen, wenn der Mandant darin eingewilligt hat.
(6) Die Absätze 2 und 3 gelten auch im Fall der Inanspruchnahme von Dienstleistungen, in die der Mandant eingewilligt hat, sofern der Mandant nicht ausdrücklich auf die Einhaltung der in den Absätzen 2 und 3 genannten Anforderungen verzichtet hat.
(7) Die Absätze 1 bis 6 gelten nicht, soweit Dienstleistungen auf Grund besonderer gesetzlicher Vorschriften in Anspruch genommen werden. Absatz 3 Satz 2 gilt nicht, soweit der Dienstleister hinsichtlich der zu erbringenden Dienstleistung gesetzlich zur Verschwiegenheit verpflichtet ist.
(8) Die Vorschriften zum Schutz personenbezogener Daten bleiben unberührt.
Strafgesetzbuch (StGB)
§ 203 Verletzung von Privatgeheimnissen
The provision is reproduced below in its binding German wording. The German Federal Ministry of Justice publishes an official English translation, which — like this Trust Center's English pages — is a convenience translation without legal force. Only the German wording is legally binding.
Full text of the provision: gesetze-im-internet.de (German)
Official English translation: Section 203 – Violation of private secrets
Binding German wording
(1) Wer unbefugt ein fremdes Geheimnis, namentlich ein zum persönlichen Lebensbereich gehörendes Geheimnis oder ein Betriebs- oder Geschäftsgeheimnis, offenbart, das ihm als
- Arzt, Zahnarzt, Tierarzt, Apotheker oder Angehörigen eines anderen Heilberufs, der für die Berufsausübung oder die Führung der Berufsbezeichnung eine staatlich geregelte Ausbildung erfordert,
- Berufspsychologen mit staatlich anerkannter wissenschaftlicher Abschlußprüfung,
- Rechtsanwalt, Kammerrechtsbeistand, Patentanwalt, Notar, Verteidiger in einem gesetzlich geordneten Verfahren, Wirtschaftsprüfer, vereidigtem Buchprüfer, Steuerberater, Steuerbevollmächtigten,
- Organ oder Mitglied eines Organs einer Wirtschaftsprüfungs-, Buchprüfungs- oder einer Berufsausübungsgesellschaft von Steuerberatern und Steuerbevollmächtigten, einer Berufsausübungsgesellschaft von Rechtsanwälten oder europäischen niedergelassenen Rechtsanwälten oder einer Berufsausübungsgesellschaft von Patentanwälten oder niedergelassenen europäischen Patentanwälten im Zusammenhang mit der Beratung und Vertretung der Wirtschaftsprüfungs-, Buchprüfungs- oder Berufsausübungsgesellschaft im Bereich der Wirtschaftsprüfung, Buchprüfung oder Hilfeleistung in Steuersachen oder ihrer rechtsanwaltlichen oder patentanwaltlichen Tätigkeit,
- Ehe-, Familien-, Erziehungs- oder Jugendberater sowie Berater für Suchtfragen in einer Beratungsstelle, die von einer Behörde oder Körperschaft, Anstalt oder Stiftung des öffentlichen Rechts anerkannt ist,
- Mitglied oder Beauftragten einer anerkannten Beratungsstelle nach den §§ 3 und 8 Absatz 1 des Schwangerschaftskonfliktgesetzes,
- staatlich anerkanntem Sozialarbeiter oder staatlich anerkanntem Sozialpädagogen oder
- Angehörigen eines Unternehmens der privaten Kranken-, Unfall- oder Lebensversicherung oder einer privatärztlichen, steuerberaterlichen oder anwaltlichen Verrechnungsstelle
anvertraut worden oder sonst bekanntgeworden ist, wird mit Freiheitsstrafe bis zu einem Jahr oder mit Geldstrafe bestraft.
(2) Ebenso wird bestraft, wer unbefugt ein fremdes Geheimnis, namentlich ein zum persönlichen Lebensbereich gehörendes Geheimnis oder ein Betriebs- oder Geschäftsgeheimnis, offenbart, das ihm als
- Amtsträger oder Europäischer Amtsträger,
- für den öffentlichen Dienst besonders Verpflichteten,
- Person, die Aufgaben oder Befugnisse nach dem Personalvertretungsrecht wahrnimmt,
- Mitglied eines für ein Gesetzgebungsorgan des Bundes oder eines Landes tätigen Untersuchungsausschusses, sonstigen Ausschusses oder Rates, das nicht selbst Mitglied des Gesetzgebungsorgans ist, oder als Hilfskraft eines solchen Ausschusses oder Rates,
- öffentlich bestelltem Sachverständigen, der auf die gewissenhafte Erfüllung seiner Obliegenheiten auf Grund eines Gesetzes förmlich verpflichtet worden ist, oder
- Person, die auf die gewissenhafte Erfüllung ihrer Geheimhaltungspflicht bei der Durchführung wissenschaftlicher Forschungsvorhaben auf Grund eines Gesetzes förmlich verpflichtet worden ist,
anvertraut worden oder sonst bekanntgeworden ist. Einem Geheimnis im Sinne des Satzes 1 stehen Einzelangaben über persönliche oder sachliche Verhältnisse eines anderen gleich, die für Aufgaben der öffentlichen Verwaltung erfaßt worden sind; Satz 1 ist jedoch nicht anzuwenden, soweit solche Einzelangaben anderen Behörden oder sonstigen Stellen für Aufgaben der öffentlichen Verwaltung bekanntgegeben werden und das Gesetz dies nicht untersagt.
(3) Kein Offenbaren im Sinne dieser Vorschrift liegt vor, wenn die in den Absätzen 1 und 2 genannten Personen Geheimnisse den bei ihnen berufsmäßig tätigen Gehilfen oder den bei ihnen zur Vorbereitung auf den Beruf tätigen Personen zugänglich machen. Die in den Absätzen 1 und 2 Genannten dürfen fremde Geheimnisse gegenüber sonstigen Personen offenbaren, die an ihrer beruflichen oder dienstlichen Tätigkeit mitwirken, soweit dies für die Inanspruchnahme der Tätigkeit der sonstigen mitwirkenden Personen erforderlich ist; das Gleiche gilt für sonstige mitwirkende Personen, wenn diese sich weiterer Personen bedienen, die an der beruflichen oder dienstlichen Tätigkeit der in den Absätzen 1 und 2 Genannten mitwirken.
(4) Mit Freiheitsstrafe bis zu einem Jahr oder mit Geldstrafe wird bestraft, wer unbefugt ein fremdes Geheimnis offenbart, das ihm bei der Ausübung oder bei Gelegenheit seiner Tätigkeit als mitwirkende Person oder als bei den in den Absätzen 1 und 2 genannten Personen tätiger Datenschutzbeauftragter bekannt geworden ist. Ebenso wird bestraft, wer
- als in den Absätzen 1 und 2 genannte Person nicht dafür Sorge getragen hat, dass eine sonstige mitwirkende Person, die unbefugt ein fremdes, ihr bei der Ausübung oder bei Gelegenheit ihrer Tätigkeit bekannt gewordenes Geheimnis offenbart, zur Geheimhaltung verpflichtet wurde; dies gilt nicht für sonstige mitwirkende Personen, die selbst eine in den Absätzen 1 oder 2 genannte Person sind,
- als im Absatz 3 genannte mitwirkende Person sich einer weiteren mitwirkenden Person, die unbefugt ein fremdes, ihr bei der Ausübung oder bei Gelegenheit ihrer Tätigkeit bekannt gewordenes Geheimnis offenbart, bedient und nicht dafür Sorge getragen hat, dass diese zur Geheimhaltung verpflichtet wurde; dies gilt nicht für sonstige mitwirkende Personen, die selbst eine in den Absätzen 1 oder 2 genannte Person sind, oder
- nach dem Tod der nach Satz 1 oder nach den Absätzen 1 oder 2 verpflichteten Person ein fremdes Geheimnis unbefugt offenbart, das er von dem Verstorbenen erfahren oder aus dessen Nachlass erlangt hat.
(5) Die Absätze 1 bis 4 sind auch anzuwenden, wenn der Täter das fremde Geheimnis nach dem Tod des Betroffenen unbefugt offenbart.
(6) Handelt der Täter gegen Entgelt oder in der Absicht, sich oder einen anderen zu bereichern oder einen anderen zu schädigen, so ist die Strafe Freiheitsstrafe bis zu zwei Jahren oder Geldstrafe.
Annex
Supplementary agreement: confidentiality undertaking and instruction for physicians
to the data processing agreement
1. Scope
This supplementary agreement applies to customers who work as physicians or members of another healthcare profession within the meaning of Section 203 of the German Criminal Code (StGB), in respect of the dedicated instance provided by neuland.ai AG. neuland.ai AG makes no assurances in respect of the "neuland.ai HUB" in this regard and this supplementary agreement does not apply to it.
2. Confidentiality
neuland.ai AG hereby undertakes towards the Customer to keep all confidential information obtained strictly secret and to protect it against access by third parties.
3. Obligation of staff
neuland.ai AG ensures that all employees involved in the processing, as well as other persons acting for neuland.ai AG (e. g. subprocessors) who may gain access to confidential information, are bound to confidentiality in text form and instructed about the criminal consequences of a breach of duty.
4. Obtaining knowledge
neuland.ai AG may obtain knowledge of confidential information only in so far as this is necessary for the obligations set out in the main agreement. neuland.ai AG is entitled to engage subprocessors to perform the agreement, provided that they are carefully selected, bound to secrecy in text form and instructed about the criminal consequences of a breach of duty. Subprocessors abroad may only be engaged if the protection of secrets existing there is comparable to the protection within Germany.
5. Instruction on criminal liability
The Customer hereby instructs neuland.ai AG that a breach of confidentiality or the exploitation of another party's secrets by neuland.ai AG is a criminal offence for the persons involved (Sections 203(1), 203(4) sentence 1 StGB, Section 204 StGB) and may be punished by imprisonment of up to one year, in the case of Section 204 StGB by imprisonment of up to two years, or by a fine. The penalty increases to imprisonment of up to two years or a fine where the person concerned acts with the intention of obtaining a benefit, even if for the benefit of a third party, or with the intention of harming another person by the act.
6. Engagement of further persons
As a precaution, the Customer instructs neuland.ai AG that persons involved commit a criminal offence punishable by imprisonment of up to one year or a fine where further persons are engaged, if such further person breaches confidentiality and the person involved has at the same time failed to ensure that the former was bound to confidentiality (Sections 203(1), 203(4) sentence 2 no. 2 StGB). The penalty increases to imprisonment of up to two years or a fine where the offender acts with the intention of obtaining a benefit, even if for the benefit of a third party, or with the intention of harming another person by the act. This obligation applies to all further subcontracting.
7. Statutory annexes
This instruction also includes the wording of the relevant statutes, attached as an annex in their current version — in particular Section 203 StGB and Sections 53a and 97 StPO.
8. Protective measures
neuland.ai AG will maintain appropriate organisational and technical measures to protect the confidentiality of the confidential information and undertakes to protect confidential information appropriately in accordance with accepted security standards reflecting the state of the art. The level of security applied must not be lower than that applied to its own confidential information.
9. Duration
The confidentiality undertaking under this agreement applies without any time limit.
10. Procedural protection (StPO)
The Customer informs neuland.ai AG that the processing may also involve data subject to a physician's professional secrecy within the meaning of Section 203 StGB.
Right to refuse to give evidence (Section 53a StPO)
Data processed by neuland.ai AG on behalf of a professional bound by professional secrecy may be subject to the right of the persons involved to refuse to give evidence (Section 53a of the German Code of Criminal Procedure, StPO). The professional bound by professional secrecy, as the Customer, decides whether that right is exercised.
If neuland.ai AG is required by law enforcement or other authorities to disclose information or give evidence that may be subject to professional secrecy, neuland.ai AG will object with reference to Section 53a StPO and inform the Customer without undue delay so that the Customer can decide whether to invoke the right to refuse to give evidence.
Protection against seizure (Section 97 StPO)
Data protected by professional secrecy that is in the custody of neuland.ai AG may be subject to the prohibition of seizure under Section 97 StPO, in particular in so far as the right of the persons involved to refuse to give evidence under Section 53a StPO applies.
neuland.ai AG does not release such data without the consent of the Customer (the professional bound by professional secrecy). In the event of a seizure or comparable access by authorities, neuland.ai AG will object to that measure and inform the Customer without undue delay.
Subprocessing
The obligations regarding the right to refuse to give evidence and protection against seizure apply accordingly to all subprocessors that may gain access to data protected by professional secrecy in the course of performing the agreement. neuland.ai AG ensures that subprocessors are informed of these rights and obligations.
Professional-law basis — physicians
Section 203 Criminal Code (StGB)
Strafgesetzbuch (StGB)
§ 203 Verletzung von Privatgeheimnissen
The provision is reproduced below in its binding German wording. The German Federal Ministry of Justice publishes an official English translation, which — like this Trust Center's English pages — is a convenience translation without legal force. Only the German wording is legally binding.
Full text of the provision: gesetze-im-internet.de (German)
Official English translation: Section 203 – Violation of private secrets
Binding German wording
(1) Wer unbefugt ein fremdes Geheimnis, namentlich ein zum persönlichen Lebensbereich gehörendes Geheimnis oder ein Betriebs- oder Geschäftsgeheimnis, offenbart, das ihm als
- Arzt, Zahnarzt, Tierarzt, Apotheker oder Angehörigen eines anderen Heilberufs, der für die Berufsausübung oder die Führung der Berufsbezeichnung eine staatlich geregelte Ausbildung erfordert,
- Berufspsychologen mit staatlich anerkannter wissenschaftlicher Abschlußprüfung,
- Rechtsanwalt, Kammerrechtsbeistand, Patentanwalt, Notar, Verteidiger in einem gesetzlich geordneten Verfahren, Wirtschaftsprüfer, vereidigtem Buchprüfer, Steuerberater, Steuerbevollmächtigten,
- Organ oder Mitglied eines Organs einer Wirtschaftsprüfungs-, Buchprüfungs- oder einer Berufsausübungsgesellschaft von Steuerberatern und Steuerbevollmächtigten, einer Berufsausübungsgesellschaft von Rechtsanwälten oder europäischen niedergelassenen Rechtsanwälten oder einer Berufsausübungsgesellschaft von Patentanwälten oder niedergelassenen europäischen Patentanwälten im Zusammenhang mit der Beratung und Vertretung der Wirtschaftsprüfungs-, Buchprüfungs- oder Berufsausübungsgesellschaft im Bereich der Wirtschaftsprüfung, Buchprüfung oder Hilfeleistung in Steuersachen oder ihrer rechtsanwaltlichen oder patentanwaltlichen Tätigkeit,
- Ehe-, Familien-, Erziehungs- oder Jugendberater sowie Berater für Suchtfragen in einer Beratungsstelle, die von einer Behörde oder Körperschaft, Anstalt oder Stiftung des öffentlichen Rechts anerkannt ist,
- Mitglied oder Beauftragten einer anerkannten Beratungsstelle nach den §§ 3 und 8 Absatz 1 des Schwangerschaftskonfliktgesetzes,
- staatlich anerkanntem Sozialarbeiter oder staatlich anerkanntem Sozialpädagogen oder
- Angehörigen eines Unternehmens der privaten Kranken-, Unfall- oder Lebensversicherung oder einer privatärztlichen, steuerberaterlichen oder anwaltlichen Verrechnungsstelle
anvertraut worden oder sonst bekanntgeworden ist, wird mit Freiheitsstrafe bis zu einem Jahr oder mit Geldstrafe bestraft.
(2) Ebenso wird bestraft, wer unbefugt ein fremdes Geheimnis, namentlich ein zum persönlichen Lebensbereich gehörendes Geheimnis oder ein Betriebs- oder Geschäftsgeheimnis, offenbart, das ihm als
- Amtsträger oder Europäischer Amtsträger,
- für den öffentlichen Dienst besonders Verpflichteten,
- Person, die Aufgaben oder Befugnisse nach dem Personalvertretungsrecht wahrnimmt,
- Mitglied eines für ein Gesetzgebungsorgan des Bundes oder eines Landes tätigen Untersuchungsausschusses, sonstigen Ausschusses oder Rates, das nicht selbst Mitglied des Gesetzgebungsorgans ist, oder als Hilfskraft eines solchen Ausschusses oder Rates,
- öffentlich bestelltem Sachverständigen, der auf die gewissenhafte Erfüllung seiner Obliegenheiten auf Grund eines Gesetzes förmlich verpflichtet worden ist, oder
- Person, die auf die gewissenhafte Erfüllung ihrer Geheimhaltungspflicht bei der Durchführung wissenschaftlicher Forschungsvorhaben auf Grund eines Gesetzes förmlich verpflichtet worden ist,
anvertraut worden oder sonst bekanntgeworden ist. Einem Geheimnis im Sinne des Satzes 1 stehen Einzelangaben über persönliche oder sachliche Verhältnisse eines anderen gleich, die für Aufgaben der öffentlichen Verwaltung erfaßt worden sind; Satz 1 ist jedoch nicht anzuwenden, soweit solche Einzelangaben anderen Behörden oder sonstigen Stellen für Aufgaben der öffentlichen Verwaltung bekanntgegeben werden und das Gesetz dies nicht untersagt.
(3) Kein Offenbaren im Sinne dieser Vorschrift liegt vor, wenn die in den Absätzen 1 und 2 genannten Personen Geheimnisse den bei ihnen berufsmäßig tätigen Gehilfen oder den bei ihnen zur Vorbereitung auf den Beruf tätigen Personen zugänglich machen. Die in den Absätzen 1 und 2 Genannten dürfen fremde Geheimnisse gegenüber sonstigen Personen offenbaren, die an ihrer beruflichen oder dienstlichen Tätigkeit mitwirken, soweit dies für die Inanspruchnahme der Tätigkeit der sonstigen mitwirkenden Personen erforderlich ist; das Gleiche gilt für sonstige mitwirkende Personen, wenn diese sich weiterer Personen bedienen, die an der beruflichen oder dienstlichen Tätigkeit der in den Absätzen 1 und 2 Genannten mitwirken.
(4) Mit Freiheitsstrafe bis zu einem Jahr oder mit Geldstrafe wird bestraft, wer unbefugt ein fremdes Geheimnis offenbart, das ihm bei der Ausübung oder bei Gelegenheit seiner Tätigkeit als mitwirkende Person oder als bei den in den Absätzen 1 und 2 genannten Personen tätiger Datenschutzbeauftragter bekannt geworden ist. Ebenso wird bestraft, wer
- als in den Absätzen 1 und 2 genannte Person nicht dafür Sorge getragen hat, dass eine sonstige mitwirkende Person, die unbefugt ein fremdes, ihr bei der Ausübung oder bei Gelegenheit ihrer Tätigkeit bekannt gewordenes Geheimnis offenbart, zur Geheimhaltung verpflichtet wurde; dies gilt nicht für sonstige mitwirkende Personen, die selbst eine in den Absätzen 1 oder 2 genannte Person sind,
- als im Absatz 3 genannte mitwirkende Person sich einer weiteren mitwirkenden Person, die unbefugt ein fremdes, ihr bei der Ausübung oder bei Gelegenheit ihrer Tätigkeit bekannt gewordenes Geheimnis offenbart, bedient und nicht dafür Sorge getragen hat, dass diese zur Geheimhaltung verpflichtet wurde; dies gilt nicht für sonstige mitwirkende Personen, die selbst eine in den Absätzen 1 oder 2 genannte Person sind, oder
- nach dem Tod der nach Satz 1 oder nach den Absätzen 1 oder 2 verpflichteten Person ein fremdes Geheimnis unbefugt offenbart, das er von dem Verstorbenen erfahren oder aus dessen Nachlass erlangt hat.
(5) Die Absätze 1 bis 4 sind auch anzuwenden, wenn der Täter das fremde Geheimnis nach dem Tod des Betroffenen unbefugt offenbart.
(6) Handelt der Täter gegen Entgelt oder in der Absicht, sich oder einen anderen zu bereichern oder einen anderen zu schädigen, so ist die Strafe Freiheitsstrafe bis zu zwei Jahren oder Geldstrafe.
Procedural-law annexes
Sections 53a and 97 Code of Criminal Procedure (StPO)
Strafprozessordnung (StPO)
§ 53a Zeugnisverweigerungsrecht der mitwirkenden Personen
The provision is reproduced below in its binding German wording. The German Federal Ministry of Justice publishes an official English translation, which — like this Trust Center's English pages — is a convenience translation without legal force. Only the German wording is legally binding.
Full text of the provision: gesetze-im-internet.de (German)
Official English translation: Section 53a – Right of persons involved to refuse testimony
Binding German wording
(1) Den Berufsgeheimnisträgern nach § 53 Absatz 1 Satz 1 Nummer 1 bis 4 stehen die Personen gleich, die im Rahmen
- eines Vertragsverhältnisses einschließlich der gemeinschaftlichen Berufsausübung,
- einer berufsvorbereitenden Tätigkeit oder
- einer sonstigen Hilfstätigkeit
an deren beruflicher Tätigkeit mitwirken. Über die Ausübung des Rechts dieser Personen, das Zeugnis zu verweigern, entscheiden die Berufsgeheimnisträger, es sei denn, dass diese Entscheidung in absehbarer Zeit nicht herbeigeführt werden kann.
(2) Die Entbindung von der Verpflichtung zur Verschwiegenheit (§ 53 Absatz 2 Satz 1) gilt auch für die nach Absatz 1 mitwirkenden Personen.
Strafprozessordnung (StPO)
§ 97 Beschlagnahmeverbot
The provision is reproduced below in its binding German wording. The German Federal Ministry of Justice publishes an official English translation, which — like this Trust Center's English pages — is a convenience translation without legal force. Only the German wording is legally binding.
Full text of the provision: gesetze-im-internet.de (German)
Official English translation: Section 97 – Prohibition of seizure
Binding German wording
(1) Der Beschlagnahme unterliegen nicht
- schriftliche Mitteilungen zwischen dem Beschuldigten und den Personen, die nach § 52 oder § 53 Abs. 1 Satz 1 Nr. 1 bis 3b das Zeugnis verweigern dürfen;
- Aufzeichnungen, welche die in § 53 Abs. 1 Satz 1 Nr. 1 bis 3b Genannten über die ihnen vom Beschuldigten anvertrauten Mitteilungen oder über andere Umstände gemacht haben, auf die sich das Zeugnisverweigerungsrecht erstreckt;
- andere Gegenstände einschließlich der ärztlichen Untersuchungsbefunde, auf die sich das Zeugnisverweigerungsrecht der in § 53 Abs. 1 Satz 1 Nr. 1 bis 3b Genannten erstreckt.
(2) Diese Beschränkungen gelten nur, wenn die Gegenstände im Gewahrsam der zur Verweigerung des Zeugnisses Berechtigten sind, es sei denn, es handelt sich um eine elektronische Gesundheitskarte im Sinne des § 291a des Fünften Buches Sozialgesetzbuch. Die Beschränkungen der Beschlagnahme gelten nicht, wenn bestimmte Tatsachen den Verdacht begründen, dass die zeugnisverweigerungsberechtigte Person an der Tat oder an einer Datenhehlerei, Begünstigung, Strafvereitelung oder Hehlerei beteiligt ist, oder wenn es sich um Gegenstände handelt, die durch eine Straftat hervorgebracht oder zur Begehung einer Straftat gebraucht oder bestimmt sind oder die aus einer Straftat herrühren.
(3) Die Absätze 1 und 2 sind entsprechend anzuwenden, soweit die Personen, die nach § 53a Absatz 1 Satz 1 an der beruflichen Tätigkeit der in § 53 Absatz 1 Satz 1 Nummer 1 bis 3b genannten Personen mitwirken, das Zeugnis verweigern dürfen.
Subprocessors' supplementary agreements
Annex to the supplementary agreement on professional secrecy
For use by professionals bound by professional secrecy, separate supplementary agreements for the protection of professional secrets are in place with the following subprocessors. These documents form part of this data processing agreement and are reproduced in full below.
Supplementary agreement for professionals bound by professional secrecy
Microsoft Deutschland GmbH
Separate supplementary agreement between neuland.ai AG and the subprocessor for the protection of professional secrets — it governs confidentiality obligations and the handling of confidential client data.
Loading document …
Supplementary agreement for professionals bound by professional secrecy
Google Cloud EMEA Limited
Separate supplementary agreement between neuland.ai AG and the subprocessor for the protection of professional secrets — it governs confidentiality obligations and the handling of confidential client data.
Loading document …
Persons authorised to issue and receive instructions
Annex to the data processing agreement pursuant to section VIII (Controller's right to issue instructions)
The following persons are authorised to issue instructions on behalf of the Controller (Example Company Ltd.):
| Name | Role | |
|---|---|---|
| Jane Doe | Management | contact@example-company.com |
The recipients of instructions at the Processor (neuland.ai AG) are:
| Name | Role | |
|---|---|---|
| Yunus Philip Uyargil | Member of the Executive Board | datenschutz@neuland.ai |
Instructions are generally to be addressed to the designated recipients of instructions. In the event of a change of contact person or a prolonged absence, the successors or deputies shall be notified to the contracting partner without undue delay and generally in writing or electronically.
Technical and organisational measures (TOMs)
neuland.ai AG · Annex to the data processing agreement
Physical access control
Denying unauthorised persons physical access to data processing facilities
Implemented measures:
- • Physical protection of server rooms and data centres
- • Biometric access controls and smart card systems
- • 24/7 monitoring by security personnel
- • Visitor management and mandatory escorting
- • Video surveillance of critical areas
System access control
Preventing unauthorised persons from using data processing systems
Implemented measures:
- • Multi-factor authentication for all systems
- • Role-based access control (RBAC)
- • Regular review and updating of user permissions
- • Automatic locking of inactive accounts
- • Single sign-on (SSO) with central user management
Data access control
Ensuring that only authorised persons can access the relevant data
Implemented measures:
- • Granular authorisation concepts at data level
- • Principle of least privilege
- • Regular access reviews and recertification
- • Automated, role-based assignment of permissions
- • Logging and monitoring of all access
Transfer control
Ensuring that personal data cannot be read without authorisation during transmission
Implemented measures:
- • End-to-end encryption of all data transmissions
- • TLS 1.3 for all web connections
- • VPN connections for remote access
- • Secure API communication using OAuth 2.0
- • Regular review of encryption standards
Input control
Traceability of who entered, changed or removed which data and when
Implemented measures:
- • Comprehensive audit logs for all data operations
- • Versioning and change tracking
- • Digital signatures for critical changes
- • Automated notifications when data is changed
- • Regular log analysis and anomaly detection
Instruction control
Ensuring that data is processed solely in accordance with the controller's instructions
Implemented measures:
- • Clear processing policies and standard operating procedures
- • Regular staff training
- • Technical enforcement of processing rules
- • Monitoring and alerting on deviations from the rules
- • Documentation of all processing activities
Availability control
Ensuring that data is protected against accidental destruction or loss
Implemented measures:
- • Redundant backup systems with geographic distribution
- • Disaster recovery plans with defined RTOs/RPOs
- • Highly available system architecture with failover
- • Regular backup tests and restore exercises
- • 24/7 monitoring and incident response
Separation control
Ensuring that data from different controllers is processed separately
Implemented measures:
- • Multi-tenant system architecture
- • Logical and physical separation of data
- • Separate processing environments per customer
- • Encryption with customer-specific keys
- • Regular review of the separation measures
Subprocessors
neuland.ai AG · Annex to the data processing agreement
Overview of all subprocessors engaged by neuland.ai AG to provide our services. All subprocessors have been carefully selected and meet the requirements of the GDPR.
Microsoft Deutschland GmbH
Germany · AI services
Address
Walter-Gropius-Straße 5, 80807 München
Service
Azure AI Studio / Azure OpenAI, Azure Container Registry, Azure Kubernetes Service, Azure Document Intelligence, Azure CosmosDB, Azure Qdrant Vector Database (Marketplace)
Purpose of processing
Provision of AI services, container management, document processing and database services
Certifications
ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3
Microsoft Ireland Operations Ltd.
Ireland (EU) · Communication
Address
One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Irland
Service
Data exchange (MS Teams or Outlook), to the extent that commissioned data is transmitted
Purpose of processing
Communication and data exchange via Microsoft Teams and Outlook — only to the extent that personal commissioned data is transmitted or stored in the process
Certifications
ISO 27001, SOC 2 Type II
Google Cloud EMEA Limited
Ireland (EU) · AI services
Address
70 Sir John Rogerson's Quay, Dublin 2, Irland
Service
Google Vertex AI (use of Anthropic and Gemini models)
Purpose of processing
Provision of AI services (including generative AI models, ML inference and AI-assisted data processing) via Google Vertex AI
Certifications
ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 1/2/3
Perplexity AI, Inc
United States · AI services
Service
AI computing for current events (optional): language processing
Purpose of processing
Processing of current events and information using AI
Safeguards
EU-US Data Privacy Framework
Certifications
SOC 2 Type II, SOC 2 Type I, GDPR, HIPAA Gap Assessment
STACKIT (Schwarz Digits Cloud GmbH & Co. KG)
Germany · AI services
Address
Stiftsbergstraße 1, 74172 Neckarsulm
Service
STACKIT AI Model Serving (LLM inference), compute & Kubernetes, object storage, managed databases / vector database, document processing
Purpose of processing
Provision of AI services (LLM inference), cloud infrastructure, database and vector database services as well as document processing in a sovereign German cloud
Certifications
ISO 27001, BSI C5, ISAE 3000 (SOC 2), ISAE 3402
