Data Processing Agreement
pursuant to Art. 28 GDPR · Last updated: 07.09.2026
1. Parties, conclusion and precedence
This Data Processing Agreement (“DPA”) is concluded between conclusia GmbH, Straße am Flugplatz 52D, 12487 Berlin, Germany (“conclusia”, the processor), and the customer using the Service (“Customer”, the controller).
The DPA is concluded when the Customer accepts our Terms of Service, and it applies for as long as the Customer has access to the Service. Where the Customer has signed a separate data processing agreement with us, that agreement takes precedence. Terms defined in the Terms of Service have the same meaning here.
2. Subject matter, nature, purpose and duration
Subject matter. Processing of personal data by conclusia in the course of providing the conclusia web application and its interfaces.
Nature and purpose. Provision of the Service as described in the Terms of Service: user management and authentication, identification and assessment of companies on the Customer’s instruction, research on publicly available sources, storage of the results, support and troubleshooting.
Duration. For the term of the agreement between the parties, followed by the deletion obligations in section 13. Types of personal data and categories of data subjects: see Annex 2.
3. Roles
The Customer is the controller and decides the purposes and means of the processing. conclusia is the processor and processes personal data only on the Customer’s behalf.
The Customer is responsible for the lawfulness of the processing, in particular for having a legal basis for it, for meeting the information obligations towards data subjects under Art. 13 and 14 GDPR, and for the lawfulness of transferring the data to us.
The functions of the Service that the Customer uses, and the settings the Customer chooses, constitute documented instructions within the meaning of Art. 28(3)(a) GDPR. Instructions beyond that must be given in text form to support@conclusia.io.
4. Instructions and unlawful instructions
conclusia processes personal data only on the documented instructions of the Customer, including with regard to transfers to third countries, unless required to do otherwise by Union or Member State law; in that case conclusia informs the Customer before processing, unless the law prohibits it.
conclusia shall inform the Customer without undue delay if, in its opinion, an instruction infringes data protection law. conclusia is entitled to suspend the execution of such an instruction until the Customer confirms or amends it.
5. Confidentiality
conclusia ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The commitment survives the end of their engagement.
6. Research columns
A research column answers one question for every company on a list, using publicly available sources and the data sources the Customer selects. Because the question is the Customer’s free text, this section sets out how the parties allocate responsibility for it.
6.1 The question is an instruction. The Customer formulates the question, selects the topic, and selects — per column, before the run starts — which sources are used, including whether the third-party contact-data provider named in Annex 3 is queried. Each of these choices is an instruction to conclusia within the meaning of section 3. conclusia does not review the content of questions for lawfulness, and has no technical means of doing so. The Customer is aware of this.
6.2 The Customer’s assurances. By starting a research column, the Customer warrants that it has a legal basis for the processing the question triggers; the question is not aimed at special categories of personal data under Art. 9 GDPR or data relating to criminal convictions under Art. 10 GDPR; the question concerns companies and the professional role of the people acting for them; and it will meet the information obligations under Art. 14 GDPR or an exception applies. The Customer shall not use the Service to compile profiles of natural persons beyond the professional information required for its business purpose.
6.3 What conclusia does. For each cell, conclusia retrieves publicly accessible web pages of the company concerned, may run a web search, and may query the data sources selected by the Customer. The retrieved content and the question are passed to the language models named in Annex 3, which produce an answer, a short justification and source references. Retrieved page content is used to answer the question in that run and is not stored by conclusia in its original form. The answer, the justification, short evidence excerpts and the source URLs are stored with the list.
6.4 Results are automated and unverified. Answers are produced by automated procedures. conclusia does not verify them against reality and does not warrant that they are accurate, complete or current. The Customer shall not use a result as the sole basis for a decision that produces legal effects concerning a natural person or similarly significantly affects them, and shall not use results for employment or creditworthiness decisions.
6.5 Visibility. Research results form part of the case in which they were created. Every user of the Customer who has access to that case can see them, including any personal data they contain. Controlling that access is the Customer’s responsibility.
7. Security of processing
conclusia implements the technical and organisational measures required by Art. 32 GDPR. They are set out in Annex 1 and are kept up to date; conclusia may change individual measures provided the level of protection is not reduced.
8. Sub-processors
The Customer grants general authorisation for the engagement of sub-processors. The sub-processors engaged at the time of conclusion are listed in Annex 3.
conclusia informs the Customer of any intended change at least two weeks in advance. The Customer may object in text form within that period for an important reason relating to data protection. If no objection is raised, the change is deemed approved. In the event of a justified objection, the parties seek an appropriate solution; if none is possible, either party may terminate with one month’s notice.
conclusia imposes on each sub-processor, by contract, data protection obligations equivalent to those in this DPA, and remains responsible to the Customer for their performance.
9. International transfers
Personal data is processed in the European Union and in the United States, as set out in Annex 3. Where personal data is transferred to a third country, conclusia ensures an adequate level of protection pursuant to Art. 44 et seq. GDPR, in particular through the EU-U.S. Data Privacy Framework or the EU Standard Contractual Clauses.
10. Assistance with data subject rights
Taking into account the nature of the processing, conclusia assists the Customer by appropriate technical and organisational measures in fulfilling its obligation to respond to requests under Chapter III GDPR — access, rectification, erasure, restriction, portability and objection.
Where a data subject approaches conclusia directly, conclusia forwards the request to the Customer without undue delay and does not respond on the merits itself. The Service provides functions for exporting, correcting and deleting content; the Customer uses these itself in the first instance.
11. Assistance with security, breaches and impact assessments
conclusia assists the Customer in complying with Art. 32 to 36 GDPR, taking into account the nature of processing and the information available to it. conclusia notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, and provides the information the Customer needs for its own notification under Art. 33 and 34 GDPR.
12. Audits
conclusia makes available to the Customer all information necessary to demonstrate compliance with Art. 28 GDPR, and allows for and contributes to audits, including inspections. Audits take place during business hours, with reasonable notice, without disrupting operations, and subject to confidentiality. conclusia may satisfy the obligation in whole or in part by providing current documentation, certifications, or reports from independent auditors.
13. Deletion and return
The Service provides an export function; the Customer is responsible for exporting its data before the end of the agreement.
After the end of the agreement, conclusia deletes the personal data processed on the Customer’s behalf, including copies held in caches and search indexes, within 30 days, unless Union or Member State law requires further storage. Backups are deleted through their rolling cycle described in the privacy policy. Deleting a research column deletes its answers. Deleting a case removes it from the Customer’s account.
14. Final provisions
This DPA is governed by German law. Where individual provisions are invalid, the remainder is unaffected. In the event of a conflict between this DPA and the Terms of Service, this DPA prevails for questions of data protection.
Annex 1 — Technical and organisational measures (Art. 32 GDPR)
1. Physical access control. conclusia uses cloud infrastructure operated by professional providers. Physical access controls to data centres are implemented by those providers.
2. System access control. Access to systems and administrative interfaces is restricted to authorised persons. Credentials are personal. Strong passwords and multi-factor authentication are used where available and appropriate.
3. Data access control. Access rights are granted on the need-to-know principle, and are adjusted or revoked when the need ceases.
4. Transmission control. Data transmitted over public networks is protected with industry-standard encryption (TLS/HTTPS).
5. Storage control. Customer data at rest in the production environment, including database backups and snapshots, is encrypted.
6. Input control and logging. Technical logging and monitoring are used to the extent necessary for security, error analysis, misuse detection and operational stability. Log retention is set out in the privacy policy.
7. Processor control. Personal data is processed only on the basis of this DPA and the documented instructions of the Customer. Sub-processors are contractually bound to equivalent obligations.
8. Availability control. Backups, monitoring and documented recovery procedures are in place.
9. Separation control. Each customer’s data is logically separated. Unauthorised cross-customer access is prevented by technical and organisational measures.
10. Confidentiality of personnel. All persons with access to personal data are bound to confidentiality.
11. Review. The measures are reviewed regularly against the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing, as well as the likelihood and severity of the risks.
Contact
conclusia GmbH · Straße am Flugplatz 52D · 12487 Berlin · Germany · support@conclusia.io
Annex 2 — Categories of data subjects and types of personal data
Category of data subjects
Types of personal data
Users authorised by the Customer
First and last name, business email address, role and access information, authentication events, activity in the application
Contact persons at researched companies
Name, position, business email address, telephone number, professional profile links, source reference — where the Customer requests a research column of this kind
Persons named in publicly available sources
Names and functions appearing in evidence excerpts quoted from company websites, for example from imprint or team pages
Annex 3 — Sub-processors
Sub-processor
Purpose
Location of processing
Amazon Web Services, Inc.
Hosting, storage, databases; AI models operated within conclusia’s own AWS environment
Frankfurt (application, database, backups); Northern Virginia and Ohio (AI models, data collection)
OpenAI, L.L.C.
Language model that carries out research on company websites; receives the research question and the page content collected for it
United States
Tavily
Web search for publicly available evidence about companies
United States
Apollo.io
Business contact data, where the Customer selects this source for a research column
United States