Data processing agreement

Version 2026-08 (as at August 2026) · Agreement under Art. 28 GDPR between the customer as controller and CITO GmbH as processor.

This page is a translation. Only the German version is legally binding; where the two differ, the German version prevails. The translation is provided to aid understanding.

1. Parties

Controller (client): the customer who uses ComLayer — [still to be determined: company, address and representation of the customer]. These details are added when the individual agreement is signed.

Processor: CITO GmbH

Jungfrauenthal 8, 20149 Hamburg, Deutschland

Represented by the Managing Director Sebastian Johnston

Amtsgericht München, HRB 214036

Email: info@comlayer.app

No data protection officer has been appointed: the processor does not reach the thresholds of § 38 BDSG. The management answers data protection requests at the address given in clause 13.

2. Subject matter, nature and purpose of the processing

The subject matter of the processing is the provision and operation of the ComLayer platform for the client in accordance with the General Terms and Conditions. The sole purpose is to deliver this service, that is, to receive, answer and manage support requests from the client's end customers.

The nature of the processing comprises collection, recording, storage, organisation, retrieval, use, transmission to the sub-processors named in clause 8, restriction and erasure. The processor does not process the data for its own purposes; in particular, it does not analyse the data to train models of its own.

The same applies to the model and embedding providers used: Both providers have contractually committed to the same exclusion: the model provider through the data processing terms of Google Cloud, the embedding provider through the terms of use of Voyage AI.

The processing runs for the term of the main contract. It ends when that contract ends and with the subsequent deletion under clause 11.

3. Categories of data subjects

  • End customers and website visitors of the client who use the support channel
  • Employees and agents of the client who work in the platform as team members
  • People named in the client's messages, knowledge content or feedback

4. Types of data processed

  • Visitor master data: name and email address, where given, page visited, approximate location, time of first contact
  • Communication content: messages from chat and from handover to staff, timestamps, assignment to a conversation, its processing status and uploaded file attachments
  • User data of team members: name, email address, role, assignment to the workspace
  • Content of the knowledge base and the embeddings generated from it
  • Feedback and roadmap contributions including the details of the person submitting them

Special categories of personal data under Art. 9 GDPR are not the subject of this agreement. If the client nevertheless transmits such data through the support channel, it does so on its own responsibility; the parties then agree the necessary additional measures separately.

5. Right to issue instructions

The processor processes the data solely on documented instructions from the client. This agreement and the use of the platform by the client and its team members constitute those instructions. Any further instruction is issued in text form to info@comlayer.app.

If the processor considers that an instruction infringes data protection law, it informs the client without delay and may suspend execution until the client confirms it. Where a transfer to a third country is required by law, the processor informs the client beforehand, unless that law prohibits it.

6. Confidentiality

For the processing, the processor uses only people who are bound to confidentiality and who have been familiarised with the relevant data protection rules. That obligation continues after their work ends. The number of people with access rights is limited to what operating the service requires.

7. Technical and organisational measures (Art. 32 GDPR)

The processor takes the following measures; they reflect the state of the art and are adjusted on an ongoing basis. A change must not fall below the level of protection.

  • Encryption of all connections via TLS; the connection to the database uses mutually authenticated, short-lived certificates
  • Encrypted storage of data at rest
  • Tenant separation: every record belongs to a workspace, and every access is checked on the server against membership of that workspace
  • Role and permission model with separate roles for administration and processing
  • File attachments are held in non-public storage and are delivered only through an access-checked route of the application
  • The public widget key can be rotated per workspace; the permitted embedding domains can be restricted
  • Request rate limiting against misuse of the public interfaces
  • Regular backups and monitored operation; recovery targets: recovery time (RTO) and maximum data loss (RPO) of 24 hours each
  • Procedure for regularly reviewing effectiveness: annually by the management

8. Sub-processors

The client gives its general authorisation for the use of the sub-processors named below. The processor binds them to a level of protection that matches this agreement and is liable for their conduct as for its own.

Clerk

Sign-in, accounts, sessions and team invitations.

Processing region: USA — transfer to a third country on the basis of the standard contractual clauses. Name, email address and session data of the team members are transferred.

Stripe

Payment processing, subscription management, invoices and customer portal.

Processing region: USA — transfer to a third country on the basis of the standard contractual clauses. The invoicing and payment data of the client are transferred.

Google Cloud SQL (PostgreSQL)

Leading database for conversations, messages, visitors, knowledge and accounts.

Processing region: europe-west3 (Frankfurt) according to the instance configuration in use; measured in the development environment.

Google Cloud Storage

Storage of file attachments and logos in a non-public bucket.

Processing region: EUROPE-WEST3; measured on 7 August 2026 against the buckets in use. Unlike the other regions, this value is in no configuration in the source code — GCS_UPLOAD_BUCKET states only the name of the bucket.

Google Firebase Realtime Database

Live update of open conversations and presence indicator.

Processing region: europe-west1 according to the database URL in use; measured in the development environment.

Anthropic (Claude) über Google Vertex AI

Generation of the AI answers as well as auxiliary functions such as subject lines and document analysis. There is no Anthropic account; the models run inside the Google Cloud environment.

Processing region: The support agent runs in the Vertex multi-region eu, the auxiliary models in europe-west1; both values are stated in the configuration of the deployment (CLOUD_ML_REGION and CLOUD_ML_REGION_UTILITY).

Voyage AI

Generation of embeddings for the semantic search in the knowledge base. Used only where configured; otherwise the search works purely on text.

Processing region: USA — transfer to a third country on the basis of the standard contractual clauses. The knowledge content itself is transferred, not merely an excerpt of it.

Resend

Sending of transactional emails to the team of the client, for example on assignment or when a request needs a human. The emails contain excerpts from conversations.

Processing region: USA — transfer to a third country on the basis of the standard contractual clauses. The notifications are transferred together with the excerpts from conversations they contain.

Vercel

Operation and delivery of the application.

Processing region: Frankfurt am Main (fra1). The provider is a US corporation, the execution of this deployment takes place in the EU.

If the client embeds an appointment booking of its own via Cal.com, Cal.com is its service provider and not a sub-processor of the processor; the processor merely receives the notification of booked appointments.

The content stays in the EU. Conversations, knowledge base and accounts are held in the database region europe-west3 (Frankfurt), file attachments and logos in the file storage of the same region, the live update of open conversations runs in europe-west1, and the AI agent answers from the Vertex multi-region eu; the auxiliary models for subject lines and document analysis run in europe-west1. The region of the file storage was measured on 7 August 2026 against the buckets in use; all the others are stated in the configuration of the deployment.

Four services process outside the EU, namely in the USA: Clerk for sign-in, accounts and sessions, Stripe for payment processing, Resend for sending the team notifications — these contain verbatim excerpts from conversations — and Voyage AI for the embeddings of the semantic search, which receives the knowledge content for that purpose. These transfers are based on the standard contractual clauses of the EU Commission; which version and which impact assessment applies to each provider is recorded in the data processing agreement. The operation of the application itself lies with Vercel, a US corporation; the serving region of this deployment has not been measured and is marked there as an open slot as well.

The processor notifies the client in text form at least one week before a sub-processor is replaced or added. The client may object for an important data protection reason; in that case either party may terminate the main contract with effect from the date of the change.

The processor bases the transfers to the USA on the standard contractual clauses of the EU Commission under Art. 46(2)(c) GDPR, in the version of Implementing Decision (EU) 2021/914 of 4 June 2021, module 2 (transfer from a controller to a processor). The providers used each supply their own transfer impact assessments, which we rely on; we do not carry out an additional assessment of our own in the individual case. While this point remains open, the list is complete and the transfer route is named, but the assessment in the individual case is not concluded.

9. Assistance for the client

The processor assists the client, as far as is reasonable, in fulfilling the rights of data subjects under Art. 15 to 22 GDPR and with data protection impact assessments and consultations under Art. 35 and 36 GDPR.

If a data subject contacts the processor directly, the processor forwards the matter to the client without delay and does not answer it itself. Information about stored data and its release or deletion is provided on request via info@comlayer.app within 48 hours.

For the data in its own workspace the client also has a self-service route: under Einstellungen → Allgemein its administrators can produce a complete, machine-readable export at any time (“Daten exportieren”, JSON format) and can request the deletion of the workspace (“Workspace löschen”). The deletion is queued with a grace period of 30 days and can be revoked until the last day. Both routes are open regardless of the plan booked.

10. Notification of personal data breaches

The processor notifies the client of every personal data breach that comes to its attention without delay, at the latest within 72 hours of becoming aware of it. The notification contains the information required by Art. 33(3) GDPR, as far as it is available; missing information is supplied later. Notifying the supervisory authority and, where applicable, the data subjects is the responsibility of the client.

11. Deletion and return

After the main contract ends, the processor deletes the data processed on behalf of the client, including existing copies, within 30 days, unless the client requests its return beforehand. Backups are overwritten as part of the regular backup cycle.

Statutory retention obligations remain unaffected; the data covered by them is restricted in processing for the duration of the retention period.

12. Evidence and audits

On request, the processor demonstrates compliance with this agreement in a suitable form, in particular by providing information about the measures taken. The client is entitled to satisfy itself of compliance after giving notice with reasonable advance warning and without disrupting operations; on-site audits are limited to cases with good reason. The processor holds no certifications or audit reports of its own at present; the evidence is provided through the information under sentence 1. For the sub-processors used, their respective certifications apply.

13. Final provisions

In the event of contradictions, the provisions of this agreement take precedence over the provisions of the main contract as far as the processing of personal data is concerned. German law applies. In all other respects the General Terms and Conditions apply, supplemented by the Privacy policy.

Questions about this contract, a wish for a signed version or deviations in an individual case: info@comlayer.app.