Data Processing Agreement for Q.wiki Now! (V2.26 - valid from 01/10/2026)

* This English version of the Data Processing Agreement is an automatically generated translation of the original German document. It is provided solely for convenience. In the event of any discrepancies or inconsistencies, the German version shall prevail and is legally binding.

Preamble

The client ("Controller") wishes to engage the contractor ("Processor") to provide the services specified in § 2. The performance of the contract involves the processing of personal data. Article 28 of the GDPR, in particular, sets out specific requirements for such data processing. To ensure compliance with these requirements, the parties enter into the following agreement.

§ 1 Definitions

For terms used in this agreement that are defined in Articles 4, 9, and 10 of the GDPR, the statutory definitions in the version applicable at the time of the conclusion of the contract shall also apply to this agreement.

§ 2 Subject Matter of the Contract

2.1 The contractor provides software-as-a-service (SaaS) for the client based on the main contract. In doing so, the contractor and its employees or those commissioned by the contractor will have access to personal data and will process it exclusively on behalf of and in accordance with the instructions of the client. The scope and purpose of the data processing by the contractor are defined in the main contract (and, if applicable, in the associated service description) as well as in Annex 1 to this agreement. The client is responsible for assessing the legality of the data processing.

2.2 The parties enter into this agreement to specify their respective rights and obligations under data protection law. In the event of any conflict, the provisions of this agreement shall take precedence over the provisions of the main contract.

2.3 The term of this agreement is governed by the term of the main contract, unless the following provisions establish obligations that extend beyond the term of the main contract. Termination rights arising from this agreement remain unaffected by the foregoing provision.

2.4 This agreement shall remain in effect beyond the end of the main contract for as long as the contractor possesses personal data that was provided by the client or collected by the contractor on the client's behalf.

2.5 The contractually agreed data processing shall generally take place within a member state of the European Union or another contracting state to the Agreement on the European Economic Area. Any transfer to a third country shall only occur if the specific requirements of Articles 44 et seq. of the GDPR are met.

§ 3 Right to Issue Instructions

3.1 The contractor may only process data within the scope of the main contract and in accordance with the client's instructions. If the contractor is required by the law of the European Union or the member states to which it is subject to perform further processing, it shall inform the client of these legal requirements prior to processing, provided that it is legally permitted to do so.

3.2 The client's instructions are initially defined by this agreement and may subsequently be changed, supplemented, or replaced by the client through individual instructions provided in writing, in text form, or via the provided software (individual instruction). The client is entitled to issue such instructions at any time. This includes instructions regarding the rectification and erasure of data as well as the restriction of processing.

3.3 All instructions issued must be documented by both the client and the contractor. Instructions that go beyond the services agreed upon in the main contract will be treated as a request for a change in services. Provisions regarding the remuneration of any additional expenses incurred by the contractor due to supplementary instructions from the client remain unaffected.

3.4 If the contractor believes that an instruction from the client violates data protection regulations, it must notify the client immediately. The contractor is entitled to suspend the execution of the instruction in question until it is confirmed or modified by the client. The contractor may refuse to carry out an obviously unlawful instruction.

Section 4 Type of Data Processed, Categories of Data Subjects

In the course of performing the main contract, the contractor will have access to the personal data of the data subjects specified in Annex 1. This data may include special categories of personal data listed and marked as such in Annex 1, provided they are submitted by the client.

Section 5 Technical and Organizational Measures of the Contractor

5.1 The Contractor is obligated to comply with statutory data protection provisions and shall not disclose information obtained from the Client to third parties or expose it to unauthorized access without appropriate instructions. Paper documents and data must be secured against unauthorized access in accordance with the state of the art.

5.2 The Contractor shall organize its internal operations within its area of responsibility to meet the specific requirements of data protection. The Contractor guarantees that it has implemented all necessary technical and organizational measures for the appropriate protection of the Client's data in accordance with Art. 32 GDPR, specifically at least the measures listed in Annex 2. Upon request by the Client, the Contractor shall disclose the specific circumstances regarding the determination and implementation of these measures. The Contractor reserves the right to improve the security measures implemented, provided that it ensures the contractually agreed level of protection is not compromised and that the Client is informed immediately of any significant changes.

5.3 The contact person for data protection at the Contractor is:

Ariadne GmbH, Am Kraftversorgungsturm 5, 52070 Aachen, Germany, Attn: Data Protection Officer, datenschutz@ariadne.io

Any change in the person of the Data Protection Officer/contact person for data protection must be communicated to the Client immediately.

5.4 Persons employed by the Contractor for data processing are prohibited from processing personal data without authorization. The Contractor shall appropriately obligate all persons entrusted with the processing and fulfillment of this contract (hereinafter referred to as employees) (confidentiality obligation, Art. 28 (3) subpara. 1 sentence 2 lit. b GDPR), instruct them on the specific data protection obligations arising from this contract as well as the existing instructions and purpose limitations, and ensure compliance with the aforementioned obligations with due care. These obligations must be structured to remain in effect even after the termination of this contract or the employment relationship between the employee and the Contractor. Upon request, the Contractor shall provide the Client with proof of these employee obligations in an appropriate manner.

Section 6 Contractor's Information Obligations

6.1 In the event of disruptions to processing activities, suspected data breaches or violations of the Contractor's contractual obligations, or suspected other security-relevant incidents involving the Contractor, persons employed by the Contractor in the context of the order, or third parties, the Contractor shall inform the Client in text form immediately, but no later than 48 hours after becoming aware of the incident. The initial report may be preliminary; missing or new information shall be provided without undue delay. The same applies to audits of the Contractor by the data protection supervisory authority that concern processing or matters relevant to the Client. The report regarding a personal data breach shall, as far as possible, contain the following information:

  • a description of the nature of the personal data breach, including, where possible, the categories and number of data subjects concerned, the categories and number of personal data records concerned
  • a description of the likely consequences of the breach
  • a description of the measures taken or proposed by the Contractor to address the breach and, where appropriate, measures to mitigate its possible adverse effects

6.2 The Contractor shall immediately take the necessary measures to secure the affected data and to mitigate possible adverse consequences for the data subject(s), inform the Client thereof, request further instructions, and provide the Client with further information at any time, provided the Client's data is affected by a breach under paragraph 1.

6.3 Should the Client's data at the Contractor be endangered by seizure or confiscation, insolvency or composition proceedings, or other events or measures by third parties, the Contractor shall inform the Client immediately, unless prohibited by court or official order. In this context, the Contractor shall immediately inform all competent authorities that the decision-making authority regarding the data lies exclusively with the Client.

6.4 The Contractor shall inform the Client immediately of any significant changes to the security measures under Section 5 (2).

6.5 The Contractor shall cooperate to a reasonable extent in the creation of the record of processing activities by the Client, as well as in the preparation of a data protection impact assessment pursuant to Art. 35 GDPR and, if applicable, in prior consultation with the data protection supervisory authorities pursuant to Art. 36 GDPR. The Contractor shall provide the Client with the necessary information in an appropriate manner.

Section 7 Client's Audit Rights

7.1 Before commencing data processing and thereafter on a regular basis, the Client shall satisfy itself of the Contractor's technical and organizational measures. For this purpose, the Client may, for example, obtain information from the Contractor, request existing expert reports, certifications, or internal audits, or, if possible and after timely coordination, personally inspect the Contractor's technical and organizational measures during normal business hours or have them inspected by a qualified third party, provided the latter is not in a competitive relationship with the Contractor. The Client shall conduct audits only to the extent necessary and shall not disproportionately disrupt the Contractor's business operations. On-site audits are secondary, i.e., they occur only if the previously provided information, reports, certifications, or questionnaires are insufficient for an appropriate assessment.

7.2 The Contractor undertakes to provide the Client, upon oral or written request and within a reasonable period, with all information and evidence necessary to conduct an audit of the Contractor's technical and organizational measures in accordance with Annex 2.

Support services that go beyond this shall be reimbursed by the Client. This does not apply to support services required due to an official order, a security incident at the Contractor, or a material breach of this agreement by the Contractor.

On-site audits must be announced in text form with at least 14 calendar days' notice and shall take place no more than once every twelve months. They are to be limited to one audit day between 9:00 a.m. and 6:00 p.m.; if this is demonstrably insufficient, the audit may be extended to immediately following working days by mutual agreement. If the Client conducts an audit beyond this without the Contractor having given cause for it, the Contractor is entitled to reimbursement of the reasonable costs incurred as a result.

Travel and accommodation expenses, as well as a reasonable daily rate for the contractor, shall be borne by the client.

7.3 The client shall document the results of the checks it performs and communicate them to the contractor. In the event of errors or irregularities, particularly those identified by the client during the review of service results, the client must inform the contractor without delay. If the inspection reveals facts that require changes to the mandated procedure to prevent future occurrences, the client shall notify the contractor of the necessary procedural changes without delay.

7.4 Upon request, the contractor shall provide the client with proof that its employees are bound by the obligations set forth in Section 5 (4).

Section 8 Use of Subcontractors

8.1 The client grants the contractor general authorization to engage further subcontractors within the meaning of Art. 28 GDPR to fulfill its contractually agreed services. The contractor shall list all existing subcontracts at the time of contract conclusion in Appendix 3 to this agreement. The client must be informed in advance of any intended addition or replacement of subcontractors.

8.2 The client may object to the engagement of additional subcontractors or the replacement of existing ones within a period of 2 (two) weeks after receiving notification of the change, either in writing or in text form. In the event of an objection, the contractor may, at its own discretion, either provide the service without the intended change or—if it is not possible for the contractor to provide the service without the intended change—terminate the services affected by the change for good cause.

8.3 The contractor is obligated to select subcontractors carefully based on their suitability and reliability. When engaging subcontractors, the contractor must impose the obligations set forth in this agreement upon them and ensure that the client can exercise its rights under this agreement (in particular its audit and inspection rights) directly against the subcontractors as well. If subcontractors are to be involved in a third country, the contractor must ensure that an adequate level of data protection is guaranteed by the respective subcontractor (e.g., by concluding an agreement based on the EU Standard Contractual Clauses). Upon request, the contractor shall provide the client with proof of the conclusion of the aforementioned agreements with its subcontractors.

Should the adequacy of the protection level under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) cease to apply, the contractor shall immediately ensure that the affected data transfers are continued on the basis of the EU Standard Contractual Clauses (SCC) and a supplementary Transfer Impact Assessment (TIA), and shall inform the client accordingly.

8.4 A subcontracting relationship within the meaning of these provisions does not exist if the contractor commissions third parties for services that are to be considered purely ancillary. These include, for example, postal, transport, and shipping services, cleaning services, telecommunications services without a specific connection to the services the contractor provides for the client, and security services. Maintenance and testing services constitute subcontracting relationships within the meaning of Paragraph 1 insofar as they are provided for IT systems that are also used in connection with the provision of services for the client.

Section 9 Inquiries and Rights of Data Subjects

9.1 The contractor shall support the client with appropriate technical and organizational measures in fulfilling the client's obligations under Art. 12–22 as well as 32 and 36 GDPR.

9.2 If a data subject asserts rights, such as the right to information, rectification, or erasure regarding their data, directly against the contractor, the contractor shall not respond independently but shall refer the data subject to the client without delay and await the client's instructions.

Section 10 Liability

10.1 The client and the contractor shall be liable to data subjects in accordance with the provisions set forth in Art. 82 GDPR. The contractor shall coordinate any fulfillment of liability claims with the client.

10.2 The contractor shall indemnify the client against all claims asserted by data subjects against the client due to a breach of an obligation imposed on the contractor by the GDPR, or due to the non-observance or violation of an obligation stipulated in this agreement or of an instruction issued separately by the client.

10.3 The parties shall each indemnify the other from liability if/to the extent that a party proves that it is in no way responsible for the circumstance that caused the damage to a data subject. Otherwise, Art. 82 (5) GDPR shall apply.

10.4 Unless otherwise stipulated above, liability under this agreement shall correspond to that of the main contract.

Section 11 Extraordinary Right of Termination

The client may terminate the main contract in whole or in part without notice if the contractor fails to comply with its obligations under this agreement, intentionally or through gross negligence violates provisions of the GDPR, or is unable or unwilling to carry out an instruction from the client. In the case of minor breaches—i.e., those that are neither intentional nor grossly negligent—the client shall grant the contractor a reasonable period of time within which the contractor may remedy the breach.

Section 12 Termination of the Main Contract

12.1 Upon termination of the main contract, or at any time upon request, the Processor shall return to the Controller all documents, data, and data carriers provided to them, or—at the Controller's request, provided there is no legal obligation under European Union or German law to store the personal data—delete them. This obligation to return or destroy data also applies to any data backups held by the Processor. The Processor must provide documented proof of proper deletion.

12.2 The Controller has the right to verify the complete and contractually compliant return or deletion of data by the Processor in an appropriate manner, or to have it audited by a qualified third party, provided that the third party is not a competitor of the Processor. Any costs incurred for the engagement and audit by a third party shall be borne by the Controller.

12.3 The Processor is obligated to maintain the confidentiality of information that becomes known to them in connection with the main contract, even after the main contract has ended.

Section 13 Church Data Protection

13.1 For a Controller subject to the Act on Church Data Protection (KDG), the parties expressly incorporate §§ 29 – 33 KDG and compliance with the provisions on data processing set forth therein.

13.2 For a Controller subject to the Church Act on Data Protection of the Evangelical Church in Germany (DSG-EKD), the parties expressly incorporate §§ 30 – 32 DSG-EKD and compliance with the provisions on data processing set forth therein.

Section 14 Final Provisions

14.1 The parties agree that the Processor has no right of retention regarding the data to be processed or the associated data carriers.

14.2 Amendments and supplements to this agreement, the declaration of termination, and any modification of this clause must be made in text form to be effective.

14.3 Should individual provisions of this agreement be or become legally invalid or unenforceable, in whole or in part, the validity of the remaining provisions shall not be affected.

14.4 This agreement is governed by German law. The exclusive place of jurisdiction is Aachen.

Section 15 Appendices

The following appendices are an integral part of this Data Processing Agreement:

  • Appendix 1 – Description of data subjects/categories of data subjects and sensitive data/categories of data
  • Appendix 2 – Technical and organizational measures of the Processor
  • Appendix 3 – Approved subcontractors

Appendix 1 – Description of data subjects/categories of data subjects and sensitive data/categories of data

Type(s) of personal data:

The types of personal data processed under this agreement include all data that the Controller voluntarily processes within the interactive management system software Q.wiki. This typically includes, in particular:

  • Customer master data (e.g., name, address, contact person, contact details)
  • Communication data
  • Usage and content data as well as
  • company-related data (role, location, department)

As a general rule, the processor does not collect or process any special categories of personal data within the meaning of Art. 9 (1) GDPR in the course of operating Q.wiki. Such data is only processed if the controller enters such information into the system voluntarily and on their own responsibility. In these cases, processing is carried out exclusively in accordance with the instructions of the controller and on the basis of this data processing agreement.

Categories of data subjects:

The group of persons affected by the data processing depends on the individuals to whom the controller grants access to the interactive management system software Q.wiki. This may include, in particular,

  • employees and customers of the controller as well as
  • other third parties (e.g., technical service providers/prospective customers or professional secret holders such as tax advisors or lawyers).

Annex 2 – Technical and organizational measures of the processor

The processor implements the following technical and organizational measures for data security within the meaning of Art. 32 GDPR.

Certification: The processor operates an information security management system (ISMS) and is certified according to ISO/IEC 27001. A current certificate can be provided upon request.

Provider standards: Physical security and data center operations are carried out according to recognized standards of the cloud/data center provider (e.g., ISO/IEC 27001).

Confidentiality

Access control (physical access)

  • Access via a chip card/transponder system operated by the landlord,
  • Key/transponder management by the landlord
  • Visitor management with registration and escort,
  • External cleaning and security services are only engaged after careful selection and a confidentiality agreement.

Access control (logical system access)

  • Strong authentication: Use of separate administrative accounts.
  • Password policy: Minimum length of 12 characters, secure storage according to state-of-the-art standards.
  • Support for Single Sign-On
  • Administrative access: IP restrictions for administrative access are applied wherever technically possible and agreed upon.

Access control (permissions and data access)

  • Role and permission concept based on the least-privilege principle; rights management by authorized personnel (Operations/Administration).
  • Separation of standard and administrative accounts; the number of privileged accounts is reduced to the necessary minimum.
  • Joiner/Mover/Leaver: Prompt setup, modification, or revocation of permissions during personnel changes.
  • Data carriers/media: Logical deletion before reuse; physical destruction of internal data carriers in accordance with ISO/IEC 21964, if applicable. For cloud storage, the provider's certified procedures apply.

Mobile working

  • Managed, encrypted devices: Mobile work is performed exclusively via fully encrypted devices managed by the contractor under MDM control; devices can be remotely locked or wiped if necessary.
  • Access protection: Remote access to systems/data is only possible via state-of-the-art encrypted connections and multi-factor authentication.
  • Rights and device security: Role-based and needs-oriented rights assignment (least privilege); no local admin rights for standard users. MDM compliance enforces current security updates as well as screen locks/timeouts.
  • Data minimization: Work data is primarily processed in central, controlled services; local storage on devices is limited to the necessary minimum. Use of approved applications/services only.
  • Incident management: Loss/theft of mobile devices must be reported immediately; remote locking/wiping and an assessment of potential risks are carried out promptly. Required notifications under the GDPR are handled by the contractor in coordination with the client.
  • Training: All employees receive mandatory training at least annually, including specific requirements for mobile working.

Pseudonymization and encryption

  • Data transmission: All connections to Q.wiki are encrypted.
  • Data storage (at rest): Encryption of data at rest using current encryption methods recognized as secure by the BSI.
  • Pseudonymization is not required by the system design

Separation control (principle of separation)

  • Multi-tenancy: Technical separation of customer data through tenant logic and access checks at the tenant level.
  • Environments: Strict separation of development, test, and production systems

Integrity

Input control

  • Personal data is processed exclusively under individual user accounts; group accounts are avoided.
  • Procedures and responsibilities for changes requiring approval are defined

Transfer control

  • Personal data is transmitted between system components, locations, and to authorized third parties exclusively via encrypted connections.
  • International transfers: Data transfers to third countries outside the EU/EEA are made exclusively to the sub-processors listed in Annex 3 on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR) or another permissible legal basis pursuant to Art. 44 et seq. GDPR, subject to prior notification.

Availability and resilience

  • Operation on highly available cloud infrastructure
  • Reduction of failure risks through redundant components and operation in professional data center environments provided by the cloud provider
  • Capacity management and regulated operational processes to maintain service quality
  • Procedures for regular testing, assessment, and evaluation

Data protection and information security management

  • Company-wide policies on data protection and information security, confidentiality obligations for all employees, and regular training
  • Operation of a certified ISMS according to ISO/IEC 27001, continuous improvement of security measures
  • Data protection by design and by default in accordance with Art. 25 GDPR (e.g., role-based access with minimal default permissions)

Handling of security incidents

  • Procedures for the identification, containment, remediation, and follow-up of security incidents
  • Assisting the controller in fulfilling their obligations under Art. 33/34 GDPR (notification/communication), including providing available information regarding the incident
  • Deletion and return of data
  • After the contract ends, processing is limited solely to the purpose of orderly termination

Endpoint security (employees)

  • Company devices with hard drive encryption, up-to-date security patches, and personalized user accounts
  • Secure remote work (e.g., VPN) and baseline hardening of endpoints, policies for handling removable media
  • Control of processing and sub-processors
  • Processing exclusively based on documented instructions from the controller; internal policies prevent unauthorized processing
  • Confidentiality obligations for all persons with access to personal data

Annex 3 – Approved Sub-processors

The processor engages third parties to process data on behalf of the controller ("sub-processors"). These include the following companies:

Subprocessors

Name and Address Description of Services Place of Service Provision / Transfer Mechanism
Relaix Networks GmbH Auf der Hüls 172, 52068 Aachen Colocation: provision of physical infrastructure (rack space, power, cooling, physical access control, network connectivity) for server hardware Germany (Aachen) No third-country transfer (EU/EEA)
Google Cloud EMEA Limited 70 Sir John Rogerson's Quay, Dublin 2, Ireland 1. Infrastructure as a Service (IaaS)
2. Model as a Service (MaaS) via the Gemini Enterprise Agent Platform
1. Germany (Frankfurt, europe-west3), Belgium (europe-west1) 2. EU EU-U.S. DPF
Microsoft Corporation One Microsoft Way, Redmond, WA 98052, USA 1. Use of Microsoft Azure services – in particular LLMs for responding to prompts, building a vector database for search, and automated translation of Q.wiki content.
2. Use of cloud and AI services for temporary data processing – such as language processing, automatic translation, semantic search, and the creation and optimization of processes.
EU EU-U.S. DPF
Cloudflare Inc. 101 Townsend St., San Francisco, CA 94107, USA Protection against web application attacks (WAF), defense against DDoS attacks, and rate limiting to ensure resource conservation and availability USA EU-U.S. DPF
Mailgun Technologies Inc. 112 E. Pecan Street, San Antonio, TX 78205, USA Q.wiki email delivery (e.g. tasks, password resets) USA EU-U.S. DPF
Userlane GmbH Rosenheimer Straße 143c, 81671 München Digital assistant for software-guided delivery of application training Germany No third-country transfer (EU/EEA)
Raintank Inc. d/b/a Grafana Labs 165 Broadway, 23rd Floor, New York, NY 10006, USA Grafana Cloud: monitoring, alerting, and visualization of metrics, logs, and traces to ensure availability and operational reliability. EU / Belgium (Google Cloud region Europe west1, St. Ghislain) EU-U.S. DPF
Freshworks Inc. 2950 S. Delaware Street, San Mateo, CA 94403, USA Ticketing and knowledge base for customer support USA EU-U.S. DPF
Mixpanel Inc. Pier 1, Bay 2, The Embarcadero, San Francisco, CA 94111 USA Analysis of usage data to improve Q.wiki USA EU-U.S. DPF
Productboard Inc. 333 Bush Street, San Francisco, CA 94104 USA Management and processing of customer feedback USA EU-U.S. DPF
360 Learning SA 37 Rue des Mathurins, Paris, France Management and delivery of user training France No third-country transfer (EU/EEA)
Hubspot Inc. 2 Canal Park, Cambridge, MA 02141, United States Customer communication and contract management USA EU-U.S. DPF

Ready to take the next step?

Do you have any questions or want to learn more?

Teammeeting Q.wiki Qualitätsmanager im modernen Büro
Write us!

Send us a message. We'll get back to you as soon as possible.

Contact now
Service Mitarbeiter Q.wiki am Laptop
Give us a call!

We are also happy to help you by telephone.

+49 241 9975 310
Q.wiki kennenlernen, Prozesslandkarte auf einem Laptop im Büro dargestellt.
Get to know Q.wiki!

Bundle knowledge and optimize processes collaboratively.

Go to Q.wiki