Version 3.0 · July 2026
Binding language version
The German version is legally binding. The English version is provided for convenience only.
Agreement for the processing of personal data on behalf of a controller pursuant to Art. 28 GDPR
between
Customer
– hereinafter the “Controller” –
and
Sleak GmbH, Rosental 7, 80331 Munich
– hereinafter the “Processor” –
1. Subject Matter
(1) As part of the provision of services under the General Terms of Use for the Sleak Platform (“Main Contract”), it is necessary for the Processor to process personal data for which the Controller acts as the data controller within the meaning of data protection regulations (“Controller Data”). This Agreement specifies the rights and obligations of the Parties under data protection law in connection with the processing of Controller Data for the performance of the Main Contract.
2. Scope of Data Processing
(1) The Processor shall process Controller Data on behalf of and in accordance with the instructions of the Controller within the meaning of Art. 28 GDPR. The Controller shall remain the controller within the meaning of data protection law.
(2) The details of the processing, in particular the categories of personal data and the purposes for which the Controller Data is processed on behalf of the Controller, are specified in Appendix 1.
3. Instructions by the Controller
(1) The Processor shall process the Controller Data only on documented instructions from the Controller, unless required to do so by Union or Member State law to which the Processor is subject. In this case, the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
(2) The Controller’s instructions are defined in this Agreement. In addition, the Processor makes available to the Controller configuration options within the Sleak Platform through which the Controller may customize the processing of Controller Data within the scope of the Platform’s standard operation. Use of these configuration options constitutes a documented instruction within the meaning of this Agreement. Instructions going beyond the foregoing that require customization of the Processor’s standard service are only binding to the extent they have been agreed in writing and documented in the Main Contract or a separate amendment.
(3) The Processor shall immediately inform the Controller if, in the Processor’s opinion, instructions given by the Controller infringe applicable data protection law.
4. Responsibility of the Controller
(1) As between the Parties, the Controller is solely responsible for the lawfulness of the instructions issued and the lawfulness of the processing of Controller Data. Should any third party bring claims against the Processor in connection with the processing of Controller Data under this Agreement, the Controller shall indemnify the Processor against such claims to the extent they are based on the Controller’s breach of this Agreement or applicable law.
(2) In particular, the Controller must ensure that an appropriate legal basis exists for use of the Platform and the processing of content and other personal data, and that required notices, consents, participations or approvals have been obtained.
(3) Upon request, the Controller shall provide the Processor with reasonable assistance in fulfilling its data protection obligations, including by supplying information required for the Processor’s records of processing activities pursuant to Art. 30 (2) GDPR and by supporting the Processor in its cooperation with supervisory authorities or other public authorities.
5. Security of Processing
(1) The Processor shall take appropriate technical and organizational measures in accordance with Art. 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing of the Controller Data as well as the risk of varying likelihood and severity for the rights and freedoms of data subjects, to ensure a level of security for the Controller Data appropriate to the risk.
(2) The Parties agree that the technical and organizational measures set out in Appendix 3 ensure an appropriate level of protection for the Controller Data at the time of conclusion of this Agreement. The Processor shall be permitted to change or adapt technical and organizational measures during the term of this Agreement as long as such measures continue to meet the statutory requirements and do not reduce the overall level of data protection set out in Appendix 3.
6. Requirements for Personnel
The Processor ensures that persons authorized to process the Controller Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
7. Use of Sub-Processors
(1) The Controller hereby grants the Processor general authorization to engage sub-processors with regard to the processing of Controller Data. The sub-processors engaged at the time of the conclusion of the Agreement are set out in Appendix 2.
(2) The Processor shall inform the Controller of any intended changes with regard to the addition or replacement of sub-processors at least 14 days prior to the planned engagement of the new sub-processor. Notification shall be made by publication at https://trust.sleak.ai/subprocessors and via email if the Controller has subscribed to email notifications on that page. The Controller is entitled to object in writing to the intended change within 14 days of publication of the change, provided that the objection is based on specific data protection grounds. If no objection is raised, the change shall be deemed approved. In the event of a timely and duly reasoned objection, the Parties shall attempt to reach a mutually agreeable solution. If no agreement is reached within 14 days of receipt of the objection, either Party shall be entitled to terminate the Main Contract and this Agreement with a notice period of 30 days.
(3) The Processor shall contractually impose on sub-processors data protection obligations that correspond to the level of protection under this Agreement (Art. 28 (4) GDPR). Where a sub-processor processes Controller Data in a third country, the Processor shall ensure that an appropriate transfer mechanism ensuring an adequate level of protection within the meaning of Art. 44 et seq. GDPR is in place, such as by entering into standard contractual clauses pursuant to Art. 46 GDPR in accordance with the applicable template of the European Commission.
(4) The Processor shall remain responsible to the Controller for the performance of the sub-processor’s obligations in accordance with its contract with the Processor.
8. International Data Transfers
(1) The Processor shall generally process Controller Data within the European Union or a state that is party to the Agreement on the European Economic Area (“EEA”). Depending on the Services purchased, the AI and voice models used, and the technical configuration of the Sleak Platform, certain processing activities - particularly the processing of inference requests by specific AI or voice models - may also take place in third countries.
(2) The processing locations envisaged at the time this Agreement is concluded, the sub-processors engaged, and the applicable transfer mechanisms are set out in Appendix 2. The Controller’s purchase of the relevant Services under this Agreement and the Main Agreement shall constitute a documented instruction from the Controller with respect to the processing and transfer of Controller Data required to provide those Services.
(3) Where Controller Data is transferred to or processed in a third country or by an international organisation by the Processor or a sub-processor, the Processor shall ensure compliance with Art. 44 et seq. GDPR and that an appropriate transfer mechanism is in place to ensure an adequate level of protection. In particular, such transfer shall be based on an adequacy decision pursuant to Art. 45 GDPR or appropriate safeguards pursuant to Art. 46 GDPR, such as Standard Contractual Clauses based on the then-current template issued by the European Commission.
9. Data Subject Rights
(1) Taking into account the nature of the processing and the information available, the Processor shall assist the Controller, by appropriate technical and organizational measures to the extent reasonable, to comply with the Controller’s obligation to respond to requests to exercise the rights of data subjects under the GDPR. For this purpose, the Processor shall make available to the Controller functionalities within the Sleak platform that enable the Controller to independently handle typical data subject requests.
(2) The Controller hereby instructs the Processor to implement requests from data subjects to exercise their rights regarding (a) the rectification of account or profile data and (b) the deactivation or deletion of the user account and the data exclusively associated with that user account independently and without prior consultation with the Controller, where such requests are submitted directly to the Processor and the identity of the data subject has been verified by appropriate means (e.g., through the email address associated with the user account).
(3) Where the Processor receives a request from a data subject to exercise the rights under the GDPR that is not handled by the Processor independently (in particular because it raises legal or factual questions or goes beyond the standard cases set out in paragraph 2), the Processor shall forward the request to the Controller without undue delay. Upon the Controller’s request, the Processor shall in such cases assist the Controller by appropriate technical and organizational measures, insofar as reasonably possible and necessary, in fulfilling the Controller’s obligations.
10. Notification and Support Obligations of the Processor
(1) In the event of a personal data breach affecting Controller Data, the Processor shall notify the Controller thereof without undue delay after becoming aware of the breach. The notification shall be made on the basis of the information available to the Processor at the time of the notification; to the extent that further relevant information becomes available, the Processor shall provide such information to the Controller without undue delay.
(2) Upon the Controller’s request, the Processor shall, taking into account the nature of the processing and the information available to the Processor, assist the Controller in fulfilling any notification and communication obligations under the GDPR, insofar as such assistance is necessary and reasonable. The legal assessment as to whether and to what extent any notification or communication obligation exists shall remain the responsibility of the Controller.
(3) Upon the Controller’s request, the Processor shall, taking into account the nature of the processing and the information available to the Processor, assist the Controller with any data protection impact assessments and prior consultations with supervisory authorities, insofar as such assistance is necessary and reasonable. To the extent that such assistance causes significant additional effort exceeding the assistance contractually owed, the Parties shall agree in advance on appropriate additional remuneration.
11. Data Deletion
(1) The Processor shall delete the Controller Data no later than 90 days after termination of the Main Contract, unless the Processor is subject to a legal obligation to retain the Controller Data for a longer period. The Processor shall confirm deletion of the Controller Data to the Controller upon request.
(2) During the term of the Main Contract and until deletion of the Controller Data pursuant to paragraph 1, the Controller shall have the option to export its Controller Data. Upon request, the Processor shall make available the export functions provided for this purpose.
(3) Documentation that serves as proof of the proper processing of Controller Data in accordance with this Agreement or for complying with statutory retention obligations may be retained by the Processor after expiry of the Agreement.
12. Verifications and Audits
(1) The Processor shall provide the Controller, at the Controller’s request, with all information necessary and available to the Processor to verify compliance with its obligations under this Agreement and under Art. 28 GDPR.
(2) The Controller shall be entitled to review the Processor’s compliance with its obligations under this Agreement and under Art. 28 GDPR.
(3) Compliance with the obligations under this Agreement and under Art. 28 GDPR shall, as a rule, be demonstrated by the provision of an appropriate and up-to-date attestation or report from an independent body or an audit report issued in connection with an IT security or data protection certification (e.g., ISO 27001).
(4) To the extent that the Controller substantiates a specific and justified suspicion of a breach of the obligations under this Agreement or under Art. 28 GDPR, or if the evidence provided pursuant to paragraph 3 does not permit an adequate review in the specific case, the Controller shall be entitled to conduct inspections. Such inspections shall be carried out with due regard to the Processor’s legitimate interests and, where possible, primarily by way of written information or remote reviews.
(5) Inspections shall only be permissible during the Processor’s normal business hours and upon reasonable prior notice and shall not unreasonably interfere with the Processor’s business operations.
(6) The Processor shall be entitled to restrict the disclosure of information to the extent necessary to preserve the confidentiality of other customers’ data, security requirements, and legitimate trade and business secrets. If the Controller appoints a third party to carry out an inspection, such third party may not be a competitor of the Processor and must be bound in writing to confidentiality and non-disclosure prior to the inspection.
13. Liability
As between the Parties, the liability provisions of the Main Contract shall apply accordingly, including any exclusions and limitations of liability. The mandatory statutory liability provisions under Art. 82 GDPR shall remain unaffected.
14. Term and Termination
The term and termination of this Agreement shall be governed by the provisions on the term and termination of the Main Contract. Termination of the Main Contract shall automatically result in termination of this Agreement; this Agreement shall, however, remain in force until the deletion of the Controller Data has been completed. An individual termination of this Agreement is excluded.
15. Final Provisions
(1) Should individual provisions of this Agreement be or become invalid or contain a gap, the remaining provisions shall remain unaffected. The Parties shall replace the invalid provision with a legally permissible provision that comes closest to the purpose of the invalid provision and meets the requirements of Art. 28 GDPR.
(2) Unless otherwise provided in this Agreement, the provisions of the Main Contract shall apply accordingly, in particular with regard to the governing law and jurisdiction. In the event of contradictions between this Agreement and other agreements between the Parties, in particular the Main Contract, the provisions of this Agreement shall take precedence.
(3) Only the German version of this Agreement shall be legally binding. The English translation is provided for information purposes only.
Appendix 1:
Purpose, nature, and scope of data processing
Purpose of data processing:
Provision of the Sleak platform for the use of AI-supported skill- and knowledge development according to the Main Contract.
Nature and scope of data processing:
- User account data: Names, email addresses, job titles and authentication credentials of users
- Content data: Communications with LLMs (e.g., chat messages or voice messages entered by users, uploaded documents, shared screen-contents and AI-generated responses); Conversation transcripts and feedback data
- Configuration data: Stored personas, scorecards, initiatives, programs and knowledge bases (to the extent that instructions or documents contain personal data)
- Usage data: Session and user ID, user-related metadata (e.g., conversation timestamps)
- Integration data: Personal data from third-party service integrations configured by the Controller and accessed via the Sleak platform
Categories of Data Subjects
- Employees and other users of the Controller who are granted access to the Sleak Platform (collectively “Users”)
- Third parties whose personal data is submitted to the Sleak platform by the Controller via documents, prompts, statements, or integrations.
Appendix 2:
List of authorized Sub-Processors
- Unternehmen, Sitz / Company, SeatMicrosoft Ireland Operations Limited, IrelandZweck / PurposeCloud-Infrastruktur und Hosting der Sleak-Plattform / Cloud infrastructure and hosting of the Sleak platformArt der Daten / Type of DataKundendaten / Controller DataOrt der Verarbeitung / Location of data processingEUTransfer-mechanismus /Transfer mechanism–
- Unternehmen, Sitz / Company, SeatMicrosoft Ireland Operations Limited, IrelandZweck / PurposeBereitstellung von KI-Diensten über Microsoft Azure / Provision of AI services via Microsoft AzureArt der Daten / Type of DataKundendaten / Controller DataOrt der Verarbeitung / Location of data processingEUTransfer-mechanismus /Transfer mechanism–
- Unternehmen, Sitz / Company, SeatGoogle Cloud EMEA Limited, IrelandZweck / PurposeBereitstellung von KI-Diensten / Provision of AI servicesArt der Daten / Type of DataKundendaten / Controller DataOrt der Verarbeitung / Location of data processingEUUS-Verarbeitung für spezifische SprachmodelleTransfer-mechanismus /Transfer mechanismEU-U.S. Data Privacy Framework, UK Extension, Swiss-U.S. Data Privacy Framework, EU SCCs, UK SCCs, Swiss Addendum
- Unternehmen, Sitz / Company, SeatSupabase, Inc., SingaporeZweck / PurposeDatenspeicherung, Datenbank und Nutzerverwaltung / Data storage, database and user managementArt der Daten / Type of DataKundendaten / Controller DataOrt der Verarbeitung / Location of data processingEUTransfer-mechanismus /Transfer mechanismEU SCCs, UK SCCs, Swiss Addendum
- Unternehmen, Sitz / Company, SeatEleven Labs Inc., USAZweck / PurposeBereitstellung von Sprach- und KI-Diensten / Provision of voice and AI servicesArt der Daten / Type of DataKundendaten / Controller DataOrt der Verarbeitung / Location of data processingEUUS-Verarbeitung für spezifische SprachmodelleTransfer-mechanismus /Transfer mechanismEU-U.S. Data Privacy Framework, UK Extension, Swiss-U.S. Data Privacy Framework, EU SCCs, UK SCCs, Swiss Addendum
- Unternehmen, Sitz / Company, SeatDeepgram, Inc., USAZweck / PurposeTemporäre Audiotranskription / Temporary audio transcriptionArt der Daten / Type of DataKundendaten / Controller DataOrt der Verarbeitung / Location of data processingEUTransfer-mechanismus /Transfer mechanismEU SCCs, UK SCCs, Swiss Addendum
- Unternehmen, Sitz / Company, SeatLiveKit Incorporated, USAZweck / PurposeWeb- & Telefon-Technologie zur Durchführung digitaler Gespräche mit virtuellen Personas / Web & telephony infrastructure for real-time conversations with virtual personasArt der Daten / Type of DataKundendaten / Controller DataOrt der Verarbeitung / Location of data processingEUTransfer-mechanismus /Transfer mechanismEU-U.S. Data Privacy Framework, UK Extension, Swiss-U.S. Data Privacy Framework, EU SCCs, UK SCCs, Swiss Addendum
- Unternehmen, Sitz / Company, SeatTwilio Germany GmbH, GermanyZweck / PurposeCloud-Kommunikationsplattform für SMS, Sprache und Telefonie / Cloud communications platform for SMS, voice and telephonyArt der Daten / Type of DataKundendaten / Controller DataOrt der Verarbeitung / Location of data processingEUWeltweit, abhängig von Dienst und Telekommunikations-RoutingTransfer-mechanismus /Transfer mechanismEU-U.S. Data Privacy Framework, UK Extension, Swiss-U.S. Data Privacy Framework, EU SCCs, UK SCCs, Swiss Addendum
- Unternehmen, Sitz / Company, SeatPostHog, Inc., USAZweck / PurposeProdukt- und Web-Analytics, Session-Replay, Feature Flags, Experimente und Umfragen / Product and web analytics, session replay, feature flags, experiments and surveysArt der Daten / Type of DataNutzungs- und Interaktionsdaten / Usage- and interaction dataOrt der Verarbeitung / Location of data processingEUTransfer-mechanismus /Transfer mechanismEU-U.S. Data Privacy Framework, UK Extension, Swiss-U.S. Data Privacy Framework, EU SCCs, UK SCCs, Swiss Addendum
- Unternehmen, Sitz / Company, SeatFunctional Software Inc. (Sentry), USAZweck / PurposeSammlung von Fehlermeldungen / Error trackingArt der Daten / Type of DataIP-Adressen, MAC-Adressen / IP addresses, MAC addressesOrt der Verarbeitung / Location of data processingEUTransfer-mechanismus /Transfer mechanismEU-U.S. Data Privacy Framework, UK Extension, Swiss-U.S. Data Privacy Framework, EU SCCs, UK SCCs, Swiss Addendum
The current list of sub-processors and notification of changes are available at trust.sleak.ai/subprocessors.
Appendix 3:
Technical and Organizational Measures implemented by the Processor
The technical and organizational measures are implemented by Sleak in accordance with Art. 32 GDPR. Sleak continuously develops these measures in line with feasibility and the state of the art and enhances the level of security and protection. ISO 27001 certification also contributes to the high level of security.
1. Confidentiality
1.1 Physical Access Control:
Measures to prevent unauthorized physical access to areas where personal data is processed. Sleak does not operate its own server rooms; employees work exclusively remotely or from rented coworking spaces. Productive data processing takes place exclusively in certified cloud infrastructures (see Appendix 2).
| Technical Measures | Organizational Measures |
|---|---|
| Physical access controls to data centers provided by the respective cloud providers (incl. SOC 2 Type II, ISO/IEC 27001) | Information Security Policy |
| Productive Controller Data is, as a rule, not permanently stored locally on end devices; documented and appropriately protected exceptions remain unaffected | Access controls of the respective coworking space providers |
1.2 Logical Access Control:
Measures to prevent data processing systems from being used by unauthorized persons.
| Technical Measures | Organizational Measures |
|---|---|
| Central authentication via directory service with Single Sign-On (SSO) | Password management system |
| Multi-factor authentication (MFA); two-factor authentication (email, biometric factor or authenticator app) | Password policy |
| Automatic logout and screen-lock procedures | Mobile device management policy |
| Full-disk encryption of managed end devices | Privileged Access Management (PAM) |
| Zero-trust architecture | No shared user accounts |
| Use of anti-virus / endpoint protection solutions | Encryption concept |
| Creation of individual user profiles |
1.3 Authorization Control:
Measures ensuring that authorized persons can only access data covered by their access authorization.
| Technical Measures | Organizational Measures |
|---|---|
| Access to servers exclusively encrypted (SSH with public key) | Role and authorization concept (RBAC) |
| Automatic account lockout after repeated incorrect password entry | Assignment of administrator rights to a minimum number of persons |
| Logging of application access | Access rights based on the need-to-know and least-privilege principles |
| Logging of administrative access, to the extent technically available and required | Documented role and authorization management |
| Regular review of access permissions |
1.4 Separation Control:
Measures ensuring that data collected for different purposes is processed separately.
| Technical Measures | Organizational Measures |
|---|---|
| Separation of production and test environments | Data Protection Policy |
| Logical tenant separation through access controls, role/authorization concepts | Control via authorization concept |
| Logical user separation | Definition of database rights |
1.5 Pseudonymization:
Processing in a manner such that data can no longer be attributed to a specific data subject without the use of additional information kept separately (Art. 32(1)(a) GDPR).
| Technical Measures | Organizational Measures |
|---|---|
| Logical separation of certain identity and content data, linked via technical identifiers to the extent provided for in the respective processing operation | Optional pseudonymized or alias-based display in suitable user interfaces |
| Removal or replacement of personally identifying fields in data exports for analytics purposes | Internal guidelines on pseudonymization/anonymization |
1.6 Encryption:
Measures ensuring that data at rest and in transit cannot be read by unauthorized persons.
| Technical Measures | Organizational Measures |
|---|---|
| Encryption of Controller Data at rest by the cloud infrastructure providers used, in accordance with recognized standards, generally at least AES-256 or a comparable standard | Key management by the respective cloud providers (provider-managed keys) in accordance with their security standards (ISO 27001, SOC 2 Type II) |
| Disk encryption of end devices (e.g. FileVault on macOS) | Encryption concept |
| Encryption of internet traffic (TLS 1.2/1.3) | |
| Encryption of data transmissions over public networks using TLS 1.2 or higher |
2. Integrity
2.1 Transfer Control:
Measures ensuring that personal data cannot be read, copied, altered or deleted without authorization during transmission or transport.
| Technical Measures | Organizational Measures |
|---|---|
| Encryption of data transmissions over public networks using TLS 1.2 or higher | Restriction and secure handling of mobile data carriers in accordance with documented guidelines, to the extent such data carriers are used |
| Encryption of internet traffic | Policies for the regular review and updating of the encryption standards used |
| Use of modern encryption protocols, generally TLS 1.2 or higher | |
| Transport encryption for email communication, to the extent supported by the respective communication channel | |
| Logging of security-relevant data access and administrative activities, to the extent technically available and required |
2.2 Input Control:
Measures enabling retrospective verification of whether and by whom data has been entered, modified or deleted.
| Technical Measures | Organizational Measures |
|---|---|
| Traceability of entry, modification and deletion through unique usernames | Assignment of rights to enter, modify and delete data on the basis of an authorization concept |
| Logging (access, entry, modification, deletion, transmission, failed access attempts) | Clear responsibilities for modifications and deletions |
| Safeguarding of log data against alteration and loss | Documented guidelines on the retention, review and protection of log data |
| Protection of log data against unauthorized alteration and loss | Regular risk-based review of security-relevant logs |
| Traceability of relevant administrative changes through individual user IDs |
2.3 Development, Change and Patch Management:
Measures to ensure integrity in the software development and deployment process.
| Technical Measures | Organizational Measures |
|---|---|
| Standardized CI/CD process with code review, automated testing, staging environment and controlled deployment | Code review and approval process |
| Automated update processes for operating systems, applications and services | Monthly review of dependencies |
| Prompt remediation of validated critical vulnerabilities; generally within 72 hours of assessment, provided a suitable patch is available and its deployment is technically feasible, otherwise implementation of appropriate compensating measures | Documentation and traceability of security-relevant changes as part of the change management process |
| Patching of the underlying infrastructure by the cloud providers |
3. Availability and Resilience
3.1 Availability Control:
Measures protecting personal data against accidental destruction or loss.
| Technical Measures | Organizational Measures |
|---|---|
| Redundant IT systems and, where used, geo-redundant system architectures of the cloud providers within the applicable agreed region or data zone | Avoidance of local data storage |
| Uninterruptible power supply, air conditioning, fire, water and surge protection in data centers (cloud providers) | Documented crisis/emergency plan (cloud providers) |
| Provider-managed storage redundancy and replication mechanisms | Regular review and updating of emergency plans |
| Automatic scaling and load balancing | |
| DDoS protection solutions | |
| Technical and organizational measures to reduce the risk of data loss |
3.2 Recoverability (Backup):
Measures for the rapid restoration of the availability of, and access to, personal data following an incident.
| Technical Measures | Organizational Measures |
|---|---|
| Automated creation of data backups | Storage of backups in a separate, secure area (cloud providers, zone redundancy) |
| Monitoring of data backups | Backup concept and disaster recovery plan |
| Defined responsibilities for data backup | |
| Regular testing of data recovery |
4. Procedures for Regular Review, Assessment and Evaluation
4.1 Data Protection Management:
Procedures and documentation to ensure ongoing compliance with data protection regulations.
| Technical Measures | Organizational Measures |
|---|---|
| Centralized data protection documentation accessible to all employees | External data protection officer appointed and responsibility for information security assigned |
| Data Protection Impact Assessment (DPIA), where required | |
| Regular review of the TOMs and of security certificates | |
| Regular audits of the scope of data | |
| Regular data protection and awareness training | |
| Documented processes for information obligations; formalized procedures for data subject requests | |
| Integration of data protection requirements into risk management |
4.2 Vulnerability and Patch Management:
Proactive measures for identifying, assessing and remediating security vulnerabilities.
| Technical Measures | Organizational Measures |
|---|---|
| Automated dependency/vulnerability monitoring | Monthly review of dependencies for security relevance |
| Prompt remediation of validated critical vulnerabilities; generally within 72 hours of assessment, provided a suitable patch is available and its deployment is technically feasible, otherwise implementation of appropriate compensating measures | Information Security Policy with defined reporting channels |
| Automated update processes for operating systems, applications and services |
4.3 Incident Response Management:
Measures for detecting, reporting and handling security and data protection incidents.
| Technical Measures | Organizational Measures |
|---|---|
| Logging and monitoring of security-relevant events | Documented procedures for detecting and monitoring incidents |
| Ability to immediately block compromised user accounts and access tokens | Documented processes for reporting security incidents |
| Documented procedure for incident response and post-incident review | |
| Documented procedure for notification of personal data breaches |
4.4 Data Protection by Design and by Default:
Measures pursuant to Art. 25 GDPR to uphold the principles of "data protection by design" and "data protection by default".
| Technical Measures | Organizational Measures |
|---|---|
| Integration of data protection default settings already at the system development stage | Documentation of the principles of data protection by design and by default in the Data Protection Policy |
| Collection of no more personal data than necessary for the respective purpose (data minimization) | Regular security reviews during development |
| Performance of Data Protection Impact Assessments (DPIAs), where legally required |
4.5 Processing Control (Sub-processors):
Measures ensuring that personal data processed on behalf of the Controller is processed only in accordance with instructions and by carefully selected sub-processors.
| Technical Measures | Organizational Measures |
|---|---|
| No uncontrolled interactive access by product-related sub-processors to production systems | Conclusion of data processing agreements pursuant to Art. 28 GDPR and/or EU Standard Contractual Clauses |
| Transmission of Controller Data to sub-processors via authenticated and encrypted interfaces or other secure transmission channels appropriate to the respective service | Data protection and security review prior to engaging material sub-processors |
| Access credentials, API keys and other secrets are appropriately protected, managed and, to the extent technically available and required, logged | Regular risk-based review based on appropriate evidence, in particular certifications, audit reports, trust center documentation and security questionnaires |
| Internal policy on the engagement of further sub-processors; cloud system security policy | |
| Provisions on the return or deletion of Controller Data after termination of the contract, taking into account agreed deletion and backup cycles |
5. Organization and Data Protection at Sleak
In its Quality, Risk and Compliance Policy, Sleak has set itself the goal, among other things, of providing its customers with products and services at the highest possible level of information security in compliance with applicable laws.
Employees are continuously informed and trained in data protection. In addition, all employees are contractually bound to data protection and confidentiality. Before commencing their work, external persons who may come into contact with personal data in the course of their activities for Sleak are required, by means of a non-disclosure agreement (NDA), to maintain secrecy and confidentiality and to comply with data protection requirements.