HomeAboutPricing
Book a demo(opens in a new tab) Get Started
Home About Pricing
EnglishDeutsch
Get Started > Book a demo(opens in a new tab)
← Legal
← Legal
  • §01 Preamble
  • §02 Subject Matter of the Agreement
  • §03 The Controller’s Authority to Issue Instructions
  • §04 Protective Measures of the Processor
  • §05 Information and Assistance Obligations of the Processor
  • §06 Other Obligations of the Processor
  • §07 Engagement of Subprocessors
  • §08 Audit Rights
  • §09 Handling of Data Subjects’ Rights
  • §10 Term and Termination
  • §11 Deletion and Return of Data upon Termination of the Agreement
  • §12 Final Provisions
  • §13 Annex 1 — Categories of Data and Data Subjects
  • §14 Annex 2 — Persons Authorised to Give / Receive Instructions
  • §15 Annex 3 — Technical and Organisational Measures
  • §16 Annex 4 — Subprocessors at the Time of Conclusion of the Agreement
01 / 16

21 min read

Download PDF

This English version is a translation provided for convenience only. The German-language version is the original and the legally binding version. In the event of any divergence, ambiguity or conflict between this English translation and the German version, the German version shall prevail.

Updated October 3, 2026

Data Processing Agreement

  • §01 Preamble
  • §02 Subject Matter of the Agreement
  • §03 The Controller’s Authority to Issue Instructions
  • §04 Protective Measures of the Processor
  • §05 Information and Assistance Obligations of the Processor
  • §06 Other Obligations of the Processor
  • §07 Engagement of Subprocessors
  • §08 Audit Rights
  • §09 Handling of Data Subjects’ Rights
  • §10 Term and Termination
  • §11 Deletion and Return of Data upon Termination of the Agreement
  • §12 Final Provisions
  • §13 Annex 1 — Categories of Data and Data Subjects
  • §14 Annex 2 — Persons Authorised to Give / Receive Instructions
  • §15 Annex 3 — Technical and Organisational Measures
  • §16 Annex 4 — Subprocessors at the Time of Conclusion of the Agreement

This Data Processing Agreement is entered into by Melious AI GmbH, Campus Starterzentrum, Geb. A1.2 , 66123 Saarbrücken (hereinafter referred to as “Processor”) and the entity accepting them (herein after referred to as “Controller”; individually referred to as “Party” and together as the “Parties”).

§01Preamble

The Processor provides the Controller with services in the field of AI inference and complementary platform services on the basis of the General Terms and Conditions of the Processor accepted at https://melious.ai/legal/terms (hereinafter: "Principal Agreement"). Part of the performance of the Principal Agreement is the processing of personal data within the meaning of the General Data Protection Regulation ("GDPR"). In order to meet the requirements of the GDPR for constellations of this kind, the Parties enter into the following Agreement.

§02Subject Matter of the Agreement

1.1 The cooperation between the Parties entails that, within the scope of performing the Principal Agreement, the Processor processes personal data for which the Controller is responsible pursuant to Art. 4 No. 7 GDPR (hereinafter "Controller Data").

1.2 The Processor processes Controller Data exclusively for the purpose of performing the Principal Agreement, and the processing is also limited to this purpose. The respective data processing is described and documented in Annex 1, under continuous versioning, in terms of categories of data, categories of data subjects and processing operations. The duration of the processing corresponds to the term of the Principal Agreement.

1.3 The processing of Controller Data takes place exclusively within the territory of the Federal Republic of Germany, in a Member State of the European Union or in another Contracting State to the Agreement on the European Economic Area. Any transfer to a third country requires the Controller’s prior written consent and may only take place if the specific conditions of Art. 44 to 49 GDPR are met.

1.4 The provisions of this Agreement shall apply to all activities connected with the Principal Agreement in which the Processor or its vicarious agents process Controller Data.

§03The Controller’s Authority to Issue Instructions

2.1 The Processor processes Controller Data exclusively on the instructions of the Controller. This applies in particular to the transfer of personal data to a third country or to an international organisation. In this respect, the Controller has the exclusive right to issue instructions on the purposes and means of the processing of Controller Data (hereinafter also "right to instruct"). If the Processor is bound by the law of the European Union or the Member States to which it is subject to carry out further processing, it shall notify the Controller of these legal requirements prior to the processing, insofar as the relevant law does not prohibit such notification.

2.2 Instructions shall as a rule be issued by the Controller in writing within the extended meaning of § 127 (2) of the German Civil Code (BGB); instructions issued orally shall be confirmed by the Processor in that form. The persons entitled to give and to receive instructions on the part of the Parties are set out in Annex 2. In the event of a change or a longer-term impediment of the persons named in Annex 2, the successor or representative shall be notified to the other Party without delay in written form. Until such notification is received by the Controller, the persons named shall continue to be deemed authorised recipients.

2.3 If the Processor takes the view that an instruction of the Controller infringes data protection provisions, it shall point this out to the Controller without delay, stating the reasons. The Processor shall be entitled to suspend execution of the instruction concerned until it has been confirmed or amended by the Controller.

§04Protective Measures of the Processor

3.1 The Processor is obliged to secure Controller Data against being taken note of by unauthorised persons, taking into account the state of the art, in a manner appropriate to the respective risk.

3.2 Furthermore, the Processor shall oblige in writing to maintain confidentiality all persons who are or will be entrusted by it with the processing of Controller Data, who have or obtain knowledge thereof, who have or obtain access thereto, or to whom Controller Data is or becomes available in any other manner (hereinafter referred to as "employees"), and shall ensure compliance with this obligation with the requisite care. Upon the Controller’s request, the Processor shall demonstrate to it the corresponding commitment of the employees in an appropriate form.

3.3 The Processor shall organise its operations in such a way that it meets the special requirements of data protection. It undertakes to take at all times all appropriate technical and organisational measures for the adequate protection of the Controller Data pursuant to Art. 32 GDPR, in particular the measures set out in Annex 3 to this Agreement, and to maintain them for the duration of the processing of the Controller Data.

3.4 The Processor reserves the right to modify the implemented technical and organisational measures, whereby it ensures that neither the contractually agreed nor the legally required level of protection is fallen short of. The Processor shall inform the Controller immediately in writing if it has reason to believe that the measures under Annex 3 are no longer sufficient, and shall consult with the Controller on further technical and organisational measures.

3.5 Upon the Controller’s request, the Processor shall demonstrate to the Controller the compliance with and effectiveness of the respectively applied technical and organisational measures in an appropriate form, in particular by means of suitable documentation.

§05Information and Assistance Obligations of the Processor

4.1 If violations of the protection of Controller Data within the Processor’s sphere of influence or responsibility – i.e. in connection with the processing of Controller Data by it, by employees or by subprocessors which derive their processing of Controller Data directly or indirectly from the Processor – become known to the Processor, it shall inform the Controller thereof without delay. The same applies if the Processor obtains knowledge of circumstances which give concrete cause to fear such a violation of the protection of Controller Data. The same applies, finally, to examinations of the Processor by the data protection supervisory authority. The notifications pursuant to Clause 4.1 sentence 1 and sentence 2 shall each contain at least the information listed in Art. 33 (3) GDPR. Any notification by the Processor shall in any case be made in due time so as to enable the Controller to comply with its statutory notification obligations.

4.2 In the event referred to in Clause 4.1, the Processor shall assist the Controller to the necessary extent in fulfilling its investigative, remedial and information measures. In particular, the Processor shall immediately take the necessary measures to secure the data and to mitigate possible adverse effects on data subjects, inform the Controller thereof and, insofar as this is possible and indispensable risk mitigation and remedial measures are not prevented or delayed, request further instructions.

4.3 The Processor undertakes to provide the Controller, upon its oral or written request and within a reasonable period, with all information and evidence required for carrying out an audit pursuant to Clause 7.1 of this Agreement. Furthermore, the Processor shall, at the Controller’s request, provide it with a complete, accurate and up-to-date data protection and security concept relating to the Controller Data. It shall furthermore, upon the Controller’s request, submit appropriate records demonstrating the risk adequacy, implementation and effectiveness of the measures provided for therein.

§06Other Obligations of the Processor

5.1 The Processor is obliged to maintain a complete record of the processing activities involving Controller Data carried out on behalf of the Controller pursuant to Art. 30 (2) GDPR. The record shall be made available to the Controller upon request.

5.2 The Processor is obliged to assist the Controller in the preparation of a data protection impact assessment pursuant to Art. 35 GDPR and, where applicable, a prior consultation of the supervisory authority pursuant to Art. 36 GDPR, with regard to the collection and analysis of measures, processes, processing activities and circumstances of the data processing within its sphere of influence and responsibility.

5.3 The Processor confirms that it has appointed a data protection officer. The contact details of the data protection officer are: ePrivacy GmbH, represented by Prof. Dr. Christoph Bauer, Stefanie Bauer, Bei den Mühren 5, 20457 Hamburg, privacy@melious.de. Any change in the person of the operational data protection officer / data protection contact person shall be notified to the Controller without delay in writing.

5.4 If the Controller Data held by the Processor are put at risk by attachment or seizure, by insolvency or composition proceedings or by other events or measures of third parties, the Processor shall inform the Controller thereof without delay, insofar as it is not prohibited from doing so by a judicial or administrative order. In this context, the Processor shall immediately inform all competent authorities or other parties involved that the authority of disposition over the data lies exclusively with the Controller as the "controller" within the meaning of the GDPR.

§07Engagement of Subprocessors

6.1 Within the scope of its contractual obligations, the Processor is entitled to enter into sub-processing arrangements with subprocessors ("sub-processing"). The Controller hereby grants its general authorisation within the meaning of Art. 28 (2) sentence 2 GDPR.

6.2 The subprocessors which, at the time of conclusion of this Agreement, are or will be entrusted by the Processor with the processing of Controller Data, including the subject matter of their engagement, are set out in Annex 4 to this Agreement.

6.3 If the Processor intends to establish one or more further sub-processing arrangements or to entrust subprocessors with further processing, the Processor shall notify the Controller thereof at least three weeks before the commencement of such sub-processing. This notice shall contain the list of subprocessors in Annex 4 in the version applicable upon commencement of such sub-processing. Amendments to Annex 4 compared with the previous version shall be identified. Such notice shall be given in writing, whereby § 127 (2) BGB applies. The Processor shall furthermore ensure that the provisions agreed in this Agreement also apply vis-à-vis the subprocessors engaged by it, whereby the Controller shall be granted all audit rights pursuant to Clause 7 of this Agreement vis-à-vis the subprocessor.

6.4 Sub-processing by third parties outside the European Economic Area is only permitted if such third parties

a) are covered by an adequacy decision pursuant to Art. 45 (1) sentence 1 GDPR, or

b) Standard Data Protection Clauses pursuant to Art. 46 (2) (c) GDPR have been validly agreed with these subcontractors. Otherwise, such sub-processing shall only be permitted subject to release by the Controller.

6.5 Sub-processing within the meaning of these provisions does not exist where the Processor engages third parties for services that are to be regarded as purely ancillary services without any specific connection to services which the Processor renders for the Controller. These include, for example, postal, transport and shipping services, cleaning services, guarding services and telecommunications services. The Processor’s obligation to ensure an adequate level of protection, in particular pursuant to Clause 3 of this Agreement, also in such cases remains unaffected by the foregoing.

§08Audit Rights

7.1 The Controller is entitled to satisfy itself, on a regular and ad hoc basis, of compliance with the provisions of this Agreement, in particular the implementation of and compliance with the technical and organisational measures pursuant to Clause 3.3 of this Agreement relating to the processing of Controller Data by the Processor, employees and subprocessors. The Controller shall determine the type, scope and frequency of such review at its reasonable discretion in view of the requirements of Art. 32 GDPR. For this purpose, it may, for example, obtain information from the Processor, have existing expert opinions, certifications or results and findings of, as well as any documentation concerning, internal audits submitted to it, or have the Processor’s technical and organisational measures audited personally or by a knowledgeable third party at normal business hours, provided that such third party is not in competition with the Processor.

7.2 The Controller shall take due account of the operational processes of the Processor and the subprocessors when scheduling and carrying out audits. The date as well as the type and scope of any examination or audit under this Clause shall be agreed between the Parties in each individual case upon a corresponding request by the Controller.

7.3 The Controller shall document the result of each audit under this Clause 7 and communicate it to the Processor. In the event of errors, defects, legal infringements or irregularities identified by the Controller, it shall inform the Processor without delay. If facts are established during the audit which require changes to the Processor’s operational processes or organisation, the Processor shall immediately ensure the necessary adjustments in order to comply with the statutory or agreed requirements for the protection of the Controller Data.

§09Handling of Data Subjects’ Rights

8.1 By means of technical and organisational measures, the Processor ensures that the Controller is able to fulfil its obligations under Art. 12 to 22 as well as Art. 32 to 36 GDPR also with regard to processing of Controller Data within the sphere of influence and responsibility of the Processor and its subprocessors. Upon corresponding request, it shall without delay provide the Controller with information on Controller Data, insofar as the Controller does not itself have the relevant information.

8.2 If a data subject asserts their rights pursuant to Art. 16 to 18 GDPR, the Processor shall, upon the Controller’s instruction, without delay rectify, erase or restrict the Controller Data. Upon request, the Processor shall demonstrate the erasure, rectification or restriction of the data to the Controller in an appropriate form.

8.3 If a data subject asserts their rights, for example to information, rectification or erasure of their data, directly vis-à-vis the Processor, the Processor shall forward such request to the Controller without delay and await the Controller’s instructions. Without a corresponding specific instruction, the Processor shall not enter into contact with the data subject.

§10Term and Termination

9.1 The term of this Agreement corresponds to the term of the Principal Agreement. If the Principal Agreement may be terminated by ordinary notice, the provisions on ordinary termination shall apply accordingly. In case of doubt, termination of the Principal Agreement shall also constitute termination of this Agreement, and termination of this Agreement shall constitute termination of the Principal Agreement.

9.2 The Parties may terminate this Agreement at any time for cause. For the Controller, cause for termination exists in particular if the Processor intentionally or at least grossly negligently infringes provisions of the GDPR or is unable to execute an instruction of the Controller or seriously refuses such execution. In the case of simple – i.e. neither intentional nor grossly negligent – infringements, the Controller shall first set the Processor a reasonable period within which the Processor may remedy the infringement. Upon fruitless expiry of this period, the Controller shall be entitled to terminate this Agreement for cause.

§11Deletion and Return of Data upon Termination of the Agreement

10.1 Upon termination of the Principal Agreement or at any time upon the Controller’s request, the Processor shall return, or completely erase at the Controller’s reasonable discretion, all documents, data and data carriers provided to it which contain Controller Data, store it or allow conclusions to be drawn therefrom, insofar as no statutory retention period applies. A so-called "hard delete" is only required upon request and only insofar as the Controller demonstrates a legal interest therein. Otherwise, a so-called "soft delete" suffices, whereby the Processor must not take any measures that delay the final deletion of the Controller Data beyond ordinary IT operations. Information contained in data backups is exempt from the obligation to erase and may be kept intact until its scheduled deletion or its restoration in the ordinary course of business. If such backups are restored, the Controller Data contained therein shall be erased by way of a "hard delete". This shall not apply to documentation serving as evidence of the contracted and proper processing of the Controller Data. Such documentation shall be retained by the Processor, in a form consistent with the principle of data minimisation, until the expiry of the fourth calendar year following the respective data processing and shall be handed over to the Controller upon request. Only thereafter shall such documentation also be erased in accordance with the provisions of this Clause.

10.2 The Processor shall confirm to the Controller in writing the fulfilment of the obligations described above. The Controller has the right to verify the complete and contract-compliant fulfilment of these obligations in an appropriate manner; Clauses 7.1 and 7.2 of this Agreement shall apply accordingly. This right shall be available to it during the first calendar year following termination of the Agreement without further preconditions; thereafter only on the condition that there are tangible indications that no contract-compliant erasure has taken place.

§12Final Provisions

11.1 The Parties agree that the Processor’s plea of right of retention with regard to claims to which it is subject under this Agreement is excluded unless such right of retention is exercised on the basis of counterclaims of the Processor that have been finally judicially determined or are undisputed.

11.2 Amendments and supplements to this Agreement must be made in writing. This also applies to any waiver of this requirement as to form.

11.3 In case of doubt, the provisions of this Agreement shall take precedence over the provisions of the Principal Agreement. Should individual provisions of this Agreement prove entirely or partially invalid or unenforceable, or become invalid or unenforceable as a result of changes in legislation or supreme court case law after conclusion of the Agreement, the validity of the remaining provisions shall remain unaffected. The invalid or unenforceable provision shall be replaced by the valid and enforceable provision that comes as close as possible to the meaning and purpose of the void provision.

11.4 This Agreement is governed by German law.

11.5 The exclusive place of jurisdiction for all disputes arising out of or in connection with this Agreement is Cologne, North Rhine-Westphalia.

11.6 This Agreement has been concluded in German and in English. In the event of any discrepancies between the language versions, the German version shall prevail.

§13Annex 1 — Categories of Data and Data Subjects

Services involving the processing of Controller Data Categories of data processed Categories of data subjects
Provision of AI models for inference (text, code, image, audio, embeddings, reranking, content safety/guardrails) via API and web interface Inputs, in particular prompts and system instructions, files, images, audio recordings, as well as outputs generated therefrom, in particular text content, code, images, transcripts and embeddings. All persons whose data the Controller transmits, in particular employees, customers, prospects and contacts of the Controller; in the case of audio processing, additionally persons whose voice is contained in the recordings; in the case of image processing, additionally persons visible in the image content;
User and access management Master personal data, communication data (e.g. e-mail address), access and authorisation data (including API keys) Employees and other users of the Controller
Operations, security and logging Usage and log data (e.g. IP address, time stamps, model used, token volumes, routing and failover decisions, error codes). Only operational metadata is logged; message contents (inputs and outputs) are not logged. Employees and other users of the Controller
Support Communication data, time stamps, contents of support requests Contacts and users of the Controller
Tools for use with AI models Inputs, in particular search queries, requested URLs and web content, transmitted documents All persons whose data the Controller transmits, in particular employees, customers, prospects and contacts of the Controller;
Vector store Documents and files uploaded by the Controller, chunks and embeddings generated therefrom as well as associated metadata; storage until deletion by the Controller. All persons whose data the Controller transmits, in particular employees, customers, prospects and contacts of the Controller;

§14Annex 2 — Persons Authorised to Give / Receive Instructions

The Controller’s authorized representative is the person who accepts the data processing agreement on behalf of and with the approval of the Controller. Instruction recipients at the Processor is: Sebastian Nell, CTO, s.nell@melious.de

§15Annex 3 — Technical and Organisational Measures

Technical and organisational measures pursuant to Art. 32 GDPR

  • Confidential handling of data in the working organisation
  • Entry and access control relating to data
  • User authentication
  • Encryption concept for data in transit and data at rest
  • Separation of third-party and own data, separation of different customers’ data records
  • Logging of access to data
  • Regular data backups and concepts for the restoration of data in the event of data loss
  • Concept for the continuation of service provision in the event of security incidents and disruptions to the infrastructure
  • Concept for the deletion and migration of data stocks
  • Concepts for secure software development
  • Concept for the detection of and response to security incidents
  • Concept for the detection and remediation of vulnerabilities, patch management
  • Documentation of security measures, regular management reviews and the principle of continuous improvement of security measures.

The specific measures taken in the individual case depend on the services booked and actually used. They are made available to customers in aggregated form upon request. Otherwise, Clause 7 applies.

§16Annex 4 — Subprocessors at the Time of Conclusion of the Agreement

Name and address Description of services Country of service provision
Berget AI AB Götgatan 18, 118 46 Stockholm, Sweden AI inference: receipt and processing of API requests, execution of AI models (open-weight models) and return of model responses; resilience through multi-provider routing Sweden
Infercom SCS 29 Boulevard Grande-Duchesse Charlotte, 1331 Luxembourg, Luxembourg AI inference: receipt and processing of API requests, execution of AI models (open-weight models) and return of model responses; resilience through multi-provider routing Luxembourg
Inceptron AB Scheelevägen 15, 223 70 Lund, Sweden AI inference: receipt and processing of API requests, execution of AI models (open-weight models) and return of model responses; resilience through multi-provider routing Sweden
Nebius Group N.V. Gustav Mahlerlaan 300, 1082 ME Amsterdam, Netherlands AI inference: receipt and processing of API requests, execution of AI models (open-weight models) and return of model responses; resilience through multi-provider routing Netherlands
SEEWEB s.r.l. (Regolo.ai) C.so Lazio 9/a, 03100 Frosinone, Italy AI inference: receipt and processing of API requests, execution of AI models (open-weight models) and return of model responses; resilience through multi-provider routing Italy
Scaleway SAS 8 Rue de la Ville l'Évêque, 75008 Paris, France AI inference: receipt and processing of API requests, execution of AI models (open-weight models) and return of model responses; resilience through multi-provider routing France
TensorX Ltd. Unit 25 Classon House, Dundrum Business Park, Dublin 14, D14 N2F6, Ireland AI inference: receipt and processing of API requests, execution of AI models (open-weight models) and return of model responses; resilience through multi-provider routing Ireland
DataCrunch Oy (Verda) Lapinlahdenkatu 16, 00180 Helsinki, Finland AI inference: receipt and processing of API requests, execution of AI models (open-weight models) and return of model responses; resilience through multi-provider routing Finland
AKI.IO GmbH Marienburger Straße 1, 10405 Berlin, Germany AI inference: receipt and processing of API requests, execution of AI models (open-weight models) and return of model responses; resilience through multi-provider routing Germany
IONOS SE Elgendorfer Str. 57, 56410 Montabaur, Germany Cloud hosting and AI inference: provision of cloud infrastructure, hosting of platform components, processing of API requests; S3 object storage for storing client-side encrypted files (region eu-central-1, Frankfurt) Germany
OVH SAS (OVHcloud) 2 Rue Kellermann, 59100 Roubaix, France Cloud hosting, object storage and AI inference: provision of cloud infrastructure, hosting of platform components, storage of files and backups (S3-compatible object storage), processing of API requests France
weber.digital GmbH (weber.cloud) Zollernstraße 49, 72336 Balingen, Germany AI inference: receipt and processing of API requests, execution of AI models (open-weight models) and return of model responses; resilience through multi-provider routing Germany
G-Core Labs S.A. (Gcore) 2-4, rue Edmond Reuter, L-5326 Contern, Luxembourg DNS service: resolution of domain names, forwarding of DNS requests, logging of accesses; reduction of loading times, DDoS protection Luxembourg
Linkup Technologies SAS 28 Avenue des Pépinières, 94260 Fresnes, France Web search: performance of real-time internet searches based on AI-generated search queries, return of structured search results; data processing exclusively in the EU, zero data retention France
Qwant SAS 42 Avenue de la Porte de Clichy, 75017 Paris, France Web search: performance of internet searches based on AI-generated search queries, return of search results; privacy-friendly search without storage of personal search history, data processing in the EU France
Mollie B.V. Keizersgracht 126, 1015 CW Amsterdam, Netherlands Payment processing: processing of pseudonymised payment references, subscription and mandate management (SEPA direct debit, credit card), refund processing Netherlands
UAB „Data troops“ (Decodo, ehemals Smartproxy) Švitrigailos str. 34, Vilnius, Lithuania Proxy service: forwarding of outgoing platform requests via proxy infrastructure, processing of technical connection data Lithuania
sevDesk GmbH Im Unteren Angel 1, 77652 Offenburg, Germany Cloud accounting software: processing and storage of invoice, accounting and financial data; creation and management of invoices, receipt capture and archiving, advance VAT return Germany
Download PDF

Related

All legal pages
/legal
Datenschutzerklärung
/legal/privacy
Subprocessors
/legal/subprocessors
Melious

Making European AI accessible. Secure, sovereign, and sustainable.

+49 681 40458050 info@melious.de

Product

InferenceToolsVectorsPricing

Resources

DocumentationBlogChangelogStatusLegal

Company

AboutLinkedInInstagramYouTube
Book a demo(opens in a new tab) Contact

© 2026 Melious AI GmbH. All rights reserved.
Privacy PolicyLegal NoticeDPA