Compliance Centre Document status 17.07.2026

Four documents.
One clear file.

The DPA, technical and organisational measures, subprocessors and EU AI Act documentation are all fully viewable online, versioned and available as PDF.

Your self-service process

  1. 01Add your company and usage details
  2. 02Review the complete DPA with annexes
  3. 03Confirm the version electronically
  4. 04Access your contract file and PDF anytime

Document library

Review the full text. Take the PDF.

Every version has a clear version number and effective date. Your personal DPA additionally stores the individually reviewed contract content and proof of acceptance.

01

Contract

v1.0 · 17.07.2026

DPA under Art. 28 GDPR

Contract text including instructions, data subject rights, incidents, deletion, TOMs and subprocessors.

02

Security

v1.0 · 17.07.2026

Technical and organisational measures

Control areas under Art. 32 GDPR with objectives and concretely documented standard measures.

03

Suppliers

v1.0 · 17.07.2026

Subprocessors

Current use, service, data types, processing location and third-country transfer mechanism.

04

Governance

v1.0 · 17.07.2026

EU AI Act documentation

Roles, intended purpose, limits of use, transparency, oversight and relevant implementation dates.

Subprocessors

No anonymous ‘cloud’.

The publicly documented list is generated from the same versioned source as the DPA. Optional external AI providers only appear according to their approval status and are only included in the customer-specific contract when that operating mode is selected.

Open the full register →
Company / roleStatus

intercolo GmbH

Rechenzentrums- und Serverbetrieb für Web-Frontend, Datenbank- und Inferenzkomponenten

Eingesetzt

OVHcloud

Externe LLM-Inferenz bei aktiver Auswahl eines Modells dieses Providers

Freigabe ausstehend

Scaleway

Externe LLM-Inferenz bei aktiver Auswahl eines Modells dieses Providers

Freigabe ausstehend

TOMs under Art. 32 GDPR

Verifiable measures, not invented figures.

The public version only contains centrally approved standard measures. Confidential operational details can be provided as part of an authorised audit process.

01

Zutrittskontrolle

Unbefugten physischen Zutritt zu Verarbeitungssystemen verhindern.

02

Zugangs- und Authentisierungskontrolle

Unbefugte Nutzung von Systemen und Konten verhindern.

03

Zugriffs- und Mandantentrennung

Sicherstellen, dass Daten nur im Rahmen der jeweiligen Berechtigung verarbeitet werden.

04

Übertragungs- und Weitergabekontrolle

Daten bei Übertragung schützen und Empfänger nachvollziehbar begrenzen.

05

Eingabe- und Protokollkontrolle

Wesentliche Änderungen und administrative Zugriffe nachvollziehbar machen.

06

Verfügbarkeit und Wiederherstellung

Verfügbarkeit und zeitnahe Wiederherstellbarkeit personenbezogener Daten unterstützen.

07

Datenschutzfreundliche Organisation

Datenschutzanforderungen über den gesamten Verarbeitungszyklus berücksichtigen.

EU AI Act

The use case determines the obligations.

The model alone does not determine the risk class. What matters is the purpose, context, impact on individuals, the customer's role and the specific integration. The EuGPT check asks through exactly these points in a structured way.

01

Stop criteria

Indicators of potentially prohibited practices lead directly to specialist review.

02

High-risk context

Employment, education, credit, biometrics and other Annex III contexts are flagged for closer review.

03

Transparency

Chatbots, public generative content and deepfakes trigger their own review tasks.

04

Governance

Human oversight, AI literacy, data protection and roles are output as measures.

Frequently asked questions

Clarified before you sign

Yes. After signing in, we guide you through the contracting party, scope of processing, data categories, data subjects, Art. 9/Art. 10 data and the provider operating mode. Before you accept, you see the complete, unamended contract.

The contract version, annexes, version number, declaration of acceptance, timestamp, contract and PDF checksums, and a server-side proof of integrity. The contract file remains accessible in your account.

In line with the DPA, intercolo notifies the controller without undue delay after becoming aware of a breach of the protection of personal data processed under the contract, and provides support with the available information. The 72-hour deadline under Art. 33 GDPR concerns the controller's notification to the supervisory authority.

No. They are only used when you actively select the relevant models and where approval is documented. For the DPA, you can choose the self-hosted operating mode or, optionally, external providers; providers without approval block the external completion mode.

No. It is a versioned initial assessment based on your answers. Potentially prohibited or high-risk uses are not approved but flagged for specialised expert review.

Ready for your documents

From full text to contract file.

Sign in, add your details and review the contract in full. For individual special arrangements, contact us directly.