Zurück zu SuperEmber

Gültig ab July 17, 2026

Data Processing Addendum

This Data Processing Addendum governs SuperEmber's processing of Customer Personal Data on behalf of business customers and is designed to satisfy Article 28 of the GDPR.

1. Parties and incorporation

This Data Processing Addendum (DPA) forms part of the SuperEmber Terms of Service or another written agreement governing the customer's use of SuperEmber (the Agreement). It is between the customer identified through the applicable account, order, or Agreement (Customer) and Sirivat Asanasuwan, a natural person operating under the unregistered business name SuperEmber from Obere Hofstadt 23, 76703 Kraichtal, Germany (SuperEmber).

This DPA applies automatically when Customer uses the Services in a business capacity and SuperEmber processes Customer Personal Data on Customer's behalf. It becomes binding when Customer accepts the Agreement, creates or uses a business account, or signs this DPA. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls.

2. Definitions

Customer Personal Data means personal data contained in content, records, instructions, files, messages, connected-service data, or other information submitted to or generated through the Services that SuperEmber processes on Customer's behalf. Data Protection Laws means the GDPR and other privacy or data-protection laws applicable to that processing. Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Services means the SuperEmber website, application, AI employee and agent runtime, messaging integrations, workspaces, workflows, connectors, and related support services.

Controller, Processor, Data Subject, Personal Data, Process or Processing, and Supervisory Authority have the meanings given in the GDPR. Subprocessor means a third party engaged by SuperEmber to process Customer Personal Data in support of the Services.

3. Roles and documented instructions

Customer is the Controller of Customer Personal Data, or a Processor acting for another Controller. SuperEmber is Customer's Processor or Subprocessor, as applicable. Each party will comply with the obligations that Data Protection Laws assign to it.

This DPA does not govern personal data that SuperEmber processes as an independent Controller for its own account administration, billing, legal compliance, abuse prevention, or business communications. That processing is described in the SuperEmber Privacy Policy.

SuperEmber will process Customer Personal Data only on Customer's documented instructions, including the Agreement, this DPA, Customer's configuration and use of the Services, instructions submitted through prompts, channels, workflows, connected services, and support requests, and any additional written instructions the parties agree. SuperEmber may process Customer Personal Data where required by applicable law, but will inform Customer before doing so unless the law prohibits that notice. SuperEmber will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws and may suspend the affected processing while the parties resolve the issue.

4. Confidentiality and access

SuperEmber will limit access to Customer Personal Data to persons who need it to provide, secure, maintain, or support the Services. Every authorized person must be bound by an appropriate duty of confidentiality and receive access appropriate to their responsibilities. As of the effective date, Sirivat Asanasuwan is the only person with production or Customer Personal Data access. The same requirements apply before any future employee or contractor receives access.

5. Security of processing

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing as well as the risks to Data Subjects, SuperEmber will maintain appropriate technical and organizational measures designed to protect Customer Personal Data in accordance with Article 32 GDPR. The current measures are described in Annex 2. SuperEmber may update those measures provided the overall level of protection is not materially reduced.

6. Subprocessors

Customer gives SuperEmber general written authorization to engage the Subprocessors listed in the public Subprocessor Register. SuperEmber will impose data-protection obligations on each Subprocessor that provide a level of protection appropriate to the processing and materially equivalent to the applicable obligations in this DPA. SuperEmber remains responsible to Customer for a Subprocessor's performance of those obligations to the extent required by Data Protection Laws.

SuperEmber will give at least 30 days' notice before a new Subprocessor begins processing Customer Personal Data, normally by updating the register and notifying subscribed customers by email or in-product notice. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a reasonable alternative. If no reasonable alternative is available, Customer may stop using the affected feature or terminate the affected Services before the new Subprocessor begins processing. Customer may contact privacy@superember.ai to subscribe to notices.

7. Data Subject requests

Taking into account the nature of the processing, SuperEmber will provide reasonable assistance through appropriate technical and organizational measures so Customer can respond to requests to exercise Data Subject rights. If SuperEmber receives a request relating to Customer Personal Data directly from a Data Subject, it will promptly forward the request to Customer and will not respond on Customer's behalf unless Customer instructs it to do so or applicable law requires a response.

8. Assistance and Security Incidents

Taking into account the nature of processing and information available to it, SuperEmber will reasonably assist Customer with obligations under Articles 32 through 36 GDPR, including security, personal-data-breach assessment and notification, data-protection impact assessments, and prior consultation.

SuperEmber will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. The notice will include available information reasonably needed for Customer's assessment and notification duties, including the nature of the incident, affected data and Data Subjects, likely consequences, mitigation, and a contact point. Information may be supplied in phases as the investigation develops. Notification is not an admission of fault or liability.

9. Return and deletion

During the term, Customer may retrieve or delete Customer Personal Data through available product features or by contacting privacy@superember.ai. On termination or Customer's written request, SuperEmber will delete or return Customer Personal Data, at Customer's choice, unless applicable law requires retention. Deletion from active systems will be followed by expiry from backups and provider systems under their applicable retention cycles. SuperEmber may retain narrowly limited records where required by law or reasonably necessary for security, fraud prevention, dispute resolution, or legal claims, and will continue to protect them under this DPA.

10. Information and audits

SuperEmber will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. Customer may request relevant policies, summaries, questionnaires, or independent assurance materials once per year and after a material Security Incident. If that evidence is insufficient, Customer may conduct or appoint an independent auditor to conduct a proportionate audit on at least 30 days' written notice, subject to confidentiality, security, tenant-isolation, and reasonable scheduling requirements. Audits must not access another customer's data, disrupt the Services, or require disclosure of information that would create a security risk. Customer bears its audit costs unless the audit identifies a material breach by SuperEmber.

11. International transfers

SuperEmber is established in Germany. Some Subprocessors or their downstream providers may process Customer Personal Data outside the European Economic Area. SuperEmber will use a lawful transfer mechanism required by Chapter V GDPR, such as an adequacy decision, the EU-US Data Privacy Framework where applicable, or the European Commission's Standard Contractual Clauses, together with supplementary measures where required.

Where Customer's transfer of Customer Personal Data to SuperEmber is itself a restricted transfer and no other lawful mechanism applies, the European Commission Standard Contractual Clauses in Decision (EU) 2021/914 are incorporated by reference: Module Two applies when Customer is a Controller and Module Three when Customer is a Processor; the docking clause applies; Clause 9 Option 2 applies with the notice period in Section 6; optional Clause 11 does not apply; German law governs Clause 17; German courts have jurisdiction under Clause 18; Annexes 1 through 3 of this DPA complete the corresponding SCC annexes. If Customer is a Processor, it confirms it is authorized to bind the relevant Controller to those clauses.

12. Customer responsibilities

Customer is responsible for the lawfulness, fairness, accuracy, and transparency of its processing and instructions; providing required notices; establishing a lawful basis; obtaining required consents; responding to Data Subjects; configuring access and integrations appropriately; and ensuring it has authority to submit Customer Personal Data. The Services are not designed for intentionally processing special-category data, criminal-conviction data, or government identifiers unless the parties first agree in writing on the use case and additional safeguards. Customer will not instruct SuperEmber to process personal data in violation of Data Protection Laws.

13. Term, liability, and contact

This DPA remains in effect while SuperEmber processes Customer Personal Data. Liability arising from this DPA is subject to the Agreement's limitations to the extent permitted by law. The governing-law and jurisdiction provisions in the Agreement apply unless Data Protection Laws require otherwise. Privacy instructions, requests, audit notices, and Subprocessor objections must be sent to privacy@superember.ai.

Annex 1 — Details of processing

  • Subject matter and purpose: providing, securing, maintaining, and supporting the Services under Customer's documented instructions.
  • Nature of processing: collection, recording, organization, structuring, storage, retrieval, consultation, transmission, transformation, generation, use, restriction, deletion, and other operations needed to receive instructions, generate responses, execute authorized workflows and connected-service actions, provide support, and protect the Services.
  • Duration and frequency: continuous or user-triggered processing for the term of the Agreement, followed by deletion or return under Section 9 and applicable provider retention cycles.
  • Data Subjects: Customer users, administrators, employees, contractors, customers, prospects, correspondents, channel participants, connected-service users, and other individuals whose data Customer submits or makes available.
  • Personal Data: names and business contact details; account, user, organization, channel, and device identifiers; authentication and authorization metadata; messages, prompts, model inputs and outputs, files, audio, images, workspace and knowledge content; connected-service records and metadata; workflow instructions and results; support communications; usage, cost, diagnostic, audit, security, IP-address, and billing metadata.
  • Sensitive data: not intentionally required. Customer may incidentally submit special-category or criminal-conviction data, but must have a lawful basis and first obtain written agreement where the processing requires added safeguards.
  • Customer rights and obligations: determined by the Agreement, this DPA, Customer's configuration and instructions, and applicable Data Protection Laws.

Annex 2 — Technical and organizational measures

  • Access control: production and Customer Personal Data access is restricted to authorized persons with least-privilege accounts; privileged access is reviewed; future personnel must be authorized and bound to confidentiality before access.
  • Authentication and secrets: managed identity and authentication controls are used for customer access; service credentials are isolated from model-visible output and durable agent state; sensitive tenant credentials are encrypted using authenticated encryption and protected key material.
  • Encryption and transmission: HTTPS/TLS protects supported network transmission; managed providers supply encryption at rest for hosted database and storage services; sensitive connector credentials receive application-layer protection where implemented.
  • Tenant separation and minimization: server-derived tenant scope, authorization checks, scoped connector sessions, bounded telemetry, and reviewed analytics allowlists reduce cross-tenant and unnecessary-data exposure.
  • AI processing: OpenRouter requests require Zero Data Retention-capable routing and disable provider data collection; production AI observability is metadata-first unless a separately controlled non-production feature is enabled for approved testing.
  • Secure development: source control, protected changes, automated tests, type checks, dependency and secret scanning, code review controls, and staged deployment checks are used in proportion to the change risk.
  • Logging and incident response: security and operational events are logged with content minimization; suspected incidents are investigated, contained, documented, and escalated; personal-data breaches are assessed for notification duties.
  • Availability and recovery: managed infrastructure, durable database state, queued delivery, provider resilience, deployment rollback, and backup or recovery capabilities supplied by applicable providers support availability. Recovery procedures and evidence are reviewed as the service matures.
  • Deletion and lifecycle: account and organization data can be removed through product or supported operational procedures; provider deletion and backup expiry follow controlled retention and deletion processes. Legal holds and required security records are isolated where applicable.
  • Supplier management: material processors are recorded, reviewed for data-protection and security terms, and disclosed in the Subprocessor Register; customer-directed connected services are accessed only when Customer authorizes them.

Annex 3 — Authorized Subprocessors

The current authorized Subprocessors, their functions, processing locations or transfer notes, and change-notice instructions are maintained in the public Subprocessor Register. That register is incorporated into this DPA.

Authoritative language and signature

This English version is the authoritative version. No separate signature is required where this DPA is incorporated into the Agreement electronically. If a separately signed copy is required, contact legal@superember.ai.