TERMS AND CONDITIONS FOR THE USE OF THE SAAS APPLICATION “FRAUNHOFER MEVIS SHOWROOM” (“APPLICATION”) FOR SCIENTIFIC NON-COMMERCIAL RESEARCH AND EVALUATION PURPOSES (hereinafter referred to as »Agreement«)¶
Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V., Hansastraße 27c, 80686 Munich, Germany (“Fraunhofer”), is an organization for application-oriented research and pursues exclusively and directly non-profit purposes.
The Fraunhofer Institute for Digital Medicine MEVIS (MEVIS) develops real-world software solutions for image and data supported early detection, diagnosis, and therapy and has developed a software to evaluate the image quality of lung CT data as part of its activities. Fraunhofer has the right to use and exploit the Software (as defined below), with the exception of those components that constitute third-party software within the meaning of this Agreement. The Software (as defined below) is currently in the development stage; it shall therefore not be used for medical purposes.
Fraunhofer is willing to grant limited rights to use the Software and Services (as defined below) for scientific non-commercial research and evaluation purposes only without the right to sublicense or transfer the Software or Services; the use for other purposes is not allowed.
1. Definitions¶
- »Field of Use« is defined as internal scientific non-commercial research and evaluation.
- »User« means the legal or natural person using the Software.
- »Third Party Software« means any computer program provided by third parties as licensors and/or authors/right holders under their own license terms, including but not limited to open source software as defined by the Open Source Initiative (www.opensource.org). Third-party software used or included is listed under https://fraunhofer-mevis-showroom.de/oss/. If Fraunhofer software is listed as Third Party Software on the aforementioned page, Fraunhofer shall also be deemed to be a third-party and the software shall be deemed to be Third Party Software for the purposes of this Agreement.
- »Software« means the web application made available by Fraunhofer under https://fraunhofer-mevis-showroom.de.
- »Services« means the services made available within the Software, such as managing the User’s Uploaded Data and executing the show-cased Algorithms on the User’s Uploaded Data.
- »Uploaded Data« means any files, including but not limited to medical data, images, annotations, or metadata, uploaded by Users to the Software.
- »User Content« means all Uploaded Data and any other data and intellectual property submitted or created by a User within the Software.
- »Results« means data produced as the output of Algorithms.
- »Algorithm« means any computational tool made available via or uploaded to the Software that processes or analyzes medical data.
2. Subject matter, registration, user account¶
2.1¶
This Agreement serves to define the legal relationship between Fraunhofer and registered Users regarding the provision of the Software and Services free of charge as software-as-a-service in accordance with Annex A.
2.2¶
A User account must be created to use the Software. After submitting the corresponding registration form, Fraunhofer may send an individual activation link to the email address provided during registration. Clicking on the activation link completes the registration process and establishes a contract in accordance with this Agreement. Upon completion of registration, the User receives password-protected access to their User account (“User Account”), where they can view and change their User data after logging into the User area (“User Area”).
2.3¶
The User must provide their legal full name, a valid email address, and any other information requested to complete the signup process.
2.4¶
A User Account may only be used by one person. A single User Account shared by multiple people is not permitted.
2.5¶
A User must only have one User Account. Multiple User Accounts for the same person are not permitted.
2.6¶
The person completing the registration (“Registrant”) warrants that they are authorized to represent the User if the User is not a natural person. If the User is a natural person, the Registrant declares that it is the User.
3. Grant of rights, permitted use, restrictions¶
3.1¶
For the duration of the Agreement and to the extent necessary for the use of the Software, the User shall receive a non-exclusive, i.e. non-sublicensable and non-transferable, right limited to the duration of the Agreement to use the Software by means of access via a web browser on the AWS infrastructure in accordance with the provisions of this Agreement. The User understands that Fraunhofer uses “Amazon Web Services” (AWS) to provide the necessary hardware, software, networking, storage, and related technology required to run the Software and Services.
3.2¶
Fraunhofer provides the Software only for use within the Field of Use. Use in the context of commercial and non-commercial offers to third parties is prohibited. In particular, the User is prohibited from offering the Software and Services to consumers within the meaning of § 13 BGB as digital products within the meaning of §§ 327 ff. BGB.
3.3¶
The use of the Software for diagnostic, therapeutic and/or other medical purposes is prohibited.
3.4¶
The Software is not physically transferred to the User.
3.5¶
If the User is a legal person, the Software may only be used by the User’s own personnel. Any further use of the Software by the User is not permitted.
4. Provision, changes, availability¶
4.1¶
Fraunhofer provides the Software free of charge. The Software may be changed or its provision discontinued at any time without prior notice.
4.2¶
Fraunhofer is not obligated to ensure a specific level of functionality and availability of the Software during the term of this Agreement. In particular, Fraunhofer is not obligated to adapt the Software to the individual needs or IT environment of the User.
4.3¶
Fraunhofer may, without being obligated to do so, update or further develop the Software at any time and, in particular, adapt it due to changes in the legal situation, technical developments, or to improve IT security. In doing so, Fraunhofer will take the legitimate interests of the User into account appropriately.
5. User obligations¶
5.1¶
The User shall protect and store their access data in accordance with the state of the art to prevent access by third parties. The User shall ensure that use is limited to the scope agreed herein. Fraunhofer shall be notified immediately of any unauthorized access. Fraunhofer will not be liable for any loss or damage from the User’s failure to comply with this security obligation.
5.2¶
The User is responsible for all User Content posted and activity that occurs under their account. The User is obliged not to store any data on the storage space provided whose use violates applicable law, official orders, third-party rights, or agreements with third parties.
5.3¶
The User shall check User Content for viruses or other harmful components before storing or using it in the Software and shall use state-of-the-art measures (e.g., virus protection programs) for this purpose.
5.4¶
The User is responsible for regularly performing appropriate data backups.
6. Third Party Software¶
Fraunhofer does not grant any rights to Third Party Software. Any use of Third Party Software is subject exclusively to the applicable third-party license terms referenced in the Third Party Software list (https://fraunhofer-mevis-showroom.de/oss/).
7. User Content, Results, intellectual property¶
7.1¶
The User retains all rights, title, and interest in any User Content uploaded to the Software.
7.2¶
For the term of this Agreement, if User Content is protected by copyrights or other rights, the User grants Fraunhofer the free, revocable, temporally and spatially unrestricted right to use such protected content in the Software within the scope of the services and functionalities for which the User has uploaded/posted it. Fraunhofer shall not use User Content for any other purpose. This license terminates upon the earliest of (i) the User deleting the relevant User Content from the Software or (ii) the User deleting their User Account.
7.3¶
User Content is not made available to other Users unless the User grants access through the Software’s sharing features. The User may revoke sharing at any time.
7.4¶
Fraunhofer does not pre-screen content. Fraunhofer may refuse, disable access to, or remove User Content where necessary to ensure the functioning and security of the Software and Services, where the content is unlawful, infringes third-party rights, or breaches this Agreement.
7.5¶
By uploading User Content, the User represents and warrants that (a) the User holds or has obtained all rights, licenses, and consents necessary to do so and to grant the license set out in this Section 7, (b) the User Content does not violate applicable law or third-party rights, and (c) where User Content contains personal data, the User has ensured that such data have been irreversibly anonymized prior to upload and that he complies with all applicable data protection laws.
7.6¶
Fraunhofer does not have nor claims any rights to Results generated by the User by using the Services of the Software, unless explicitly agreed otherwise in writing. However, the User shall not use Results for any other purposes as those within the Field of Use.
8. Voluntary support¶
Fraunhofer is not obligated to provide maintenance, care, or support. If Fraunhofer does provide such services, this is done either voluntarily or based on a separate agreement with the User. Fraunhofer is not obligated to conclude such separate agreement.
9. Commencement, duration and termination of the Agreement¶
9.1¶
Upon completion of the registration process, this Agreement enters into force, which entitles the User to use the Software to the extent specified in clause 3 and in accordance with this Agreement.
9.2¶
This Agreement can be terminated by either party at any time by giving notice in writing (email sufficient). The User should send an email to support@fraunhofer-mevis-showroom.de from the email address associated with the User’s account to terminate their account.
9.3¶
The User shall receive confirmation in writing of the receipt of a notice of termination issued by the User and the date of termination of this Agreement.
9.4¶
The right of the parties to terminate the Agreement without notice remains unaffected by the provisions of the preceding paragraphs.
9.5¶
Upon termination of the Agreement or deletion of the User Account, the User’s right to access and use the Software and Services ceases.
10. Liability, Warranty¶
10.1¶
With regard to Fraunhofer's warranty and liability, the statutory provisions on lending (§§ 598ff. BGB) apply. The Software is a work in progress. The Software is not complete and may therefore contain errors ("bugs"), as is inherent in this type of development.
10.2¶
Except in cases of intentional and grossly negligent conduct, Fraunhofer, its legal representatives, trustees, officers and employees shall not be liable for direct or indirect, material or immaterial loss or damage of any kind arising from this Agreement or the use of the Software; this applies, among other things, but not exclusively, to loss of goodwill, loss of production, computer failures or errors, loss of data or economic loss or damage, even if Fraunhofer has been notified of the possibility of such loss or damage.
10.3¶
Irrespective of clause 10.1, Fraunhofer shall only be liable within the scope of statutory product liability to the extent that the respective provisions are applicable to the Software.
10.4¶
The User indemnifies Fraunhofer against any claims of third parties, including related costs such as reasonable lawyers' fees and court costs, asserted against Fraunhofer in connection with the User’s exercise of the license and the right to access and use the Software and Services or due to a breach of the terms of this Agreement by the User.
10.5¶
The User indemnifies Fraunhofer against all claims by third parties in connection with the use of the User Content uploaded and/or posted by the User, insofar as Fraunhofer has used this content within the scope of providing the Software. This includes reimbursement of reasonable costs incurred in defending against such third-party claims; the User shall support Fraunhofer in its defense to a reasonable extent.
10.6¶
With regard to the Software and Services, Fraunhofer has not complied with any regulatory requirements (including norms or other standards) applicable to medical devices, in-vitro diagnostics or medicinal products.
Fraunhofer has not provided any technical documentation, quality assurance, risk management or risk analysis (e.g. in accordance with EN ISO 13485, 14971 or 62304).
Fraunhofer makes no representations regarding the therapeutic, diagnostic or other medical purpose, usability, performance or safety of the Software or its suitability for conformity assessment purposes of medical devices or in-vitro diagnostics. Fraunhofer is not responsible for the usability and quality of the Software being unaffected if implemented in other results or used in conjunction with other results.
The User understands and accepts that the Software and Services are considered research software and are not a medical device. Furthermore, the User knows and accepts that all results generated or obtained by using the Software may not be used for diagnostic or therapeutic or other medical purposes. Furthermore, the Software is not intended for use in therapeutic or diagnostic applications on humans or for other medical purposes.
11. Data protection, confidentiality¶
11.1¶
The parties are aware of the requirements of the applicable data protection regulations (in particular, the EU General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG)) and support each other in complying with them.
11.2¶
The User acknowledges that it is the User's sole responsibility to ensure that all Uploaded Data has been irreversibly anonymized prior to upload. In particular, the User shall remove all identifying metadata (such as patient names, dates of birth, patient identifiers, and examination dates) from image data before uploading. The Parties acknowledge that, despite such anonymization efforts, it cannot be entirely excluded that Uploaded Data may, in individual cases, constitute or contain personal data within the meaning of Art. 4(1) GDPR. As a precautionary measure, the Parties therefore enter into a data processing agreement pursuant to Art. 28 GDPR, which is attached as Annex B and forms an integral part of this Agreement. In the event of any conflict between this Agreement and Annex B with respect to the processing of personal data contained in Uploaded Data, Annex B shall prevail.
11.3¶
With regard to registration data collected by Fraunhofer (such as username, email address, first name, last name, institution, department, and country), Fraunhofer acts as an independent controller within the meaning of Art. 4(7) GDPR. The processing of such registration data is governed by Fraunhofer's privacy notice and is not subject to the data processing agreement in Annex B.
12. No Trademarks¶
This Agreement does not grant permission to use the trade names, trademarks, service marks or product names of Fraunhofer.
13. Applicable Law, Place of Jurisdiction¶
13.1¶
The laws of the Federal Republic of Germany apply exclusively to the exclusion of the conflict of law provisions and the United Nations Convention on Contracts for the International Sale of Goods (CISG). The courts of Munich are hereby agreed as place of jurisdiction for all disputes arising from or connected with this Agreement. However, Fraunhofer is also entitled to bring legal action before the courts responsible for the User's place of business.
13.2¶
The contract language is English.
13.3¶
If one or more of the above clauses are or become invalid over time, the remaining clauses shall remain unaffected.
13.4¶
The User may only assign rights and obligations arising from this Agreement with Fraunhofer's prior express consent.
13.5¶
The User may only offset claims by Fraunhofer with undisputed or legally established claims.
Annex A – Application¶
The Fraunhofer MEVIS Showroom is a cloud-based software-as-a-service application hosted by the Fraunhofer Institute for Digital Medicine MEVIS on Amazon Web Services (AWS) infrastructure. After registration and verification, the User can upload medical imaging datasets. The User is responsible for ensuring proper anonymization prior to uploading any data. The web application contains an automatic quality assessment algorithm for lung CT data that the User can execute on a limited number of their uploaded medical images. Afterwards, the User can view the Results of the Algorithm via an integrated medical image viewer and download the Results. The Software is considered research software and is not a medical device. Results generated or obtained by using the Software may not be used for diagnostic or therapeutic or for other medical purposes. Furthermore, the Software is not intended for use in therapeutic or diagnostic applications on humans or for other medical purposes.
Annex B – Data Processing Agreement¶
Pursuant to Art. 28 GDPR
Between the User of the Software as defined in the Agreement (hereinafter "Controller")
and
Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V., Hansastraße 27c, 80686 Munich, Germany, represented by the Fraunhofer Institute for Digital Medicine MEVIS (hereinafter "Processor")
collectively the "Parties"
Preamble¶
This Data Processing Agreement ("DPA") supplements the Terms and Conditions for the use of the SaaS application "Fraunhofer MEVIS Showroom" ("Agreement") between the Parties.
The Processor provides a SaaS application that enables the Controller to upload lung CT image data and to execute quality assessment algorithms on such data. Prior to any upload, the Controller is required to irreversibly anonymise all Uploaded Data, in particular by removing all identifying metadata (such as patient names, dates of birth, patient identifiers, and examination dates) in accordance with Section 10.5 of the Agreement. The Parties proceed on the assumption that, as a result of such anonymisation, no personal data within the meaning of Art. 4(1) GDPR will be contained in the Uploaded Data.
However, the Parties acknowledge that (a) it cannot be fully guaranteed that the Controller will remove all identifying metadata in every case, and (b) in individual cases, a reference to an identifiable natural person may potentially be derived from the image data itself. This DPA is therefore concluded as a precautionary measure to ensure compliance with Art. 28 GDPR in the event that Uploaded Data does, contrary to the Parties' expectations, constitute or contain personal data.
For the avoidance of doubt: This DPA applies exclusively to the processing of Uploaded Data (as defined in the Agreement). With regard to registration data collected by Fraunhofer (such as username, email address, first name, last name, institution, department, and country), Fraunhofer acts as an independent controller within the meaning of Art. 4(7) GDPR. The processing of registration data is not subject to this DPA.
Section 1 – Subject matter and duration¶
(1) Subject matter¶
The subject matter of this DPA is determined by the Agreement. The Processor stores and processes Uploaded Data on behalf of the Controller on cloud infrastructure for the purpose of executing quality assessment algorithms for lung CT image data and providing the Results to the Controller.
(2) Duration¶
The duration of this DPA corresponds to the term of the Agreement. This DPA shall, in any event, remain in force for as long as the Processor processes Uploaded Data that may contain personal data on behalf of the Controller.
(3) Precedence¶
This DPA shall take precedence over any other agreements between the Parties relating to the protection of personal data, unless the Parties expressly agree otherwise.
Section 2 – Specification of the processing¶
(1) Nature and purpose of the processing¶
The Processor processes Uploaded Data on behalf of the Controller for the following purposes:
- Storage of Uploaded Data (lung CT image data) on cloud infrastructure (AWS);
- Execution of quality assessment algorithms on the Uploaded Data;
- Provision of Results to the Controller;
- Deletion of Uploaded Data upon the Controller's instruction or upon termination of the Agreement.
The Processor shall not use the Uploaded Data for any other purpose, including its own research purposes.
(2) Types of data¶
The following categories of data may be subject to processing under this DPA, to the extent that they constitute personal data despite the Controller's anonymisation efforts:
- Lung CT image data (DICOM or other image formats);
- Metadata potentially contained in the image files (e.g. patient name, date of birth, patient identifier, examination date, institution name) — to the extent not removed by the Controller prior to upload;
- Results of the algorithmic analysis, to the extent that they permit identification of a natural person.
The Parties expect that, under normal circumstances, none of the above data will constitute personal data. This DPA applies on a precautionary basis in the event that this expectation does not hold true in individual cases.
(3) Categories of data subjects¶
Patients whose CT image data is uploaded by the Controller, to the extent that such persons are identifiable.
Section 3 – Technical and organisational measures¶
(1)¶
The Processor shall implement all necessary technical and organisational measures pursuant to Art. 32 GDPR to protect any personal data contained in the Uploaded Data and shall provide the Controller with documentation of such measures (Annex B.1). The Controller shall review the measures and inform the Processor without undue delay of any concerns. Upon acceptance by the Controller, the documented measures shall form the basis of this DPA.
(2)¶
Where a review or audit by the Controller identifies a need for adjustments, such adjustments shall be implemented by mutual agreement.
(3)¶
The agreed technical and organisational measures are subject to technical progress and further development. The Processor is permitted to implement alternative adequate measures, provided that the security level of the agreed measures is not reduced. The Processor shall inform the Controller without undue delay of any material changes, which shall be documented by the Processor.
Section 4 – Rights of data subjects¶
(1)¶
The Processor shall, within its area of responsibility and to the extent possible, assist the Controller by means of appropriate technical and organisational measures in fulfilling requests from data subjects regarding their data protection rights. Where the Processor provides software to the Controller, the Processor is not obligated to design the software so that data subject rights under the GDPR can be fulfilled by means of integrated functions, unless this is expressly part of the Agreement. The Processor shall not disclose, port, rectify, erase, or restrict the processing of data processed on behalf of the Controller on its own initiative, but only upon documented instructions from the Controller. Where a data subject contacts the Processor directly, the Processor shall forward such request to the Controller without undue delay.
(2)¶
The Controller may at any time delete Uploaded Data using the deletion functionality provided within the Software. Upon deletion of the Controller's User Account or upon termination of the Agreement, the Processor shall delete all Uploaded Data in accordance with Section 10 of this DPA.
Section 5 – Quality assurance and other obligations of the Processor¶
(1)¶
The Processor has its own statutory obligations under the GDPR; in particular, the Processor ensures compliance with the following:
- (a) Confidentiality pursuant to Art. 28(3)(b), Art. 29, Art. 32(4) GDPR. The Processor shall only deploy personnel who have been bound to confidentiality and have been familiarised with the relevant data protection provisions. The Processor and any person acting under its authority who has access to personal data shall process such data exclusively in accordance with the Controller's instructions, including the authorisations granted under this DPA, unless required to do so by Union or Member State law.
- (b) The Controller and the Processor shall, upon request, cooperate with the supervisory authority in the performance of its tasks.
- (c) The Processor shall inform the Controller without undue delay of any inspections or measures by the supervisory authority, insofar as they relate to this DPA. This shall also apply where a competent authority investigates the Processor in connection with administrative offence or criminal proceedings relating to the processing of personal data in the context of this DPA.
- (d) Where the Controller is subject to an inspection by the supervisory authority, administrative offence or criminal proceedings, a liability claim by a data subject or a third party, or any other claim or request for information in connection with the processing by the Processor, the Processor shall provide reasonable support.
- (e) The Processor shall regularly monitor its internal processes as well as the technical and organisational measures to ensure that processing within its area of responsibility complies with applicable data protection law and that the rights of data subjects are protected.
- (f) The Processor shall be able to demonstrate the technical and organisational measures taken to the Controller within the scope of the Controller's audit rights under Section 8 of this DPA.
- (g) The Processor shall report any personal data breach to the Controller without undue delay in a manner that enables the Controller to fulfil its statutory obligations, in particular under Art. 33 and Art. 34 GDPR.
- (h) The Processor shall provide reasonable support to the Controller with regard to notification obligations towards supervisory authorities and data subjects and shall make all relevant information available without undue delay.
- (i) Where the Controller is required to carry out a data protection impact assessment, the Processor shall provide support, taking into account the nature of the processing and the information available to it. The same shall apply to any obligation to consult the competent supervisory authority.
(2)¶
This DPA does not release the Processor from compliance with other provisions of the GDPR.
Section 6 – Sub-processing¶
(1)¶
Sub-processing relationships within the meaning of this Section are services that directly relate to the provision of the main service. Ancillary services (e.g. telecommunications, postal/transport services, cleaning, security services) do not constitute sub-processing. Maintenance and testing services constitute sub-processing where they are provided for IT systems used in connection with the Processor's services under this DPA. The Processor is, however, obligated to ensure appropriate and lawful contractual arrangements and control measures for ancillary services in order to guarantee the protection and security of the Controller's data.
(2)¶
The Controller hereby grants general authorisation for the engagement of sub-processors, subject to the conditions set out below.
- (a) The Controller approves the engagement of the sub-processor(s) listed in Annex 2, subject to the conclusion of a contractual arrangement in accordance with Art. 28(2)–(4) GDPR with the sub-processor. The contractual arrangement shall be provided to the Controller upon request, with the exception of commercial clauses without data protection relevance.
- (b) The engagement of additional sub-processors and the replacement of existing sub-processors listed in Annex 2 shall be permissible, provided that:
- the Processor notifies the Controller of such engagement in writing or in text form (email or publication on website is sufficient) with reasonable advance notice of no less than 14 days; and
- the Controller does not object in writing or in text form to the planned engagement by the time the data is handed over to the sub-processor; and
- a contractual arrangement in accordance with Art. 28(2)–(4) GDPR is in place.
(3)¶
The transfer of personal data to the sub-processor and the sub-processor's commencement of processing shall only be permitted once all requirements for sub-processing have been met.
(4)¶
Where the sub-processor provides the agreed services outside the EU/EEA, the Processor shall ensure the lawfulness of the data transfer by appropriate measures under data protection law. The same applies to ancillary service providers within the meaning of paragraph (1).
(5)¶
The relationship between the Processor and AWS as sub-processor is governed by the AWS service terms (including the AWS GDPR Data Processing Addendum). By entering into this DPA, the Controller acknowledges and accepts this arrangement.
Section 7 – International data transfers¶
(1)¶
Any transfer of personal data to a third country or an international organisation requires a documented instruction from the Controller (including approval of a corresponding sub-processor) and compliance with the requirements for the transfer of personal data to third countries under Chapter V of the GDPR.
(2)¶
The contractually agreed data processing takes place exclusively in a Member State of the European Union or in another Contracting State of the Agreement on the European Economic Area, unless otherwise agreed, for example in the form of an approved sub-processing arrangement in a third country.
(3)¶
Where the Controller instructs a transfer to a third country, the Controller shall be responsible for compliance with Chapter V of the GDPR.
Section 8 – Audit rights of the Controller¶
(1)¶
The Controller shall have the right, in consultation with the Processor, to carry out inspections or to have them carried out by auditors to be designated on a case-by-case basis. The Controller shall have the right to satisfy itself of the Processor's compliance with this DPA by means of spot checks, which shall generally be announced in advance in a timely manner, at the Processor's premises during normal business hours. With respect to sub-processors, the Processor shall exercise its audit rights vis-à-vis the relevant sub-processor in accordance with the Controller's instructions; any costs charged by the sub-processor in connection with such audit shall be borne by the Controller.
(2)¶
The Processor shall ensure that the Controller is able to verify the Processor's compliance with its obligations under Art. 28 GDPR. The Processor undertakes to provide the Controller, upon request, with the necessary information and, in particular, to demonstrate the implementation of the technical and organisational measures.
Section 9 – Instructions of the Controller¶
(1)¶
The Processor shall process personal data only on the basis of documented instructions from the Controller, unless required to do so by Union or Member State law. Oral instructions shall be confirmed by the Controller without undue delay (at least in text form). The initial instructions of the Controller are set out in this DPA and in the Agreement.
(2)¶
The Processor shall inform the Controller without undue delay if, in its opinion, an instruction infringes data protection law. The Processor shall be entitled to suspend the execution of the relevant instruction until it is confirmed or amended by the Controller.
Section 10 – Deletion and return of personal data¶
(1)¶
Copies or duplicates of the data shall not be created without the Controller's knowledge. Excluded from this are back-up copies to the extent necessary to ensure proper data processing, as well as data required for compliance with statutory retention obligations.
(2)¶
The Processor shall delete all Uploaded Data:
- (a) upon the Controller's manual deletion of Uploaded Data using the Software's deletion functionality;
- (b) upon deletion or termination of the Controller's User Account in accordance with Section 3.3 of the Agreement;
- (c) upon termination of the Agreement, or earlier upon the Controller's request.
After deletion, the Processor shall, upon request, provide a record of the deletion.
Upon termination of the Agreement, the Processor will upon the Controller’s request return the data before it is deleted. Return of data shall be in the format in which the data is stored or processed by the Processor or, at the Processor's choice, in another common format (e.g. CSV, XML, JSON). Return in another format requires a separate agreement.
(3)¶
The Processor shall not retain or use the Uploaded Data for its own purposes, including research purposes, after the events described in paragraph (2) or at any other time.
Section 11 – Remuneration¶
(1)¶
The Processor's services under this DPA are covered by the Agreement, which provides the Software free of charge. However, the following services may give rise to additional costs:
- Efforts caused by the fulfilment of the Processor's support obligations (in particular Art. 28(3)(e) and (f) GDPR);
- Implementation of instructions whose content exceeds what the Processor owes the Controller under the Agreement;
- Efforts arising from audits (in particular pursuant to Section 8(1)), excluding efforts relating to the demonstration of general security measures.
(2)¶
No remuneration shall be due if and to the extent that the effort was caused by a culpable breach of duty by the Processor.
(3)¶
Costs include, in addition to third-party costs (e.g. travel expenses), remuneration for working time of the Processor's personnel at a rate of EUR 90.00 (net) per hour. For efforts up to 8 hours per calendar year, no separate remuneration shall be due. The Processor shall inform the Controller in advance if additional costs would arise under this provision and shall obtain the Controller's prior approval before incurring such costs.
Annex B.1 – Technical and organisational measures¶
The SaaS application is hosted on AWS. AWS is independently audited and certified under ISO 27001, 27017, 27018, 27701, SOC 1/2/3, and BSI C5. The Processor inherits AWS’s physical data center security, environmental safeguards, and network resilience across multiple availability zones. These measures are governed by the AWS Data Processing Addendum (https://d1.awsstatic.com/legal/aws-dpa/aws-dpa.pdf) and summarized in the public AWS SOC 3 Report (https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/whitepapers/compliance/AWS_SOC3_Report.pdf).
The Processor configures and operates the cloud resources, application, and access controls under the AWS shared responsibility model (see https://aws.amazon.com/compliance/shared-responsibility-model/). The following sections describe the technical and organisational measures implemented by the Processor, considering the nature, scope, context, and purposes of the processing as well as the varying likelihood and severity of the risk to the rights and freedoms of data subjects:
1. Pseudonymisation and Encryption¶
Pseudonymisation:
- In general, the Uploaded Data is only transferred by the Controller in a pseudonymized/anonymized form. Any pseudonymization key remains on the Controller’s side and is not accessible to the Processor at any time. The responsibility for the chosen pseudonymization/anonymization procedure lies with the Controller.
Encryption in transit
- All external traffic uses HTTPS (TLS) via an AWS Application Load Balancer with ACM-managed certificates; HTTP is redirected to HTTPS.
- TLS is enforced for service-to-service connections, including database connections and Redis/ElastiCache.
- Access to AWS services (e.g., S3/SQS) uses TLS; policies deny non-secure transport where applicable.
Encryption at rest
- Uploaded Data and Results are stored in purpose-separated Amazon S3 buckets (e.g., uploads/private/protected/public/logs).
- All S3 buckets created by the platform enforce default server-side encryption at rest (SSE-S3, AES-256).
- The relational database (RDS) storage is encrypted at rest using a customer-managed AWS KMS key.
2. Confidentiality¶
Data Residency
- All data is stored and processed exclusively in AWS infrastructure located in Germany (Region: eu-central-1, Frankfurt). Data does not leave the EU/EEA without a separate agreement.
Access Control
- End-user access to the application requires two-factor authentication; sessions are managed with defined expiry timeouts.
- Administrative access is restricted to authorized personnel on a need-to-know basis (least privilege), using AWS IAM roles/policies.
- Secrets (database credentials, application secrets, OAuth secrets, etc.) are stored in AWS Secrets Manager and injected into runtime components as needed (no hard-coding in infrastructure code).
Network security & segmentation
- Network segmentation via a dedicated VPC with public and private subnets; core services (database/cache/compute tasks) run in private subnets and are not directly reachable from the public internet.
- Ingress to the application is through an AWS Application Load Balancer with HTTPS; security groups restrict traffic flows between components (e.g., only application tasks can reach the database port and cache).
- IP-based access restriction to the Processor’s VPN IP address for administrative endpoints.
- Egress uses controlled paths (e.g., NAT gateway) rather than exposing internal services publicly.
Application isolation & workload security
- Application components run as managed container tasks (ECS/Fargate), reducing direct host management and enabling immutable deployments.
- Separate worker pools handle different job classes; permissions are assigned per task role (least-privilege IAM per service/worker).
- Container images are stored in a private registry (ECR) with controlled access; workstation components have read-only ECR access as required.
Perimeter protections
- Web-facing entrypoint is protected using AWS WAF, including geo-restriction deny lists, to reduce exposure to abusive traffic.
Data minimisation, deletion, and purpose limitation
- Processing is limited to providing the algorithm evaluation service.
- The Controller may delete Uploaded Data using clearly visible controls in the user interface. Deletion events are logged, and a record of deletion is provided to the Controller upon request.
- Data retention is implemented via S3 lifecycle policies. Data in the “uploads” bucket is automatically expired after 1 day. For versioned buckets, non-current object versions are automatically removed after 7 days, and incomplete multipart uploads are aborted after 7 days to reduce residual storage. Log data in the dedicated logs bucket is automatically expired after one year.
3. Integrity¶
Logging, monitoring, and detection
- Centralized logging and metrics via CloudWatch; log retention is configured (365 days).
- Monitoring covers load balancer health and application/worker services; alerting is configured for queue depth (SQS), service health, and error metrics.
- Audit-relevant events (e.g., deployment/build events) are captured via event routing mechanisms (e.g., EventBridge to SQS).
Secure development
- Infrastructure is managed as code, enabling reviewable, reproducible changes.
- Code changes are reviewed before deployment.
- Changes are applied through controlled deployment processes, and configuration is versioned.
- Automatic vulnerability scanning runs at least weekly. Detected vulnerabilities are assessed and mitigated in a timely manner.
4. Availability & Resilience¶
Scope note
- The service is a non-production algorithm evaluation environment. Uploaded Data is short-lived by design and not intended as permanent storage. Availability and restore measures are therefore proportionate to this limited purpose.
Service availability
- The platform is deployed across multiple availability zones for networking and computing services, supporting continued operation in the event of an availability zone impairment.
- Service capacity is controlled via defined desired/min/max settings for ECS services and worker pools; asynchronous processing is decoupled via SQS queues to buffer workload and support graceful recovery from transient failures.
Restore ability
- The database uses AWS managed backups with a configured retention period of 7 days and a defined backup window (03:00–06:00). Restore is performed using standard AWS RDS restore mechanisms (e.g., point in time restore within the retention window).
5. Procedures for regular review, assessment and evaluation¶
Incident Response
- Within the framework of the quality management system established by the Processor, processes for incident response management are monitored accordingly. If a personal data breach is confirmed or cannot be ruled out, the Controller is notified without undue delay.
- Logging/monitoring supports investigation (CloudWatch logs/metrics, access logs for S3 buckets).
Data Protection Management
- Technical and organizational measures of data protection are monitored within the framework of the quality management system established by the Processor.
- The employees of the Processor assigned to the data processing activities are demonstrably trained in data protection law via eLearning and are committed in writing to adhere to the data protection requirements.
Annex B.2 – Approved sub-processors¶
| Company / Sub-processor | Address / Country | Service | Safeguards for third-country transfers |
|---|---|---|---|
| Amazon Web Services EMEA SARL | 38 Avenue John F. Kennedy, L-1855 Luxembourg | Cloud hosting (compute, storage, networking) of the SaaS application; AWS Region EU (Frankfurt, eu-central-1) | No third-country transfer (EU hosting). Processing governed by AWS Data Processing Addendum. |
The contractual relationship between the Processor and Amazon Web Services as sub-processor is governed by the applicable AWS service terms and data protection conditions, including the AWS Data Processing Addendum (available at https://d1.awsstatic.com/legal/aws-dpa/aws-dpa.pdf). The Controller hereby acknowledges and accepts these terms as the basis for the sub-processing arrangement between the Processor and AWS.