Erium
Data Processing Agreement
This Data Processing Agreement (“DPA”) governs the processing of customer data by Erium GmbH (hereinafter “Processor”) in connection with the provision of the Halerium Platform. The Halerium Platform enables customers to process data and to use, evaluate, further process and transform it using machine learning algorithms and artificial intelligence (including large language models such as ChatGPT). This DPA applies worldwide and is part of a separate Software-as-a-Service (SaaS) contract that governs the use of the Halerium Platform by the customer (hereinafter “Data Controller”).
Erium GmbH, with its office at Lichtenbergstraße 8, 85748 Garching near Munich, acts as a Processor and undertakes to process personal data such as names, e-mail addresses, usage data of the platform and unstructured data uploaded by the users themselves exclusively in accordance with the instructions of the Data Controller and in compliance with the data protection laws applicable in Germany, the European Union, the United States, Japan, and other applicable legal systems.
The parties acknowledge that in the context of data processing, Erium GmbH acts as a Processor for the Data Controller and undertakes to protect and process all personal data in accordance with the requirements of the General Data Protection Regulation (GDPR).
1. Processing requirements
1.1 The Processor (Erium GmbH) undertakes to process the personal data provided by the Data Controller (customer) exclusively in the context of the provision of the agreed-upon services on the Halerium Platform and in accordance with the written instructions of the Data Controller. The processing includes, among other things, the use of machine learning algorithms and artificial intelligence, in particular large language models, for the evaluation, further processing and transformation of all types of data (e.g. text, image, audio and numerical data).
1.2 The Processor will not use, sell, rent or otherwise commercially exploit the Personal Data for its own purposes. Any processing will be in accordance with the General Data Protection Regulation (GDPR).
1.3 The Processor shall immediately inform the Controller in writing if it believes that an instruction from the Controller violates applicable data protection laws. In such a case, the Processor shall suspend the execution of the instruction until it is either confirmed or amended.
1.4 The Processor shall ensure that its employees and all other persons who have access to the personal data are bound to confidentiality and act in accordance with the Processor’s obligations under data protection law within the scope of this DPA and the underlying contract.
1.5 Use of subcontractors
The Processor is entitled to use subcontractors (hereinafter referred to as “Subcontractors”) to fulfill its contractual obligations, which are listed in the list of subcontractors published on the website https://halerium.com/subprocessors/ (hereinafter referred to as the “Subcontractor List”). The Data Controller agrees to the use of the named subcontractors. The Processor undertakes to inform the Controller of any intended changes to the Subcontractor List by e-mail at least fifteen (15) days before such changes come into effect. Should the Data Controller wish to object to the use of a new subcontractor, it shall be entitled to express its objection to the Data Processor within a period of fifteen (15) days for comprehensible reasons relating in particular to the protection of personal data. In this case, the Processor has the following options to address the objection:
1) The Processor shall refrain from using the subcontractor concerned for the processing of the personal data or offer an alternative solution that enables the provision of the services without the use of the subcontractor;
2) The Processor shall carry out the corrective measures required by the Data Controller and deploy the subcontractor taking these measures into account;
3) The Processor temporarily or permanently ceases to provide or the Data Controller ceases to use the specific service aspect or feature that requires the use of the subcontractor;
4) The Processor shall cease to accept personal data from the Data Controller, the processing of which would require the use of the subcontractor.
If none of these options are commercially reasonable for the Processor and the Data Controller’s objections cannot be resolved to the satisfaction of both parties within thirty (30) days of receipt of the objection, either party shall be permitted to terminate for cause any service agreements, orders, or uses that are not feasible without the use of the relevant subcontractor. In such a case, the Data Controller shall receive a refund for fees already paid in advance for the relevant services, insofar as these relate to periods after the termination takes effect. This right of termination is the Data Controller’s sole and exclusive remedy should it object to the engagement of a new subcontractor. The Processor undertakes to enter into contractual agreements with each subcontractor to ensure a level of data protection and information security equivalent to that set out in this Data Processing Agreement (DPA).
1.6 The Processor shall, at the request of the Controller, provide all relevant information once a year to demonstrate compliance with the obligations set out in this DPA.
1.7 The Processor shall notify the Controller immediately if it becomes aware of a request from a supervisory authority or from data subjects regarding the processed personal data.
1.8 The Processor shall assist the Controller in fulfilling its obligations in connection with responding to requests from data subjects in accordance with data protection laws.
2. Object and duration of processing
2.1 Type of data
The following data may be processed:
– Name, contact information and usage data of users
– Unstructured data provided by the user
Personal data within the meaning of this agreement is all information that relates to an identified or identifiable living person. Various pieces of information that together can lead to the identification of a specific person also constitute personal data. This also includes data from users of the client’s applications, including names, contact information, demographic information and other unstructured data provided by the user. The processing is based on the service contract between the parties (hereinafter referred to as the “main contract”).
2.2 Duration
Processing shall commence when the main contract comes into force and shall continue indefinitely until this contract or the main contract is terminated by one of the parties.
2.3 Type of processing
Processing is of the following nature: collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of data.
2.4 Purpose of the processing
The processing serves the purpose of performing the services described in the main contract.
2.5 Categories of data subjects
The following are affected by the processing:
- Employees of the client who use the contractor’s applications.
- Persons whose personal data is contained in the client’s unstructured data.
3. Notification of the customer
The Processor (Erium GmbH) undertakes to inform the customer’s Data Controller immediately if it becomes aware of the following circumstances:
- Any legally binding request to disclose Customer Data by a law enforcement agency, unless the Processor is prohibited by law from informing the Customer, for example to protect the confidentiality of a law enforcement investigation;
- Any notification, request or investigation by an independent public supervisory authority established by a Member State pursuant to Article 51 of the GDPR (General Data Protection Regulation) in relation to the Customer Data;
- Any complaint or request (including, but not limited to, requests for access, rectification or blocking of Customer Data) received directly from the Data Subjects or from the Customer’s customers (End Users). The Processor will not respond to such a request or complaint independently, but will immediately inform the Controller and await the Controller’s written instructions before taking any action.
The Processor shall take all reasonable and appropriate steps to inform the Customer without undue delay of the aforementioned matters so that the Customer is able to respond appropriately to the request or inquiry. The Processor will not disclose any information that could jeopardize the rights and freedoms of data subjects or the integrity and confidentiality of Customer Data, unless required by law.
4. Support for the Data Controller
4.1 The Processor shall use its best efforts, taking into account the nature of the processing, to assist the Controller in fulfilling its obligations, in particular with regard to responding to requests from data subjects under data protection laws for access, rectification, erasure, restriction, data portability, objection, blocking or erasure of their personal data processed by the Processor on behalf of the Controller. If a data subject makes such a request directly to the data Processor, the data Processor will forward the request to the Data Controller without delay.
4.2 The Processor shall assist the Controller in investigating and reporting any personal data breaches that result in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data processed by the Processor on behalf of the Controller (“Personal Data Breach”).
4.3 The Processor shall assist the Controller, as appropriate and necessary, in preparing data protection impact assessments and, if necessary, in conducting consultations with the competent supervisory authorities in connection with the Processing of Personal Data by the Processor.
5. Required processing
The Processor will only process personal data if this is necessary to fulfill its obligations under the underlying contract or if it is obliged to do so under mandatory, applicable data protection laws. If the Processor is required by law to carry out such processing that does not fall within the contractually agreed purposes, it shall inform the Controller of this legal requirement prior to processing, unless legal provisions, in particular with regard to maintaining the confidentiality of investigations by law enforcement authorities, prohibit such notification.
6. Security
Erium GmbH is committed to the following measures:
- Maintain reasonable and appropriate organizational and technical security measures to prevent unauthorized or accidental access, loss, alteration, disclosure or destruction of Customer Data and to protect the rights of Data Subjects. This includes, but is not limited to, the measures described in Appendix A of this DPA in relation to personnel, facilities, hardware and software, storage and networks, access controls, monitoring and logging, vulnerability and breach detection, incident response and encryption.
- To take appropriate steps to ensure that Erium GmbH personnel protect the security, privacy and confidentiality of customer data in accordance with the requirements of this DPA.
- To notify the customer immediately if Erium GmbH, its subcontractors or other third parties acting on behalf of Erium GmbH become aware of a personal data breach.
7. Obligations of the customer
7.1 The Customer represents and warrants that it has and will maintain all necessary rights, consents and authorizations during the term of the Agreement to transfer the Customer Data to the Processor and to authorize the Processor to use, disclose, store and otherwise process the Customer Data in accordance with this DPA, the underlying Agreement and/or any other processing instructions provided by the Processor.
7.2 The customer undertakes to comply with all applicable data protection laws.
7.3 The Customer shall reasonably cooperate with the Processor to assist the Processor in fulfilling its obligations in connection with requests from the Customer’s Data Subjects.
7.4 Without prejudice to the Processor’s security obligations under Section 5 of this DPA, the Customer acknowledges and agrees that it, and not the Processor, is responsible for certain configurations of the Services that the Processor provides to the Customer and that the Customer, and not the Processor, must implement such configurations in a manner that complies with applicable Data Protection Laws.
7.5 The Customer may only transfer Customer Data to the Processor via agreed mechanisms. The Customer represents, warrants and undertakes that it will only transfer Customer Data to the Processor via secure, adequate and appropriate mechanisms to the extent that such mechanisms are within the control of the Customer.
8. Term; return and deletion of data
This DPA shall remain in force for as long as Erium GmbH carries out data processing operations on behalf of the Customer or until termination of the Agreement (and all Customer Data has been returned or deleted in accordance with this DPA). Erium GmbH will retain Customer Data of the Halerium Service during the term of the Agreement, unless otherwise specified in the Agreement or the Order Form. Upon termination of this DPA, Erium GmbH will instruct any SubProcessor to delete the Customer Data within thirty (30) days of termination of the DPA, unless prohibited by law. For the avoidance of doubt, Erium GmbH may continue to process information derived from Customer Data that has been de-identified, anonymized and/or aggregated so that the data is no longer considered personal data under applicable data protection laws and in a manner that does not identify any individual or customer in order to improve Erium GmbH’s systems and services.
Appendix A: Security
1. Security measures
1.1 Corporate identity, authentication and authorization controls
Erium maintains industry best practices for authentication and authorization of internal employee and service access, including the following measures:
- Whenever practical, Erium uses Single Sign-On (SSO) to authenticate to third party services used in the provision of the Services. Role-based access controls (RBAC) are used when providing internal access to the services.
- Each employee is assigned unique login information.
- Established review and approval processes for all access requests to services that store customer data.
- Established procedures for the immediate revocation of access rights when employees leave the company.
- Established procedures for reporting and revoking compromised credentials such as passwords and API keys.
- Established password reset procedures, including procedures designed to verify a user’s identity before issuing a new, replacement or temporary password.
1.2 Customer identity, authentication and authorization controls
Erium maintains industry best practices for authenticating and authorizing customers to the Services, including the following measures:
- Use of hashing techniques to manage customer identity, which means that Erium does not store user-supplied passwords in plain text.
- Logical separation of customer data by organizational account using unique identifiers. Unique user accounts are supported within an organization account.
1.3 Cloud infrastructure and network security
Erium maintains industry best practices for securing and operating its cloud infrastructure, including the following measures:
- Separation of production and non-production environments
- Primary backend resources are provided in a virtual private network
- The services are routinely checked for security vulnerabilities.
- Network security policies and firewalls are configured for access with minimal rights against a predefined set of permitted traffic flows. Non-permitted traffic flows are blocked.
- Service protocols are monitored for security and availability.
1.4 System and workplace control
Erium maintains industry best practices for securing Erium’s enterprise systems, including laptops and on-site infrastructure, including:
- Endpoint management of company workstations
- Endpoint management of mobile devices
- Process definitions for patch management
- Use of appropriate security protocols.
1.5 Data access control
Erium maintains industry best practices to prevent employees from accessing data beyond their authorized access rights and to prevent the unauthorized entry, reading, copying, removal, modification or disclosure of data. These measures include, but are not limited to:
- Employee access to the services follows the principle of minimal rights. Only employees whose job function involves supporting the provision of services are authorized for the respective service environment.
- Customer data transmitted to the services will only be used in accordance with the terms of the DPA, the respective customer contract and any other applicable contractual agreements that exist with the customer.
1.6 Disclosure control
Erium maintains industry best practices to prevent unauthorized access, modification or removal of data in transit and to keep all transmissions secure and logged. These measures include:
- Encryption of data at rest in production data stores with strong encryption algorithms
- Encryption of data during transmission
- Full disk encryption is required on all enterprise workstations
- Customer data can be deleted on request.
1.7 Availability control
Erium maintains industry best practices to maintain the functionality of the Services through accidents or malicious intent, including:
- Ensure that systems can be restored in the event of an interruption
- Ensure that systems work and errors are reported
1.8 Separation control
Erium maintains industry best practices for the segregated processing of data collected for various purposes, including:
- Logical separation of customer data
- Restricting access to data stored for different purposes according to staff roles and responsibilities
- Separation of business information system functions
- Separation of test and production information system environments
1.9 Personnel
Erium maintains industry best practices for screening, training and managing personnel with respect to safety matters, including annual safety training for employees and supplemental safety training as appropriate.
1.10 Physical access control
Erium maintains industry best practices to prevent unauthorized physical access to Erium facilities, including physical barrier controls such as locked doors and gates.
1.11 Risk management for third parties
Erium maintains industry best practices for managing third-party security risks, including with respect to any subProcessor or subcontractor to whom Erium provides Customer Data, including the following measures:
- Written contracts designed to ensure that each agent agrees to maintain reasonable and appropriate security measures to protect customer data
- Vendor security assessments: All third-party vendors go through a formal vendor assessment process.
1.12 Security incident response
Erium maintains a security incident response plan for responding to and recovering from events that compromise the confidentiality, availability or integrity of the Services or Customer Data, including the following:
- Erium aggregates system logs for security and general observability from a range of systems to facilitate detection and response
- If Erium becomes aware that a personal data breach has occurred, Erium will notify the customer in accordance with the DPA.
1.13 Safety assessments
Erium conducts periodic security and vulnerability assessments to evaluate whether key controls are properly implemented and effective, as measured against industry security standards and its policies and procedures, and to ensure ongoing compliance with obligations imposed by law, regulation or contract with respect to the security of customer data and the maintenance and structure of Erium’s information systems.
Please contact info@erium.de with any questions or concerns.