Data Processing Agreement (DPA)
pursuant to Art. 28 GDPR and Art. 9 FADP · codAIx GmbH, CRA compliance platform crAIready · Version 3.4 - as at: 04.09.2026
Convenience translation. This English version is provided for information only. The German version is the legally binding one.
Parties
Controller (“Customer”): the company designated in the order or registration.
Processor (“codAIx”): codAIx GmbH, c/o JULITH GmbH, Erlengasse 3, 8240 Thayngen, Switzerland, UID CHE-249.882.147.
Representative in the EU: JULITH UG (haftungsbeschränkt), Rennbahnstrasse 72, 60528 Frankfurt am Main, Germany.
This DPA is an annex to the General Terms and Conditions. It applies insofar as codAIx processes personal data on behalf of the Customer. Processing for codAIx's own purposes, in particular account, contract, billing, abuse-prevention and codAIx's own security data, is governed by the Privacy Policy.
§ 1 Subject matter, nature, purpose, place and duration
(1) codAIx processes the personal data described in Annex 1 for the purpose of providing the crAIready SaaS platform on the documented instructions of the Customer.
(2) The processing comprises in particular the collection, recording, organisation, storage, adaptation, retrieval, use, consultation, making available, export, restriction and erasure of the content entered by the Customer.
(3) Processing takes place for the term of the main agreement. Erasure and return are governed by § 11.
(4) Processing on the core systems operated by codAIx itself takes place on codAIx's own infrastructure at the operating site Erlengasse 3, 8240 Thayngen, Switzerland. External processing takes place only with the services listed in Annex 3 and only when the respective function is used.
(5) The pre-contractual public Quick Check is not covered by this DPA. Its data processing is carried out under codAIx's own responsibility and is described in the Privacy Policy. Individual Quick Check answers do not form part of the product file unless the Customer subsequently re-enters them itself.
§ 2 Instructions
(1) The order, the service description, the General Terms and Conditions and this DPA constitute the initial instruction. The Customer issues further instructions in text form via the contact form at https://www.craiready.com/en/contact/?topic=privacy. The Customer receives an automatic confirmation of receipt containing the transmitted text and the time of receipt.
(2) codAIx processes data only on documented instructions, including instructions regarding transfers to third countries, unless an applicable legal provision requires processing. In that case codAIx informs the Customer in advance, insofar as legally permitted.
(3) If codAIx considers an instruction to infringe data protection law, it shall inform the Customer without undue delay and may suspend execution until the instruction has been confirmed or amended.
§ 3 Obligations of codAIx
codAIx warrants in particular:
- processing only on documented instructions;
- commitment of all authorised persons to confidentiality;
- access on a need-to-know and role basis;
- implementation of the technical and organisational measures pursuant to Annex 2;
- assistance with data subject rights and with the obligations under Art. 32 to 36 GDPR;
- notification of personal data breaches pursuant to § 7;
- erasure or return pursuant to § 11;
- information and audit support pursuant to § 10;
- maintenance of the required records and cooperation with supervisory authorities.
The contact person for data protection is Dr. Judith Behr. Messages are to be submitted via the contact form at https://www.craiready.com/en/contact/?topic=privacy. This does not constitute any statement regarding a statutory obligation or the formal designation of a data protection officer.
§ 4 Technical and organisational measures
(1) codAIx maintains the measures described in Annex 2, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the likelihood and severity of the risks.
(2) codAIx may further develop the measures provided that the agreed level of protection is not reduced. Material changes are documented and communicated to the Customer on request.
(3) Specific certifications or attestations are owed only where they have been expressly agreed.
§ 5 Sub-processors
(1) The Customer grants a general authorisation for the providers designated as sub-processors in Annex 3.
(2) codAIx gives at least two weeks' notice before any intended addition or replacement. Within this period the Customer may object on important grounds relating to data protection law. If no reasonable alternative is possible, either party may terminate the affected part of the service.
(3) codAIx imposes on sub-processors, in accordance with Art. 28(4) GDPR, obligations that are essentially equivalent, and remains responsible to the Customer for their fulfilment.
(4) Telecommunications, energy, building services, cleaning and the mere retrieval of public technical vulnerability information without personal customer data do not constitute sub-processing within the meaning of this provision.
(5) Stripe processes payment and billing data partly as an independent controller and partly as a processor of codAIx under the Stripe DPA. Stripe does not receive any customer content from the crAIready product file and is therefore not a sub-processor for the customer data covered by this DPA.
§ 6 Data subject rights
(1) If codAIx receives a request relating to data for which the Customer is responsible, codAIx forwards it to the Customer without undue delay and responds only on instruction, unless codAIx has an obligation of its own.
(2) codAIx assists the Customer, using the available functions, with access, rectification, erasure, restriction, objection and data portability. Additional effort beyond the standard functions may be remunerated by prior arrangement, insofar as legally permitted.
§ 7 Personal data breaches
(1) codAIx informs the Customer without undue delay after becoming aware of a breach affecting personal data processed on the Customer's behalf, as a rule within 48 hours.
(2) The notification contains, where available, the nature of the breach, the data and persons affected, the likely consequences, the measures taken or proposed and a point of contact. Information may be supplemented in phases.
(3) The decision on, and responsibility for, notifications to supervisory authorities or data subjects lie with the Customer insofar as it is the controller. codAIx provides reasonable support.
§ 8 Data protection impact assessment
codAIx provides the Customer with reasonable assistance in data protection impact assessments and prior consultations pursuant to Art. 35 and 36 GDPR, taking into account the nature of the processing and the information available.
§ 9 Transfers to third countries
(1) For transfers from the EU/EEA, Switzerland is a third country with an adequate level of data protection on the basis of the adequacy decision of the European Commission. Transfers under Swiss law are governed by Art. 16 et seq. FADP and the list of states in the Data Protection Ordinance.
(2) Transfers to other third countries take place only on documented instructions and with a permissible transfer mechanism, in particular an adequacy decision or standard contractual clauses together with any necessary supplementary measures.
(3) Where a cloud AI provider can be selected, the Customer's selection is deemed an instruction. Before activation, codAIx provides information on the provider, location, purpose, categories of data and transfer mechanism.
§ 10 Evidence and audits
(1) codAIx makes available to the Customer the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR, primarily by means of documentation of the technical and organisational measures (TOM documentation), policies, test records or existing attestations.
(2) If, for justified reasons, this evidence is insufficient, codAIx permits, upon at least four weeks' notice and during business hours, an audit by the Customer or by an independent auditor bound to confidentiality. Audits must not impair operations, security or the rights of other customers.
(3) Audits prompted by a security incident remain unaffected. Disproportionate additional effort may be remunerated by prior agreement.
§ 11 Erasure and return
(1) After the end of the main agreement, codAIx erases or returns, at the Customer's choice, all data processed on the Customer's behalf, unless a statutory retention obligation exists.
(2) An export is provided in accordance with the General Terms and Conditions. Production data is erased within 30 days after the end of the agreement or after completion of the export.
(3) Backup copies are overwritten or erased in the regular backup cycle, at the latest within 30 days, and are blocked for productive use until then. Restoration takes place exclusively for emergency and integrity purposes.
(4) Temporary migration copies are erased after successful acceptance and expiry of the required fallback period, at the latest within 30 days. System and security logs are erased or anonymised once their purpose has ceased to apply and applicable evidence retention periods have expired.
(5) The long-term retention of technical documentation under the CRA is the Customer's responsibility. The Customer exports the required documents before the end of the agreement.
§ 12 Liability
Liability is governed by Art. 82 GDPR. In the internal relationship between the parties, the liability provisions of the General Terms and Conditions apply in addition, insofar as mandatory data protection law does not preclude this.
§ 13 Swiss data protection law
Insofar as the Swiss Federal Act on Data Protection applies, this DPA is deemed an agreement on processing by a processor pursuant to Art. 9 FADP. Terms and obligations are interpreted accordingly.
§ 14 Final provisions
(1) In data protection matters, this DPA takes precedence over the General Terms and Conditions.
(2) Amendments must be made in text form. Electronic acceptance with a logged document version is sufficient.
(3) Governing law and place of jurisdiction are determined by the General Terms and Conditions, unless mandatory data protection law provides otherwise.
(4) Should any provision be invalid, the remainder of the DPA remains valid.
Annex 1 – Description of the processing
Subject matter and purpose: provision of the crAIready platform for product-related CRA workflows, in particular product/scope management, SBOM and vulnerability management, risk assessment, supply chain/role management, documentation, incident and reporting preparation, tasks, approvals and logging.
Data subjects: employees and contact persons of the Customer; contact persons of suppliers, authorised representatives, importers, distributors and other economic operators; security researchers and reporters; other persons whose data is contained in lawfully uploaded documents or metadata.
Categories of data: business identification and contact data; role and permission data; personal references in document, repository, commit, SBOM, supply chain and CVD metadata; editing, approval and audit data; content entered by the Customer in prompts where AI is activated.
Not covered: codAIx's own account, contract, invoicing and security data; pre-contractual Quick Check data; payment data insofar as Stripe processes it as an independent controller.
Special categories: not envisaged. The Customer enters such data only under a separate agreement and with a documented legal basis.
Duration: term of the agreement plus the export, erasure and backup periods pursuant to § 11.
Annex 2 – Technical and organisational measures
Confirmed measures as at 04.09.2026
- Physical access: servers in a locked room at the operating site; physical access is restricted to Judith Behr and Thomas Riehn. Any relocation within the same office building is recorded in the internal TOM documentation.
- Transport: encrypted transmission via HTTPS/TLS.
- Storage: protection of production data through separated customer environments, role-based permissions, need-to-know/least-privilege principle and restricted administrative access. Backups are stored in encrypted form.
- Administrative access: VPN and additional password protection; no claim is made that MFA is already in place across the board.
- Permissions: individual accounts, role-based access, need-to-know and least-privilege principle; separated customer environments in accordance with the production architecture.
- Logging: central product-related editing and approval operations are logged for the term of the agreement to ensure traceability and, after the end of the agreement, exported and erased together with the other production data pursuant to § 11. Technical server and security logs are governed by the Privacy Policy.
- Backups: daily, local and encrypted backups; last documented successful restore test on 02.09.2026.
- Operations: security updates, monitoring, malware protection, regulated incident and emergency access as well as procedures for notifying personal data breaches.
- Organisation: confidentiality commitments, documented instructions, permission reviews, selection and monitoring of service providers.
Annex 3 – Approved sub-processors
The Customer's selection of one of these cloud AI providers is deemed a documented instruction. Without such a selection, AI processing takes place locally on codAIx's infrastructure in Thayngen.
| Provider/service | Processing and purpose | Location/transfer | Condition of use |
|---|---|---|---|
| OpenAI Ireland Ltd. and the affiliated companies and sub-processors designated in the OpenAI DPA | AI processing of the prompts and product content required for the selected function | EEA and, where applicable, further locations on the basis of adequacy decisions or standard contractual clauses in accordance with the OpenAI DPA | only where OpenAI is selected by the Customer |
| Anthropic, PBC, USA, and the sub-processors designated in the Anthropic DPA | AI processing of the prompts and product content required for the selected function | USA and further locations designated in the Anthropic DPA; standard contractual clauses and necessary supplementary measures | only where Anthropic is selected by the Customer |
Annex 4 – Delimitation of further technical services
- OnLumis/JULITH GmbH: OnLumis runs locally on codAIx's infrastructure. Prompts and customer data are not transferred to JULITH. JULITH has no remote maintenance access and cannot view customer data. The server merely establishes an outgoing connection to the deployment server for licence verification and software updates; no prompts or customer content are transferred. To that extent, JULITH is not a sub-processor for customer data.
- Umami: audience measurement is operated by codAIx itself in Thayngen; no external sub-processor is used for this purpose.
- Stripe: Stripe Payments Europe, Ltd. and affiliated companies are used exclusively for ordering, payment, billing and fraud prevention. Stripe does not receive any customer content from the crAIready product file and to that extent is not a sub-processor under this DPA. In payment processing, Stripe acts in accordance with the Stripe DPA partly as an independent controller and partly as a processor of codAIx.
- Technical information sources: the mere retrieval of public CVE, package and vulnerability information does not constitute sub-processing, provided that exclusively technical identifiers without any reference to persons or customers are transmitted.
Acceptance: electronically in the ordering process with logging of version and time, or by signature. As at: 04.09.2026 · codAIx GmbH, Thayngen (CH)