Data Processing Agreement
This Data Processing Agreement (the “DPA”) forms part of the Terms of Service. It applies where the Customer is a business or other organization and we process personal data in that organization’s workspace on its behalf. By accepting the Terms of Service, such a Customer also agrees to this DPA. It does not apply where a private individual uses Cortee for their own use; that case is covered by the Privacy Policy.
The Customer is the controller. We (Nándor Babina, as identified in the Imprint) are the processor. Words used in the Terms of Service or the GDPR have the same meaning here.
1. What we process
We process personal data only as needed to provide, maintain, secure, and support Cortee, and only on the Customer’s instructions (including this DPA and how the Customer uses the Service) unless the law requires otherwise. If the law requires us to process data differently, we will tell the Customer unless we are forbidden to do so. We do not use customer content to train models.
The processing is described in Annex A. Payment data is handled by Paddle Payments Ltd. as an independent controller and is outside this DPA.
2. Security and access
We take appropriate technical and organizational measures to protect personal data. A detailed explanation of how we secure the Customer’s data, including the security controls we apply, is set out in the Trust Center. Access is limited to what is needed for the Service, and anyone with access is bound to keep it confidential.
3. Subprocessors
The Customer authorizes us to use the subprocessors listed in Annex B. We impose data-protection obligations on them that are no less protective than this DPA, and we remain responsible for their work.
We may update the list by changing Annex B or the Privacy Policy. For a material change we will give notice. The Customer may object on reasonable data-protection grounds within fourteen (14) days. If we cannot resolve the objection, the Customer may terminate the affected Service.
4. Rights, breaches, and assessments
We will help the Customer respond to data-subject requests where the nature of the processing allows. If we receive such a request about the Customer’s data, we will forward it and will not answer it ourselves unless the Customer instructs us to or the law requires it.
If we become aware of a personal-data breach affecting the Customer’s data, we will notify the Customer without undue delay and give the information needed for the Customer’s own notifications. We will also give reasonable help with data-protection impact assessments and consultations with authorities, where they relate to our processing.
5. Deletion
When the Customer stops using Cortee for this processing, we will delete or return the personal data at the Customer’s choice, and delete remaining copies, unless the law requires us to keep them. Deletion follows the retention periods in the Privacy Policy. The Customer’s export rights under the Terms of Service remain unaffected.
6. Audits
We will provide information reasonably needed to show that we comply with this DPA. Audits are preferably done by questionnaire, documentation, and available third-party reports. On-site audits are limited to what is necessary when those are not enough, require reasonable notice, and are at the Customer’s expense unless they show a material breach by us.
7. Transfers
The Customer authorizes transfers to the subprocessors and locations in Annex B and the Privacy Policy, including the United States where a listed subprocessor operates there, under appropriate safeguards such as an adequacy decision (including the EU–US Data Privacy Framework where it applies) or standard contractual clauses.
8. Governing law
This DPA is governed by German law. Disputes are subject to the courts of Stuttgart, Germany, unless mandatory law provides otherwise. If this DPA conflicts with the Terms of Service on how we process personal data on the Customer’s behalf, this DPA prevails.
Annex A: Description of processing
Subject matter: providing Cortee to the Customer.
Duration: for the term of the subscription, then until deletion under Section 5.
Nature and purpose: hosting, storing, transmitting, displaying, and AI-assisted processing of workspace content as needed to run and secure the Service on the Customer’s instructions.
Types of personal data: workspace content and related metadata (for example authorship and edit history), and notes submitted to update a page. The raw note is not saved.
Data subjects: the Customer’s users and invitees, and anyone whose personal data appears in workspace content.
Annex B: Subprocessors
| Subprocessor | Categories of data | Location | Applies |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Workspace content, including pages, claims, files, and embeddings; the organization name; subscription and plan usage; audit and access logs; firewall and network data; and monitoring. | Europe | — |
| Marqo Inc. | Notes, pages, and files, to run the language model. | United States | Until 12 Oct 2026 |
| Clerk, Inc. | Account data and sign-in. | United States | — |
| Lyceum Technology Germany GmbH | Notes, pages, and files, to run the language model. | Europe | Effective 12 Oct 2026 |
| Melious AI GmbH | Notes, pages, and files, to run the language model. | Europe | Effective 12 Oct 2026 |
| Vercel Inc. | The website and the application, including pages, audit and access logs, firewall data, network data, and traffic and performance measurement. Data passes through its servers on the way to ours. | Europe | — |