

DATA PROCESSING AGREEMENT
THIS DATA PROCESSING AGREEMENT (DPA) SPECIFIES THE DATA PROTECTION OBLIGATIONS ARISING FROM THE CONTRACT CONCLUDED BETWEEN THE CUSTOMER AND SIMPLECLUB. THIS DPA APPLIES TO ALL ACTIVITIES RELATED TO THE CONTRACT IN WHICH EMPLOYEES OF SIMPLECLUB OR SUB-PROCESSORS ENGAGED BY SIMPLECLUB PROCESS PERSONAL DATA OF THE CUSTOMER.
Effective from: 1 December 2026 (until then, the previous DPA dated 13 November 2024 remains in effect)
I. Data Processing Agreement pursuant to Art. 28 GDPR
1. Definitions
1.1. "App" The mobile app of simpleclub in which Learning Content is made available.
1.2. "EEA" The states of the European Economic Area.
1.3. "Learning Content" The Learning Content comprises various learning modules and content for vocational training occupations and other educational programmes that are provided via the simpleclub Platform.
1.4. "User" The person authorised by the Customer to use simpleclub. Users include, for example, employees of the Customer.
1.5. "Platform" The Platform comprises the Website and the App together.
1.6. "Agreement" The Agreement comprises the Contract between the Customer and simpleclub as well as the contractual terms and conditions.
1.7. "Contract" The signed document (e.g. order form) for the purchase of services by the Customer from simpleclub, including any schedules or amendments thereto.
1.8. "Website" The website of simpleclub on which Learning Content is made available.
2. Subject Matter and Duration
2.1. simpleclub shall process personal data of the Customer only on the Customer's documented instructions. The Customer shall confirm oral instructions in text form without undue delay. simpleclub shall inform the Customer if, in simpleclub's opinion, an instruction infringes data protection provisions. simpleclub is entitled not to carry out the instruction until the Customer confirms or amends it.
2.2. The data processing is carried out for the purpose of performing the Contract (in particular supporting the initial and continuing vocational training of the Customer's employees) in order to enable the Customer to use the learning software "simpleclub" as intended.
2.3. The following data of the Customer's trainees and trainers and, where applicable, of other persons to whom the Customer grants permissions are processed (including, among other things, collected, processed, stored and deleted):
- name, email address, organisational affiliation;
- type of vocational training, year of training, Learning Content accessed and content data, time of access, results of learning tasks;
- technical communication data (e.g. IP address, device information data);
- usage data technically necessary to provide in-app functions (e.g. algorithm for suggesting content);
- unless otherwise agreed with the Customer and where the User has given consent: data on the use of the web application and the mobile app.
2.4. No special categories of personal data pursuant to Art. 9(1) GDPR are processed.
2.5. The duration of the processing of personal data is determined by the Contract referred to above.
2.6. Notwithstanding the preceding paragraph, this DPA shall remain in force for as long as simpleclub processes personal data of the Customer (including backups).
2.7. In the event of any conflict between this DPA and the provisions of related agreements that exist between the parties or are subsequently entered into or concluded, this DPA shall prevail.
2.8. The contractually agreed data processing shall only take place outside the EEA if the requirements of Art. 44 et seq. GDPR are met.
3. Protective Measures by simpleclub
3.1. simpleclub is obliged to comply with the data protection provisions and not to disclose information obtained from the Customer to third parties or expose it to access by third parties. Documents and data shall be secured against disclosure to unauthorised persons, taking into account the state of the art.
3.2. simpleclub ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.
3.3. In accordance with Art. 32 GDPR, simpleclub shall implement and maintain the technical and organisational measures set out in Section II to protect the Customer's personal data. simpleclub is permitted to adapt the measures to technical progress, provided that the level of security of the specified measures is not reduced.
3.4. Where a review or an audit by the Customer reveals a need for adjustment, such adjustment shall be implemented by mutual agreement.
4. Information and Assistance Obligations of simpleclub
4.1. If simpleclub becomes aware of a personal data breach, simpleclub shall inform the Customer without undue delay, and at the latest within 24 hours.
4.2. simpleclub shall assist the Customer in complying with the obligations under Chapter III GDPR and Art. 32 to 36 GDPR (Art. 28(3)(e) and (f) GDPR).
4.3. Where simpleclub is required to process the personal data by a provision of national or European Union law, simpleclub shall inform the Customer of that processing promptly, unless such notification is prohibited (Art. 28(3)(a) GDPR).
4.4. If and to the extent that simpleclub receives a request from a supervisory authority or any other competent body in connection with the processing of data, simpleclub shall inform the Customer without undue delay and forward the request to the Customer without undue delay.
4.5. simpleclub shall provide the Customer with all information the Customer needs to safeguard the rights of data subjects. Should data subjects or other third parties address data protection requests to simpleclub or assert data protection rights against simpleclub, simpleclub shall forward such requests to the Customer without undue delay.
5. Sub-processing
5.1. The engagement of sub-processors generally requires the Customer's approval. The Customer's approval of the engagement or replacement of a sub-processor shall be deemed granted if simpleclub notifies the Customer thereof in advance in text form and the Customer does not object in text form within a period of four (4) weeks. simpleclub shall ensure by contract that these provisions also apply to sub-processors. Furthermore, the Customer agrees that sub-processors may in turn engage sub-processors, provided that the requirements of Art. 28 GDPR are met.
5.2. The processing of data on behalf of the Customer shall in principle take place within the territory of the European Union (EU) or the European Economic Area (EEA). Any transfer of data by simpleclub to a third country or an international organisation shall take place exclusively on the basis of written (or documented electronic) instructions from the Customer or in order to comply with a specific provision of Union or Member State law to which simpleclub is subject, and must comply with Chapter V GDPR. The fundamental requirements for the lawfulness of processing remain unaffected.
5.3. If, in the event of an objection, simpleclub can no longer reasonably be expected to continue the processing and thus the Contract, the parties shall have a right of extraordinary termination with a reasonable phase-out period, without simpleclub being obliged to compensate for any damage resulting from the termination of the Contract, provided that the parties are unable to reach an agreement.
5.4. The Customer hereby approves the engagement of the sub-processors listed in Section III as well as the processing locations specified therein and, where applicable, transfers to third countries or international organisations.
5.5. Where a sub-processor provides the agreed services outside the EEA, simpleclub shall comply with the requirements of Art. 44 et seq. GDPR.
5.6. simpleclub's liability for breaches of duty by engaged sub-processors is governed by the statutory provisions of Art. 28(4) GDPR.
5.7. Services that simpleclub uses from third parties as ancillary services to support the performance of the processing shall not be considered sub-processing, provided that these third parties do not obtain access to the Customer's personal data in the course of their activities, or such access is purely incidental and not part of the actual service. These include, for example, telecommunication services, maintenance and user support, cleaning staff or auditors. However, simpleclub is obliged to conclude appropriate and legally compliant contractual arrangements and to take control measures in order to ensure the protection and security of the Customer's data, also in the case of outsourced ancillary services.
6. Inspection Rights of the Customer
6.1. The Customer may, to a reasonable extent, verify compliance with data protection law and with the contractual agreements itself or through third parties commissioned by the Customer, in particular by obtaining information, by inspecting the stored data and by conducting on-site checks. Inspections at simpleclub shall be carried out without avoidable disruption to business operations. Unless otherwise indicated for urgent reasons, inspections shall take place after reasonable advance notice, during simpleclub's business hours and not more frequently than once every twelve months.
6.2. simpleclub undertakes to provide the Customer with information upon request and to demonstrate the implementation of the technical and organisational measures.
6.3. Evidence of such measures that do not relate solely to the specific engagement may be provided by:
- adherence to approved codes of conduct pursuant to Art. 40 GDPR;
- certification under an approved certification mechanism pursuant to Art. 42 GDPR;
- current attestations, reports or report extracts from independent bodies (e.g. certified public accountants, internal audit, data protection officer and consultants, IT security department, data protection auditors, quality auditors);
- suitable certification by way of an IT security or data protection audit (e.g. in accordance with BSI IT-Grundschutz or ISO 31700).
7. Deletion and Return of Personal Data
7.1. Upon the Customer's request, and at the latest upon termination of the Contract, simpleclub shall destroy all personal data in compliance with data protection law or hand it over to the Customer. This does not apply to documentation that serves as evidence of processing in accordance with the instructions and in a proper manner and that must be retained beyond the end of the Contract, or to other data that must be stored due to a legal obligation.
8. Amendment of the Data Processing Agreement (DPA)
8.1. simpleclub may amend this DPA during the ongoing contractual relationship if and to the extent that there is a compelling reason. Such a compelling reason may in particular consist of a relevant change in legislation, a change in supreme court case law or a change in the processing activities.
8.2. simpleclub shall offer amendments to the Customer in text form no later than 4 weeks before the proposed effective date. The Customer's approval shall be deemed granted if the Customer does not object to the amendments before the proposed effective date. simpleclub shall specifically draw the Customer's attention to this deemed approval in its amendment offer.
8.3. If the Customer objects to the new DPA, the DPA shall continue to apply in its previous version.
9. Final Provisions
9.1. simpleclub and the Customer shall be liable to third parties, within the scope of their respective responsibilities and in accordance with the statutory provisions of Art. 82 GDPR, for damage caused by processing that does not comply with the GDPR.
9.2. Any offer to amend this DPA as well as unilateral declarations of intent by a party require text form. This also applies to any offer to amend this text form clause.
9.3. Should individual provisions be or become invalid, this shall not affect the validity of the remaining provisions. An invalid provision shall be replaced by what comes closest to the intended purpose. The same applies in the event of contractual gaps.
II. Technical and Organisational Measures
The following technical and organisational measures apply to the processing of personal data by simpleclub. Further details and documentation are available in the simpleclub Trust Center: https://trust.simpleclub.com
For hosting, the technical and organisational measures of our sub-processors apply ("Sub-processor TOMs"):
- Google Cloud Data Processing Terms
- Cloudflare TOMs
- Braze AVV inkl. TOMs
- Intercom TOMs
- Loom TOMs
- Algolia TOMs
- Adjust Trust-Center
- Ory AVV inkl. TOMs
- Elasticsearch Trust-Center
- Mailjet AVV inkl. TOMs
- Posthog Trust-Center
- Microsoft Trust-Center
- Langfuse Trust-Center
1. Confidentiality
1.1. Physical access control
- As simpleclub is a remote company without central office buildings, our measures focus on securing the decentralised working environments and our cloud infrastructure.
- Our cloud services are hosted exclusively with certified providers (at least ISO 27001 or SOC 2 Type 2) that implement physical security measures at the highest level (e.g. security perimeters, physical entry controls, surveillance). Details can be found in the Sub-processor TOMs.
- For employees working from home, policies on the secure set-up of the workplace apply in order to prevent unauthorised physical access to company property.
1.2. System access control (system level)
- Identity and authentication management: We manage the entire lifecycle of digital identities (identity management). Access to systems is governed by a central identity management system.
- Secure passwords & MFA: We enforce the use of strong, complex passwords (at least 12 characters). Strong two-factor authentication (2FA), preferably via FIDO2 hardware keys, is mandatory for all employees for access to critical systems.
- Endpoint security: All endpoint devices (laptops, smartphones) are protected by passwords/biometrics and configured with a screen lock that activates automatically after a short period of inactivity (15 minutes). Laptop hard drives are encrypted.
1.3. Data access control (data level)
- Principle of least privilege: Access rights are granted on a need-to-know basis. Employees receive only the rights necessary for their specific tasks. This is implemented through role-based access control (RBAC). Rights are revoked no later than 24 business hours after an employee leaves or changes role, which is ensured by quarterly access reviews for high-risk systems and annual access reviews for all systems.
- Management of privileged rights: Rights with extended access (e.g. administrator accounts) are strictly controlled and restricted to a minimum number of persons, and their use is logged.
- Segregation of duties: Critical and conflicting areas of responsibility (e.g. development and approval of code) are separated organisationally and technically in order to prevent misuse.
- Logging: Access to systems and data is logged in detail in order to be able to trace unauthorised activities.
1.4. Separation control
- Logical tenant separation: Data of different customers is logically separated within our system architecture in order to prevent unauthorised access.
- Network segmentation: Our networks are segmented in order to isolate sensitive areas (such as production environments) from the rest.
- Separation of environments: Development, test and production environments are strictly separated. No production customer data is used in development and test environments.
1.5. Anonymisation and pseudonymisation
- AI functions: User inputs are passed through technical filters that detect and mask personal data before the data is passed on to the AI models. The AI models are technically connected via simpleclub's server infrastructure, so that no other user data (e.g. IP address, device data) can be transferred to the sub-processors used. The data is not used to train the AI models.
- Langfuse is used exclusively in pseudonymised form. No real names, email addresses or other personal data are transferred to or stored with Langfuse.
- Data protection principles: We adhere to the principles of data protection, including pseudonymisation wherever this is possible and appropriate to minimise risk (e.g. use of a user ID instead of an email address).
2. Integrity
2.1. Transfer control
- Encryption in transit: All data transmission over public networks takes place exclusively via encrypted protocols such as HTTPS with TLS 1.2 or higher; HSTS is enforced.
- Encryption at rest: All data is encrypted at storage level using AES-256.
- Data leakage prevention: We use measures to detect and prevent the unauthorised outflow of sensitive data.
- Employee training: Employees are regularly trained in the secure handling and transfer of data.
2.2. Input control
- Logging: Changes, entries and deletions of data in our systems are logged in order to ensure traceability.
- Secure coding: Our developers follow secure coding principles in order to prevent vulnerabilities such as injection attacks from the outset.
- Vulnerability management: We continuously identify and assess technical vulnerabilities in our systems and remediate them based on their risk.
3. Availability and Resilience
- Redundancy and fault tolerance: Our infrastructure at certified cloud providers is designed redundantly in order to ensure availability even if individual components fail.
- Regular backups: We create regular daily backups of critical systems and data. These are encrypted and stored securely.
- Business continuity & disaster recovery: We have established contingency plans and processes to ensure the restoration of systems after a serious incident. The effectiveness of these plans is tested regularly.
- Protective measures: We use modern protective software such as antivirus software and firewalls and keep our systems up to date through consistent patch management.
- Capacity management: The utilisation of our resources is monitored in order to identify bottlenecks at an early stage and to ensure performance.
4. Process for Regularly Testing, Assessing and Evaluating
- ISMS in accordance with ISO 27001: We have implemented an ISO 27001-certified information security management system for our entire company, which is continuously operated, monitored and improved. This includes regular risk assessments and management reviews.
- Internal and external audits: We conduct internal audits at planned intervals and have our ISMS certified by independent external auditors in order to verify the conformity and effectiveness of our measures.
- Penetration tests: External security experts regularly conduct penetration tests of our systems in order to proactively identify vulnerabilities.
- Documented incident response process with defined roles as well as escalation and reporting channels.
- Automatic and manual data deletion in accordance with the internal deletion concept.
- Compliance monitoring: An internal Compliance Manager and an Information Security Team monitor compliance with all relevant legal, regulatory and contractual requirements.
- Data protection by design and by default (Art. 25 GDPR): When new products and processes are developed, data protection and data security are an integral part from the outset (in particular through the early involvement and consultation of our Compliance Manager).
- Processor control: We conclude contracts pursuant to Art. 28 GDPR with all processors and regularly review their technical and organisational measures.
- Training and confidentiality: All employees receive training on data protection and information security when they join and regularly thereafter, and are bound to confidentiality. In addition, internal policies on data protection, information security and the EU AI Act have been established, which are regularly evaluated and improved with regard to their effectiveness.
- Data protection officer: We have appointed an external data protection officer who advises us and monitors compliance with data protection regulations: Proliance GmbH, Leopoldstr. 21, 80802 Munich, Germany, email: datenschutzbeauftragter@datenschutzexperte.de
- Record of processing activities (RoPA): We maintain a record of processing activities pursuant to Art. 30 GDPR.
