Für UnternehmenFür BildungsanbieterFür Kliniken & PflegeschulenFür die Schule

Produkt

Produkt

Inhalte

Ausbildungsberufe

Kaufmännische Berufe

Gewerblich-technische Berufe

Informationstechnik

Handwerkliche Berufe

Gesundheitsberufe

Jetzt entdecken

Praxislehrgänge

Für Praktika & Lehrgänge

Qualität & Tiefe der Inhalte

Höchste Standards

Grundlagen aus der Schule

Lernlücken einfach schließen

Skills fürs Leben

Coding, Unternehmertum uvm.

Die einzige Plattform für Ihre gesamte Ausbildung & Umschulung.

Funktionen

Lernmanagement (LMS)

Ausbilderprofil

Lernpläne erstellen & zuweisen

Eigene Inhalte erstellen

Test Manager

Ausbilder-Report

Prüfungsvorbereitung

Jetzt entdecken

Lernerlebnis

Lernvideos & Erklärungen

Interaktive Animationen

Übungsaufgaben

Lernpläne mit Tagesplaner

KI-Tutor

Karteikarten

Jetzt entdecken

Ausbildungsmanagement

Einsatzplanung mit KI-Unterstützung

Digitales Berichtsheft

Automatische Lernplan-Zuweisung

Tests je Einsatzstation

Vollständiges Reporting

Karteikarten

Jetzt entdecken

Demnächst

Neu: Der KI-Assistent

Wie ein zusätzlicher Ausbilder.
Für jeden Azubi.

->

Künstliche Intelligenz bei simpleclub

Innovative KI-Tools

Die einzige Lernplattform,
die Sie für die Ausbildung brauchen.

Lösungen

Lösungen

Für diese Herausforderungen

Für Betriebsinhaber & Leadership:
Ausbildungskosten senken

Für HR-Verantwortliche:
Auszubildende gewinnen und binden

Für Ausbilder:
Einfacher ausbilden und Zeit sparen

Für Unternehmen

Für Bildungsanbieter

Kunden

Ressourcen

Ressourcen

Für diese Herausforderungen

Studie

Wie effektiv ist simpleclub?

Blog

Beschreibung

ROI-Rechner

Was können Sie mit simpleclub 
sparen?

Events & Webinars

Wie führende Experten den Azubi-Mangel lösen uvm.

Über simpleclub

Unsere Geschichte

Wie simpleclub die beliebteste Lernplattform Deutschlands wurde.

Karriere

We’re hiring!

Presse

Willkommen im simpleclub Newsroom.

Support & Kontakt

Hilfe & Support

Preise
Jetzt kaufenJetzt beraten lassen
Jetzt kaufen

Jetzt beraten lassen

Jetzt beraten lassen

Zurück

DATA PROCESSING AGREEMENT

THIS DATA PROCESSING AGREEMENT (DPA) SPECIFIES THE DATA PROTECTION OBLIGATIONS ARISING FROM THE CONTRACT CONCLUDED BETWEEN THE CUSTOMER AND SIMPLECLUB. THIS DPA APPLIES TO ALL ACTIVITIES RELATED TO THE CONTRACT IN WHICH EMPLOYEES OF SIMPLECLUB OR SUB-PROCESSORS ENGAGED BY SIMPLECLUB PROCESS PERSONAL DATA OF THE CUSTOMER.

‍

Effective from: 1 December 2026 (until then, the previous DPA dated 13 November 2024 remains in effect)

‍

‍

I. Data Processing Agreement pursuant to Art. 28 GDPR

‍

1. Definitions

‍
1.1. "App" The mobile app of simpleclub in which Learning Content is made available.

‍
1.2. "EEA" The states of the European Economic Area.

‍
1.3. "Learning Content" The Learning Content comprises various learning modules and content for vocational training occupations and other educational programmes that are provided via the simpleclub Platform.

‍
1.4. "User" The person authorised by the Customer to use simpleclub. Users include, for example, employees of the Customer.

‍
1.5. "Platform" The Platform comprises the Website and the App together.

‍
1.6. "Agreement" The Agreement comprises the Contract between the Customer and simpleclub as well as the contractual terms and conditions.

‍
1.7. "Contract" The signed document (e.g. order form) for the purchase of services by the Customer from simpleclub, including any schedules or amendments thereto.

‍
1.8. "Website" The website of simpleclub on which Learning Content is made available.

‍

‍

2. Subject Matter and Duration

‍
2.1. simpleclub shall process personal data of the Customer only on the Customer's documented instructions. The Customer shall confirm oral instructions in text form without undue delay. simpleclub shall inform the Customer if, in simpleclub's opinion, an instruction infringes data protection provisions. simpleclub is entitled not to carry out the instruction until the Customer confirms or amends it.

‍
2.2. The data processing is carried out for the purpose of performing the Contract (in particular supporting the initial and continuing vocational training of the Customer's employees) in order to enable the Customer to use the learning software "simpleclub" as intended.

‍
2.3. The following data of the Customer's trainees and trainers and, where applicable, of other persons to whom the Customer grants permissions are processed (including, among other things, collected, processed, stored and deleted):
- name, email address, organisational affiliation;
- type of vocational training, year of training, Learning Content accessed and content data, time of access, results of learning tasks;
- technical communication data (e.g. IP address, device information data);
- usage data technically necessary to provide in-app functions (e.g. algorithm for suggesting content);
- unless otherwise agreed with the Customer and where the User has given consent: data on the use of the web application and the mobile app.

‍
2.4. No special categories of personal data pursuant to Art. 9(1) GDPR are processed.

‍
2.5. The duration of the processing of personal data is determined by the Contract referred to above.

‍
2.6. Notwithstanding the preceding paragraph, this DPA shall remain in force for as long as simpleclub processes personal data of the Customer (including backups).

‍
2.7. In the event of any conflict between this DPA and the provisions of related agreements that exist between the parties or are subsequently entered into or concluded, this DPA shall prevail.

‍
2.8. The contractually agreed data processing shall only take place outside the EEA if the requirements of Art. 44 et seq. GDPR are met.

‍

‍

3. Protective Measures by simpleclub

‍
3.1. simpleclub is obliged to comply with the data protection provisions and not to disclose information obtained from the Customer to third parties or expose it to access by third parties. Documents and data shall be secured against disclosure to unauthorised persons, taking into account the state of the art.

‍
3.2. simpleclub ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.

‍
3.3. In accordance with Art. 32 GDPR, simpleclub shall implement and maintain the technical and organisational measures set out in Section II to protect the Customer's personal data. simpleclub is permitted to adapt the measures to technical progress, provided that the level of security of the specified measures is not reduced.

‍
3.4. Where a review or an audit by the Customer reveals a need for adjustment, such adjustment shall be implemented by mutual agreement.

‍

‍

4. Information and Assistance Obligations of simpleclub

‍
4.1. If simpleclub becomes aware of a personal data breach, simpleclub shall inform the Customer without undue delay, and at the latest within 24 hours.

‍
4.2. simpleclub shall assist the Customer in complying with the obligations under Chapter III GDPR and Art. 32 to 36 GDPR (Art. 28(3)(e) and (f) GDPR).

‍
4.3. Where simpleclub is required to process the personal data by a provision of national or European Union law, simpleclub shall inform the Customer of that processing promptly, unless such notification is prohibited (Art. 28(3)(a) GDPR).

‍
4.4. If and to the extent that simpleclub receives a request from a supervisory authority or any other competent body in connection with the processing of data, simpleclub shall inform the Customer without undue delay and forward the request to the Customer without undue delay.

‍
4.5. simpleclub shall provide the Customer with all information the Customer needs to safeguard the rights of data subjects. Should data subjects or other third parties address data protection requests to simpleclub or assert data protection rights against simpleclub, simpleclub shall forward such requests to the Customer without undue delay.

‍

‍

5. Sub-processing

‍
5.1. The engagement of sub-processors generally requires the Customer's approval. The Customer's approval of the engagement or replacement of a sub-processor shall be deemed granted if simpleclub notifies the Customer thereof in advance in text form and the Customer does not object in text form within a period of four (4) weeks. simpleclub shall ensure by contract that these provisions also apply to sub-processors. Furthermore, the Customer agrees that sub-processors may in turn engage sub-processors, provided that the requirements of Art. 28 GDPR are met.

‍
5.2. The processing of data on behalf of the Customer shall in principle take place within the territory of the European Union (EU) or the European Economic Area (EEA). Any transfer of data by simpleclub to a third country or an international organisation shall take place exclusively on the basis of written (or documented electronic) instructions from the Customer or in order to comply with a specific provision of Union or Member State law to which simpleclub is subject, and must comply with Chapter V GDPR. The fundamental requirements for the lawfulness of processing remain unaffected.

‍
5.3. If, in the event of an objection, simpleclub can no longer reasonably be expected to continue the processing and thus the Contract, the parties shall have a right of extraordinary termination with a reasonable phase-out period, without simpleclub being obliged to compensate for any damage resulting from the termination of the Contract, provided that the parties are unable to reach an agreement.

‍
5.4. The Customer hereby approves the engagement of the sub-processors listed in Section III as well as the processing locations specified therein and, where applicable, transfers to third countries or international organisations.

‍
5.5. Where a sub-processor provides the agreed services outside the EEA, simpleclub shall comply with the requirements of Art. 44 et seq. GDPR.

‍
5.6. simpleclub's liability for breaches of duty by engaged sub-processors is governed by the statutory provisions of Art. 28(4) GDPR.

‍
5.7. Services that simpleclub uses from third parties as ancillary services to support the performance of the processing shall not be considered sub-processing, provided that these third parties do not obtain access to the Customer's personal data in the course of their activities, or such access is purely incidental and not part of the actual service. These include, for example, telecommunication services, maintenance and user support, cleaning staff or auditors. However, simpleclub is obliged to conclude appropriate and legally compliant contractual arrangements and to take control measures in order to ensure the protection and security of the Customer's data, also in the case of outsourced ancillary services.

‍

‍

6. Inspection Rights of the Customer

‍
6.1. The Customer may, to a reasonable extent, verify compliance with data protection law and with the contractual agreements itself or through third parties commissioned by the Customer, in particular by obtaining information, by inspecting the stored data and by conducting on-site checks. Inspections at simpleclub shall be carried out without avoidable disruption to business operations. Unless otherwise indicated for urgent reasons, inspections shall take place after reasonable advance notice, during simpleclub's business hours and not more frequently than once every twelve months.

‍
6.2. simpleclub undertakes to provide the Customer with information upon request and to demonstrate the implementation of the technical and organisational measures.

‍
6.3. Evidence of such measures that do not relate solely to the specific engagement may be provided by:
- adherence to approved codes of conduct pursuant to Art. 40 GDPR;
- certification under an approved certification mechanism pursuant to Art. 42 GDPR;
- current attestations, reports or report extracts from independent bodies (e.g. certified public accountants, internal audit, data protection officer and consultants, IT security department, data protection auditors, quality auditors);
- suitable certification by way of an IT security or data protection audit (e.g. in accordance with BSI IT-Grundschutz or ISO 31700).

‍

‍

7. Deletion and Return of Personal Data

‍
7.1. Upon the Customer's request, and at the latest upon termination of the Contract, simpleclub shall destroy all personal data in compliance with data protection law or hand it over to the Customer. This does not apply to documentation that serves as evidence of processing in accordance with the instructions and in a proper manner and that must be retained beyond the end of the Contract, or to other data that must be stored due to a legal obligation.

‍

‍

8. Amendment of the Data Processing Agreement (DPA)

‍
8.1. simpleclub may amend this DPA during the ongoing contractual relationship if and to the extent that there is a compelling reason. Such a compelling reason may in particular consist of a relevant change in legislation, a change in supreme court case law or a change in the processing activities.

‍
8.2. simpleclub shall offer amendments to the Customer in text form no later than 4 weeks before the proposed effective date. The Customer's approval shall be deemed granted if the Customer does not object to the amendments before the proposed effective date. simpleclub shall specifically draw the Customer's attention to this deemed approval in its amendment offer.

‍
8.3. If the Customer objects to the new DPA, the DPA shall continue to apply in its previous version.

‍

‍

9. Final Provisions

‍
9.1. simpleclub and the Customer shall be liable to third parties, within the scope of their respective responsibilities and in accordance with the statutory provisions of Art. 82 GDPR, for damage caused by processing that does not comply with the GDPR.

‍
9.2. Any offer to amend this DPA as well as unilateral declarations of intent by a party require text form. This also applies to any offer to amend this text form clause.

‍
9.3. Should individual provisions be or become invalid, this shall not affect the validity of the remaining provisions. An invalid provision shall be replaced by what comes closest to the intended purpose. The same applies in the event of contractual gaps.

‍

‍

II. Technical and Organisational Measures

‍

The following technical and organisational measures apply to the processing of personal data by simpleclub. Further details and documentation are available in the simpleclub Trust Center: https://trust.simpleclub.com

For hosting, the technical and organisational measures of our sub-processors apply ("Sub-processor TOMs"):
- Google Cloud Data Processing Terms
- Cloudflare TOMs
- Braze AVV inkl. TOMs
- Intercom TOMs
- Loom TOMs
- Algolia TOMs
- Adjust Trust-Center
- Ory AVV inkl. TOMs
- Elasticsearch Trust-Center
- Mailjet AVV inkl. TOMs
- Posthog Trust-Center
- Microsoft Trust-Center
- Langfuse Trust-Center

‍

‍

1. Confidentiality

1.1. Physical access control
- As simpleclub is a remote company without central office buildings, our measures focus on securing the decentralised working environments and our cloud infrastructure.
- Our cloud services are hosted exclusively with certified providers (at least ISO 27001 or SOC 2 Type 2) that implement physical security measures at the highest level (e.g. security perimeters, physical entry controls, surveillance). Details can be found in the Sub-processor TOMs.
- For employees working from home, policies on the secure set-up of the workplace apply in order to prevent unauthorised physical access to company property.

‍

1.2. System access control (system level)
- Identity and authentication management: We manage the entire lifecycle of digital identities (identity management). Access to systems is governed by a central identity management system.
- Secure passwords & MFA: We enforce the use of strong, complex passwords (at least 12 characters). Strong two-factor authentication (2FA), preferably via FIDO2 hardware keys, is mandatory for all employees for access to critical systems.
- Endpoint security: All endpoint devices (laptops, smartphones) are protected by passwords/biometrics and configured with a screen lock that activates automatically after a short period of inactivity (15 minutes). Laptop hard drives are encrypted.

‍

1.3. Data access control (data level)
- Principle of least privilege: Access rights are granted on a need-to-know basis. Employees receive only the rights necessary for their specific tasks. This is implemented through role-based access control (RBAC). Rights are revoked no later than 24 business hours after an employee leaves or changes role, which is ensured by quarterly access reviews for high-risk systems and annual access reviews for all systems.
- Management of privileged rights: Rights with extended access (e.g. administrator accounts) are strictly controlled and restricted to a minimum number of persons, and their use is logged.
- Segregation of duties: Critical and conflicting areas of responsibility (e.g. development and approval of code) are separated organisationally and technically in order to prevent misuse.
- Logging: Access to systems and data is logged in detail in order to be able to trace unauthorised activities.

‍

1.4. Separation control
- Logical tenant separation: Data of different customers is logically separated within our system architecture in order to prevent unauthorised access.
- Network segmentation: Our networks are segmented in order to isolate sensitive areas (such as production environments) from the rest.
- Separation of environments: Development, test and production environments are strictly separated. No production customer data is used in development and test environments.

‍

1.5. Anonymisation and pseudonymisation
- AI functions: User inputs are passed through technical filters that detect and mask personal data before the data is passed on to the AI models. The AI models are technically connected via simpleclub's server infrastructure, so that no other user data (e.g. IP address, device data) can be transferred to the sub-processors used. The data is not used to train the AI models.
- Langfuse is used exclusively in pseudonymised form. No real names, email addresses or other personal data are transferred to or stored with Langfuse.
- Data protection principles: We adhere to the principles of data protection, including pseudonymisation wherever this is possible and appropriate to minimise risk (e.g. use of a user ID instead of an email address).

‍

‍

2. Integrity

‍

2.1. Transfer control
- Encryption in transit: All data transmission over public networks takes place exclusively via encrypted protocols such as HTTPS with TLS 1.2 or higher; HSTS is enforced.
- Encryption at rest: All data is encrypted at storage level using AES-256.
- Data leakage prevention: We use measures to detect and prevent the unauthorised outflow of sensitive data.
- Employee training: Employees are regularly trained in the secure handling and transfer of data.

‍

2.2. Input control
- Logging: Changes, entries and deletions of data in our systems are logged in order to ensure traceability.
- Secure coding: Our developers follow secure coding principles in order to prevent vulnerabilities such as injection attacks from the outset.
- Vulnerability management: We continuously identify and assess technical vulnerabilities in our systems and remediate them based on their risk.

‍

‍

3. Availability and Resilience

‍
- Redundancy and fault tolerance: Our infrastructure at certified cloud providers is designed redundantly in order to ensure availability even if individual components fail.
- Regular backups: We create regular daily backups of critical systems and data. These are encrypted and stored securely.
- Business continuity & disaster recovery: We have established contingency plans and processes to ensure the restoration of systems after a serious incident. The effectiveness of these plans is tested regularly.
- Protective measures: We use modern protective software such as antivirus software and firewalls and keep our systems up to date through consistent patch management.
- Capacity management: The utilisation of our resources is monitored in order to identify bottlenecks at an early stage and to ensure performance.

‍

‍

4. Process for Regularly Testing, Assessing and Evaluating

‍
- ISMS in accordance with ISO 27001: We have implemented an ISO 27001-certified information security management system for our entire company, which is continuously operated, monitored and improved. This includes regular risk assessments and management reviews.
- Internal and external audits: We conduct internal audits at planned intervals and have our ISMS certified by independent external auditors in order to verify the conformity and effectiveness of our measures.
- Penetration tests: External security experts regularly conduct penetration tests of our systems in order to proactively identify vulnerabilities.
- Documented incident response process with defined roles as well as escalation and reporting channels.
- Automatic and manual data deletion in accordance with the internal deletion concept.
- Compliance monitoring: An internal Compliance Manager and an Information Security Team monitor compliance with all relevant legal, regulatory and contractual requirements.
- Data protection by design and by default (Art. 25 GDPR): When new products and processes are developed, data protection and data security are an integral part from the outset (in particular through the early involvement and consultation of our Compliance Manager).
- Processor control: We conclude contracts pursuant to Art. 28 GDPR with all processors and regularly review their technical and organisational measures.
- Training and confidentiality: All employees receive training on data protection and information security when they join and regularly thereafter, and are bound to confidentiality. In addition, internal policies on data protection, information security and the EU AI Act have been established, which are regularly evaluated and improved with regard to their effectiveness.
- Data protection officer: We have appointed an external data protection officer who advises us and monitors compliance with data protection regulations: Proliance GmbH, Leopoldstr. 21, 80802 Munich, Germany, email: datenschutzbeauftragter@datenschutzexperte.de
- Record of processing activities (RoPA): We maintain a record of processing activities pursuant to Art. 30 GDPR.

III. Sub-processing

Sub-processorDescription of servicesServer locationAddress & contactFurther information

Google Cloud EMEA Limited

Google Ireland Limited

Hosting (services: "Google Cloud Platform" and "Google Firebase")

Anonymised usage statistics for the provision of in-app functions.

EU

Gordon House
Barrow Street
Dublin 4
Ireland

dpo-google@google.com
https://cloud.google.com/securityhttps://firebase.google.com/support/privacy?hl=enhttps://policies.google.com/privacy?hl=en

Cloudflare Germany GmbH

Content delivery network for optimal performance and availability of the service

EU

Rosental 7
80331 Munich
Germany

privacyquestions@cloudflare.com
https://www.cloudflare.com/privacypolicy/

Braze Inc.

Customer engagement platform (email, push notifications & in-app messages)

EU

318 W. 39th Street
5th Floor
New York, NY 10018
USA

privacy@braze.com
https://www.braze.com/privacy

Intercom R&D Unlimited Company

Customer service & help centre

EU

124 St Stephen's Green
Dublin 2, D02 C628
Ireland

legal@intercom.io
https://www.intercom.com/legal/privacy#transfers-of-your-personal-data

Loom, Inc

Video hosting in the help centre

EU

140 2nd St Fl 6
San Francisco, CA 94105
USA

dataprotectionframework@atlassian.com
https://www.atlassian.com/legal/privacy-policy

Algolia SAS

Search functionality

EU

55 Rue d’Amsterdam
75008 Paris
France

privacy@algolia.com
https://www.algolia.com/policies/privacy/

Adjust GmbH

Mobile tracking
‍(only after opt-in)

EU

Saarbrücker Str. 38a
10405 Berlin
Germany

privacy@adjust.com
https://www.adjust.com/terms/privacy-policy/

Ory Corp

Single sign-on authentication
‍(only if actively used)

EU

15169 N. Scottsdale Rd., Suite 205
Scottsdale, AZ 85254
USA

https://www.ory.sh/privacy/

Elasticsearch B.V.

Search functionality

EU

Keizersgracht 281
1016 ED Amsterdam
Netherlands

https://www.elastic.co/legal/privacy-statement

Mailjet GmbH

Email delivery

EU

Friedrichstraße 68
10117 Berlin
Germany

https://www.mailjet.com/de/rechtliches/datenschutzerklaerung/

PostHog, Inc.

Quality assurance and error handling

EU

261 Market Street #4008
San Francisco, CA 94111
USA

https://posthog.com/blog/posthog-cloud-eu

Exadel sp. z o.o. (formerly CODETE Global sp. z o.o.)

Web development

EU

ul. Na Zjeździe 11
30-527 Kraków
Poland

Unterauftragnehmer bei Nutzung von KI-Funktionen (z.B. AI Tutor)

Sub-processorDescription of servicesServer locationAddress & contactFurther information

Microsoft Ireland Operations Limited

Provision of large language models (LLMs)
‍(only when using AI functions)

EU

South County Business Park, One Microsoft Place, Carmanhall And Leopardstown, Dublin, D18 P521, Ireland

https://www.microsoft.com/en-us/privacy/privacystatement

Langfuse GmbH

Prompt management and quality management of the AI functions
‍(only when using AI functions)

EU

Oranienburgerstraße 91
10178 Berlin
Germany

https://langfuse.com/privacy

Produkt

AusbildungsberufeLernmanagementLernerlebnis

Lösungen

Für Betriebsinhaber & Leadership:
Ausbildungskosten senken
Für HR-Verantwortliche:
Auszubildende gewinnen und binden
Für Ausbilder:
Einfacher ausbilden und Zeit sparen

Ressourcen

StudieUnsere GeschichteKarrierePresseSupport & KontaktBrand GuidelinesMedia Kit für PartnerTrust Center
PreiseKunden
Jetzt beraten lassen
->
Jetzt kaufen
->
ImpressumDatenschutzNutzungsbedingungen

Privatsphäre-Einstellungen

Verstoß melden

© 2026 simpleclub GmbH