GuideData Processing Agreements

06Compliance

Request a data-processing agreement from each AI provider

An operator checklist for putting an Art. 28 GDPR Auftragsverarbeitungsvertrag (AVV / DPA) in place with every AI sub-processor Lokrix relies on. You (the operator, Dominic Bachl IT Solutions & Consulting) are the controller; each AI provider is a processor. Below: where each DPA lives, whether it is self-serve or contact-legal, what to supply, and how to file it.

Last updated · Stand: 02. Juli 2026

Keine Rechtsberatung / Not legal advice

Dies ist keine Rechtsberatung, sondern eine Betreiber-Checkliste für das Anfordern von Auftragsverarbeitungsverträgen (AVV) gemäß Art. 28 DSGVO. Anbieter, URLs und Vertragsbedingungen ändern sich — prüfen Sie jede Angabe beim jeweiligen Anbieter und mit Ihrer eigenen Rechtsberatung, bevor Sie sich darauf verlassen.

This is not legal advice — it is an operator checklist for requesting Art. 28 GDPR data-processing agreements (DPAs). Providers, URLs and terms change; verify every detail with each provider and your own counsel before relying on it.

01The basics

What an AVV / DPA is, and when you need one.

Whenever a provider processes personal data on your behalf and on your instructions (a processor), Art. 28 GDPR requires a written Auftragsverarbeitungsvertrag (data-processing agreement). Lokrix sends prompt text, target URLs and brand identifiers to AI and search APIs to run the GEO scan — so each of those providers is a sub-processor you must cover with a DPA. Where the provider sits outside the EEA (all of the ones below are US-based), the DPA must also carry a valid transfer mechanism — Standard Contractual Clauses (SCCs, controller→processor Module 2), and, where the provider is certified, the EU-US Data Privacy Framework as an additional basis.

Your role
You are the controller toward your users; each AI/search provider is a processor / sub-processor. The DPA is between Dominic Bachl IT Solutions & Consulting and the provider.
What to have ready
Legal entity Dominic Bachl IT Solutions & Consulting, address Niederviehbacher Str. 92, 94315 Straubing, Deutschland, VAT DE459146729, controller contact info@bachl-systems.de, the processing purpose (LLM / search answer-engine queries), and the data categories (prompts, target URLs, brand identifiers).
Two flavours
Some providers auto-incorporate a DPA when you use the service (self-serve); others only issue a countersigned DPA on request (contact legal). Both are noted per provider below.
OpenAI note
OpenAI is intentionally excluded from this tutorial (handle its Enterprise DPA separately). This does not mean OpenAI lacks a DPA — its DPA row remains in the sub-processor list.

02Anthropic — Claude

Anthropic (Claude).

The Claude models run under Anthropic's Commercial Terms. A signed DPA for API / commercial use is available via the Trust Center or on request — treat it as a contact-legal flow for a standard API account.

Where it lives
Trust Center trust.anthropic.com; Commercial Terms & Privacy Policy at anthropic.com/legal (verify current).
Self-serve or contact
Request via the Trust Center or write to privacy@anthropic.com. Self-serve DPA acceptance for standard API accounts is limited.
What to provide
Legal entity Dominic Bachl IT Solutions & Consulting; controller contact info@bachl-systems.de; purpose: LLM answer-engine queries; data categories: prompts / URLs, brand identifiers.
SCCs (US transfer)
Yes — Anthropic PBC is US-based; the DPA incorporates SCCs, controller→processor (Module 2).
How to file
Store the countersigned PDF in your DPA register; record the signature date and version, and cross-reference it in the sub-processor list.

03Google — Gemini / Cloud

Google (Gemini via Google Cloud / AI Studio).

Gemini API usage through Google Cloud is governed by the Google Cloud Data Processing Addendum (CDPA), which is generally self-serve and auto-incorporated for Cloud customers. Confirm which entity/API you actually call (Gemini API vs. Vertex AI) and cite the matching addendum. The Google Ads DPA is separate. Note: Advertising (Google AdSense) is out of scope of this GEO-processor checklist; its Google Ads DPA is covered separately in the privacy sub-processor list.

Self-serve or contact
Mostly self-serve — accept the CDPA online in the Cloud console (or by using the service under the CDPA). No countersignature needed for standard Cloud accounts.
What to provide
Cloud billing account / legal entity Dominic Bachl IT Solutions & Consulting; controller contact info@bachl-systems.de. The SCCs are already embedded in the CDPA (verify the module).
SCCs (US transfer)
Yes — SCCs embedded in the CDPA. Google LLC is also EU-US DPF-certified, which can serve as an additional Art. 45 basis (verify the certification is live).
How to file
Export / download the accepted CDPA version, log the acceptance date, and record it in your DPA register.

04Perplexity — Sonar

Perplexity (Sonar API).

Perplexity's Sonar API combines search and an LLM. A signed DPA is obtained by contacting legal/support — a self-serve DPA is not consistently published, so request it explicitly.

Where it lives
perplexity.ai/hub/legal (Terms of Service, Privacy Policy); the DPA is issued via support / the API terms (verify current).
Self-serve or contact
Contact legal — write to support@perplexity.ai (or your enterprise/API contact) to request the DPA for Sonar/API usage.
What to provide
Legal entity Dominic Bachl IT Solutions & Consulting; controller contact info@bachl-systems.de; purpose: search + LLM answer-engine queries; data categories: prompts / URLs, brand identifiers.
SCCs (US transfer)
Yes — Perplexity AI, Inc. is US-based; ensure the DPA carries SCCs, controller→processor (Module 2).
How to file
Store the countersigned copy in your DPA register with the signature date and version.

05xAI — Grok

xAI (Grok API).

The Grok API is governed by xAI's Terms of Service and Privacy Policy. Obtain and sign the DPA by contacting xAI legal / support — a self-serve DPA is not published, so request it.

Where it lives
x.ai/legal (Terms of Service, Privacy Policy) · console: console.x.ai (verify current).
Self-serve or contact
Contact xAI legal / support to obtain and sign the DPA for API usage.
What to provide
Legal entity Dominic Bachl IT Solutions & Consulting; controller contact info@bachl-systems.de; purpose: Grok answer-engine queries; data categories: prompts / URLs, brand identifiers.
SCCs (US transfer)
Yes — X.AI LLC is US-based; ensure the DPA carries SCCs, controller→processor (Module 2).
How to file
Store the countersigned copy in your DPA register with the signature date and version.

06Search & infrastructure

The other sub-processors — a quick pass.

The AI models are not the only recipients. The search/retrieval APIs and the infrastructure providers below also process data on your behalf — each needs a DPA on file too. Same rule as above (not legal advice; verify every URL and term).

ProviderRole at LokrixDPA / legal entry pointPosture
Brave Search API (Brave Software, Inc.)Search / retrieval — GEO scanbrave.com/search/apiRequest DPA — contact legal
Serper (serper.dev)Search / retrieval (proxies Google organic) — GEO scanserper.devRequest DPA — contact support
TavilySearch / retrieval — GEO scantavily.comRequest DPA — contact legal
Exa (Exa Labs, Inc.)Search / retrieval — GEO scanexa.aiEnterprise / request DPA
Bing Web Search — Microsoft CorporationSearch / retrieval — GEO scanmicrosoft.com — Products & Services DPASelf-serve / auto-incorporated
Amazon Web Services (AWS)Hosting, storage (S3), Kubernetes (EKS), self-hosted analytics/telemetryaws.amazon.com/compliance/gdpr-centerSelf-serve / auto-incorporated (AWS GDPR DPA)
StripePayment processingstripe.com/legal/dpaSelf-serve
WorkOS, Inc.Enterprise SSO / SAML / SCIMworkos.com/legalDPA on request
Sentry (Functional Software, Inc.)Error & performance monitoringsentry.io/legal/dpaSelf-serve
Slack — Slack Technologies, LLC (Salesforce)Outbound alert/notification delivery + slash-command integrationslack.com/trust/complianceSelf-serve / auto-incorporated (Salesforce DPA)

The web app and the analytics/telemetry stores run on the operator's own AWS infrastructure (EKS / S3), so they are covered by the AWS DPA rather than a separate hosting vendor. Transactional email is sent via a deployment-configured SMTP relay; cover whichever relay you enable. Together / Fireworks (open-model routing) are not currently enabled and therefore carry no DPA obligation.

07Stay current

Keep a DPA register — and review it.

A DPA register is simply a table (a spreadsheet is fine) that proves, per Art. 5(2) / Art. 28 GDPR accountability, that every processor is covered. Give each provider one row with these columns:

Processor & legal entity
Exact company name and country (e.g. Anthropic PBC, USA).
DPA source & version
The URL or document, the version/date, and whether it is self-serve or countersigned.
Signature / acceptance date
When you executed or accepted it — plus your next review date.
Transfer mechanism
SCC module (controller→processor) and, if applicable, DPF certification.
Data categories & purpose
What personal data is shared and why (prompts/URLs, brand identifiers; GEO scan).
Sub-processor list link
Confirm the provider also appears in the public sub-processor list, and vice-versa.

Every processor here must also be listed in the binding Datenschutzerklärung §5 (Auftragsverarbeiter) — every GEO-scan processor listed here must also appear in the public sub-processor list. Advertising processors (e.g. Google AdSense) and other out-of-scope services belong in the privacy sub-processor list but are not part of this GEO-processor checklist. Re-check the register whenever you add or remove a provider.

Keine Rechtsberatung / Not legal advice

Dies ist keine Rechtsberatung, sondern eine Betreiber-Checkliste für das Anfordern von Auftragsverarbeitungsverträgen (AVV) gemäß Art. 28 DSGVO. Anbieter, URLs und Vertragsbedingungen ändern sich — prüfen Sie jede Angabe beim jeweiligen Anbieter und mit Ihrer eigenen Rechtsberatung, bevor Sie sich darauf verlassen.

This is not legal advice — it is an operator checklist for requesting Art. 28 GDPR data-processing agreements (DPAs). Providers, URLs and terms change; verify every detail with each provider and your own counsel before relying on it.

lokrix ai

Data honesty extends to compliance.

Lokrix names every processor it uses — in the checklist above and in the binding privacy policy. Verify each provider's current terms, put the DPAs in place, and keep your register up to date.