Keine Rechtsberatung / Not legal advice
Dies ist keine Rechtsberatung, sondern eine Betreiber-Checkliste für das Anfordern von Auftragsverarbeitungsverträgen (AVV) gemäß Art. 28 DSGVO. Anbieter, URLs und Vertragsbedingungen ändern sich — prüfen Sie jede Angabe beim jeweiligen Anbieter und mit Ihrer eigenen Rechtsberatung, bevor Sie sich darauf verlassen.
This is not legal advice — it is an operator checklist for requesting Art. 28 GDPR data-processing agreements (DPAs). Providers, URLs and terms change; verify every detail with each provider and your own counsel before relying on it.
01The basics
What an AVV / DPA is, and when you need one.
Whenever a provider processes personal data on your behalf and on your instructions (a processor), Art. 28 GDPR requires a written Auftragsverarbeitungsvertrag (data-processing agreement). Lokrix sends prompt text, target URLs and brand identifiers to AI and search APIs to run the GEO scan — so each of those providers is a sub-processor you must cover with a DPA. Where the provider sits outside the EEA (all of the ones below are US-based), the DPA must also carry a valid transfer mechanism — Standard Contractual Clauses (SCCs, controller→processor Module 2), and, where the provider is certified, the EU-US Data Privacy Framework as an additional basis.
- Your role
- You are the controller toward your users; each AI/search provider is a processor / sub-processor. The DPA is between Dominic Bachl IT Solutions & Consulting and the provider.
- What to have ready
- Legal entity Dominic Bachl IT Solutions & Consulting, address Niederviehbacher Str. 92, 94315 Straubing, Deutschland, VAT DE459146729, controller contact info@bachl-systems.de, the processing purpose (LLM / search answer-engine queries), and the data categories (prompts, target URLs, brand identifiers).
- Two flavours
- Some providers auto-incorporate a DPA when you use the service (self-serve); others only issue a countersigned DPA on request (contact legal). Both are noted per provider below.
- OpenAI note
- OpenAI is intentionally excluded from this tutorial (handle its Enterprise DPA separately). This does not mean OpenAI lacks a DPA — its DPA row remains in the sub-processor list.
02Anthropic — Claude
Anthropic (Claude).
The Claude models run under Anthropic's Commercial Terms. A signed DPA for API / commercial use is available via the Trust Center or on request — treat it as a contact-legal flow for a standard API account.
- Where it lives
- Trust Center trust.anthropic.com; Commercial Terms & Privacy Policy at anthropic.com/legal (verify current).
- Self-serve or contact
- Request via the Trust Center or write to privacy@anthropic.com. Self-serve DPA acceptance for standard API accounts is limited.
- What to provide
- Legal entity Dominic Bachl IT Solutions & Consulting; controller contact info@bachl-systems.de; purpose: LLM answer-engine queries; data categories: prompts / URLs, brand identifiers.
- SCCs (US transfer)
- Yes — Anthropic PBC is US-based; the DPA incorporates SCCs, controller→processor (Module 2).
- How to file
- Store the countersigned PDF in your DPA register; record the signature date and version, and cross-reference it in the sub-processor list.
03Google — Gemini / Cloud
Google (Gemini via Google Cloud / AI Studio).
Gemini API usage through Google Cloud is governed by the Google Cloud Data Processing Addendum (CDPA), which is generally self-serve and auto-incorporated for Cloud customers. Confirm which entity/API you actually call (Gemini API vs. Vertex AI) and cite the matching addendum. The Google Ads DPA is separate. Note: Advertising (Google AdSense) is out of scope of this GEO-processor checklist; its Google Ads DPA is covered separately in the privacy sub-processor list.
- Where it lives
- cloud.google.com/terms/data-processing-addendum · Trust: cloud.google.com/security/compliance · Privacy: policies.google.com (verify current).
- Self-serve or contact
- Mostly self-serve — accept the CDPA online in the Cloud console (or by using the service under the CDPA). No countersignature needed for standard Cloud accounts.
- What to provide
- Cloud billing account / legal entity Dominic Bachl IT Solutions & Consulting; controller contact info@bachl-systems.de. The SCCs are already embedded in the CDPA (verify the module).
- SCCs (US transfer)
- Yes — SCCs embedded in the CDPA. Google LLC is also EU-US DPF-certified, which can serve as an additional Art. 45 basis (verify the certification is live).
- How to file
- Export / download the accepted CDPA version, log the acceptance date, and record it in your DPA register.
04Perplexity — Sonar
Perplexity (Sonar API).
Perplexity's Sonar API combines search and an LLM. A signed DPA is obtained by contacting legal/support — a self-serve DPA is not consistently published, so request it explicitly.
- Where it lives
- perplexity.ai/hub/legal (Terms of Service, Privacy Policy); the DPA is issued via support / the API terms (verify current).
- Self-serve or contact
- Contact legal — write to support@perplexity.ai (or your enterprise/API contact) to request the DPA for Sonar/API usage.
- What to provide
- Legal entity Dominic Bachl IT Solutions & Consulting; controller contact info@bachl-systems.de; purpose: search + LLM answer-engine queries; data categories: prompts / URLs, brand identifiers.
- SCCs (US transfer)
- Yes — Perplexity AI, Inc. is US-based; ensure the DPA carries SCCs, controller→processor (Module 2).
- How to file
- Store the countersigned copy in your DPA register with the signature date and version.
05xAI — Grok
xAI (Grok API).
The Grok API is governed by xAI's Terms of Service and Privacy Policy. Obtain and sign the DPA by contacting xAI legal / support — a self-serve DPA is not published, so request it.
- Where it lives
- x.ai/legal (Terms of Service, Privacy Policy) · console: console.x.ai (verify current).
- Self-serve or contact
- Contact xAI legal / support to obtain and sign the DPA for API usage.
- What to provide
- Legal entity Dominic Bachl IT Solutions & Consulting; controller contact info@bachl-systems.de; purpose: Grok answer-engine queries; data categories: prompts / URLs, brand identifiers.
- SCCs (US transfer)
- Yes — X.AI LLC is US-based; ensure the DPA carries SCCs, controller→processor (Module 2).
- How to file
- Store the countersigned copy in your DPA register with the signature date and version.
06Search & infrastructure
The other sub-processors — a quick pass.
The AI models are not the only recipients. The search/retrieval APIs and the infrastructure providers below also process data on your behalf — each needs a DPA on file too. Same rule as above (not legal advice; verify every URL and term).
| Provider | Role at Lokrix | DPA / legal entry point | Posture |
|---|---|---|---|
| Brave Search API (Brave Software, Inc.) | Search / retrieval — GEO scan | brave.com/search/api | Request DPA — contact legal |
| Serper (serper.dev) | Search / retrieval (proxies Google organic) — GEO scan | serper.dev | Request DPA — contact support |
| Tavily | Search / retrieval — GEO scan | tavily.com | Request DPA — contact legal |
| Exa (Exa Labs, Inc.) | Search / retrieval — GEO scan | exa.ai | Enterprise / request DPA |
| Bing Web Search — Microsoft Corporation | Search / retrieval — GEO scan | microsoft.com — Products & Services DPA | Self-serve / auto-incorporated |
| Amazon Web Services (AWS) | Hosting, storage (S3), Kubernetes (EKS), self-hosted analytics/telemetry | aws.amazon.com/compliance/gdpr-center | Self-serve / auto-incorporated (AWS GDPR DPA) |
| Stripe | Payment processing | stripe.com/legal/dpa | Self-serve |
| WorkOS, Inc. | Enterprise SSO / SAML / SCIM | workos.com/legal | DPA on request |
| Sentry (Functional Software, Inc.) | Error & performance monitoring | sentry.io/legal/dpa | Self-serve |
| Slack — Slack Technologies, LLC (Salesforce) | Outbound alert/notification delivery + slash-command integration | slack.com/trust/compliance | Self-serve / auto-incorporated (Salesforce DPA) |
The web app and the analytics/telemetry stores run on the operator's own AWS infrastructure (EKS / S3), so they are covered by the AWS DPA rather than a separate hosting vendor. Transactional email is sent via a deployment-configured SMTP relay; cover whichever relay you enable. Together / Fireworks (open-model routing) are not currently enabled and therefore carry no DPA obligation.
07Stay current
Keep a DPA register — and review it.
A DPA register is simply a table (a spreadsheet is fine) that proves, per Art. 5(2) / Art. 28 GDPR accountability, that every processor is covered. Give each provider one row with these columns:
- Processor & legal entity
- Exact company name and country (e.g. Anthropic PBC, USA).
- DPA source & version
- The URL or document, the version/date, and whether it is self-serve or countersigned.
- Signature / acceptance date
- When you executed or accepted it — plus your next review date.
- Transfer mechanism
- SCC module (controller→processor) and, if applicable, DPF certification.
- Data categories & purpose
- What personal data is shared and why (prompts/URLs, brand identifiers; GEO scan).
- Sub-processor list link
- Confirm the provider also appears in the public sub-processor list, and vice-versa.
Every processor here must also be listed in the binding Datenschutzerklärung §5 (Auftragsverarbeiter) — every GEO-scan processor listed here must also appear in the public sub-processor list. Advertising processors (e.g. Google AdSense) and other out-of-scope services belong in the privacy sub-processor list but are not part of this GEO-processor checklist. Re-check the register whenever you add or remove a provider.
Keine Rechtsberatung / Not legal advice
Dies ist keine Rechtsberatung, sondern eine Betreiber-Checkliste für das Anfordern von Auftragsverarbeitungsverträgen (AVV) gemäß Art. 28 DSGVO. Anbieter, URLs und Vertragsbedingungen ändern sich — prüfen Sie jede Angabe beim jeweiligen Anbieter und mit Ihrer eigenen Rechtsberatung, bevor Sie sich darauf verlassen.
This is not legal advice — it is an operator checklist for requesting Art. 28 GDPR data-processing agreements (DPAs). Providers, URLs and terms change; verify every detail with each provider and your own counsel before relying on it.
Data honesty extends to compliance.
Lokrix names every processor it uses — in the checklist above and in the binding privacy policy. Verify each provider's current terms, put the DPAs in place, and keep your register up to date.