Processing on your behalf

Data Processing Agreement (DPA) under Art. 28 GDPR

The agreement organisations sign inside their Tribelume account — here in full, before you decide. Including the technical and organisational measures (Annex 1) and the list of sub-processors (Annex 2).

Version 1.4 September 2026 Art. 28 GDPR

The agreement becomes binding when it is accepted inside the account, where the version and a checksum of the contract text are recorded. This page renders the same source for reading; it is not a second agreement.

Working translation. Die deutsche Fassung ist maßgeblich / The German version prevails. Only the German text is accepted in the account and covered by the checksum; this English text is provided so you can read and review the agreement. The German original is at /avv.

Jump to: Annex 1 — technical and organisational measures · Annex 2 — sub-processors

This agreement on commissioned data processing (hereinafter “DPA”) is concluded between the customer as controller within the meaning of Art. 4(7) GDPR (hereinafter “Controller”) and Press Sensation UG (haftungsbeschränkt), Pappelallee 78/79, 10437 Berlin, Germany, represented by Thomas Jentzsch (hereinafter “Processor”). It specifies the parties’ data protection obligations arising from the main contract on the use of the Tribelume platform (https://tribelume.com) and takes precedence over the provisions of the main contract with regard to the processing of personal data.

§ 1 Subject matter and duration of processing

The Processor provides the Controller with services for the production and operation of online courses: from material provided by the Controller it creates interactive courses and operates them on its learning platform — including a public course page and course access, participant management, learning groups with community features (posts, replies, reactions, private reflections), certificates and reports, as well as an optional AI assistant. The subject matter of this DPA is the processing of personal data on behalf of the Controller required for these services.

The duration of processing corresponds to the term of the main contract. This DPA ends with the complete deletion or return of the personal data in accordance with § 11.

§ 2 Nature and purpose of processing, categories of data, data subjects

Nature and purpose: production of the courses from the Controller’s material; provision of the learning platform and the course page; management of user accounts, organisational structures and course access (assignments, seat allocations, invitations and access links); delivery of the courses; sending of invitation, reminder and platform emails; operation of learning groups and community spaces (publishing, replying to, reporting and moderating posts, reactions, private reflection answers); issuing of participation certificates; progress and participation reports and — where activated or used by the Controller — an optional AI assistant (answering product and dashboard questions; read-only access within the existing permissions).

Categories of personal data: master data (name, email address), organisation and access data (organisation, team, role, assigned or booked courses, invitation and access status), usage and learning-progress data (progress, exercise and test results, completion data, certificates), community data (membership and role in learning groups, published posts and replies including titles, reactions, reports and moderation notes, read status, the level derived from course points and participation, and private reflection answers visible only to the person who wrote them), log data (sign-in times, technical logs) and personal data contained in the course material provided by the Controller.

Categories of data subjects: the Controller’s participants — in particular its employees, its customers and other persons invited by it or admitted through access it provides (access links, seat allocations) —, moderators of learning groups, the Controller’s administrators, and persons named in the Controller’s course material.

Where the Controller provides courses of a coach or creator, that person receives only aggregated figures without personal reference from this commission. The Processor grants insight into participants’ personal data only where the Controller expressly releases it; such a release is an instruction under § 3 and can be revoked at any time.

This DPA does not cover the processing of data of persons who purchase a course directly from the Processor (direct sale via a course page). In that respect the Processor is itself the controller; details are set out in its privacy policy.

Special categories of personal data (Art. 9 GDPR): the platform is not intended for processing special categories of personal data; the data fields provided do not foresee such data. Should such data nevertheless enter the processing — for example through entries in free-text fields, through posts and reflection answers in learning groups or through content of the course material provided —, the Processor treats it with the increased level of protection under § 6 of this agreement; the Controller is responsible for the lawfulness of its collection and processing. The Controller is urged to refrain from entering such data and to design reflection tasks so that they can be answered without personal disclosure; to that end the platform provides an alternative without personal disclosure for every reflection task.

§ 3 Controller’s right to issue instructions

The Processor processes personal data only on documented instructions from the Controller — including with regard to transfers of personal data to a third country or an international organisation —, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28(3)(a) GDPR).

The Controller’s use of the platform functions (e.g. creating users, assigning courses, activating modules) constitutes an instruction. Supplementary instructions require text form.

The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions.

§ 4 Confidentiality and professional secrecy

The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR). Access to personal data is limited to the persons who need it to perform the contract.

The confidentiality obligation continues after the respective person’s activity ends and after termination of this agreement.

Where the Controller is subject to a special duty of secrecy — in particular professional secrecy under § 203 of the German Criminal Code (StGB), for example in healthcare institutions —, the following applies: the Processor and the sub-processors engaged by it are other contributing persons within the meaning of § 203(3) and (4) StGB. The Processor selects the persons and sub-processors engaged in processing with care, expressly obliges them to keep secret the third-party secrets that become accessible to them and informs them that unauthorised disclosure is a criminal offence. On request, it informs the Controller of the measures taken.

§ 5 Purpose limitation, no own use, no AI training

The Processor processes the personal data entrusted to it exclusively for the purposes set out in § 2. No processing takes place for the Processor’s own purposes — in particular for advertising, market or opinion research or profiling.

Neither the Processor nor the sub-processors listed in Annex 2 use the personal data processed on behalf of the Controller for training, developing or improving artificial intelligence models. The Processor only uses AI services where training on customer data is contractually excluded.

Aggregated and anonymised evaluations for improving the service remain permissible, provided that no personal reference can be established and no conclusions about individual controllers are possible.

§ 6 Technical and organisational measures (Art. 32 GDPR)

The Processor takes the technical and organisational measures described in Annex 1 and develops them further taking into account the state of the art. Measures may be replaced by equivalent or better ones, provided that the level of protection does not decrease.

§ 7 Sub-processing

The Controller grants general authorisation to engage the sub-processors listed in Annex 2 (Art. 28(2) GDPR).

The Processor informs the Controller in text form of any intended changes (addition or replacement) at least 30 days before they take effect — even where the change is at the same time part of a new version of this DPA. Within this period the Controller may object for an important reason under data protection law; if the objection means that the service cannot be provided, both parties have a special right to terminate the main contract.

Contracts are concluded with each sub-processor that meet the requirements of Art. 28(4) GDPR and impose on it the same data protection obligations that are incumbent on the Processor under this agreement. The Processor is liable to the Controller for the sub-processor’s compliance with these obligations.

Ancillary services that the Processor obtains from third parties without these third parties having intended access to personal data from this commission (e.g. telecommunications and cleaning services) do not constitute sub-processing.

§ 8 Third-country transfers and requests from authorities

Personal data is processed outside the EU or the EEA only where this is shown in Annex 2. For these transfers the Processor ensures appropriate safeguards under Chapter V GDPR — primarily an adequacy decision of the European Commission (for recipients in the USA: valid certification under the EU-US Data Privacy Framework), otherwise EU Standard Contractual Clauses together with a documented assessment of the legal situation in the recipient country and supplementary measures.

If the Processor receives a legally binding request from an authority of a third country to disclose personal data processed on behalf of the Controller, it informs the Controller without undue delay, unless applicable law prohibits this. It primarily refers the requesting authority to the Controller, examines the lawfulness of the request, exhausts reasonable legal remedies and — if disclosure is unavoidable — discloses only the data that is legally mandatory. If notification is prohibited, it works towards having that prohibition lifted and documents its efforts; it informs the Controller about the number and type of such requests to the extent permissible.

§ 9 Assistance to the Controller

The Processor assists the Controller with appropriate technical and organisational measures in fulfilling data subjects’ rights (Art. 12–23 GDPR), in particular through the platform’s export, rectification and deletion functions. If a data subject contacts the Processor directly, it forwards the request to the Controller without undue delay and does not answer it itself.

It further assists the Controller in complying with the obligations under Art. 32 to 36 GDPR (security of processing, notification of breaches, data protection impact assessment, prior consultation), taking into account the nature of processing and the information available to it.

The Processor maintains a record of all categories of processing activities carried out on behalf of the Controller (Art. 30(2) GDPR) and provides the Controller with the information concerning it on request.

§ 10 Notification of personal data breaches

The Processor notifies the Controller of any personal data breach concerning data processed under this commission without undue delay, and at the latest within 24 hours of becoming aware of it. Notification is made to the contact point designated by the Controller (§ 13).

The notification contains — as far as available — the information under Art. 33(3) GDPR; if not all information is available immediately, the Processor first notifies incompletely and provides the missing information without undue delay. It takes appropriate containment measures without undue delay and documents the incident.

Notifications to the supervisory authority (Art. 33 GDPR) and to data subjects (Art. 34 GDPR) are made by the Controller alone; the Processor does not act externally on its own in this respect.

§ 11 Deletion and return

After the end of the provision of processing services, the Processor, at the Controller’s choice, deletes all personal data or returns it (export in a common, machine-readable format) and deletes existing copies, unless Union or Member State law requires storage.

The Controller communicates its choice within 30 days after the end of the contract; if it makes no choice, the data is deleted. Deletion takes place within 90 days after the end of the contract or after the choice has been communicated. Backup copies are overwritten within the regular backup cycles (max. 35 days); until overwritten they remain protected against access and are not restored.

On request, the Processor confirms complete deletion to the Controller in text form.

Evidence issued by the Controller itself (e.g. downloaded certificates and audit exports) remains the Controller’s responsibility.

§ 12 Evidence and audits

The Processor provides the Controller with all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR (in particular a description of the measures under Annex 1 and information on sub-processors).

The Controller may carry out audits — including inspections — or have them carried out by a suitable auditor bound to confidentiality. Audits take place after reasonable advance notice, during usual business hours and without disproportionate disruption of operations. Existing evidence (documentation, attestations) is used primarily.

§ 13 Contacts and data protection officer

The Processor’s contact point for all questions about this agreement, for instructions and for notifications under § 10: datenschutz@conformbase.com, Press Sensation UG (haftungsbeschränkt), Pappelallee 78/79, 10437 Berlin.

As the threshold of § 38(1) of the German Federal Data Protection Act (BDSG) is not reached, the Processor has not appointed a data protection officer; the tasks are performed by the management. The Processor will inform the Controller of any later appointment without undue delay.

The Controller names to the Processor a contact point for data protection matters and — where applicable — its data protection officer, and keeps this information up to date. It further names the persons authorised to issue instructions.

§ 14 Liability

The parties’ liability is governed by Art. 82 GDPR and the liability provisions of the main contract.

§ 15 Final provisions

Amendments and additions to this DPA require text form. This also applies to any amendment of this clause.

Should individual provisions be invalid, the validity of the remaining provisions remains unaffected.

The law of the Federal Republic of Germany applies. This DPA is concluded electronically: the Processor signs the document digitally; acceptance by an authorised signatory of the Controller is recorded in an audit-proof manner with name, time and document checksum (SHA-256) and shown in the final document. The parties agree that this electronic conclusion satisfies the form requirement of Art. 28(9) GDPR (electronic format).

Annex 1: Technical and organisational measures (summary)

Hosting & location: platform data (database, file storage, authentication) is processed and stored in data centres within the EU (Frankfurt region). Delivery and individual additional functions shown in Annex 2 may access infrastructure outside the EEA; the safeguards under § 8 apply in these cases. Tenant separation at database level through row-level security.

Access control: role-based permissions (platform admin, organisation admin, learners), authentication with secure session procedures, password policies; administrative access on the least-privilege principle and with two-factor authentication.

Transmission and storage control: transport encryption (TLS) for all connections, encryption of data at rest, end-to-end encryption of the content of whistleblower reports.

Availability control: automated backups with defined retention, redundant infrastructure of the hosting provider, monitoring.

Input control: logging of security-relevant events; learning-progress and certificate data with timestamps and verification numbers.

Organisational measures: confidentiality obligation of all staff, documented processes for data breaches, regular review of the measures.

This annex describes the measures in summarised form. The Processor provides a detailed version on request.

Annex 2: Approved sub-processors

This list is exhaustive: every service that processes personal data from this commission is listed here.

Supabase Inc., 970 Toa Payoh North, Singapore (EU operation) — database, authentication, file storage, server functions; data processed: all platform data under § 2; place of processing: EU (Frankfurt region); safeguards: data processing agreement, EU Standard Contractual Clauses.

Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA — content delivery, edge delivery of the application, DDoS protection and operation of the AI assistant including short-term caching of conversation states in the EU; data processed: connection and request data, assistant input; place of processing: EU/worldwide (edge); safeguards: data processing agreement, EU Standard Contractual Clauses.

Brevo GmbH (formerly Sendinblue GmbH), Köpenicker Str. 126, 10179 Berlin — sending of invitation and platform emails to users, maintaining contact profiles of user accounts for platform communication (name, email address, role, organisation and lifecycle status) and customer communication with administrator contacts; no learning-progress or test-result data; place of processing: EU; safeguards: data processing agreement.

OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland — AI assistant/dashboard copilot (only where the Controller’s users use the function): processing of chat input and of the dashboard information required for the answer, limited by the existing permissions; model outputs are not stored as API resources retrievable later (store=false), abuse logs by default for max. 30 days; no training on customer data; processing in or onward transfer to the USA possible; safeguards: data processing agreement (OpenAI DPA), EU Standard Contractual Clauses, EU-US Data Privacy Framework.

Anthropic PBC, 548 Market Street, San Francisco, CA 94104, USA — language model for evaluating feedback on course content; data processed: free texts from feedback (without real names; attribution via pseudonyms); no training on customer data; place of processing: USA; safeguards: data processing agreement, EU Standard Contractual Clauses, EU-US Data Privacy Framework.

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Gemini API) — language model for creating and translating course content from the material provided, for AI functions in the dashboard where they are used, and as a fallback model when the evaluation of feedback via Anthropic is unavailable; data processed: course content and the material provided for it, administrators’ input into AI functions and, in the fallback case, free texts from feedback (without real names; attribution via pseudonyms); no training on customer data; place of processing: EU/USA; safeguards: data processing agreement, EU Standard Contractual Clauses, EU-US Data Privacy Framework.

The AI services with which the Processor generates voices, images and videos for course content are not sub-processors. They receive course content only — narration texts and image and scene descriptions — and no participant data and no account, organisation or progress data; they do not use the content provided to train AI models. The Controller provides personal data of third parties in the material (such as names in case studies) only in anonymised form. If the voice or image of a real person is to be used, the Processor first adds the service concerned as a sub-processor under § 7.

Also not sub-processors are services for which the Processor acts under its own responsibility: Stripe Payments Europe, Ltd. (payment processing for the main contract; contact and billing data, no participant data) and Expert Systems AG (ProvenExpert; name and email address only if a person clicks the review link on the completion screen themselves).

Consent-based web analytics services run exclusively on the public pages and in the sign-in and onboarding area of the main domain (see privacy policy); no web analytics take place on the learning platform or on customer subdomains, and learning-progress, training or course-content data is not transmitted to web analytics providers.

Processor: Press Sensation UG (haftungsbeschränkt), Pappelallee 78/79, 10437 Berlin. Questions about the agreement: contact@conformbase.com · data-protection requests: datenschutz@conformbase.com · Privacy policy · Terms

Last updated: 2026-09-25 · version 1.4