Legal
Data Processing Agreement (Art. 28 GDPR)
Since 9 October 2026, System1 Models operates under the name Decision Models (decisionmodels.io). References to System1 Models and system1models.ai in this document mean Decision Models and decisionmodels.io; nothing else changes.
Where the Free Pilot Addendum applies, the Customer accepts this agreement in text form (for example by email) instead of in the dashboard. Acceptance takes effect when we confirm the account in text form, and we record date, accepting person and version. The dashboard acceptance described below applies to future paid accounts.
under Article 28 of the General Data Protection Regulation (GDPR)
Version 1.2 · Last updated: 1 October 2026
Between the customer that accepts this agreement in the System1 Models dashboard or, for a free named pilot account under the Free Pilot Addendum, in text form ("Controller" or "Customer")
and productivity-boost.com Betriebs UG (haftungsbeschränkt) & Co. KG, Reichenberger Str. 2, 94036 Passau, Germany, Amtsgericht Passau HRA 12725, represented by its general partner productivity-boost.com UG (haftungsbeschränkt), itself represented by its managing director Florian Standhartinger ("Processor" or "we").
The Customer accepts this agreement electronically in the dashboard; acceptance is recorded with date, version and the accepting user. For a free named pilot account under the Free Pilot Addendum, the Customer instead accepts this agreement in text form (for example by email), in the version we name in our request for acceptance; acceptance takes effect when we confirm the account in text form, and we record the date, the accepting person and the version. Acceptance in electronic or text form satisfies Art. 28(9) GDPR. A signed PDF copy is available on request. A German version exists; if the two versions differ, the German version prevails.
1. Subject matter, scope and duration
1.1 This agreement governs the processing of personal data by the Processor on behalf of the Controller in connection with the System1 Models Service, in both the EU tier and the Peer-to-Peer tier, under the Terms of Service ("Main Contract").
1.2 It does not apply to account, billing and usage data that the Processor processes as a controller for its own purposes (see the Privacy Policy).
1.3 The subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
1.4 This agreement runs for as long as the Processor processes personal data for the Controller under the Main Contract. It ends automatically when the Main Contract ends and all personal data have been deleted in accordance with section 11.
2. Instructions
2.1 The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by Union or Member State law; in that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest (Art. 28(3)(a) GDPR).
2.2 The Main Contract, this agreement and the Controller's use and configuration of the Service (for example, choice of tier, model and retention setting through the API or dashboard) constitute the Controller's complete documented instructions at the time of conclusion. Further instructions must be given in text form to info@productivity-boost.com. Instructions that go beyond the agreed scope of the Service are handled as a change request; the Processor may charge reasonable additional costs agreed in advance.
2.3 The Processor informs the Controller without undue delay if it believes that an instruction infringes the GDPR or other Union or Member State data protection provisions. The Processor may suspend carrying out the instruction until the Controller confirms or changes it.
3. Obligations of the Controller
3.1 The Controller is responsible for the lawfulness of the processing, including the legal basis, the information of data subjects and the assessment of whether its use case requires a data protection impact assessment or falls under Art. 22 GDPR or the EU AI Act.
3.2 The Controller sends personal data only to the extent necessary for its purpose. Special categories of personal data (Art. 9 GDPR) and data relating to criminal convictions (Art. 10 GDPR) may only be sent if the Controller has a legal basis for it and has assessed that the measures in Annex 2 are appropriate.
3.3 The Controller informs the Processor without undue delay if it finds errors or irregularities in the processing.
4. Confidentiality
The Processor ensures that all persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR), and that they process the data only on the Controller's instructions.
5. Security of processing
5.1 The Processor takes all measures required under Art. 32 GDPR. The technical and organisational measures (TOMs) in effect are described in Annex 2.
5.2 The TOMs are subject to technical progress. The Processor may implement alternative adequate measures, provided the level of security is not reduced. Material changes are documented and announced on the Security page.
6. Sub-processors
6.1 The Controller gives the Processor general written authorisation to engage sub-processors (Art. 28(2) GDPR). The sub-processors engaged when this agreement is concluded are listed in Annex 3 and at /legal/subprocessors; the Controller approves them.
6.2 The Processor informs the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance by email to the account's email address and by updating /legal/subprocessors. The Controller may object in text form within this period for reasonable data protection grounds. If the Processor cannot reasonably accommodate the objection, either party may terminate the affected part of the Main Contract with effect from the date of the change; unused prepaid credit is refunded. In urgent cases (for example, the sudden failure of a sub-processor), the notice period may be shortened; the objection right remains.
6.3 The Processor imposes on each sub-processor, by contract, the same data protection obligations as set out in this agreement, in particular sufficient guarantees for appropriate technical and organisational measures (Art. 28(4) GDPR). The Processor remains fully liable to the Controller for the performance of the sub-processor's obligations.
6.4 EU-tier requests are processed only in the EU and have priority. The Peer-to-Peer tier first uses spare EU capacity, with lower priority than EU-tier requests. When that capacity is busy, Peer-to-Peer requests may use on-demand GPU capacity rented through Lium (lium.io). Independent third-party providers operate the GPU hardware in various countries, including outside the EU/EEA. Processing outside the EU happens only for API keys whose customer has explicitly enabled the "Allow worldwide processing" switch. Without that opt-in, Peer-to-Peer requests stay on EU capacity and may be queued or rejected with a retryable error when busy. EU-tier requests always stay in the EU and have priority. Existing customers keep EU-only processing unless they opt in for the individual key. Request and response content is not stored on any node (zero payload retention). The notice and objection procedure under section 6.2 and the conditions in section 7 continue to apply to Lium and the independent GPU providers.
6.5 Ancillary services that do not involve access to the Controller's personal data (for example telecommunications, postal services, or the maintenance of hardware without data access) are not sub-processing.
7. Transfers to third countries
The API gateway and database remain in the EU. EU-tier requests, and Peer-to-Peer requests without per-key worldwide opt-in, are processed only in the EU. For opted-in Peer-to-Peer keys, GPU processing may take place in various countries on capacity rented through Lium. A transfer to a third country requires the Controller's prior documented instruction and compliance with Chapter V GDPR. Transfers outside the EU/EEA happen only for keys you opted in; you are responsible for not sending personal data on such keys unless an adequate transfer basis applies for your use. The switch itself is not a transfer basis under Chapter V GDPR. The Processor's obligations under sections 2.3 and 6.3 remain unchanged; no signed Standard Contractual Clauses or Lium certifications are asserted here.
8. Support with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR (Art. 28(3)(e) GDPR). Because content is not stored (Annex 1, section 5), there is normally no stored content to access, correct or delete. If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay and does not answer it itself, unless instructed.
9. Support with Articles 32 to 36 GDPR; personal data breaches
9.1 The Processor assists the Controller in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to it (Art. 28(3)(f) GDPR). This includes providing information needed for a data protection impact assessment and prior consultation.
9.2 The Processor notifies the Controller without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach affecting the Controller's data. The notification contains, as far as available: a description of the nature of the breach including the categories and approximate number of data subjects and records concerned; the name and contact details of a contact point; the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects. Information that is not yet available is provided in phases without undue further delay.
9.3 The Processor takes the necessary measures to secure the data and mitigate possible adverse consequences and documents the breach.
9.4 The Processor may charge reasonable costs for support under sections 8 and 9.1 only if the support goes beyond what is needed to meet its own obligations and the need for it was not caused by a breach on the Processor's part.
10. Audits and information
10.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller (Art. 28(3)(h) GDPR).
10.2 The Processor may first provide current documentation, including this agreement, the TOMs, the sub-processor list and, where available, certificates or audit reports of its sub-processors (for example ISO/IEC 27001 certificates of the data centre operators). If this documentation is not sufficient to demonstrate compliance, the Controller may carry out inspections, including on-site. The Controller announces inspections with reasonable notice, normally 14 days, or without delay where there is a specific cause such as a personal data breach or an inquiry by a supervisory authority. Inspections take place during normal business hours and avoid unnecessary disruption of operations. The Controller's auditors must be bound to confidentiality; the Processor may object to an auditor who is its direct competitor, in which case the Controller appoints another auditor. The Processor may charge reasonable, proven costs for its support with on-site inspections if the Controller conducts more than one per calendar year without specific cause, unless an inspection reveals a material breach by the Processor.
10.3 Rights of supervisory authorities remain unaffected.
11. Deletion and return at the end of processing
11.1 Content sent to the Service is deleted as soon as the response has been returned (Annex 1, section 5). Idempotency records (Annex 1, section 5) are deleted automatically after 24 hours. No content therefore remains to be returned or deleted at the end of the Main Contract.
11.2 Deletion is confirmed in text form on request.
12. Liability
Liability towards data subjects is governed by Art. 82 GDPR. In the relationship between the parties, the liability provisions of the Main Contract apply, unless mandatory law provides otherwise.
13. Final provisions
13.1 In the event of any conflict, this agreement takes precedence over the Main Contract as regards the processing of personal data.
13.2 Changes to this agreement are made in the same way as changes to the Terms of Service (section 14 of the Terms). Changes to the sub-processor list follow section 6.2. Changes to the TOMs follow section 5.2.
13.3 If a provision of this agreement is invalid, the rest remains valid. German law applies. The place of jurisdiction is determined by the Main Contract.
Annex 1 — Details of the processing
1. Subject matter and purpose: typed-decision inference: the Controller sends a state (text and, where supported, images) and questions to the Service (EU tier or Peer-to-Peer tier); a machine-learning model computes probabilities for the answer options and returns them to the Controller. The purpose is solely to provide this result to the Controller.
2. Nature of processing: receipt over an encrypted connection, temporary storage in the working memory of the API gateway and GPU servers, computation by the model, return of the result, deletion. Collection of metadata without content for billing and security (see the Privacy Policy).
3. Types of personal data: determined by the Controller. Typically: any personal data contained in the texts or images the Controller submits, for example names, contact details, contents of messages, tickets, documents or transactions, descriptions of behaviour or preferences, and images that may show people. Special categories of personal data only under section 3.2 of this agreement.
4. Categories of data subjects: determined by the Controller. Typically: the Controller's customers, users, prospects, employees, contractors and business partners, and other people mentioned in the submitted content.
5. Retention of content: content (states, questions, images) and results are not written to logs, databases, disk or any other persistent storage (zero data retention). They are held in volatile working memory while the request is processed. For performance, the inference server may keep intermediate values of recent requests in GPU memory (prefix cache) until they are overwritten by later requests, and at the latest until the server process restarts; this cache is never persisted, is isolated per model instance and cannot be read through the API. If the Controller sends an optional Idempotency-Key, the Processor keeps for 24 hours a keyed (HMAC) digest of the request body, the request ID, the processing status and the usage receipt, without content, to prevent duplicate processing and charging. Metadata without content (request ID, time, key ID, model, tier, token count, number of decisions, latency, status) is processed by the Processor as a controller for billing and security.
6. Place of processing: API gateway and database: EU (Hetzner, Helsinki). EU-tier inference and Peer-to-Peer inference without worldwide opt-in: EU (Verda, Finland). Opted-in Peer-to-Peer inference: spare EU capacity first, then on-demand Lium capacity operated by independent third-party GPU providers worldwide, including outside the EU/EEA, subject to sections 6 and 7. Zero payload retention applies on every node.
7. Contact for data protection: info@productivity-boost.com.
8. Duration of the processing: for the duration of the Main Contract, until deletion under section 11 (see section 1.4).
Annex 2 — Technical and organisational measures (Art. 32 GDPR)
The measures below apply to both tiers. They are also published on the Security page.
2.1 Pseudonymisation and encryption (Art. 32(1)(a))
- All connections to the API, dashboard and MCP server use TLS 1.2 or higher; plain HTTP is redirected or refused. HSTS is enabled.
- Connections between the API gateway and GPU servers are encrypted (TLS or WireGuard tunnel) and authenticated.
- API keys are stored only as salted cryptographic hashes; the full key is shown once.
- Database backups are encrypted.
- Content is not stored, so there is no stored content to pseudonymise; usage records carry only IDs, never content.
2.2 Confidentiality (Art. 32(1)(b))
- Physical access control: EU infrastructure runs in the data centres of Hetzner and Verda with the existing provider safeguards. Peer-to-Peer overflow uses independent GPU providers via Lium; the certifications of our EU providers do not extend to them. We operate no own server rooms.
- System access control: administrative access only through SSH with public keys or through the provider's console with two-factor authentication; no password logins; firewalls allow only the required ports.
- Data access control: role-based access; production access is limited to the managing director and named administrators on a need-to-know basis; every customer's requests are isolated by API key and account; no shared state between requests other than the model weights.
- Separation: EU-tier requests have priority and stay only on EU capacity. Peer-to-Peer requests first use spare EU capacity; worldwide overflow requires explicit per-key opt-in. Customer data is logically separated by account ID and API key; development and test systems use no customer data.
- Minimal logging: logs record only IDs, sizes, latency, model, tier and status — never request or response content.
2.3 Integrity (Art. 32(1)(b))
- Transfer control: encryption in transit (see 2.1); no removable media.
- Input control: administrative actions and changes to deployments are logged; deployments are made from version-controlled, reviewed code.
- Container images are pinned by digest and model weights by revision and SHA-256 checksum.
2.4 Availability and resilience (Art. 32(1)(b) and (c))
- A permanently running base GPU node in the EU.
- Health checks and automatic restart of failed services.
- Daily encrypted database backups (account and usage data; no content), stored in the EU.
- Uninterruptible power supply, redundant network and fire protection in the data centres of our providers.
- Rate limits and abuse protection per API key.
2.5 Regular testing and evaluation (Art. 32(1)(d))
- Security review of our own code before each major release; dependency and image vulnerability scanning.
- Review of these measures at least once a year and after every security incident.
- Documented incident process: detection, containment, assessment, notification of affected controllers within 48 hours (section 9.2 of the DPA), follow-up.
2.6 Organisational measures
- Everyone with access is bound to confidentiality and instructed in data protection.
- We require Art. 28 GDPR agreements with sub-processors before opening customer-data processing.
- Secrets are kept in protected configuration stores, never in source code or logs.
Annex 3 — Sub-processors and tier scope
| Sub-processor | Service | Location of processing | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Hosting of the websites (including the dashboard), API gateway and database | EU | Provider's standard Art. 28 GDPR agreement, required before customer-data processing |
| DataCrunch Oy (trading as Verda), Helsinki, Finland | GPU servers for model inference | Finland (EU) | Data processing terms under Art. 28 GDPR |
| Lium (lium.io), with independent third-party GPU providers | On-demand GPU inference for opted-in Peer-to-Peer keys when spare EU capacity is busy | worldwide (third-party GPU providers) | Transfers outside the EU/EEA happen only for keys you opted in; you are responsible for not sending personal data on such keys unless an adequate transfer basis applies for your use. The switch itself is not a transfer basis under Chapter V GDPR. |
The following providers do not process API content but process account-related data that we handle as a controller (see the Privacy Policy): Stripe Payments Europe, Ltd. (payments), Scaleway SAS (service emails). Lium and its independent GPU providers are limited to Peer-to-Peer overflow for opted-in keys; EU-tier traffic never uses them. Existing customers retain the notice and objection rights in section 6.2 and EU-only processing unless they opt in under section 6.4.