Terms under which Hremia processes personal data as a processor on behalf of the customer (the controller).
Last updated: 2026-09-28
Template — review with your counsel before relying on it. This document is provided for information only and is not legal advice.
This document is published in English, which is the authoritative version. If you need it in another language for your procurement or works council, contact [email protected].
This Addendum forms part of the agreement between the customer (the controller) and Hremia (the processor). It applies to Hremia's processing of personal data on the customer's behalf in connection with the service. Hremia processes such data only on the customer's documented instructions, including those set out in the agreement and configuration of the service.
Hremia implements appropriate technical and organisational measures, including:
The customer authorises Hremia to engage the sub-processors named in Hremia's sub-processor list, including Hetzner Online GmbH (hosting and storage, Falkenstein, Germany) and the AI model providers used for the customer's organisation. Each is bound by written terms, including a data-processing agreement, imposing data-protection obligations no less protective than this Addendum. AI model providers are engaged on paid, business terms under which they do not use the customer's data to train their models and retain it only for a limited period. Hremia maintains a current list and notifies material changes in advance so the customer may object.
Customer data is stored in the EU (Hetzner Online GmbH, Falkenstein, Germany). For the AI features (the assistant's replies, translations and training questions), the text the task needs, such as the conversation and the context needed to answer it, is sent to the AI model provider named in the sub-processor list. Where a provider processes personal data outside the EU/EEA, the transfer relies on a safeguard under Chapter V GDPR, such as an adequacy decision or the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), as stated for each provider in the sub-processor list.
Taking into account the nature of the processing, Hremia assists the controller by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights. Where Hremia receives such a request directly, it promptly forwards it to the controller and supports its response, including for employees' private conversations, which the controller cannot read itself.
Hremia notifies the controller without undue delay after becoming aware of a personal-data breach affecting the controller's data, providing the information reasonably needed for the controller to meet its own notification obligations.
Hremia makes available the information necessary to demonstrate compliance with this Addendum and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates, subject to reasonable confidentiality and security arrangements.
On termination, and at the controller's choice, Hremia deletes or returns the personal data it processes and deletes existing copies, unless retention is required by law.
To request or execute this Addendum, or for data-processing questions, write to [email protected].
AES-256-GCM · Stored in the EU · Encrypted & isolated by design.