1. Parties and subject matter

This agreement applies between the customer as controller and Evosis Software UG (haftungsbeschränkt) as processor for the processing of personal data in the context of Keycloak as a Service.

It is concluded before delivery, by the customer accepting it during the order. Evosis records the time and the version of that acceptance and provides the customer with a copy. Electronic form is sufficient under Article 28(9) GDPR.

It does not apply to the Claude Code Ruleset. There, Evosis processes no personal data of the customer.

2. Nature, purpose and duration

Purpose: operating a sign-in and user management system (Keycloak) for the customer, including provisioning, updates, backups, monitoring and fault resolution.

Nature of processing: storing, organising, retrieving, altering and erasing the data entered by the customer or its users, together with the log data arising from operations.

Duration: for the term of the main contract, plus the periods for return and erasure set out in section 8.

3. Types of data and categories of data subjects

Categories of data subjects: users of the customer's applications, in particular its staff, its customers and its business partners.

Categories of personal data:

  • identification data: username, first and last name, email address
  • credentials: password hashes, second-factor enrolment data
  • authorisation data: roles, groups, memberships
  • usage data: sign-in times, IP addresses, session and event logs
  • any further attributes the customer creates in its own realm

The customer alone decides which further attributes it creates. Special categories under Article 9 GDPR are not covered by this agreement. Processing such data requires a separate prior arrangement.

4. Instructions

Evosis processes the data solely on the documented instructions of the customer. The main contract with its service description and this agreement constitute the initial instruction. Further instructions are given in text form to the address in the legal notice.

Where Evosis considers an instruction unlawful, it says so without delay and may suspend execution until the matter is settled.

There is no processing for Evosis's own purposes, in particular no analysis, no training of models and no disclosure to third parties.

5. Confidentiality

Evosis engages only persons who are bound to confidentiality and have been instructed in the relevant data protection obligations. That obligation continues beyond the end of their engagement.

6. Technical and organisational measures

Evosis takes the measures required by Article 32 GDPR. Their current state in detail:

  • Separation: each customer receives its own Keycloak installation in its own namespace, with its own database and its own realm. There is no shared user database.
  • Transmission: external access exclusively over TLS. The directory is not reachable from outside.
  • Access control: administrative access only through personal or individually revocable application credentials, never through shared passwords.
  • Restorability: the data of every installation is backed up daily, the backups are held in the geo-redundant object storage of the same provider, that is in two German data centres, and are kept for 30 days. Every backup is checked for readability immediately after it is written; a backup failing that check counts as failed and is reported.
  • Logging: access to the installation and administrative access to the cluster are logged. Log data is kept for 30 days and erased automatically thereafter.
  • Traceability: infrastructure changes are made through versioned descriptions and are dated and attributable to a person.
  • Certification: Evosis itself holds no certification. The infrastructure is operated by SysEleven GmbH, which is certified to ISO/IEC 27001 on the basis of IT-Grundschutz (certificate BSI-IGZ-0671-2025 issued by the German Federal Office for Information Security, valid until 5 March 2028). Its scope covers MetaKube and the OpenStack cloud, which are precisely the services the installations run on.

Evosis deliberately gives no undertaking on encryption at rest: it depends on properties of the storage that the provider determines. Only what Evosis produces itself and can demonstrate is undertaken here.

The measures may be developed further as long as the level of protection does not fall. Evosis notifies material changes in text form.

7. Subprocessors

The customer consents to the subprocessors listed below. Evosis concludes an agreement with each of them imposing substantially the same obligations.

  • SysEleven GmbH, Berlin, a company of secunet Security Networks AG: operation of the cloud infrastructure and the container platform. This is where the installation, the database and the directory live. Evosis selects the Düsseldorf data centre as its region; backups are additionally held geo-redundantly in the Hamburg data centre. Both sites are in Germany. Contractually, SysEleven undertakes to process exclusively within the European Union or the European Economic Area; the restriction to Germany follows from the region Evosis selects.
  • Amazon Web Services: delivery of system and notification email via Amazon SES. This covers the recipient address and the content of the message concerned. Delivery exclusively through the Frankfurt region (eu-central-1), processing location European Union.

SysEleven in turn engages further processors. They have no access to the contents of the installation, but they do have access to the facilities housing it: providers of on-site data centre services (Atlas Edge GmbH, IPB Internet Provider in Berlin GmbH, NTT Global Data Centers EMEA), a network operator (Inter.link GmbH), a certified disposal firm for storage media (shred-it) and a support ticket system (Zendesk GmbH). The governing list is Annex 2 of the agreement between Evosis and SysEleven as it stands at the time, which Evosis produces on request.

No other service is given access to the data in the installation. Error monitoring is configured to transmit no personal data, and the payment provider processes only the customer's own contract data, which is not data governed by this agreement.

Evosis announces any change in text form at least four weeks in advance. The customer may object on serious data protection grounds. Failing agreement, the customer may terminate the main contract with effect from the date of the change.

8. Erasure and return

After the main contract ends, Evosis provides the customer on request with a complete export of its data in a common, machine-readable format. The export may also be requested at any time during the term.

Evosis then erases the data including backups and confirms the erasure on request. Statutory retention obligations remain unaffected; for the data concerned, restriction of processing takes the place of erasure.

The periods in detail: the end of the contract starts a period of 30 days. During that time the installation stays reachable and the customer can request the export. Once the period has passed the installation is torn down, meaning the application, the database and the directory are erased. An export provided beforehand stays available until the end of that same period.

9. Assistance to the controller

Evosis assists the customer by appropriate measures in responding to requests from data subjects under Articles 15 to 22 GDPR and in meeting its obligations under Articles 32 to 36 GDPR.

Where a data subject approaches Evosis directly, Evosis forwards the request to the customer without delay and does not answer it itself.

10. Personal data breaches

Evosis notifies the customer of any personal data breach in text form without undue delay after becoming aware of it, at the latest within 24 hours. As far as known, the notification states the nature of the breach, the categories of data affected, the likely consequences and the measures taken.

Notification to the supervisory authority under Article 33 GDPR is the customer's responsibility.

11. Evidence and audits

On request, Evosis demonstrates compliance with this agreement, primarily by providing information, by the measures under section 6 as they stand at the time, and by producing the infrastructure operator's certificate.

The customer may in addition carry out audits or have them carried out. Such audits are announced with reasonable notice of at least two weeks, take place during normal business hours and must not unreasonably interfere with operations. Evosis may reject auditors who compete with it.

12. Place of processing

Processing takes place exclusively in data centres within the Federal Republic of Germany. There is no transfer to a third country; any such transfer would require a prior arrangement and the basis required under Chapter V GDPR.

13. Final provisions

Where this agreement and the main contract conflict, this agreement prevails in all matters concerning the processing of personal data.

Evosis announces changes to this agreement in text form at least six weeks before they take effect. If the customer objects, either party may terminate the main contract with effect from that date.

Should any provision be invalid, the remainder of the agreement stays in force.