Data protection compliance
Consolidated self-assessment under the GDPR
Consolidated overview of how DeepMask implements the central GDPR requirements — DPA under Art. 28, TOMs under Art. 32, a transparent list of subprocessors, the appointed data protection officer, reporting channels and data subject rights. Exportable as a PDF and therefore ideal as an annex to the contract.
Data processing agreement (DPA)
Configurable and ready to sign
The DPA under Art. 28 GDPR between you as controller and DeepMask GmbH as processor. In the configurator you enter your details, select data categories and subprocessors, and export the finished agreement including the TOM annex as a PDF.
Technical and organisational measures
Annex to the DPA under Art. 32 GDPR
Full description of the technical and organisational measures — from physical access control in the STACKIT data centres through encryption and tenant separation to the AI-specific measures such as the contractual exclusion of model training.
List of subprocessors
All engaged service providers under Art. 28(4) GDPR
Complete, always current list of all subprocessors with their location, purpose, certifications and safeguards for third-country transfers — including hosting partner STACKIT and every model provider.
EU AI Act — compliance
Roles and obligations under Regulation (EU) 2024/1689
How DeepMask fits into the AI Act: who is the provider, who is the deployer, which transparency obligations apply to whom — and how DeepMask supports you in meeting your obligations as a deployer.
Professional secrecy
Confidentiality undertaking under Section 203 StGB
For law firms, patent attorneys, tax advisors and others bound by professional secrecy: the legal basis for participating in professional secrets, plus the confidentiality undertaking and instruction that can be attached to the DPA.
Terms of use
Contractual basis for using the platform
The terms of use govern scope of services, availability, support, remuneration and liability when using the DeepMask platform.
Fair usage policy
Fair use of the AI allowances
The fair usage policy describes how the unlimited AI requests in the Pro plan behave in practice and which limits apply to protect all users.
ISO/IEC 27001
Information security management system
The ISMS to ISO/IEC 27001 is being established; certification is in progress. Until it is completed we evidence the security of the platform through the certifications of our infrastructure partners — STACKIT is certified to ISO 27001 and BSI C5.