Data Processing Agreement
This is a courtesy translation. The agreement is concluded in German; in case of doubt the German version is authoritative.
Download annexes 1 to 3 as a PDF
This page describes the agreement for using the Claritava platform. It does not cover your visit to this website — our privacy policy applies to that.
Contracting parties
between
– hereinafter the “controller” –
and
Kibo AI GmbHLaufertorgraben 2
90489 Nürnberg, Germany
– hereinafter the “processor” –
and jointly referred to as the “parties” – the following is agreed.
Annex 1 – Commissioned services and contact details
Subject of the processing
Provision, operation and maintenance (servicing, updates, technical support) of the web-based SaaS platform Claritava for implementing the EU Pay Transparency Directive (2023/970) and the German Pay Transparency Act. The customer uses the platform to carry out pay equity analyses, job evaluations using the Hay method and to meet its statutory and internal reporting obligations.
Nature and purpose of the processing
Nature of the processing:
- Collection through transfer or upload of data records (in particular pay and employee data) by the customer into the processor's platform
- Storage, organisation, structuring and consolidation of the data records within the platform
- Evaluation and analysis of the data against the requirements of the Pay Transparency Directive and, where applicable, further criteria specified by the customer (comparison of pay groups, departments, genders, hierarchy levels)
- Creation of evaluations, reports, dashboards and metrics (statistics, aggregations, comparative analyses)
- Anonymisation pursuant to § 5 of this agreement
- Access by the processor's staff exclusively where required to deliver the contractually owed services (support, error analysis, maintenance)
Purpose of the processing:
- Reviewing and ensuring compliance with EU Pay Transparency Directive 2023/970
- Carrying out internal pay equity and pay structure analyses at the customer
- Producing evidence and documentation for supervisory authorities or internal bodies (works council)
- Using the platform features for the sustained management and control of pay structures
Types of personal data
To the extent transferred into the platform by the customer:
- Master data: first name, last name, personnel number or internal identifiers, where applicable year of birth, gender
- Employment data: job title, function, department, organisational unit, start date, working time (full-time/part-time), hierarchy level (L1–L8, EX-1), location
- Pay data: base salary, variable pay components (bonuses, commissions), allowances, benefits in kind, shares/equity, benefits, historical pay data
- Contract and organisational data: type of employment relationship, full-time or part-time status, where applicable information on absences
As a rule the customer is not to transfer special categories of personal data within the meaning of Art. 9 GDPR.
Categories of data subjects
- Active employees of the customer
- Where applicable former employees (retrospective analyses)
- Where applicable interns, working students, apprentices, temporary agency workers
Duration of the processing
For the term of the main contract between the parties (Claritava SaaS agreement). After the contract ends: deletion or return pursuant to § 10 of this agreement within 30 days.
Data protection officers
- Controller (customer side)
- The controller has not appointed a data protection officer.
- Processor (Kibo AI GmbH)
- The processor has not appointed a data protection officer. Contact for data protection matters: datenschutz@kibo-ai.com
Annex 2 – Sub-processors
| Sub-processor | Address | Processing location | Description of processing |
|---|---|---|---|
| Google Cloud EMEA Limited | 70 Sir John Rogerson’s Quay, Dublin 2, Ireland | Google Cloud region europe-west3, Frankfurt am Main, Germany | Cloud hosting (Cloud Run), database operation (Cloud SQL PostgreSQL), storage of all customer data, automatic encrypted backups |
| Anthropic, LLC | 548 Market St, PMB 90375, San Francisco, CA 94104, USA | USA (processing on Anthropic servers) | AI-assisted generation of job descriptions and compliance recommendations. Only non-personal data is transmitted (job title, level, department name), no employee or pay data. Legal basis: Art. 46 GDPR (standard contractual clauses / DPA with Anthropic) |
| HR4You AG (planned, once the integration is activated) | Stadttor 1, 40219 Düsseldorf, Germany | Germany | HR data sync: transfer of employee master and pay data for automatic reconciliation. Certified to ISO/IEC 27001 and 27701. The three-week prior notice under § 7 is given separately. |
Note on Anthropic / third country: Kibo AI GmbH enables the “Zero Data Retention” (ZDR) option at Anthropic so that no transmitted data is used for training purposes. The conclusion of standard contractual clauses (SCCs) with Anthropic is documented.
Annex 3 – Technical and organisational measures
A. Physical access control – server rooms
- A1.0: Yes – personal data is stored on servers.
- A1.1 Server location: Google Cloud Platform, region europe-west3, data centre location Frankfurt am Main, Germany.
- A1.2 Multiple locations: Yes – automatic backups also in region europe-west3 (geo-redundant within Frankfurt).
- A1.4 Consistent measures: Yes – all locations on Google Cloud infrastructure with consistent security measures.
Physical access control: Handled entirely by Google Cloud (ISO 27001 certified, SOC 2 Type II). Google data centres are secured with biometric access control, continuous video surveillance, multi-factor authentication and security staff.
B. System access control (IT systems)
| Measure | Implementation |
|---|---|
| Authentication | JWT tokens (RS256), OAuth 2.0 (Google login), 24-hour session timeout |
| Password policy | Passwords are stored hashed with bcrypt (cost factor 12); implementation by go-live |
| Multi-factor authentication | Via Google OAuth where the customer uses Google login; native MFA planned |
| Administrator access | Only two people (development team) have direct database access |
| Remote access | Exclusively over an encrypted connection (GCP IAP / VPN) |
C. Data access control (permissions)
| Role | Data access | Scope |
|---|---|---|
| ADMIN (customer side) | All data of its own tenant | Read, write, configure |
| HR | All employee data of the tenant | Read and write |
| MANAGER | Own department | Read and limited write (merit proposals) |
| USER | Own personnel data | Read only |
| Kibo AI support | Only with documented customer permission, logged | Technical support |
Tenant separation: Strict TenantId filtering at database level on every query. Cross-tenant data access is technically impossible.
D. Transfer control and transmission security
| Measure | Implementation |
|---|---|
| Encryption in transit | HTTPS / TLS 1.2+ (enforced via Cloud Run, HSTS) |
| Encryption at rest | AES-256 (Google Cloud SQL managed encryption) |
| API file export | CSV export exclusively via authenticated API endpoints |
| Third-country transfers | Only the Anthropic API (USA) – non-personal data only, SCCs in place |
E. Availability control
| Measure | Implementation |
|---|---|
| Uptime SLA | Google Cloud Run: 99.9 % |
| Autoscaling | Cloud Run, automatic scaling |
| Database backups | Automatic daily backups (Cloud SQL, 7-day retention) |
| Recovery objectives | RTO under 4 hours, RPO under 24 hours |
| Monitoring | GCP Cloud Monitoring and alerting |
F. Separation control
- Strict logical tenant separation at database level (TenantId on every table)
- Production, test and development environments are separated
- Anonymised benchmark data is stored in a separate table (no join with personnel data)
G. Processing control
- All staff with data access are bound to confidentiality
- Sub-processors are documented in Annex 2
- Data breaches are reported internally without delay, at the latest within 24 hours; forwarding to the controller takes place within 48 hours
Download annexes 1 to 3 as a PDF
Last updated: August 2026 · Kibo AI GmbH, Nuremberg