between the Customer (“Controller”) and NeoRebels GmbH (“Processor”), Dreiherrnsteinplatz 11, 63263 Neu-Isenburg, Germany, represented by its Managing Director Ufuk Ören, Amtsgericht Offenbach am Main HRB 56637.
Concluded under Article 28(3) GDPR and forming part of the Terms and Conditions. Where the two conflict, this agreement prevails for the processing of personal data.
1. Subject matter, duration, nature and purpose
The Processor operates Sqemes Cloud, an AI management platform on which the Controller stores reusable templates — prompts, assistants and skills — with the context files they draw on, and distributes them to the surfaces its team uses.
The Processor processes personal data only to provide that service and only on the Controller’s documented instructions. This agreement runs for as long as the subscription; the obligations on confidentiality and deletion survive its end.
2. Types of personal data and categories of data subjects
Data subjects: the Controller’s employees and others it grants access to its workspace, and any person whose personal data the Controller chooses to put into the workspace.
Types of data: account data (name, email, password hash, role, membership, last sign-in) · content the Controller provides (templates, context files, brand settings, tags, listings) · chat data (messages, responses, the model used) · usage data (AI credits, counted in tokens not content) · technical data (error reports with stack traces and browser context).
The second category is open-ended, and we would rather say so than hide it in a table. A context file can contain anything the Controller uploads — a contract, a client list, a personnel record. The Controller decides what goes in; the Processor neither inspects nor restricts it. That is precisely why the Controller remains the controller.
3. Instructions
The Processor processes personal data only on the Controller’s documented instructions, given by the Terms, this agreement, and the Controller’s use of the product. Instructions may also be given in text form.
The Processor shall inform the Controller if, in its opinion, an instruction infringes data protection law, and may suspend that instruction until the Controller confirms it.
4. Confidentiality
Everyone authorised by the Processor to process personal data is bound to confidentiality, contractually or by statute, and that obligation survives the end of their engagement.
5. Security of processing (Article 32)
Encryption in transit throughout, and encryption at rest for provider API keys · passwords stored only as hashes · access control enforced in the database by row-level security tied to workspace membership, not by application code alone · a content security policy preventing foreign scripts · separated environments, so testing does not run against production data · error monitoring configured to errors only — no session recording, no performance tracing, retained 30 days in the EU.
6. Sub-processors
The Controller grants general authorisation for the engagement of sub-processors. The Processor maintains the current list at [URL der Subprozessoren-Seite] and binds each by contract to data protection obligations no less protective than those in this agreement.
The Processor informs the Controller at least 30 days before adding or replacing a sub-processor, giving the Controller the opportunity to object. If the Controller objects on reasonable data protection grounds and the parties cannot agree, the Controller may terminate the affected subscription without notice.
| Sub-processor | Purpose | Location | Transfer basis | |
|---|---|---|---|---|
| Supabase | database, authentication, file storage, backend functions | European Union (Frankfurt) | — | |
| Vercel | delivery of the application | global CDN; the application is static and stores no personal data there. IP addresses in access logs | SCCs | |
| Stripe Payments Europe Ltd., Ireland | payment and subscription processing | European Union | — | |
| Mistral AI, Paris, France | the model behind Sqemes-funded AI credits | European Union | — | |
| Sentry | error monitoring | European Union | — | |
| Plus Five Five, Inc. (“Resend”), USA | transactional email | United States | EU SCCs, Module Two, plus the UK addendum |
Stripe — dual capacity. For processing a payment on the Controller’s behalf, Stripe is a sub-processor and bound accordingly. For fraud prevention, anti-money-laundering checks and its own regulatory obligations, Stripe acts as an independent controller; that processing is not on the Processor’s instructions and is outside the scope of this agreement.
Third-party AI providers the Controller connects with its own key are not sub-processors, nor are connectors the Controller links. Those go to that provider under the Controller’s own contract.
7. Assistance to the Controller
The Processor assists the Controller, taking into account the nature of processing and the information available to it:
- With data subject requests (Articles 12–23). Where a request reaches the Processor directly it is forwarded to the Controller without undue delay and not answered by the Processor. The product covers the two most frequent cases without us: the Controller can export its data and delete its account from within the application, including after the subscription has lapsed.
- With the obligations under Articles 32 to 36 — security, breach notification, impact assessments.
- On a personal data breach, the Processor notifies the Controller without undue delay after becoming aware, with the information available, so the Controller can meet its own 72-hour obligation.
8. Deletion and return
On termination the Processor deletes the Controller’s personal data or returns it, at the Controller’s choice, unless law requires further storage.
In practice: 30 days of export access after the term ends, a further 60 days of retention, deletion after 90 days. Billing records are retained for up to ten years under § 147 AO and § 257 HGB and are exempt for that period.
9. Audits
The Processor makes available the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, by the Controller or an auditor it mandates.
In practice, and honestly: the Processor is a small company. Audits are satisfied primarily by documentation and written answers; an on-site inspection requires reasonable notice, must not disrupt operations and is at the Controller’s expense.
10. International transfers
Where a sub-processor processes personal data outside the EU/EEA the Processor ensures an adequate basis under Chapter V GDPR. Today this concerns one provider — transactional email through Resend in the United States, covered by the Standard Contractual Clauses. The current position for each sub-processor is stated in Section 6.
11. Liability and governing law
Liability follows the Terms and Conditions. German law applies.
