D&D Audit

⚠ DRAFT — not a legally binding, reviewed document

This is a discussion and negotiation draft, not a document finally reviewed by a lawyer or data protection officer. It was prepared based on publicly known requirements of GDPR Art. 28, but it does not replace individual legal advice. Please have this draft reviewed by your data protection officer (DPO) or a law firm specialising in data protection law before signing — in particular with regard to your specific processing situation, categories of data subjects, and any sector-specific requirements.

Privacy

Data Processing Agreement (DPA) — Draft

§1 Subject matter and scope

This Data Processing Agreement (DPA) governs, under GDPR Art. 28, the processing of personal data carried out by UAB NVGroup ("Processor") on behalf of the customer ("Controller") in connection with the use of the D&D Audit (demurrit.eu) and/or Cargo Intelligence (cargo.demurrit.eu) services. The subject matter of processing is, in particular, data from uploaded freight documents (CMR, SMGS/CIM consignment notes, fuel receipts, B/L, D&D invoices) and contact data of the persons designated by the customer.

§2 Location of data processing

The primary processing and storage of application data (uploaded documents, extracted data, customer accounts) takes place exclusively on a server in the Federal Republic of Germany (Nuremberg data centre, operated by netcup GmbH — see the subprocessor register below).

Important note for completeness: Three limited side processes leave this server:

(1) Transactional email delivery (e.g. invoice PDFs) and automated backup run via Proton AG infrastructure, registered in Switzerland. Switzerland has a European Commission adequacy decision under GDPR Art. 45 — transfers there are treated as equivalent to the EU/EEA and do not require additional standard contractual clauses (SCC).

(2) For automated extraction of data from uploaded documents (AI-based text recognition), the document content is transmitted to Anthropic PBC, registered in the USA. The USA does not have a general adequacy decision; the transfer is based on the EU Standard Contractual Clauses (GDPR Art. 46), which form part of Anthropic's data processing terms. According to Anthropic's own statement, it does not use the transmitted content to train its AI models. See §3 for details.

§3 Subprocessor register (approved subprocessors)

Subprocessor Location Purpose
netcup GmbH Registered: Karlsruhe, DE
Data centre: Nuremberg, DE
Server hosting, infrastructure (application + database)
Proton AG Geneva, Switzerland
(GDPR Art. 45 adequacy decision)
Delivery of transactional emails; encrypted backup storage
Anthropic PBC San Francisco, USA
(GDPR Art. 46 standard contractual clauses)
AI-based data extraction from uploaded documents

The Processor undertakes to inform the Controller of any intended change concerning the engagement or replacement of further subprocessors, so that the Controller has the opportunity to object to such changes.

§4 Technical and organisational measures (TOMs)

The following measures are actually implemented at the time this document was prepared (2026-09-01). This is an honest, verified list — not a marketing checklist:

Transparent note on limitations: Encryption of the database at rest (e.g. full block-level disk encryption) is currently not separately verified and should be clarified with the provider before signing the contract, or as part of technical due diligence. Likewise, no separate network firewall/intrusion detection system is currently active at the operating system level (access protection currently relies on SSH key authentication and the application layer). We state this deliberately rather than omit it — a data protection officer will ask exactly this.

§5 Retention period and deletion

Original document files (invoices, consignment notes, receipts) are automatically and irrevocably deleted from the disk 12 months after upload (hard delete). The structured data extracted from them (e.g. amounts, dates, parties) remains in the database for as long as the contract with the customer is active, as it forms the basis for reports and evidence. Invoices and claim letters issued by Demurrit itself are subject to different, legally prescribed retention periods (commercial/tax law) and are not automatically deleted.

§6 Contact

For questions about this draft, agreeing an individual DPA, or questions from your data protection officer: info@demurrit.eu. UAB NVGroup, Lithuania.

⚠ Reminder

This draft does not replace legal advice. Before signing, please have it reviewed by your data protection officer or lawyer — in particular §3 (subprocessors) and §4 (TOMs), as this information must exactly match your actual technical situation.