Skip to content
Confidentiality · Sec. 203 StGB · Art. 28 GDPR · As of 2026-07

Confidentiality, before the first access.

What we commit to when we work for firms and practices bound by professional secrecy, and how to get the paperwork before anything technical starts.

§ 01

Why this page exists

Working with law firms, tax practices and medical practices means touching data covered by professional secrecy. Under German law (sec. 203 (3) sentence 2 StGB, as amended in 2017), professionals may involve external service providers, but must commit them to secrecy in text form beforehand and select them carefully. So the paperwork is ready here: you request it, we return it signature-ready, before any access is set up.

§ 02

Confidentiality commitment (sec. 203 StGB)

Our commitment covers, bindingly:

  • Secrecy about every third-party secret learned during the work, explicitly beyond the end of the engagement and without time limit.
  • Acknowledged awareness that unauthorised disclosure is a criminal offence under sec. 203 StGB.
  • Passing information to our own staff or subcontractors only after an equivalent written commitment, and only to the extent required.
  • Access limited to the data the agreed process actually needs; no access to case or patient files where the process does not touch them.
  • Return or verified deletion of all data and access at the end of the engagement.
§ 03

Data processing agreement (Art. 28 GDPR)

Where we process personal data on your behalf, a data processing agreement is signed before we start: subject, duration, nature and purpose, categories of data subjects, instruction-bound processing, support with data-subject rights, breach notification, audit rights, deletion and return. Sub-processors are named; new ones are announced in advance with a right to object. On request we sign your template instead of ours, which is the norm with law firms and no obstacle for us.

§ 04

Technical and organisational measures

Measures are adapted to the specific process and annexed to the contract. Baseline:

  • Personal accounts, multi-factor authentication where the system supports it, no shared logins.
  • Least-privilege access, limited to the systems and periods the process requires.
  • Encrypted transmission and storage; servers in the European Union where the process runs on our own systems.
  • Separated client environments; no mixing of data from different clients.
  • Logging of security-relevant events, so access is traceable if ever questioned.
  • No use of client data to train models; the services used are named and contractually bound.
  • Orderly termination: deletion or return after the engagement, with written confirmation on request.
§ 05

Retention and German GoBD

Where our processes touch tax-relevant documents, retention happens in the electronic original format, unalterable and machine-readable, including the structured data of an e-invoice. Process documentation is part of the operation and is supplied for the part we build, so it exists when it is needed rather than being reconstructed afterwards.

§ 06

Roles and liability

Where a firm recommends us, the client contracts with us directly. The firm is not a party to the implementation, receives no compensation for a recommendation and is not liable for our work. Professional responsibility stays entirely with the firm; we build and operate the technical route only.

§ 07

How to request the documents

An informal message with one sentence about the planned process is enough. You receive the confidentiality commitment and the data processing agreement as signature-ready documents, usually the same or next business day, without any obligation.

Request the documentsPrivacy notice