§ 01
Why this page exists
Working with law firms, tax practices and medical practices means touching data covered by professional secrecy. Under German law (sec. 203 (3) sentence 2 StGB, as amended in 2017), professionals may involve external service providers, but must commit them to secrecy in text form beforehand and select them carefully. So the paperwork is ready here: you request it, we return it signature-ready, before any access is set up.
§ 02
Confidentiality commitment (sec. 203 StGB)
Our commitment covers, bindingly:
- Secrecy about every third-party secret learned during the work, explicitly beyond the end of the engagement and without time limit.
- Acknowledged awareness that unauthorised disclosure is a criminal offence under sec. 203 StGB.
- Passing information to our own staff or subcontractors only after an equivalent written commitment, and only to the extent required.
- Access limited to the data the agreed process actually needs; no access to case or patient files where the process does not touch them.
- Return or verified deletion of all data and access at the end of the engagement.
§ 03
Data processing agreement (Art. 28 GDPR)
Where we process personal data on your behalf, a data processing agreement is signed before we start: subject, duration, nature and purpose, categories of data subjects, instruction-bound processing, support with data-subject rights, breach notification, audit rights, deletion and return. Sub-processors are named; new ones are announced in advance with a right to object. On request we sign your template instead of ours, which is the norm with law firms and no obstacle for us.
§ 04
Technical and organisational measures
Measures are adapted to the specific process and annexed to the contract. Baseline:
- Personal accounts, multi-factor authentication where the system supports it, no shared logins.
- Least-privilege access, limited to the systems and periods the process requires.
- Encrypted transmission and storage; servers in the European Union where the process runs on our own systems.
- Separated client environments; no mixing of data from different clients.
- Logging of security-relevant events, so access is traceable if ever questioned.
- No use of client data to train models; the services used are named and contractually bound.
- Orderly termination: deletion or return after the engagement, with written confirmation on request.
§ 05
Retention and German GoBD
Where our processes touch tax-relevant documents, retention happens in the electronic original format, unalterable and machine-readable, including the structured data of an e-invoice. Process documentation is part of the operation and is supplied for the part we build, so it exists when it is needed rather than being reconstructed afterwards.
§ 06
Roles and liability
Where a firm recommends us, the client contracts with us directly. The firm is not a party to the implementation, receives no compensation for a recommendation and is not liable for our work. Professional responsibility stays entirely with the firm; we build and operate the technical route only.
§ 07
How to request the documents
An informal message with one sentence about the planned process is enough. You receive the confidentiality commitment and the data processing agreement as signature-ready documents, usually the same or next business day, without any obligation.