GENERATED
FunktionenAutomatisiertes BloggenPreiseÜber unsBlog
AnmeldenLoslegen
GENERATED
FunktionenAutomatisiertes BloggenPreiseÜber unsBlog
AnmeldenLoslegen

Auftragsverarbeitungsvertrag

Zuletzt aktualisiert: 18. August 2026

Entwurf — juristische Prüfung ausstehend. Dieses Dokument beschreibt, wie der Dienst heute funktioniert, und wird zur Prüfung veröffentlicht. Es ist noch nicht anwaltlich freigegeben und kann sich vor der allgemeinen Verfügbarkeit ändern.

Der vollständige Rechtstext steht unten auf Englisch; bei Abweichungen ist die englische Fassung maßgeblich.

This agreement covers the personal data that AppMaster Inc ("Generated", "Processor") processes on behalf of a customer ("Controller") when it generates content for the customer's projects and hosts a blog on the customer's own domain. It supplements the Terms of Service and takes precedence over them for matters of data protection. To execute it for your organisation, write to [email protected] with your legal entity name, address and signatory.

1. Roles

The Controller determines the purposes and means of the processing described in Annex I. The Processor processes that personal data only on the Controller's behalf. Where the Processor determines its own purposes — its account, billing and security records — it acts as a controller, and its privacy policy applies to that processing instead.

2. Instructions

The Processor processes personal data only on the Controller's documented instructions, which are these: to run the generation pipeline for the Controller's projects, to build and serve the resulting pages on the Controller's domain, and to provide support. Using the service and its settings constitutes an instruction. The Processor will tell the Controller if, in its opinion, an instruction infringes applicable data protection law, and may suspend the affected processing until it is resolved. Where law requires processing beyond these instructions, the Processor will inform the Controller before processing unless that law forbids it.

3. Confidentiality

Personnel authorised to process the personal data are bound by confidentiality obligations and receive access only to what their role requires.

4. Security

The Processor implements the technical and organisational measures set out in Annex II, and will not materially reduce them during the term.

5. Subprocessors

The Controller gives general authorisation for the subprocessors listed in Annex III. The Processor remains liable for their performance and imposes data protection obligations on them equivalent to those in this agreement. The Processor will give at least 30 days' notice before adding or replacing a subprocessor; the Controller may object on reasonable data protection grounds, and if the objection cannot be resolved, may terminate the affected service without penalty for the remainder of the paid period.

6. Data subject requests

Taking into account the nature of the processing, the Processor assists the Controller with requests from data subjects exercising their rights. Requests received directly by the Processor are forwarded to the Controller without undue delay and are not answered by the Processor on its own initiative.

7. Personal data breaches

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provides the information the Controller reasonably needs to meet its own notification obligations.

8. Assistance

The Processor assists the Controller, at the Controller's cost where the effort is substantial, with data protection impact assessments and prior consultations relating to the processing described in Annex I.

9. Deletion and return

Content stays in the Controller's account for as long as the account exists, including after a subscription lapses. On written request, or on account closure, the Processor deletes the personal data it processes on the Controller's behalf, except where law requires it to be retained. The Controller can export its content through the platform's content API while the account is active.

10. Audits

The Processor makes available the information needed to demonstrate compliance with this agreement and allows for audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable notice, no more than once a year unless a breach or a supervisory authority requires otherwise, and subject to confidentiality.

11. International transfers

Where the processing involves a transfer of personal data out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the parties rely on the applicable standard contractual clauses, which are incorporated by reference and completed by the annexes below.

12. Analytics the Controller adds

If the Controller configures a Google Analytics measurement ID for a project, the Processor injects that tag into the Controller's hosted pages as an instruction under section 2. The resulting processing by Google is between the Controller and Google: the Controller is responsible for its legal basis, for its cookie and consent notices on its own domain, and for its own agreement with Google. Google is not a subprocessor of the Processor for this purpose. Without a measurement ID, hosted pages carry no analytics from the Processor.

Annex I — Details of the processing

  • Subject matter: generation of content for the Controller's projects and publication of that content on a domain the Controller owns.
  • Duration: for the term of the subscription and until deletion under section 9.
  • Nature and purpose: storage, generation, translation, image production, static site building, delivery through a content delivery network, and support.
  • Types of personal data: identifiers and contact details of the Controller's users; any personal data the Controller includes in project settings, topics or published content; technical data of visitors to the hosted blog such as IP address and user agent, processed for delivery and security.
  • Categories of data subjects: the Controller's personnel and users; the Controller's website and blog visitors; any individuals mentioned in content the Controller supplies or publishes.
  • Special categories: none are requested, and the service is not designed for them. The Controller should not submit them.

Annex II — Technical and organisational measures

  • Encryption of traffic in transit, including TLS on every customer domain served.
  • Authentication with hashed credentials and session tokens; access to production systems restricted to authorised personnel.
  • Tenant separation: each customer's content is served on that customer's own domain, from its own build output.
  • Server-side sanitisation of generated HTML before storage, to keep injected markup out of published pages.
  • Logging and monitoring of platform errors and delivery failures, with limited retention.
  • Backups of the platform database and of built sites, held off the serving host, with a documented restore path.
  • Change management through version control, code review and automated tests before deployment.

Annex III — Approved subprocessors

  • Stripe — payment and subscription processing.
  • Cloudflare — TLS certificates for customer domains, content delivery and edge protection.
  • AI model providers — generation of text, translations and images from the Controller's topics and content.
  • Sentry — error monitoring of the Processor's applications.
  • LeadPending — delivery of contact-form submissions made on generated.app.
Generated

AI-powered content generation platform for modern businesses. Create engaging blogs, stunning images, and more in minutes.

Produkt

FunktionenAutomatisiertes BloggenPreiseBlog

Ressourcen

Über unsKontaktieren Sie unsSupport

Rechtliches

DatenschutzrichtlinieNutzungsbedingungenAuftragsverarbeitungsvertrag

© 2026 Generated. Alle Rechte vorbehalten.