GDPR art. 28 · catknows hosted
Auftragsverarbeitungsvertrag nach Art. 28 DSGVO
Between
you, the customer ("controller") — the person or organisation holding a catknows account
and
Niklas Schröer Am Pickerweg 32 49401 Damme Germany nklsschroeer@gmail.com
("processor", "I", "me").
Version 1.0, 2026-08-11. This agreement supplements the privacy policy and takes effect when you first store a Skool session on the hosted service. It governs only the data described in §2 — for your own account data (your email address, your password) I am the controller, not your processor, and the privacy policy applies instead.
When you use catknows against your Skool community, the service reads personal data about other people — your members' names, handles, activity, sometimes their email addresses. You decide that this happens and for what purpose, so under the GDPR you are the controller for that data. I only process it because you instructed me to, which makes me your processor and this contract mandatory (art. 28(3)).
If you never store a Skool session, no such processing occurs and this agreement stays dormant.
| Subject matter | Retrieving data from Skool on your behalf via Skool's own endpoints, and returning it to the AI client you connected |
| Purpose | Solely to execute the tool calls you (or your AI assistant acting for you) make. No other use. |
| Categories of data | Names, Skool handles, profile data, membership and activity data, points/levels, posts, comments, chat messages, calendar and course data, and — where Skool exposes it to your account — member email addresses |
| Categories of data subjects | Members, admins and moderators of the Skool communities you access; authors of posts and comments visible to your account |
| Duration | For as long as you keep a Skool session stored. It ends when you delete that session or your account. |
| Nature of processing | Retrieval, transient caching, format conversion, transmission to your AI client. No storage of member data (§3). |
Special categories (art. 9) are not intentionally processed. Skool profiles are free text, so a member may of course write something revealing about themselves in a bio or a post; that content passes through unread and unclassified. Do not use this service to deliberately compile art. 9 data.
This is the core technical fact of this agreement:
Authorization and Cookie headers are stripped before writing.Consequence worth being explicit about: because nothing is retained, I usually cannot help you answer a data subject's access or erasure request from my systems — there is nothing there to search. The data lives in Skool, and that is where such requests have to be served. What I can do is delete your stored session, which stops all further processing immediately.
I will:
Current state, honestly described:
Honest limitations, so you can judge the risk yourself:
| Sub-processor | Role | Location |
|---|---|---|
| netcup GmbH | Hosting (the VPS) | Nuremberg, Germany |
| Scaleway SAS | Transactional email (account verification, password reset) | France |
You give general authorisation for these (art. 28(2)). Both are bound by their own art. 28 agreements. Neither receives member data: netcup hosts the machine on which nothing member-related is persisted, and Scaleway only ever sees your email address, for messages to you.
I will inform you at least 30 days before adding or replacing a sub-processor, where I have that much notice myself — both of mine grant me the same 30 days, and I pass it on. You may object on reasonable data protection grounds; if the change is unavoidable and you object, you may terminate and delete your session.
Both sub-processors are established in the EU and host the data concerned there. Where either of them engages further sub-processors of its own, its own art. 28 agreement governs that, including the standard contractual clauses required for any transfer outside the EEA.
Read this twice, because it is the part people get wrong.
Whatever a tool returns goes straight into your conversation with your AI provider (Anthropic, or whichever client you connected). That transfer is initiated by you, to a party you chose, under your own agreement with them. They are not my sub-processor and I have no contract with them about your data.
For that leg you are responsible for having a lawful basis and, where needed, your own processing agreement with that provider. If you route member data into a chat interface, that data is in your provider's conversation logs — I cannot retract it. Pull what you need, not everything you can.
Ask, and I will provide the information needed to demonstrate compliance — answers about the setup, this document, the privacy policy, and the relevant source code, which is public and can be read rather than taken on trust.
For an on-site or third-party audit: I will cooperate reasonably, with notice, during working hours, without disrupting operations, and against confidentiality undertakings. Given the size of this operation, my own documentation plus the public source code will usually get you further than an inspection would.
forget_skool_session) or your account.If your compliance process needs a signed instrument rather than a published document, write to the address above and I will send this text as a PDF, signed. State the controller's legal name and address; it will be filled in on the counterparty side.