Skip to main content
SIXSENTENCES_

VERSION 1.11 · EFFECTIVE: SEPTEMBER 12, 2026

Data Processing Agreement

This Data Processing Agreement (DPA) pursuant to Art. 28 GDPR forms part of the agreement between the customer and Lukas Buck whenever a SixSentences_ workspace is used to process personal data on the customer's behalf. A countersigned PDF copy is available on request at hello@sixsentences.com.

1. Parties and roles

Processor: Lukas Buck, Dorfstraße 11, 72660 Beuren, Germany (SixSentences_). Controller: the person or organisation that determines the purposes and essential means of the processing, identified by the customer when concluding this DPA. This may be an institution represented by the workspace owner, not necessarily that owner personally. The person concluding this DPA must be authorised to act for that controller. If the customer is itself a processor, it must have the controller's authorisation to appoint SixSentences_ as a sub-processor and communicate the applicable instructions; the customer's controller-facing duties and the required downstream terms remain unaffected. SixSentences_' own controller processing for accounts, billing, the website, the waitlist and service-usage metadata is described in the Privacy Policy and is outside this DPA. SixSentences_ also determines the purposes and essential means of the separate public-source discovery service described in the Privacy Policy. That limited operation is outside this DPA. Subsequent processing of those sources within customer-directed workspace workflows remains governed by this DPA where it involves personal data processed on the customer's behalf.

2. Subject matter, duration, nature and purpose

The processing covers hosting and storage of customer content, text extraction from documents and photos, transcription and analysis of interview audio, streaming of live-interview audio from a participant browser through a transient SixSentences_ server relay to Google Gemini Live, server-controlled continuation of the same active interview across connection rotations, storage of provider-generated transcripts and aggregate usage measurements, surveys and responses, customer-directed AI analysis, screening, writing and figure generation, excluding the separate public-source discovery operation described in section 1, Browser Capture, the Companion and exports. Processing is solely for providing those features. This DPA runs while the account exists and ends with deletion, subject to section 9.

3. Data and data subjects

Data can include uploaded documents, source photos, research files, interview audio and transcripts, provider-generated transcript fragments with speaker roles and session-relative timestamps, technical connection data and aggregate usage measurements for a live interview, survey responses and optional participant labels, reviewer comments, and names or contact details contained in those materials. Data subjects can include interview participants, survey respondents, persons mentioned in source material, authors, reviewers, collaborators and others whose data appears in customer content. The customer determines the concrete content and legal basis. AI processing of private workspace content uses the direct Gemini Paid API, not OpenRouter. Processing special categories under Art. 9 GDPR, criminal-conviction or offence data under Art. 10 GDPR, or confidential third-party information requires the applicable legal basis, authority, suitable safeguards and an appropriate feature configuration. Selecting a model does not establish these requirements. The separate OpenRouter/Perplexity public-source route receives only the search-input scope explicitly confirmed for the current request as public, non-personal, non-confidential and non-sensitive, never those private research materials. Public source results and metadata can nevertheless contain ordinary personal data such as author names. Their collection is SixSentences_' separate controller processing and is outside this DPA. Section 7 explains the boundary, the limited derivation of search variants and single-query approval.

4. Documented instructions

SixSentences_ processes workspace content only on documented instructions: this DPA, the customer's use and configuration of the Service, and the feature and model selected for an AI request. Private workspace AI requests go directly to Gemini Paid Services. The available text-model choices are limited to the approved Gemini catalog; an unavailable route does not fall back to OpenRouter. A request to use the separate public-source discovery service does not authorise disclosure of private workspace content or customer-controlled personal data to OpenRouter. It does not change the processor role applicable to subsequent customer-directed workspace processing. The discovery route is pinned exclusively to the Perplexity Sonar route identified in section 7. Additional instructions can be sent in text form to hello@sixsentences.com. SixSentences_ will inform the customer without undue delay if an instruction appears unlawful and may suspend it pending clarification. Workspace content is not used for SixSentences_' own purposes or to train models.

5. Confidentiality

Only persons bound to confidentiality may process workspace content. Any future employee or contractor will be bound in writing before access. SixSentences_ accesses content only where technically unavoidable for operation, legally required, or explicitly requested by the customer, for example for support.

6. Security of processing

Measures under Art. 32 GDPR include: hosting in German Hetzner data centres under an Art. 28 agreement; TLS in transit; salted PBKDF2 password hashes and SHA-256 API-token hashes; application-layer workspace isolation; interactive authentication for administration and least-privilege production access; locally encrypted disaster-recovery backups in a private Backblaze B2 EU Central bucket in Amsterdam with up to 14 daily, 8 weekly and 12 monthly snapshots; a documented human governance review of the applicable Backblaze account status, contractual role chain, transfer terms, externally separated recovery-key custody and a restore test using that external copy; size-based container-log rotation (at most five 10 MiB files per container) and system-journal retention of at most 30 days, subject to the configured size limits; and self-service export and deletion. Size-based rotation alone does not provide a fixed time-based deletion deadline. Client-side encryption limits provider exposure but does not itself determine legal roles or replace an applicable Art. 28(4) arrangement or transfer safeguard. Measures may evolve without reducing the agreed protection level.

7. Sub-processors

The customer gives general written authorization for:

  • Hetzner Online GmbH, Germany, for hosting and stored content.
  • IONOS SE, Germany, for transactional-email transport.
  • Backblaze, Inc., USA, for client-side encrypted disaster-recovery backups in EU Central (Amsterdam). Backblaze's published standard DPA describes a processor role for organisation customers and a different role arrangement for individual customers. It does not expressly resolve every role in an individual sole-proprietor account used in a customer processor chain. SixSentences_ therefore does not present the encryption, DPA, SCCs or stated EU-US DPF participation as resolving that classification by themselves. The route is subject to the documented human governance review described in section 6, including an explicit residual-risk decision. Where Art. 28(4) applies, SixSentences_ remains responsible for ensuring the required downstream terms; the customer's statutory rights remain unaffected.
  • Google Cloud EMEA Limited, Ireland, with Google affiliates, including Google LLC, USA, and authorised processors, for direct paid Gemini text reasoning, document and manuscript assistance, data, survey and interview analysis, figure generation, transcription, photo and live-voice processing. The applicable Business Data Processing Addendum covers the customer acting as controller or as an authorised processor appointing another processor; selecting Paid Services does not remove the customer's own legal duties. The private-workspace route is not offered as Zero Data Retention. In an AI-led live interview, the participant browser streams audio through the SixSentences_ server relay to the Gemini Live API. The relay buffers audio transiently in memory for transmission; it does not create a raw-audio archive. Any separately selected recording retention remains governed by the customer's workspace settings. Provider-generated transcript fragments are stored with speaker roles and session-relative timestamps. Aggregate usage measurements, such as token-cost estimates, audio duration and turn counts, support capacity accounting and service security without retaining audio in those measurements. Provider transcripts are machine-generated, not an independent verification against a recording. Session resumption is controlled by the server only to continue that same active interview across Google's periodic connection rotation; provider credentials and resumption handles are not exposed to the participant browser. Google states that generating a resumption handle can retain the related conversation state, including audio and text, for up to 24 hours. This live-resumption route is therefore not a Zero Data Retention path, and a transcript-only workspace setting does not shorten that provider-side period. Paid EEA processing is governed by the applicable Google processor terms, and Google states that prompts and responses are not used to improve Google products. Separately from the live-resumption state described above, the Paid Services terms describe abuse-monitoring logs and required legal or regulatory disclosures. Google's published Gemini API usage policies specify 55 days for text prompts, contextual information and outputs used for abuse monitoring. Flagged material may be reviewed by authorised Google personnel. That policy does not separately specify the retention of raw audio; the 55-day period must not be read as a raw-audio retention guarantee. The stated no-product-improvement use does not exclude the policy-enforcement uses described by Google. Google states that this data may be stored transiently or cached in any country in which Google or its agents maintain facilities. Sources: https://ai.google.dev/gemini-api/terms and https://ai.google.dev/gemini-api/docs/usage-policies. Separate public-source discovery — outside this DPA For this separate operation, SixSentences_ acts as controller, OpenRouter as its processor, and Perplexity AI, Inc., USA, as the exclusively selected downstream operator. They are not authorised through this DPA and are not used as processors of private customer research content. The OpenRouter standard DPA identifies its customer as controller, includes the EU Standard Contractual Clauses, Module Two, and identifies US Google Cloud regions for its standard service; no EU endpoint is promised for this route. Public-source discovery is pinned to perplexity/sonar, without provider fallback. Only a server-scrubbed, minimized search query is transmitted: account details, uploaded files, source full text, transcripts and manuscripts are not included. Public results can nevertheless contain ordinary personal data from source pages, including author names. The generated Sonar answer is discarded after SixSentences_ extracts source metadata such as title, URL, snippet and publication date. Any later storage or use of that metadata in a customer workspace is a subsequent operation and is governed by this DPA where SixSentences_ processes it on the customer's behalf. Every request sets data_collection=deny and zdr=true and sends X-OpenRouter-Cache: false. The header disables OpenRouter's response cache for that request. ZDR restricts routing to an endpoint carrying the selected ZDR commitment. Those controls do not by themselves establish retention periods or training restrictions for every native web-search or tool-processing step. Technical usage metadata can remain available for billing and operations. Before enabling web research, the user confirms that the current question and, at a protocol approval step, the displayed criteria contain only public, non-personal, non-confidential and non-sensitive information. An initial Quick Answer or systematic review may derive a bounded set of search variants from that confirmed question and criteria generated from it or separately approved, for example to locate documentation or reports. It does not send each generated variant for individual approval. When the chat interface presents a single concrete query for approval, only those approved terms may be sent, not another query derived from chat history. Private conversation history, uploaded material, transcripts and manuscripts are not included in the search-query context. The confirmation is not a substitute for processing or transfer terms. OpenRouter's endpoint registry relies on provider representations; it is not independent proof of contractual compliance or a transfer safeguard. The request fails if the pinned ZDR route is unavailable. This route is not authorised for Sensitive Data, GDPR Art. 9 categories or confidential personal data; OpenRouter's standard DPA does not cover such use unless expressly amended. The Privacy Policy describes SixSentences_' purpose, legal basis, recipients, transfers, retention boundaries and data-subject rights for this separate operation.

Customer-content sub-processors receive only the material needed for the triggered request, not the account profile. Additions or replacements under SixSentences_' direct control are announced to active customers in advance with a reasonable opportunity to object on data-protection grounds. The private Gemini route may not be replaced silently. If an affected customer-content provider is unacceptable, the customer must not use it and may terminate the affected processing if no reasonable alternative exists. Changes to the separate public-source discovery route are handled under the Privacy Policy and applicable controller information duties, not as customer sub-processor authorisation under this DPA. No provider may receive customer personal data until the required Art. 28(4) terms and transfer safeguards are active; a public privacy notice, API key or ZDR flag alone is insufficient. The identity and role of an applicable sub-processor and relevant safeguards can be requested at legal@sixsentences.com. The customer's Art. 28 information and authorisation rights remain unaffected.

8. Assistance

Taking account of the nature of processing, SixSentences_ assists with data subject rights and Art. 32-36 duties. Content can be inspected, exported and deleted through the Service. Requests received directly are forwarded to the controller without undue delay. A personal-data breach affecting customer content is reported without undue delay with Art. 33(3) information as it becomes available.

9. Deletion and return

During the agreement, the customer can export and delete content or the whole account. At the end, at the customer's choice, SixSentences_ makes personal data available in a supported export format and then deletes remaining copies, or deletes without return. A legally required retained copy is disclosed where permitted and isolated. Active-system deletion is immediate in the ordinary workflow. Encrypted disaster-recovery copies expire under the 14 daily, 8 weekly and 12 monthly rotation, and a deletion ledger prevents silent restore. A Gemini Live resumption state expires under Google's stated maximum 24-hour period; deleting or choosing not to retain a SixSentences_ recording does not promise earlier deletion of that separate provider state. Separately, Google states a 55-day abuse-monitoring period for text prompts, contextual information and outputs in its usage policies; no separate raw-audio retention period is specified there. Deleting workspace content does not promise earlier deletion of those provider logs. This is separate from the up-to-24-hour Live resumption state and SixSentences_' own workspace retention.

10. Information and audits

SixSentences_ provides information necessary to demonstrate Art. 28 compliance, initially through this DPA, the Privacy Policy and written answers. It permits and contributes to reasonable customer or mandated-independent-auditor audits. Scope, timing and security are coordinated on reasonable notice. Current reports may be used first where sufficient but do not replace a reasonably necessary inspection. Shorter notice or additional audits remain possible where required by an authority, after a breach or on credible material non-compliance. Auditors must protect confidentiality and follow reasonable security requirements.

11. International transfers

Active workspace content is stored in Germany; encrypted disaster-recovery snapshots are stored in Amsterdam. Customer-content transfers can occur to Google and its authorised processors under the safeguards described in section 7 and only when the relevant feature is used. Separately, the public-source discovery operation outside this DPA can be processed in the USA by OpenRouter and Perplexity. For that operation, OpenRouter's standard DPA describes US hosting and includes the EU Standard Contractual Clauses, Module Two; no EU endpoint is promised. Its controller processing, recipient roles and transfer information are described in the Privacy Policy. Google states that the abuse-monitoring prompt and response logs described in section 7 may be stored transiently or cached in any country in which Google or its agents maintain facilities. The temporary Gemini Live resumption state can likewise be processed outside the EEA. The applicable Google terms and DPA govern this processing; SixSentences_ does not promise a specific processing location for either path. Copies of applicable SCCs can be requested from the provider or SixSentences_.

12. Controller responsibilities

The customer ensures a legal basis, including the requirements of Art. 9 and Art. 10 where applicable; gives Art. 13/14 notices; keeps survey and interview disclosures accurate; and obtains any required authorisation from the speakers before recording or processing non-public conversations, including under § 201 StGB. Browser microphone permission alone is not that authorisation. The live-interview confirmation supports the participant flow but does not itself establish the customer's legal basis or authorise earlier recordings. Information for an AI-led live interview must cover audio processing through the SixSentences_ server relay by Google, storage of provider-generated transcripts and aggregate usage measurements, and the possible provider-side retention of resumption state for up to 24 hours, and the separate 55-day abuse-monitoring period stated for text prompts, contextual information and outputs, with possible transient storage or caching in any country where Google or its agents maintain facilities. Google's usage policy does not specify a separate raw-audio retention period. Separately from the customer's controller duties under this DPA, the Service terms prohibit submitting Sensitive Data, Art. 9 data or confidential personal data in a public-source search query.

13. Final provisions

Liability follows Art. 82 GDPR and the general agreement. This DPA prevails for workspace-content processing. German law applies. Invalid provisions do not affect the remainder; the applicable statutory rules apply in their place. Material changes are announced in advance like sub-processor changes. The version and effective date identify the applicable text.

Previous contract editions