Last updated: September 20, 2026· 2026.09
Version 2026.09. This agreement is concluded with your acceptance of the Terms of Use and applies between you (Controller) and the Provider (Processor).
Between Kofel — Alexander Leonhartsberger-Schrott, Dörferstrasse 26c, 6065 Thaur, Österreich ("Processor") and the registered owner of the Lithify account ("Controller"), the following agreement on data processing pursuant to Art. 28 GDPR is concluded. It forms part of the contractual relationship between the parties regarding the use of Lithify (lithify.ai).
The Processor processes personal data on behalf of the Controller. The duration corresponds to the term of the usage agreement. The Processor shall process the data exclusively on the instructions of the Controller and in accordance with the provisions of this agreement, unless it is obliged to process the data by Union or Member State law.
The Processor processes the data that the Controller stores in Lithify or that is received via the service's interfaces, namely:
Instructions are issued by the Controller or its designated representatives via the functionalities of Lithify (configuration, data and account management) or in writing to hello@kofel.io. The Processor shall inform the Controller immediately if it considers an instruction to infringe data protection law; it is entitled to suspend the execution of such an instruction until the matter is clarified.
The Processor binds persons entrusted with processing to confidentiality and ensures that they can only access the data they require to perform their tasks.
The processor has implemented the following technical and organisational measures to ensure the security of processing within the meaning of Art. 32 GDPR. The measures are adapted to technical progress and risk developments without reducing the level of protection.
The Processor may engage sub-processors only with the Controller's prior authorisation. Such authorisation is deemed granted for the sub-processors published in the sub-processor list at https://lithify.ai/legal/sub-processors. The Processor shall inform the Controller of intended changes (adding or replacing sub-processors) at least 30 calendar days in advance so that the Controller may object. The Processor ensures that an agreement within the meaning of Art. 28(4) GDPR providing at least the obligations of this agreement is in place with every sub-processor.
The Processor assists the Controller, to the extent of the service's functionalities (in particular access, export and deletion within the application), in responding to data subjects' requests to exercise their rights under Art. 15 to 22 GDPR.
The Processor shall notify the Controller of any personal data breach occurring at the Processor or a sub-processor without undue delay, at the latest 48 hours after becoming aware, where the breach is likely to result in a risk to the rights of data subjects. The notification contains the information pursuant to Art. 33(3) GDPR insofar as available at the time of notification.
Upon termination of the engagement, the Processor shall delete all personal data processed in connection with the engagement at the latest 90 calendar days after the end of the agreement, unless Union or Member State law requires further storage (in which case the Processor shall return the data unaffected by this obligation and block it from further processing). Before expiry of this period, the Controller may export its data in common formats.
The Controller may verify the Processor's compliance with its obligations after reasonable prior notice during normal business operations or have them verified by a third party to be bound by confidentiality. The Processor shall provide the necessary support; upon request, it shall make available the results of its own audits.
Where service providers based outside the EU process personal data (in particular providers based in the United States), the transfer takes place only on one of the following bases:
The current overview of providers and the safeguards applied is available in the sub-processor list.
Amendments and supplements to this agreement require text form; this also applies to any waiver of the text form requirement. Should individual provisions of this agreement be invalid, the validity of the remaining provisions shall remain unaffected. Otherwise, the contractual agreements concluded between the parties apply, in particular the terms and conditions. This agreement is governed by — subject to deviating agreements in the main contract — Austrian law.
Where the Controller configures an AI provider with its own credentials ("bring your own key"), that provider acts on the Controller's behalf and under its direction; the Processor merely transmits content to the endpoint designated by the Controller. The Controller is responsible for the lawful use of that provider, in particular for any required agreements and data protection safeguards for it. The Processor stores such credentials only in encrypted form and uses them exclusively to perform the Controller's instructions within the service.