Trust Center

Documents

Here you will find key documents on data protection and compliance topics.

Data protection compliance

Overview of how the GDPR requirements are implemented

Last updated: 14/08/2026

Consolidated overview of how the central GDPR requirements are implemented at neuland.ai — DPA pursuant to Art. 28, TOMs pursuant to Art. 32, a transparent list of subprocessors, an appointed data protection officer, reporting channels and data subject rights. Ideal as a supplementary document to the contract, documenting the status at the time of signing.

Supplementary agreement with Microsoft

Additional provisions for professionals bound by professional secrecy

Valid until: 31 Dec 2035

Additional provisions to the Microsoft Customer Agreement with specific clauses for professionals bound by professional secrecy. The document governs confidentiality obligations and the handling of confidential client data when using Microsoft services.

Supplementary agreement with Google

Additional provisions for professionals bound by professional secrecy

Valid from: 30 Jun 2026

Additional provisions to the Google Cloud agreement with specific clauses for professionals bound by professional secrecy (Section 203 StGB). The document governs confidentiality obligations and the handling of confidential client data when using Google services such as Vertex AI — including the obligation to bind engaged subprocessors accordingly.

SaaS contract terms

Contractual basis

Last updated: May 2026

Our SaaS contract terms govern the use of our software-as-a-service offerings. They contain provisions on the scope of services, availability, support, remuneration and liability.

General terms and conditions

Contractual basis

Last updated: 20 Feb 2024

Our general terms and conditions govern the contractual basis of the cooperation with our customers and partners.

Supplementary agreement DORA

Digital Operational Resilience Act

Valid from: 17 Jan 2025

The supplementary agreement for DORA-regulated financial entities governs specific requirements for digital operational resilience. It supplements the processing arrangement with particular obligations regarding IT security, risk management and reporting duties under the DORA Regulation.

Supplementary agreement BRAO

German Federal Lawyers' Act

Valid from: 01 Jan 2025

The supplementary agreement for lawyers and law firms governs particular requirements arising from the BRAO. It contains specific clauses on lawyers' duty of confidentiality, the protection of client secrets and compliance with professional-law requirements during data processing.

Supplementary agreement StBerG

German Tax Advisory Act

Valid from: 01 Jan 2025

The supplementary agreement for tax advisors and tax advisory firms governs particular requirements arising from the StBerG. It contains specific clauses on professional confidentiality, the protection of client secrets and compliance with professional-law requirements during data processing.

ISO 27001 certificate

Information security management systems

Official certificate to ISO/IEC 27001 — the international standard for information security management systems (ISMS).

ISO 9001 certificate

Quality management systems

Official certificate to ISO 9001 — the globally recognised standard for quality management systems.