Data protection compliance
Data protection compliance
Summary: neuland.ai is data protection compliant
neuland AI AG processes personal data exclusively in accordance with the GDPR, the German Federal Data Protection Act (BDSG) and — where applicable — supplementary professional-law requirements (e. g. Section 43e BRAO). All required building blocks are implemented, documented and reviewed regularly:
- ✓ Data processing agreement pursuant to Art. 28 GDPR
- ✓ Fully documented TOMs pursuant to Art. 32 GDPR
- ✓ Transparent list of subprocessors
- ✓ External data protection officer appointed
- ✓ Standard processing in the EU / Germany
- ✓ Established reporting channels for data protection incidents
- ✓ Record of processing activities maintained
- ✓ Employees bound to confidentiality
Controller and data protection officer
neuland AI AG
Konrad-Adenauer-Ufer 83, 50668 Cologne, Germany
Executive Board: Karl-Heinz Land, Yunus Philip Uyargil
Phone: +49 221 999697-30
Email: hello@neuland.ai
Maxim Ciebiera (DATATINO)
Werinherstraße 3, 81541 Munich, Germany
Contact for data subject requests via the privacy information.
Data processing agreement (Art. 28 GDPR)
neuland AI AG provides a data processing agreement (DPA) in text form to every customer that processes personal data via our services. The DPA covers all mandatory content pursuant to Art. 28(3) GDPR — including the obligation to follow instructions, purpose limitation, assistance obligations, a deletion concept and audit rights.
You can request the DPA at any time on the DPA page.
Technical and organisational measures (Art. 32 GDPR)
We implement a level of protection reflecting the state of the art. This includes physical access control, system access control and data access control, end-to-end transport and storage encryption, pseudonymisation where appropriate, a role-based authorisation concept (least privilege / need to know), regular backups, documented recovery procedures and continuous monitoring.
The complete TOM documentation is available on the TOM page.
Subprocessors
All engaged subprocessors are carefully selected, contractually bound pursuant to Art. 28 GDPR and maintained transparently in a public list. Standard processing takes place in Germany or the EU/EEA.
Optional services involving third countries (e. g. Perplexity in the United States for web search and deep research) are only used after explicit activation by the customer. In those cases the third-country transfer is safeguarded via the EU-US Data Privacy Framework; on request supplemented by standard contractual clauses (SCC) pursuant to Art. 46 GDPR.
The complete, up-to-date list — including the respective safeguards — is available on the subprocessors page. We give advance notice of changes in line with the contractually agreed mechanisms.
Data subject rights and assistance obligations
Data subjects may exercise their rights under Art. 15–22 GDPR at any time (access, rectification, erasure, restriction, data portability, objection). As a processor, we assist our customers in handling these requests with appropriate technical and organisational means pursuant to Art. 28(3)(e) GDPR.
Reporting channels for data protection incidents (Art. 33 GDPR)
We have established internal processes for detecting, assessing and reporting data protection incidents. In the event of a personal data breach, the controllers concerned are informed without undue delay — as a rule within 24 hours of becoming aware — so that they can meet their 72-hour notification obligation under Art. 33 GDPR.
Status & contact
This self-declaration is current as of 14/08/2026. The building blocks described here are implemented at neuland AI AG and are continuously monitored and developed further. The detailed individual documents (DPA, TOMs, subprocessors, supplementary agreements) are linked in the documents section of the Trust Center.
If you have any questions, you can reach us at hello@neuland.ai .