1. Scope and parties
This Data Processing Agreement under Article 28 GDPR applies between the customer (controller) and anycast.io UG (haftungsbeschränkt), Hintere Straße 125a, 90768 Fürth, Deutschland (processor), where personal data is processed on the customer's behalf when using 2342.ai.
It forms part of the service agreement for business customers. Organization owners and admins can accept the current version electronically in the organization area; the acceptance record contains the version, timestamp, accepting person and document fingerprint. We provide a countersigned copy on request using the contact details in our imprint.
2. Subject matter, duration, nature and purpose
The subject matter is operation of the 2342.ai platform: AI chat, API gateway, research functions, file storage and vector stores, automations, team administration and budget management.
The duration corresponds to the term of the service agreement. The purpose is to provide the platform functions used by the customer, including forwarding requests through the selected external AI data path.
3. Data types and data subjects
Data subjects include in particular the customer's employees and end users, as well as third parties whose data the customer submits to the platform.
- Account and master data (name, email address, roles)
- Content data (chats, prompts, files, vector stores and research results)
- Usage and billing data (model, tokens, cost and timestamps)
- Technical data (IP addresses, device information and logs)
4. Processor obligations
- Process data only on documented instructions from the customer (Article 28(3)(a) GDPR)
- Ensure that every person authorized to process the data is bound by confidentiality
- Maintain technical and organizational measures under Article 32 GDPR (Section 8)
- Notify the customer of personal data breaches without undue delay
- Assist the customer with data-subject rights, data protection impact assessments and supervisory-authority requests
- Demonstrate compliance with this agreement and allow audits (Article 28(3)(h) GDPR)
5. Subprocessors
The customer grants general authorization to use subprocessors. The current list is published at https://2342.ai/en/subprocessors.
We inform customers with a DPA in advance of intended changes. The customer may object for compelling data-protection reasons.
For transfers to third countries, appropriate safeguards under Chapter V GDPR are used, in particular EU Standard Contractual Clauses or an adequacy decision such as the EU-U.S. Data Privacy Framework.
6. AI model use
GLM 5.2 uses a regional European endpoint. We do not promise Germany-only processing or zero data retention for this data path. For external models, data required for the request is transmitted to the subprocessors involved according to model and configuration.
For external models, processing location, retention, misuse detection and any use of inputs or outputs depend on the applicable agreements. 2342.ai does not use customer data to train its own foundation models. For GLM 5.2 as a Public Preview model, Mistral reserves the right to use inputs and outputs for training; the general training opt-out and ZDR do not apply under the preview terms.
7. Deletion and return
After the processing services end, personal data is deleted or returned at the customer's choice unless statutory retention obligations apply.
Customers can delete content, accounts and organizations themselves; a complete data export is available through the platform.
8. Technical and organizational measures (Article 32 GDPR)
- Operation of the 2342.ai core platform on our own access-controlled infrastructure at the Deutschherrnkarree in Nuremberg; Core-Backbone provides colocation and network connectivity
- Encryption of data in transit using TLS
- Role-based access control and tenant separation for organization data
- Technical access and error logs for secure operation and misuse prevention
- Regional GLM processing
9. Final provisions
German law applies. If any provision is invalid, the remaining provisions remain effective.
If this DPA conflicts with the Terms and Conditions, this DPA prevails with respect to data protection.
Electronic acceptance in the organization area is the standard method of concluding this DPA for self-service and beta customers. A countersigned copy can also be provided on request.