Last updated8 September 2026
Data processing
This page explains the parties' roles, the scope of the data processing agreement, the model providers involved and how to request an agreement. A final section names the governing language.
§ 1
The parties
Citerra is Citerra GbR, a partnership of Fadi Al Eliwi, Fares Al Eliwi, Mauro Maus and Yefan Jiang. Its address is c/o Collective Incubator, Jülicher Straße 209q/s, 52070 Aachen, Germany. That partnership is the entity that signs, in both of the roles below.
For the content an organization creates, the documents, sources, citations and annotations, the organization is the controller and Citerra is the processor. Citerra acts on the organization's instructions and does not decide what is put into a paper.
For the account itself, the sign-in identity and the operational records that keep the service running, Citerra is the controller. The privacy policy covers Citerra's processing of account data.
§ 2
What the agreement covers
The agreement is a data processing agreement under Article 28 of the GDPR. It is offered to organizations on the Team and Enterprise editions, and to any organization whose institution requires one.
- Scope and instructions
- The categories of data processed, the purpose, and the commitment that Citerra processes them only on the organization's documented instructions.
- Subprocessors
- The current list is a published register, and the agreement commits Citerra to notifying the organization before a new subprocessor begins processing.
- Technical and organizational measures
- Encryption in transit, and at rest on each provider's platform. EU data residency for the database and generated artifacts. Multi-factor authentication on every administrative account that can reach production.
- Transfers outside the EU
- The agreement will identify the safeguards for transfers outside the EU. Citerra is verifying provider agreements and transfer safeguards before launch.
- Assistance and audit
- Support with data subject requests and with impact assessments, and the audit rights Article 28 requires.
- Deletion and return
- Deletion of the organization's data on termination, with the export path and the 30-day grace window described in the privacy policy.
§ 3
Model providers
The assistant sends the passages relevant to a question to OpenAI, the model provider, never the full library. The provider's API terms exclude API content from training.
Organizations can use their own endpoint for assistant responses. Library indexing, search and reranking still use OpenAI. Organization admins can also turn AI off entirely.
§ 4
How to request it
Write to security@citerra.de with the legal entity that will sign and the institution or department it covers. Include any template your institution requires Citerra to work from.
§ 5
Governing language
This page is published in English and in German, and both versions describe the same agreement.
The English version governs until counsel has reviewed both texts. Where the two differ before that review, the English wording applies.