Last updated23 August 2026
Data processing
When an organization uses Citerra, Citerra processes personal data on that organization's behalf. This page names which party is which, what the agreement covers, which model providers are involved, and how to request it.
§ 1
Who is which party
Citerra is Citerra GbR, a partnership of Fadi Al Eliwi, Fares Al Eliwi, Mauro Maus and Yefan Jiang. Its address is c/o Collective Incubator, Jülicher Straße 209q/s, 52070 Aachen, Germany. That partnership is the entity that signs, in both of the roles below.
For the content an organization creates, the documents, sources, citations and annotations, the organization is the controller and Citerra is the processor. Citerra acts on the organization's instructions and does not decide what is put into a paper.
For the account itself, the sign-in identity and the operational records that keep the service running, Citerra is the controller. The privacy policy covers that half.
§ 2
What the agreement covers
The agreement is a data processing agreement under Article 28 of the GDPR. It is offered to organizations on the Team and Enterprise editions, and to any organization whose institution requires one.
- Scope and instructions
- The categories of data processed, the purpose, and the commitment that Citerra processes them only on the organization's documented instructions.
- Subprocessors
- The current list is a published register, and the agreement commits Citerra to notifying the organization before a new subprocessor begins processing.
- Technical and organizational measures
- Encryption in transit, and at rest on each provider's platform. EU data residency for the database and generated artifacts. Multi-factor authentication on every administrative account that can reach production.
- Transfers outside the EU
- Standard Contractual Clauses for the providers that operate outside the EU, which the subprocessor register names individually.
- Assistance and audit
- Support with data subject requests and with impact assessments, and the audit rights Article 28 requires.
- Deletion and return
- Deletion of the organization's data on termination, with the export path and the 30-day grace window described in the privacy policy.
§ 3
Model providers
The assistant sends the passages relevant to a question to OpenAI, the model provider, never the full library. The provider's API terms exclude API content from training.
An organization that would rather not involve a third-party model can point Citerra at its own endpoint, or turn AI off entirely. Both are settings an organization admin controls.
§ 4
How to request it
Write to security@citerra.de with the legal entity that will sign and the institution or department it covers. Include any template your institution requires Citerra to work from.