AVV Review
A 30-minute call to walk through Gemma’s AVV (Auftragsverarbeitungsvertrag) template ahead of finalizing the engagement contract, with IT lead Torsten Rex. Rex had pre-reviewed the document; Manu Lachmann (Colayer) sent contract comments separately for Rex to review over the weekend. Bijan sent the updated AVV and a change-summary email the same afternoon.
Changes agreed
| Clause | Change | Status |
|---|---|---|
| §7.3 Authorized contacts | Name Peterseim + Junker as ROTOP-side authorized contacts, delegation possible via them | Agreed |
| §7.5 Data scope | Data processed only after prior individual instruction (Einzelweisung) | Agreed |
| Annex 2 Purpose | ROTOP data not passed to third parties | Agreed |
| §4 AI/LLM usage | Dedicated clause covering LLM usage | Agreed |
| Annex 4 Sub-contractors | Include Gemma’s full list; note the active tools (notably Fireflies + Anthropic) | Agreed |
| §6 Third-country transfer | Rex to check internally, possibly remove | Open (Rex) |
| TOMs Admin-access logging | Removed (Snowflake query history covers the audit trail) | Agreed, removed |
| §9 Audit clause | Rex to propose concrete placement | Open (Rex) |
| §9 Incident reporting | Explicit 24-hour reporting deadline | Agreed |
| §10.4/10.5 Deletion/return | Gemma deletes data on request at end of engagement | Agreed |
Next steps
- Rex: resolve §6 and §9 by Mon/Tue; DocuSign to follow; review Manu’s contract comments over the weekend.
- Both: project kickoff call booked for Friday 2026-06-27, 10:00-11:00 (Git repo, server access, project setup), with Bianca Frost joining as Gemma project lead. (Held slightly earlier, on 2026-06-26; see the project’s tech kickoff.)