AVV Review

A 30-minute call to walk through Gemma’s AVV (Auftragsverarbeitungsvertrag) template ahead of finalizing the engagement contract, with IT lead Torsten Rex. Rex had pre-reviewed the document; Manu Lachmann (Colayer) sent contract comments separately for Rex to review over the weekend. Bijan sent the updated AVV and a change-summary email the same afternoon.

Changes agreed

ClauseChangeStatus
§7.3 Authorized contactsName Peterseim + Junker as ROTOP-side authorized contacts, delegation possible via themAgreed
§7.5 Data scopeData processed only after prior individual instruction (Einzelweisung)Agreed
Annex 2 PurposeROTOP data not passed to third partiesAgreed
§4 AI/LLM usageDedicated clause covering LLM usageAgreed
Annex 4 Sub-contractorsInclude Gemma’s full list; note the active tools (notably Fireflies + Anthropic)Agreed
§6 Third-country transferRex to check internally, possibly removeOpen (Rex)
TOMs Admin-access loggingRemoved (Snowflake query history covers the audit trail)Agreed, removed
§9 Audit clauseRex to propose concrete placementOpen (Rex)
§9 Incident reportingExplicit 24-hour reporting deadlineAgreed
§10.4/10.5 Deletion/returnGemma deletes data on request at end of engagementAgreed

Next steps

  • Rex: resolve §6 and §9 by Mon/Tue; DocuSign to follow; review Manu’s contract comments over the weekend.
  • Both: project kickoff call booked for Friday 2026-06-27, 10:00-11:00 (Git repo, server access, project setup), with Bianca Frost joining as Gemma project lead. (Held slightly earlier, on 2026-06-26; see the project’s tech kickoff.)