llmstxt.info · Art. 28 GDPR

Data Processing Agreement

For llms.txt hosting at llmstxt.info

Version 1.0 · as of 23 August 2026

With llms.txt hosting we store and publish content that you determine. Where that content contains personal data, we process it on your behalf. This page is the agreement required for that under Art. 28(3) GDPR. It becomes part of the hosting contract as soon as you book llms.txt hosting; the electronic format is expressly sufficient (Art. 28(9) GDPR).

When you need this agreement — and when you do not. It applies only to paid llms.txt hosting. It does not apply to a plain directory listing without hosting: there we decide on purposes and means ourselves and act as our own controller. If your hosted files contain no personal data at all, the agreement simply has nothing to bite on — but it does no harm either.

Contents

  1. Parties and roles
  2. Subject matter, duration, nature and purpose
  3. Instructions
  4. Confidentiality
  5. Technical and organisational measures
  6. Sub-processors and server location
  7. Assistance with data subject rights
  8. Notification of breaches
  9. Deletion and return
  10. Evidence and audits
  11. Your obligations as controller
  12. Changes to this agreement

Parties and roles

Controller within the meaning of Art. 4(7) GDPR is you as the customer: you determine which content is hosted and what it says.

Processor within the meaning of Art. 4(8) GDPR is the operator of llmstxt.info. Full provider details are in the legal notice.

For everything that is not the hosting of your files — directory listing, payment processing, server log files, analytics — we act as our own controller. What happens there is described in the privacy policy.

Subject matter, duration, nature and purpose

Subject matter
Storage and public provision of the content you determine as llms.txt and llms-full.txt at llmstxt.info/hosted/….
Nature of processing
Collection from your input, structuring into the llms.txt format, storage, provision, erasure.
Purpose
Performance of the hosting contract: making your content retrievable at a stable address for AI systems and people.
Types of data
Only the data you provide in the hosted content — typically organisational and product data, where applicable names of contact persons, contact details and links to profiles.
Categories of data subjects
The persons you name, in particular contact persons and owners.
Duration
For the term of the hosting contract; thereafter as set out in section 9.

Special categories under Art. 9 GDPR are not covered by this agreement. Please do not place health, religious, trade-union, biometric or comparable data into hosted content. Data under Art. 10 GDPR (criminal convictions) is likewise not covered.

Instructions

We process personal data from hosted content only on your documented instructions (Art. 28(3)(a) GDPR). The hosting contract itself constitutes an instruction, as does any change you make via the customer portal or by email.

If we consider an instruction unlawful, we will inform you and may suspend execution until the matter is resolved. We do not process hosted content for our own purposes. Legal obligations are excepted — in that case we will inform you beforehand unless the law prohibits it.

One exception we name openly: we may remove or disable hosted content that infringes applicable law or third-party rights (Terms § 12a, Art. 16 of Regulation (EU) 2022/2065). That is not processing for our own purposes but compliance with our own legal obligation.

Confidentiality

Persons authorised to process the data are bound to confidentiality (Art. 28(3)(b) GDPR). The service is operated by a single individual; there are no further employees. Where service providers are involved, they are bound as set out in section 6.

Technical and organisational measures

Pursuant to Art. 32 GDPR the following are implemented in particular:

  • Transport encryption (TLS) for all requests; HSTS enabled.
  • Server access exclusively via SFTP with personal credentials; no unencrypted access.
  • Separate storage of hosted files per customer; directory protection against listing and against script execution.
  • Administration access with bcrypt password hashing and lockout after failed login attempts.
  • Regular backups by the hosting provider within the same data centre group in Germany.
  • No third-party resources embedded in delivered pages; no third-party analytics or advertising services.

The measures of the hosting provider additionally follow from its data processing agreement and the technical and organisational measures agreed there.

Sub-processors and server location

By concluding the hosting contract you grant general written authorisation for the use of the sub-processors listed below (Art. 28(2) GDPR). A contract under Art. 28(4) GDPR is in place with each of them, imposing the same obligations.

ALL-INKL.COM — Neue Medien Münnich
Owner: René Münnich · Hauptstraße 68, 02742 Friedersdorf, Germany
Service
Web hosting: storage and delivery of the hosted files, server operation, backups
Place of processing
Germany — the provider’s own data centres in Dresden

The hosting provider in turn uses affiliated companies for data centre operations; details follow from its privacy information.

No transfer to third countries. Hosted content is stored and delivered exclusively on servers in Germany. No transfer to a country outside the EU/EEA under Chapter V GDPR takes place for the hosting. The information on the data centre location is based on the provider’s own statements.

Changes. If we intend to add or replace a sub-processor, we will inform you at least 30 days in advance by email to the address held in your customer account and update this page. You may object within that period. If you object for a substantiated data protection reason and no solution can be found, you may terminate the hosting contract extraordinarily with effect from the change; fees already paid will be refunded pro rata.

Assistance with data subject rights

If a data subject approaches us with a request for access, rectification, erasure or objection concerning hosted content, we will forward it to you and will not answer it ourselves. We support you with appropriate measures in fulfilling such requests (Art. 28(3)(e) GDPR) and in your obligations under Art. 32 to 36 GDPR (point (f)).

In practice this is simple: you can change hosted content yourself at any time via the customer portal, or end the hosting.

Notification of personal data breaches

If we become aware of a personal data breach affecting hosted content, we will inform you without undue delay — as a rule within 24 hours of becoming aware — with the information available to us under Art. 33(3) GDPR. Notification to the supervisory authority and, where applicable, to data subjects is your responsibility as controller.

Deletion and return

After the hosting contract ends we delete the hosted files within 30 days, unless you request their return beforehand. On request we will provide the files in their original format before deletion. Backup copies held by the hosting provider are overwritten within its retention cycles.

Statutory retention obligations remain unaffected; they concern contract and invoice data, not the content of the hosted files.

Evidence and audits

On request we provide the information necessary to demonstrate compliance and allow for audits (Art. 28(3)(h) GDPR). As a rule this is done by written information and by presenting the data processing agreement with the hosting provider. An on-site audit is possible after prior arrangement during normal business hours.

Your obligations as controller

You remain responsible for the content you have hosted. In particular this means:

  • You need a legal basis under Art. 6 GDPR for every item of personal data in the content.
  • You fulfil the information obligations under Art. 13 and 14 GDPR towards the data subjects.
  • You answer data subject requests concerning that content.
  • You ensure the content infringes no third-party rights, including copyright and trade marks (Terms § 7).
  • You do not include data under Art. 9 or Art. 10 GDPR.

We do not review the content and are not obliged to do so (Terms § 7(0a)). This also corresponds to the prohibition of a general monitoring obligation under Art. 8 of Regulation (EU) 2022/2065.

Changes to this agreement

We may adapt this agreement if the legal situation, the service providers used or the scope of services change. We will inform you of substantive changes at least 30 days in advance by email. The applicable version with version number and date is shown at the top of this page.

In the event of conflict between this agreement and the general terms and conditions, this agreement prevails for the processing of personal data on behalf of the controller.

Questions, or would you like a signed copy? A message to Connect@llmstxt.info is enough — on request we will provide this agreement as a signed PDF.