← All articles
Trust

What a signable AVV actually contains

German schools are asked to sign a data processing agreement for every tool they use. Most vendors treat it as paperwork. Here is what is actually in ours, and why we publish it before you ask.

GDPRAVVData protectionProcurement

If you work in a German school, you know the ritual. A colleague finds a useful tool. The Datenschutzbeauftragte asks whether there is an AVV. Someone emails the vendor. Three weeks later a PDF arrives that raises more questions than it answers, and the tool quietly stops being used.

The Auftragsverarbeitungsvertrag — a data processing agreement under Article 28 GDPR — is not optional and not a formality. A school that puts student data into software without one is the party at fault, not the vendor. So it is worth understanding what the document is supposed to contain, and why "we are GDPR compliant" on a website is not the same thing as having one.

Why a badge is not an agreement

GDPR compliance is not a certification you obtain. There is no authority that issues a "GDPR compliant" stamp for software. When a vendor's site shows a shield icon with those words, it is a claim about themselves, made by themselves.

Article 28 requires something concrete instead: a contract between you (the controller — the school) and us (the processor), setting out specific terms. The regulation lists what must be in it. A vendor either has a document containing those clauses, ready to sign, or does not.

The eight things Article 28 requires

Anyone can check a proposed AVV against this list. If something is missing, the document is not sufficient regardless of how official it looks.

RequirementWhat it means in practice
Subject matter and durationWhat processing happens, and for how long
Nature and purposeWhy the data is processed — here: producing and publishing a timetable
Types of personal dataNamed explicitly, not "user data"
Categories of data subjectsTeachers, students, staff
Instruction bindingThe processor acts only on documented instructions from the school
ConfidentialityEveryone with access is bound to confidentiality
Security measures (Art. 32)Concrete technical and organisational measures — TOMs
Sub-processors, deletion, auditWho else is involved, what happens at the end, your right to check

What is in ours, specifically

Rather than describe the genre, here is what our agreement actually says. If you are evaluating any timetabling vendor, these are reasonable things to demand from all of them.

The data we process — named

Teachers: name, short code, email, subjects taught, availability, workload. Students: name, class, student number, and — where the school uses student-based scheduling — course choices. Rooms, subjects and lesson structure carry no personal data. Account users: name, email, role, login timestamps.

That is the whole list. We do not process grades, attendance, addresses, guardian contacts, medical information or disciplinary records, because timetabling does not need them and holding data you do not need is a liability rather than a feature.

Where it lives

German data centres, EU region only. No replication outside the EU, including for backups. The provider and region are named in the agreement rather than described as "our cloud partner", because Datenschutzbeauftragte quite reasonably want to know who the sub-processor is.

Technical measures, in concrete terms

  • Encryption in transit (TLS) and at rest.
  • Tenant isolation: each school's data is separated at the database level, and every query is scoped by tenant. A cross-school data leak would require a code defect, not a misconfigured permission.
  • Role-based access with a documented permission matrix — the school decides who sees what.
  • Daily backups with point-in-time restore.
  • Access by our staff only for support, on request, logged.

What happens at the end

On termination: export your data in a usable format, then deletion within a defined window, backups included. Specified in the agreement rather than left to goodwill.

The AI clause. Our assistant sends the minimum necessary context to a language model to interpret a request. School data is never used to train models — not ours, not a provider's. This is stated in the AVV because the question is now the second one every DPO asks, and "we would never do that" is not a contractual term.

Available before you ask

Our AVV is downloadable, and it is the same document for everyone — no negotiation round, no "send us your requirements and we'll see." You can read it during a free trial, before any money or data changes hands, and hand it to your DPO while you are still deciding whether you like the software.

This is deliberate. The most common failure in school software procurement is not rejection; it is stalling — a promising tool that dies in a three-week email thread. A document nobody has to request cannot stall.

Two honest caveats

We are not ISO 27001 certified. Untis has held that certification since 2016, and for some public procurement processes it is a hard requirement. We are a young company; the certification is a goal, not a claim. If your tender requires it today, we do not qualify today.

An AVV is a contract, not a guarantee of good behaviour. It defines obligations and remedies. What it actually buys you is that the obligations are written down and enforceable — which is precisely what "GDPR compliant" on a landing page does not buy you.

What we would ask, in your position

Four questions that separate a serious answer from a vague one, for any vendor:

  • Can I read your AVV now, without signing an NDA or booking a call?
  • Which data centre, in which country, and who operates it?
  • Which sub-processors touch our data, and for what?
  • If we leave, what is the deletion window — and does it include backups?

A vendor who can answer all four in one email is a vendor whose data protection story is real. It is a surprisingly effective filter.


Bildena GmbH is a German company; Bildena Scheduler runs in German data centres. The AVV per Art. 28 GDPR is available at onboarding and on request during any trial.

See it solve your own timetable

Import from aSc, Untis or Excel and run a full generation free — first timetable in 3 minutes.

Start free

Keep reading