Legal

Information under the EU Data Act

This page contains the information that nara GmbH, as a provider of data processing services, makes available online under Regulation (EU) 2023/2854 (Data Act). It supplements our General Terms and Conditions, in particular section 9 (switching providers, data portability) including Annex 1, as well as the individual contract concluded with each customer.

§ 1 Provider, infrastructure, and applicable law

nara GmbH Leightonstraße 3 97074 Würzburg, Germany Commercial register: Amtsgericht Würzburg, HRB 17918

The sole contracting party for all data processing services is nara GmbH, based in Germany. The contracts are governed by German law, and the place of jurisdiction is the registered office of nara GmbH.

The ICT infrastructure used to operate the core platform is located in a data center in Germany and is subject to German and European law. Where subprocessors are used for individual service components, we list them and their processing locations in the subprocessor register that forms part of our data processing agreement.

§ 2 Protection against unlawful international governmental access

nara GmbH has adopted technical, organizational, and contractual measures to prevent unlawful international governmental access to data held in the Union and unlawful transfer of such data, where such access or transfer would conflict with Union law or the law of a Member State (Article 28 Data Act).

Technical measures:

  • The core platform runs on dedicated infrastructure controlled by nara in a data center in Germany.
  • Data is encrypted in transit (TLS 1.2 and TLS 1.3) and at rest.
  • Tenant-separated data storage: the data of each customer organization is stored logically separated.
  • Role-based and resource-based access control down to the level of individual resources, with sign-in via enterprise SSO (SAML and OIDC).
  • Integration credentials are stored encrypted (AES-256-GCM), and API access tokens are stored exclusively as cryptographic hashes.
  • Administrative access and all agent actions are logged. Support access by nara requires individual approval, is time-limited, and is fully logged.

Organizational measures:

  • Information security management in accordance with ISO 27001.
  • Access to customer data is limited to authorized employees bound to confidentiality, on a need-to-know basis.
  • A defined procedure for governmental requests for information or disclosure: every request is reviewed legally. Data is disclosed only where an obligation exists under the law of the European Union or of a Member State. We act on decisions of courts or authorities of third countries only if they are based on an international agreement, such as a mutual legal assistance treaty, or if the conditions of Article 28(2) and (3) of the Data Act are met.
  • For every request, we review its reasoning, specificity, and proportionality, pursue the available legal remedies against disproportionate or unlawful requests, and disclose no more than the minimum amount of data strictly required in the individual case.
  • We inform the affected customer of such a request before complying with it, to the extent we are legally permitted to do so.

Contractual measures:

  • All customer contracts are governed by German law, and nara GmbH is the sole contracting party.
  • Subprocessors are carefully selected and contractually bound, in particular through data processing agreements under Article 28 GDPR, confidentiality obligations, and the duty to act only on documented instructions.
  • Where a subprocessor has a third-country connection, additional safeguards are agreed, in particular EU standard contractual clauses and supplementary technical protection measures.

§ 3 Procedures for switching and transferring content

Customers may at any time switch to another provider covering the same service type or request the transfer of their exportable data and digital assets to their own ICT infrastructure. The procedure is governed by section 9 of our General Terms and Conditions. The key points:

  • Notice of the switch with a notice period of 2 months.
  • A transition period of no more than 30 calendar days from the end of the notice period. If this is technically not feasible, we will notify the customer within 14 working days and specify an alternative transition period of no more than seven months.
  • After the end of the transition period, the exportable data remains retrievable for a further 30 calendar days (retrieval period).
  • Until January 12, 2027, reduced switching charges may be levied that correspond exclusively to the directly attributable, demonstrable costs. From January 12, 2027, the switching process is free of charge.

Transfer methods:

  • Export of structured data via the application and via the documented REST API (docs.nara.de).
  • More extensive or complete exports of individual data categories are provided on request.
  • Delivery of export files via a secured, encrypted transfer channel.
  • On request, we additionally support the switch through separately commissioned services, such as accelerated migration or conversion into special formats.

File formats:

  • Structured data is provided in open, machine-readable formats, in particular CSV and JSON (each UTF-8).
  • Files and attachments are handed over in their original format.

Known restrictions and technical limitations:

  • For technical reasons, large data sets are provided in volume-limited partial exports.
  • Data that serves exclusively the internal functioning of the service is not exportable, nor is protected content within the meaning of section 9 of our General Terms and Conditions and Annex 1 thereto, such as models, embeddings, and proprietary system configurations.
  • The transfer requires a compatible destination service or destination environment. We do not owe services within the infrastructure of the new provider.

Please direct switching requests to privacy@nara.de.

§ 4 Register of data structures and data formats of exportable data

The following register describes, in accordance with Article 26(b) of the Data Act, the data structures and data formats in which exportable data is available, as well as the underlying standards and open specifications. It is updated on an ongoing basis. Which data is exportable in detail is set out in Annex 1 to our General Terms and Conditions.

  • Tickets and ticket history: structured export as CSV and JSON with metadata such as status, priority, categories, classification, and timestamps.
  • Conversations and messages: JSON.
  • Knowledge data (memory objects): JSON. The structure follows the data types defined in the customer account based on JSON Schema and can be retrieved via the REST API.
  • Files and attachments: handover in the original format with associated metadata.
  • Agent and workflow configurations: JSON.
  • Account, organization, and integration master data (excluding credentials) as well as usage and billing overviews: JSON or CSV.
  • Logs and reports: CSV and JSON, where exportable.

Underlying standards and open specifications: HTTPS with TLS 1.2/1.3, REST, JSON (RFC 8259), JSON Schema, CSV (RFC 4180), UTF-8.

§ 5 Contact

Please direct questions about this page, about switching providers, or about the handling of governmental access requests to:

nara GmbH Leightonstraße 3 97074 Würzburg, Germany privacy@nara.de

Last updated: August 2026