GDPR

EU law

Data processing agreements per Art. 28 GDPR. Documented technical and organisational measures. Data transit within EU/CH only.

ISO/IEC 27001

Information security

Certified ISMS. Risk analysis, incident response, access control, encryption.

ISO 9001

Quality management

Certified QMS. Defined processes for development, deployment, support.

Hosting

Dawico Deutschland GmbH

Operated by Dawico Deutschland GmbH in a Tier-IV data center. Geo-redundant, BSI IT baseline protection, renewable energy.

CLOUD Act

not applicable

Swiss AG without US parent. No US authority access. No FISA 702 orders.

Encryption

at rest, in transit

TLS 1.3 in transit. AES-256 at rest. HSM-backed key management. CMK on request.

Data processing

What happens to data.

Processing

We store only contract and billing data pursuant to Art. 6 (1) (b) GDPR. AI content — prompts, inputs and model outputs — is processed ephemerally during inference, never persisted, no logging.

No training

Customer data is never used to train models. No third-party sharing.