Security & compliance
Optimaite is hosted in the EU, is GDPR-compliant and protects your data with industry-leading security measures. Transparency matters to us.
What we commit to, contractually and operationally
Our platform meets the strict requirements of European data protection and security standards.
GDPR
Full compliance with the European General Data Protection Regulation. Data processing agreement, TOMs and subprocessor register available.
CompliantEU hosting
All application data is processed and stored exclusively in the EU. Infrastructure on Hetzner Cloud in Germany.
GermanyNo AI training
Your data is never used to train AI models. All AI processing happens exclusively inside the EU via Azure AI (Germany) and AWS (Frankfurt) under zero-retention agreements.
GuaranteedSecurity measures
Technical and organisational measures that protect your data.
Infrastructure
12 controls- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Kubernetes cluster with network segmentation
- Automated backups with point-in-time recovery
Access control
8 controls- Multi-tenant isolation at the database layer
- JWT-based authentication with tenant scoping
- Role-based access control (RBAC)
Data protection
10 controls- Data processing exclusively inside the EU
- Automatic data deletion at end of contract
- Data classification and retention policies
Organisation
9 controls- Regular security training for every employee
- Incident response plan documented and tested
- Confidentiality agreements with every employee
Data processing
How your data flows through our platform and where it is processed.
Infrastructure
Kubernetes cluster
Hetzner Cloud, Falkenstein/Nuremberg, DE
Database
Self-hosted PostgreSQL (CloudNativePG), Hetzner, DE
Object storage
Hetzner S3-compatible, Falkenstein, DE
Website & edge
Vercel, EU regions
Data we process
Name & email address
User accounts & authentication
Documents & files
Document processing, AI analysis
Chat messages
AI assistance & communication
IP addresses & metadata
Security logging & error diagnosis
Subprocessors
Hetzner Cloud
Infrastructure & storage · Germany
Zilliz Cloud
Vector database (embeddings) · EU (Frankfurt)
Azure AI Foundry
AI provider (GPT, Gemini) · EU (Germany)
AWS Bedrock
AI provider (Claude) · EU (Frankfurt)
Google Cloud
Vertex AI & speech-to-text · EU
Vercel
Website hosting · EU regions
Stripe
Payment processing · Ireland, EU
Mailgun
Transactional email · EU
Sentry
Error monitoring · EU
LangSmith
AI observability · EU
The AI services process document content in EU data centres under zero-retention terms: inputs are discarded after processing and never used for training. Customers can supply their own API keys and control the processing chain themselves.
Legal documents
Every document you need for a compliance review. The binding version of each is German.
Terms of service
General terms and conditions for using the Optimaite platform. Binding German text.
Read the termsData processing agreement
Processing agreement under Art. 28 GDPR incl. technical and organisational measures. Binding German text.
Read the DPAPrivacy policy
How we handle personal data. Binding German text.
Read the policyAI & product notices
Notes on AI output, human review, model limits and data processing. Binding German text.
Read the noticesPilot & demo terms
Terms for time-limited trial, demo and pilot access. Binding German text.
Read the termsSubprocessors
Complete list of every subprocessor we use.
Show the listSecurity measures
Technical and organisational measures (TOMs).
Show detailsLegal notice
Company details under § 5 DDG and legal information. Binding German text.
Read the noticeFrequently asked questions
Answers to the questions we are asked most about security, data protection and compliance at Optimaite.
Question not answered here?
We are happy to walk you through the platform live and answer everything else in person.
Book a demoQuestions about security & compliance?
Our team is available for security questions, DPA requests and compliance reviews — also at security@optimaite.eu.
14 Tage kostenlos testen · Keine Kreditkarte · DSGVO-konform