Trust & Security

Trust & Security

Developed in Germany. Hosted in Germany. Support from Germany.You stay in control — Felix prepares, you approve.

🇩🇪 Hosting Frankfurt (EU) GDPR-compliant SOC 2 Type II (Supabase) AI with no training on your data DPA under Art. 28 Four-eyes principle Encryption TLS 1.2+ / AES-256

Where Your Data Lives

Backend, database and authentication run on Supabase in the AWS region eu-central-1 (Frankfurt). Web hosting is provided by IONOS (Germany).

All personal data remains within the EU. Regular backups are kept within the EU region.

AI Transparency (Felix)

For AI-assisted analyses and the compliance co-worker Felix, AIGOY uses the Claude model from Anthropic PBC (USA).

No-training commitment: Anthropic contractually does not train its models on the data submitted via the API.

For the transfer to a third country, Standard Contractual Clauses (SCC, Art. 46(2)(c) GDPR) and the EU-U.S. Data Privacy Framework apply; a DPA under Art. 28 GDPR is in place.

Felix never acts on its own — every implementation goes through the four-eyes approval.

Outlook: EU inference (AWS Bedrock Frankfurt) and customer-side model/key choice (BYOK) are in preparation.

Sub-processors

An overview of the processors used by AIGOY.

ProviderLocationPurposeNote
IONOS SEGermany 🇩🇪Web hostingDPA Art. 28
Supabase Inc.AWS eu-central-1, Frankfurt 🇩🇪 (EU)Backend, database, auth, edge functionsDPA Art. 28, SOC 2 Type II
Anthropic PBCUSA 🇺🇸AI service (Claude model)No training on data, SCC/DPF, DPA Art. 28
Stripe Payments Europe, Ltd.Dublin, Ireland 🇮🇪 (EU)Payment processingBusiness/Enterprise only

Technical & Organizational Measures (TOM)

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Row Level Security (RLS) — users only see their own data
  • INSERT-only audit trail — tamper-resistant logging
  • Four-eyes approval cockpit for all of Felix's actions
  • Least-privilege access
  • Backups within the EU

Your Rights & Compliance

  • Data subject rights under Art. 15–22 GDPR
  • DPA under Art. 28 GDPR available on request
  • Aligned with the EU AI Act, NIS2 and DORA

Request DPA

Data processing agreement under Art. 28 GDPR — available on request.

View & download DPA → Privacy Policy →

Last updated: May 2026. Changes to sub-processors will be updated here.