SmartDataTwin

Security & privacy

Your data is yours. EU-compliant by default, not bolted on.

SmartDataTwin is built for the Mittelstand's GDPR duties, not retrofitted. Hosted in Frankfurt, DPAs at onboarding, seven-year audit log.

What we build on.

  • 01

    Your data in the EU

    All data in Frankfurt. Managed Postgres + cloud + backup storage, EU only.

  • 02

    Cleanly separated

    One database, every customer strictly isolated. Defense in depth at DB and API level.

  • 03

    Swappable AI vendor

    Vendor-agnostic. Zero-retention contractually agreed, EU region where available.

  • 04

    Encrypted

    TLS in transit, AES-256 at rest. Sensitive fields additionally per-customer encrypted.

  • 05

    Full audit trail

    Every action logged — who, when, before/after. Kept for 7 years.

  • 06

    Right of access

    Full data export and deletion any time. No proprietary formats.

Voice data — handled deliberately.

For phone and voice features: explicit consent before any recording. Storage in the EU only. Retention configurable — default 90 days.

Certification.

  1. Today EU hosting Frankfurt, GDPR-ready, DPAs standard.
  2. Planned External penetration test.
  3. Mid-term TISAX when needed, SOC 2 in preparation.
  4. Long-term ISO 27001 targeted.
Discuss security