Security & privacy
Your data is yours. EU-compliant by default, not bolted on.
SmartDataTwin is built for the Mittelstand's GDPR duties, not retrofitted. Hosted in Frankfurt, DPAs at onboarding, seven-year audit log.
What we build on.
- 01
Your data in the EU
All data in Frankfurt. Managed Postgres + cloud + backup storage, EU only.
- 02
Cleanly separated
One database, every customer strictly isolated. Defense in depth at DB and API level.
- 03
Swappable AI vendor
Vendor-agnostic. Zero-retention contractually agreed, EU region where available.
- 04
Encrypted
TLS in transit, AES-256 at rest. Sensitive fields additionally per-customer encrypted.
- 05
Full audit trail
Every action logged — who, when, before/after. Kept for 7 years.
- 06
Right of access
Full data export and deletion any time. No proprietary formats.
Voice data — handled deliberately.
For phone and voice features: explicit consent before any recording. Storage in the EU only. Retention configurable — default 90 days.
Certification.
- Today EU hosting Frankfurt, GDPR-ready, DPAs standard.
- Planned External penetration test.
- Mid-term TISAX when needed, SOC 2 in preparation.
- Long-term ISO 27001 targeted.