Data security
Where your data lives —
and who has access
Everyone writes "GDPR-compliant". Here is what that concretely means at AIVANCE — with locations, contracts and retention periods instead of claims.
Hosting locations, by name
Your data stays in its jurisdiction: clients based in Germany and the EU are hosted on European servers, clients based in the USA on US servers. No processing takes place outside the respective region.
Hetzner Online GmbH
Data centers in Nuremberg & Falkenstein, Germany. The default for client systems with personal data from the EU.
Amazon Web Services (EU)
Region eu-central-1 (Frankfurt am Main). For systems that require AWS services — data stays in the EU.
Amazon Web Services (USA)
US region, exclusively for clients based in the USA. Contracts and safeguards follow US law instead of the GDPR.
We only use other locations at your explicit request — never silently.
Data processing under Art. 28 GDPR
Before we receive access to personal data, we conclude a data processing agreement (DPA) with you. It governs purpose, duration, sub-processors and your rights of control.
Request DPA template →You receive the template in advance for review by your data protection officer — before any engagement.
Technical and organizational measures (Art. 32 GDPR)
We provide the full TOM documentation together with the DPA — also for your record of processing activities.
No model training on client data
Where we use AI models, we choose access routes where the provider contractually guarantees not to use your data for training its models:
Anthropic (Claude) — Commercial Terms
No training on customer content via the commercial API. Processing on the basis of a Data Processing Agreement.
OpenAI — API / Enterprise terms
Under the Business Terms, API data is not used for model training. We use the API only, never consumer products.
AWS Bedrock (EU region)
Model calls never leave the chosen region and are not used for training — governed by the AWS Service Terms.
Which providers are concretely used in your project is named in the DPA — including the respective contract clause.
Deletion concept and retention
| Type of data | Period |
|---|---|
| Contact inquiries without an engagement | Deleted after conclusion, at the latest after 24 months |
| Project data after contract end | Return or deletion, your choice — proof on request |
| Backups | Automatically overwritten after a defined cycle (project-dependent, set out in the DPA) |
| Invoice-relevant data | Statutory retention periods (German HGB/AO) |
For professionals bound by confidentiality law: Section 203 StGB and Section 62 StBerG
Physicians and tax advisors in Germany may only involve service providers under extended conditions: professional confidentiality under Section 203 StGB also applies towards IT providers, and Section 62 StBerG requires the provider's written commitment to secrecy.
That is why every practice and firm project at AIVANCE includes:
- Written confidentiality commitment of all contributors under Section 203 (3) StGB or Section 62 StBerG — before we receive access
- Data processing agreement under Art. 28 GDPR with named sub-processors
- Processing of patient or client data exclusively on servers in Germany or the EU
- Documented safeguards for your own accountability obligations (Art. 9, Art. 32 GDPR)
These statements describe our technical and contractual measures. They are not legal advice.
Contact for data protection
Questions about data processing, the DPA or TOMs are answered directly by:
Data protection questions first?
Especially for practices and firms: we're happy to answer the compliance questions before the first conversation about technology.