Skip to content

Data security

Where your data lives —
and who has access

Everyone writes "GDPR-compliant". Here is what that concretely means at AIVANCE — with locations, contracts and retention periods instead of claims.

Hosting locations, by name

Your data stays in its jurisdiction: clients based in Germany and the EU are hosted on European servers, clients based in the USA on US servers. No processing takes place outside the respective region.

Hetzner Online GmbH

Data centers in Nuremberg & Falkenstein, Germany. The default for client systems with personal data from the EU.

Amazon Web Services (EU)

Region eu-central-1 (Frankfurt am Main). For systems that require AWS services — data stays in the EU.

Amazon Web Services (USA)

US region, exclusively for clients based in the USA. Contracts and safeguards follow US law instead of the GDPR.

We only use other locations at your explicit request — never silently.

Data processing under Art. 28 GDPR

Before we receive access to personal data, we conclude a data processing agreement (DPA) with you. It governs purpose, duration, sub-processors and your rights of control.

Request DPA template →

You receive the template in advance for review by your data protection officer — before any engagement.

Technical and organizational measures (Art. 32 GDPR)

We provide the full TOM documentation together with the DPA — also for your record of processing activities.

No model training on client data

Where we use AI models, we choose access routes where the provider contractually guarantees not to use your data for training its models:

Anthropic (Claude) — Commercial Terms

No training on customer content via the commercial API. Processing on the basis of a Data Processing Agreement.

OpenAI — API / Enterprise terms

Under the Business Terms, API data is not used for model training. We use the API only, never consumer products.

AWS Bedrock (EU region)

Model calls never leave the chosen region and are not used for training — governed by the AWS Service Terms.

Which providers are concretely used in your project is named in the DPA — including the respective contract clause.

Deletion concept and retention

Type of data Period
Contact inquiries without an engagementDeleted after conclusion, at the latest after 24 months
Project data after contract endReturn or deletion, your choice — proof on request
BackupsAutomatically overwritten after a defined cycle (project-dependent, set out in the DPA)
Invoice-relevant dataStatutory retention periods (German HGB/AO)

For professionals bound by confidentiality law: Section 203 StGB and Section 62 StBerG

Physicians and tax advisors in Germany may only involve service providers under extended conditions: professional confidentiality under Section 203 StGB also applies towards IT providers, and Section 62 StBerG requires the provider's written commitment to secrecy.

That is why every practice and firm project at AIVANCE includes:

  • Written confidentiality commitment of all contributors under Section 203 (3) StGB or Section 62 StBerG — before we receive access
  • Data processing agreement under Art. 28 GDPR with named sub-processors
  • Processing of patient or client data exclusively on servers in Germany or the EU
  • Documented safeguards for your own accountability obligations (Art. 9, Art. 32 GDPR)

These statements describe our technical and contractual measures. They are not legal advice.

Contact for data protection

Questions about data processing, the DPA or TOMs are answered directly by:

Ajay Nagulendran

Co-Founder · Engineering & operations

ajay.nagulendran@ai-vance.de
Next step

Data protection questions first?

Especially for practices and firms: we're happy to answer the compliance questions before the first conversation about technology.