Trust Center

Everything about security, privacy and compliance in one place.

Here you will find our agreements, the service providers involved, our security measures and answers to the questions data protection officers and IT security ask us most often.

Overview

What you can rely on.

Six commitments that are written into our agreements. You will find the details on the linked page.

Hosting in Germany

The platform and all stored customer data are hosted by Hetzner in Falkenstein and Nuremberg. Encrypted backups are kept separately at OVH in Germany and France.

Infrastructure

Pseudonymization before external models

Names, addresses, identifiers and other personal data are replaced by placeholders before any text is sent to an external AI model. The mapping stays encrypted with us.

Secure anonymization

No training on your data

We never use your content for our own purposes. We connect external models only through business interfaces with a data processing agreement that do not use inputs for training.

Sub-processors

Protection of professional secrecy

For law firms, medical practices, clinics and tax advisers we additionally commit under § 203 German Criminal Code and the professional rules, with a dedicated confidentiality agreement.

Confidentiality agreement

Control for your administrators

Enforce pseudonymization and manual approval, release models per workspace, set retention from immediate deletion to unlimited, log access.

Compliance

Own models without third parties

With anymize's own models you process content on our infrastructure in Germany without any external model provider being involved.

anymize models

Evidence and status

  • GDPR · data processing agreement under Art. 28anymize GmbHActive
  • Confidentiality under § 203 StGB and § 43e BRAOanymize GmbHActive
  • DORA · addendum under Art. 30anymize GmbHActive
  • ISO/IEC 27001:2022Hetzner data centersActive
  • BSI C5:2020 Type 2 attestationHetzner data centersActive
  • ISO 27001, SOC 2 Type II, BSI C5anymize platformIn preparation
Certification roadmap

Documents

All documents to download.

Public documents can be downloaded directly. We send confidential documents on request.

  • Data Processing Agreement (DPA)

    Version 1.5 · as of 24 September 2026 · German

    Agreement under Art. 28 GDPR. Applies automatically when you accept the terms; a countersigned copy is available on request.

  • List of sub-processors

    Annex 2 to the DPA · as of 24 September 2026 · German

    All service providers involved, with purpose, place of processing and safeguards.

  • Data flow

    Overview

    Which component runs where: in Germany, in the EU and at external models you choose.

  • Confidentiality agreement for professionals bound by secrecy

    Version 2.4 · as of 21 September 2026 · German

    Under § 203 German Criminal Code, § 43e BRAO, § 62a StBerG and further professional rules in Germany, Austria and Switzerland.

  • Change log for the confidentiality agreement

    Version 2.3 to 2.4 · German

    Side-by-side comparison of both versions with the reason for each change.

  • DORA addendum

    Version 1.0 · as of 24 September 2026 · for financial entities · German

    Supplementary agreement under Art. 30 DORA: locations, information security, incident notification, business continuity, exit, audit and termination rights. Acceptance by email is sufficient.

  • Technical and organisational measures (TOM)

    Version 3.1 · Annex 1 to the DPA · confidential · German

    Complete documentation of the measures under Art. 32 GDPR.

  • Security concept

    Version 1.3 · confidential · German

    Architecture, key management, processing paths and contingency planning in detail.

  • Security questionnaire

    completed · confidential · German

    Answers to the usual security questionnaires for supplier reviews.

  • Terms and Conditions

    as of 24 September 2026

    Contractual basis for using anymize, with an archive of previous versions.

  • Privacy Policy

    Version 1.6 · as of 24 September 2026

    How we process personal data on the website and in the service.

  • Handout for data protection officers

    per industry · printable · German

    The key facts for the review by your data protection officer, in the GDPR roadmap per industry.

Security measures

What we do technically and organisationally.

The core measures from Annex 1 of our data processing agreement. You can request the complete documentation.

Encryption

  • TLS 1.3 for all data transfers
  • AES-256 for stored content and mappings, with keys per workspace
  • Keys kept separately from the data

Infrastructure and availability

  • Production systems in certified data centers in Germany (ISO/IEC 27001, BSI C5)
  • Daily encrypted backups on separate infrastructure in the EU
  • Recovery in under 4 hours, data loss of 24 hours at most, tested regularly

Access

  • Logical separation per workspace, role-based permissions
  • No plain-text access by staff in regular operation
  • Two-factor authentication and VPN for administration, all access logged

Organisation

  • All staff bound to confidentiality and under § 203 (4) StGB
  • Annual training on data protection and information security
  • Initial notification of personal data breaches within 24 hours
  • Annual review of all sub-processors

Product

  • Pseudonymization before any processing by external models
  • Administrators can enforce pseudonymization and approval
  • Selectable retention periods, original files not stored in their original form

Sub-processors

Who is involved in processing.

Permanent service providers are involved in every use. Usage-dependent ones only act when an external model or web search is chosen. Purpose, location and safeguards per provider are in the full list (German).

Permanent

  • Hetzner Online GmbH
  • OVH GmbH
  • GRVITY GmbH
  • Stripe, Inc. / Stripe Technology Europe Ltd.

Usage-dependent

  • Requesty Ltd
  • OpenAI Ireland Ltd.
  • Anthropic, PBC
  • Google LLC
  • Mistral AI SAS
  • Perplexity AI, Inc.
  • SpaceXAI LLC (xAI)

Frequently asked questions

On data storage, agreements and security.

In Germany. The platform and all stored customer data are hosted by Hetzner Online GmbH in its Falkenstein and Nuremberg data centers. Encrypted backups are kept on separate infrastructure of OVH GmbH in Germany and France, i.e. within the EU. We store the mapping between placeholders and original values for the retention period you choose, as well as extracted content and chat histories, encrypted in your workspace until you delete them. Original files are not stored in their original form. Only when you choose an external AI model is the pseudonymized text sent to its provider. All service providers involved: sub-processors (/legal/unterauftragsverarbeiter).

Updates

What has changed.

  • 24 Sep 2026DORA

    DORA addendum for financial entities

    Banks, insurers, payment service providers and other financial entities receive the contractual commitments under Art. 30 DORA in a dedicated supplementary agreement: locations, incident notification within 24 hours, business continuity, exit, audit and termination rights. Acceptance by email is sufficient.

    To the addendum (PDF, German)
  • 24 Sep 2026Sub-processors

    Updated list of sub-processors

    EU-hosted models run through the AI gateway of Requesty Ltd with an EU endpoint in Frankfurt am Main. Perplexity AI (web search and models with web search) and xAI (Grok) have been added. The OpenRouter relay service is no longer used.

    To the list
  • 24 Sep 2026Legal documents

    New versions for medical practices, clinics and all customers

    With our opening to healthcare we have extended the DPA (version 1.5), the terms and the privacy policy (version 1.6): more rights as controller, initial incident notification within 24 hours and full transparency about every service provider.

    To the DPA
  • 21 Sep 2026Professional secrecy

    Confidentiality agreement version 2.4

    The agreement now describes storage, key management and processing paths precisely and covers deletion confirmations and requests from authorities.

    To the agreement

Contact

Questions about privacy and security?

Our team and our data protection officer answer questions from customers, data protection officers and auditors. We send confidential documents after a brief review.

Privacy and documents
datenschutz@anymize.ai
Report security incidents
security@anymize.ai
Data protection officer
Manuel Langeheinecke, digitalNORD GmbH, Kiel
Provider
anymize GmbH, Schauenburgerstr. 116, 24118 Kiel, Germany