Hosting in Germany
The platform and all stored customer data are hosted by Hetzner in Falkenstein and Nuremberg. Encrypted backups are kept separately at OVH in Germany and France.
InfrastructureEverything about security, privacy and compliance in one place.
Here you will find our agreements, the service providers involved, our security measures and answers to the questions data protection officers and IT security ask us most often.
Overview
Six commitments that are written into our agreements. You will find the details on the linked page.
The platform and all stored customer data are hosted by Hetzner in Falkenstein and Nuremberg. Encrypted backups are kept separately at OVH in Germany and France.
InfrastructureNames, addresses, identifiers and other personal data are replaced by placeholders before any text is sent to an external AI model. The mapping stays encrypted with us.
Secure anonymizationWe never use your content for our own purposes. We connect external models only through business interfaces with a data processing agreement that do not use inputs for training.
Sub-processorsFor law firms, medical practices, clinics and tax advisers we additionally commit under § 203 German Criminal Code and the professional rules, with a dedicated confidentiality agreement.
Confidentiality agreementEnforce pseudonymization and manual approval, release models per workspace, set retention from immediate deletion to unlimited, log access.
ComplianceWith anymize's own models you process content on our infrastructure in Germany without any external model provider being involved.
anymize modelsDocuments
Public documents can be downloaded directly. We send confidential documents on request.
Version 1.5 · as of 24 September 2026 · German
Agreement under Art. 28 GDPR. Applies automatically when you accept the terms; a countersigned copy is available on request.
Annex 2 to the DPA · as of 24 September 2026 · German
All service providers involved, with purpose, place of processing and safeguards.
Overview
Which component runs where: in Germany, in the EU and at external models you choose.
Version 2.4 · as of 21 September 2026 · German
Under § 203 German Criminal Code, § 43e BRAO, § 62a StBerG and further professional rules in Germany, Austria and Switzerland.
Version 2.3 to 2.4 · German
Side-by-side comparison of both versions with the reason for each change.
Version 1.0 · as of 24 September 2026 · for financial entities · German
Supplementary agreement under Art. 30 DORA: locations, information security, incident notification, business continuity, exit, audit and termination rights. Acceptance by email is sufficient.
Version 3.1 · Annex 1 to the DPA · confidential · German
Complete documentation of the measures under Art. 32 GDPR.
Version 1.3 · confidential · German
Architecture, key management, processing paths and contingency planning in detail.
completed · confidential · German
Answers to the usual security questionnaires for supplier reviews.
as of 24 September 2026
Contractual basis for using anymize, with an archive of previous versions.
Version 1.6 · as of 24 September 2026
How we process personal data on the website and in the service.
per industry · printable · German
The key facts for the review by your data protection officer, in the GDPR roadmap per industry.
Security measures
The core measures from Annex 1 of our data processing agreement. You can request the complete documentation.
Sub-processors
Permanent service providers are involved in every use. Usage-dependent ones only act when an external model or web search is chosen. Purpose, location and safeguards per provider are in the full list (German).
Permanent
Usage-dependent
On data storage, agreements and security.
In Germany. The platform and all stored customer data are hosted by Hetzner Online GmbH in its Falkenstein and Nuremberg data centers. Encrypted backups are kept on separate infrastructure of OVH GmbH in Germany and France, i.e. within the EU. We store the mapping between placeholders and original values for the retention period you choose, as well as extracted content and chat histories, encrypted in your workspace until you delete them. Original files are not stored in their original form. Only when you choose an external AI model is the pseudonymized text sent to its provider. All service providers involved: sub-processors (/legal/unterauftragsverarbeiter).
Updates
Banks, insurers, payment service providers and other financial entities receive the contractual commitments under Art. 30 DORA in a dedicated supplementary agreement: locations, incident notification within 24 hours, business continuity, exit, audit and termination rights. Acceptance by email is sufficient.
To the addendum (PDF, German)EU-hosted models run through the AI gateway of Requesty Ltd with an EU endpoint in Frankfurt am Main. Perplexity AI (web search and models with web search) and xAI (Grok) have been added. The OpenRouter relay service is no longer used.
To the listWith our opening to healthcare we have extended the DPA (version 1.5), the terms and the privacy policy (version 1.6): more rights as controller, initial incident notification within 24 hours and full transparency about every service provider.
To the DPAThe agreement now describes storage, key management and processing paths precisely and covers deletion confirmations and requests from authorities.
To the agreementContact
Our team and our data protection officer answer questions from customers, data protection officers and auditors. We send confidential documents after a brief review.