08 Data sovereignty

Hosting in Germany, AI off by default.

Your application data sits on servers in Germany. AI is off by default, so without your release no content leaves the system. Switch it on and the package you picked states openly who processes, in which jurisdiction, and whether your content is used for training.

Data in Germany

Application data on German servers, data processing agreement included.

AI off on delivery

Without your release no content leaves the system.

In black and white

Jurisdiction and training use appear verbatim in your data processing agreement.

Released per object

What becomes searchable is up to you to release, for conversations one by one.

Five jurisdiction tiers
  1. 01 A model you run yourself, nothing leaves your system
  2. 02 European provider, processing in the EU
  3. 03 EU region, non-European provider
  4. 04 EU provider, processing in a third country
  5. 05 Provider and processing outside the EU
// Step by step

How this works

01
The data sits in Germany

The application data sits on German servers, the data processing agreement comes with it and costs nothing extra.

02
The AI is off

As delivered, nothing computes. Until someone in your organisation switches the AI on, no content leaves the system, not even to try it out.

03
You choose the jurisdiction

When switching it on you decide where the computing happens. The tiers run from a self-hosted model to a provider outside the EU, and they are named rather than hidden behind the word "secure".

04
Release per object

What becomes searchable, you release. Meetings one at a time, so a confidential conversation does not slip into the chat because someone opened up an area.

// Honestly

What it does not do

Two points where others tend to go vague.

  • The bottom tier does not hide itself. Choose a provider outside the EU and it says so, instead of being wrapped up as "globally available".
  • Running it on your own infrastructure is available on request only, not as self-service.
// Frequently asked

What people ask at this point

Is this enough for a public-sector client of mine?
Their procurement office decides that, not us. What you get are the facts they will ask for: where the application data sits, who processes it, which AI provider under which jurisdiction is configured, and a contract that says so.
What exactly does "AI off by default" mean?
That a fresh account runs no AI feature until someone with the necessary rights switches it on and picks a provider. There is no preview mode that sends content off beforehand.
And if I have to get stricter later?
Then you move to a tier with a narrower jurisdiction. That is a setting, not a migration, and what has already been written stays where it is.

Look at it
rather than take our word for it.

Productive in under 5 minutes. No sales loop.