Trust and compliance
The compliance pack for your data protection officer. Every proof, ready to download.
The compliance pack
- Data processing agreement (Art. 28 GDPR)
- Technical and organisational measures (TOM)
- Subprocessor list
- Professional secrecy undertaking (Section 203 German Criminal Code)
- GoBD statement
Where your data lives
- Backend hosting in Frankfurt am Main.
- Database and object storage (S3/MinIO) in the EU.
- Print centres EU-bound: LetterXPress in Germany for German letters, Pingen for Austria, Switzerland and international.
- Delivery by post: in Germany through Deutsche Post DHL, internationally through local postal partners.
- US subprocessors (Stripe, OpenAI) only under Standard Contractual Clauses (SCC) plus a documented transfer impact assessment.
- Logging via Axiom in the EU.
- For German letters the print centre is in Germany. See the subprocessor list for detail.
Compliance questions?
Write to us and we usually reply within two business days. We do not promise a ticketing system, just a real answer.