Security & Compliance

Security you
can trust

GDPR compliant, EU AI Act ready, hosted in Germany. Full transparency on infrastructure, encryption and data flows.

99.9%

Uptime SLA

Frankfurt, DE

Hosting location

DE/EU

Core operations

GDPR

DPA & TOMs

GDPR compliance

EuGPT was built from the ground up for GDPR-oriented use. Core self-hosted inference runs in Germany; optional external services and providers are documented and only used once configured.

Germany/EU by default

Core self-hosted inference runs by default on servers in Germany. Optional external providers are clearly labelled and must be activated to match your desired data protection and region setup.

DPA available

We provide a complete data processing agreement (DPA) pursuant to Art. 28 GDPR — customised on request.

Zero-Training Policy

Your data belongs to you. We do not use your inputs and documents to train our models.

Self-hosted inference in Germany

EuGPT’s own self-hosted models run on GPU infrastructure in our Frankfurt data centre. External models are labelled separately.

Deletion policy

Transparent deletion policy with defined retention periods. Chat histories can be deleted completely at any time.

EU AI Act — governance prepared

The EU AI Act introduces new requirements for providers and deployers of AI systems. EuGPT supports transparency, documentation and risk assessment; the specific risk category depends on the customer’s intended use.

Transparent model information

We favour traceable models and provide model information, vendor details and version data wherever available.

Risk assessment

Risk assessment aligned with the EU AI Act categories — including guidance on when your specific use case needs separate review.

Documentation available

Technical documentation, model cards and usage guidelines are provided wherever available for the model and provider.

Support for users

EuGPT provides building blocks for your own EU AI Act documentation. Deployer obligations remain dependent on your specific use case.

Infrastructure & encryption

Dedicated GPU infrastructure in our Frankfurt data centre — operated by intercolo GmbH. External models and providers are optional and clearly separated from self-hosted operations.

TLS 1.3

Encrypted data transmission using the latest standard

AES-256

Encryption of all data at rest

Access control

Role-based access control & multi-factor authentication

24/7 Monitoring

Real-time monitoring of all systems and anomaly detection

Documents

Certificates & downloads

All the documents you need for your compliance review

→ Full compliance hub with subprocessor table, TOMs preview and EU AI Act classification

DPA

Data processing agreement (DPA) pursuant to Art. 28 GDPR

Available on request

Technical documentation

Technical and organisational measures (TOMs)

Available on request

Privacy policy

Full privacy policy for EuGPT

View page

Still have questions?

Our team is happy to answer any questions about data protection, security and compliance. Get in touch.