Security and compliance
ISO 27001, DPA, hosting in the EU.
The contracting party is aiio GmbH in Magdeburg. Certified to ISO/IEC 27001, certificate 02260301-01, valid until 4 June 2029. All customer data sits on servers within the European Union. Data processing under Art. 28 GDPR, including technical and organizational measures.
Documents and agreements.
All of it without a form, without a sales conversation, downloadable directly.
- ISO/IEC 27001 certificateCertificate 02260301-01 · valid until 4 June 2029
The certifying body's document, with the scope: which sites and which processes are certified.
RequestOn request - Operations and IT security conceptPDF · German · version 3.0 · as of 14 August 2025 · 17 pages
Architecture, roles and permissions, data backup, deletion concept, tenant separation, encryption, logging, contingency plan. Answers most security questionnaires.
Download PDFDirect download - Data processing agreement (DPA)PDF · DE/EN · Art. 28 GDPR
The annex under Art. 28(3) GDPR in the version aiio signs. Includes the technical and organizational measures as an annex.
Download PDFDirect download - List of sub-processorsPDF · DE/EN · valid from 15 June 2026
Who is involved, for what, in which country and on what legal basis. New sub-processors are announced with a four-week objection period.
Download PDFDirect download - General SaaS termsPDF · DE/EN · as of 1 June 2025
Scope of service, availability, terms, remuneration. Plus return and deletion of the data at the end of the contract.
Download PDFDirect download - Functional specificationPDF · German · as of 15 June 2026
Which functions belong to the product — the contractual basis for what is owed.
Download PDFDirect download - General terms of engagementPDF · DE/EN · 8 pages
For rollout, training and workshops. Independent of the SaaS contract.
Download PDFDirect download - Supplier self-disclosure
The procurement questionnaire gets filled in and countersigned. For the common catalogues the answers are already on file.
Send questionnaireOn request - Privacy policy
Processing on this website: purposes, legal bases, retention, data subject rights.
OpenPublic - Register details and representation
Company name, address, register court, HRB number, VAT ID, management.
OpenPublic
A document missing? ask for it →
Where the data sits.
All customer data sits on servers in the EU. Operations, development and support run out of one company in Magdeburg — no chain of holdings, no reseller, no offshore provider in between.
- Platform
- Microsoft Azure, West Europe regionA dedicated Azure tenant with a Kubernetes cluster, MySQL and Redis in a closed virtual network. The data centre environments are operated by Microsoft Ireland Operations and AWS EMEA, place of processing EU.
- Storage location
- Servers within the European UnionThe exception is the optional AI functions: depending on the provider chosen, a transfer to a third country can take place there. The organization makes that choice itself.
- Encryption
- AES-256 at rest, TLS 1.2+ in transitVirtual disks, backups and snapshots via Azure Storage Service Encryption. Internal communication between the services is encrypted as well.
- Backup
- Daily, 30 days, geo-redundantAutomatic database backups, replicated into a geographically separate partner region. Backup files are deleted after 30 days, earlier on request.
- Tenant separation
- Via the tenant ID from Microsoft EntraEvery record is assigned to a tenant, and every request is filtered on it. The tenant information is issued by the Microsoft authentication servers and cannot be altered.
- Sign-in
- Microsoft Entra ID, SSOPassword policies and multi-factor stay in the hands of the organization: aiio enforces whatever is configured in its own tenant, and stores no credentials.
- Deletion
- At any time, with a recordAfter deletion, a deletion record goes to the organization. At the end of a contract the data is deleted at the latest on uninstallation, immediately where instructed.
- Export
- PDF, SVG, CSV, Excel, APIProcesses, org charts, process lists, requirements, resources, sites and staff. A change of provider does not founder on the format.
All details in the operations and IT security concept: Download PDF →
What the AI does with the data.
The AI functions are off by default. Only once they have been switched on and a provider selected is any content transmitted — until then nothing leaves the environment.
- Choice of provider
- Made by the organization, not by aiioThe options are OpenAI, OpenAI via Azure, Anthropic, Google Vertex AI, Groq and Mistral. Without an explicit selection, no data goes to any of them. A newly added provider does not change an existing configuration.
- Model training
- Does not happen on customer contentContractually assured for every listed provider: no use of the transmitted content for training or model improvement purposes.
- Personal data
- Is not transmitted to the AI servicesProcessing personal data is not the purpose. Where uploaded documents contain it, it is processed incidentally — aiio recommends pseudonymizing beforehand.
- Data residency
- Frankfurt selectableOpenAI via Azure runs in the Germany West Central region, Google Vertex AI in europe-west3 — both without third-country transfer. Mistral processes within the EEA. OpenAI directly, Anthropic and Groq process in the USA under standard contractual clauses.
- Retention at the provider
- Zero data retention configurableWhere the provider offers it, it is used. Otherwise the contractually agreed period applies — with OpenAI and Mistral up to 30 days for abuse monitoring, with Groq no retention of inference data.
- Transparency
- Its use is visible in the productWherever an AI function is at work, that is apparent to the user. Every statement in a representation leads back to the document it came from.
- Role under the AI Act
- Provider of an AI systemProcess analysis, summarization and versioning fall, by our own assessment, into none of the high-risk categories of the AI Act. The underlying foundation models are subject to the GPAI requirements at their own providers.
Sub-processor agreements.
Every data processing agreement aiio has concluded with a sub-processor is published — including those with the AI providers.
- Amazon Web ServicesDPA · as of 16 February 2026
Hosting and data centre environment. AWS EMEA SARL, Luxembourg, place of processing EU.
Download PDFDirect download - MicrosoftData Protection Addendum
Hosting, authentication and Azure OpenAI services. Microsoft Ireland Operations, Dublin.
OpenPublic - OpenAIDPA · signed
AI provider, usable directly. OpenAI Ireland Ltd., processing in the USA under standard contractual clauses.
Download PDFDirect download - AnthropicDPA · as of 22 September 2023
AI provider. Anthropic Ireland Ltd., processing in the USA under standard contractual clauses, no training on customer content.
Download PDFDirect download - GoogleData Processing Addendum
AI provider Vertex AI. Google Cloud EMEA, processing in the Frankfurt data centre.
OpenPublic - GroqDPA
AI provider. Groq Inc., processing in the USA under standard contractual clauses, inference data is not retained.
Download PDFDirect download - MistralData Processing Addendum
AI provider. Mistral AI SAS, Paris, processing within the EEA.
OpenPublic - ClerkDPA
Authentication platform. Clerk Inc., USA, Data Privacy Framework and standard contractual clauses.
OpenPublic - ZohoDPA · signed
Customer data management. Zoho Corporation GmbH, Düsseldorf, processing in Amsterdam and Dublin.
Download PDFDirect download - DATEVDPA · as of 1 January 2025
Customer data management for accounting. DATEV eG, Nuremberg, processing in Germany.
Download PDFDirect download
The complete list with purpose, location and legal basis: Download PDF →
Commitments and limits.
Every commitment here also stands in the contract. Beside it stands where it ends.
Reporting channels.
Someone answers who knows the installation. No outsourced first level in between.
- Security incident
- support@aiio.de · 0391 251 948 63A suspicion is enough. Where personal data is affected, the route from the DPA runs in parallel.
- Vulnerability
- support@aiio.deFrom outside as well. Receipt is confirmed before the finding is resolved.
- Data protection
- via the contact formAccess, rectification and erasure under Art. 15 to 17 GDPR. For existing customers additionally via the body named in the DPA.
- Service disruption
- Monday to Friday, business hoursMonitoring catches most disruptions before they are noticed. Resolution time follows the agreed SLA; whoever reported it is kept informed.
The contracting party.
One company, one register entry, one location — no chain of holding, sales and operating entities.
Klausenerstraße 10a, 39112 Magdeburg. Amtsgericht Stendal, HRB 6552. VAT ID DE 254461500.
Dr. Christian Graup, Knut Köchli, Jobst von Heintze, Lars Bendler. The representation arrangements are recorded in the commercial register.
Certificate 02260301-01, valid until 4 June 2029. Document and scope on request.

Entered on 18 June 2007, trading under the name aiio since March 2022. Register entry, location and team unchanged.
Customer data on servers within the European Union. Seat, development and support in Magdeburg.
Institutionally funded since 2024, eight-figure valuation. For the credit check.
Origins, management and advisory board: to the company →
Something missing?
Whatever is not here is either confidential or does not exist. Ask, and you get told which of the two.