Security and compliance

ISO 27001, DPA, hosting in the EU.

The contracting party is aiio GmbH in Magdeburg. Certified to ISO/IEC 27001, certificate 02260301-01, valid until 4 June 2029. Hosting and storage are within the European Union; processing in the USA covers sign-in depending on the product, error logging, and any AI providers chosen. Data processing under Art. 28 GDPR, including technical and organizational measures.

Documents and agreements.

All of it without a form, without a sales conversation, downloadable directly.

  • ISO/IEC 27001 certificatePDF · German/English · EN ISO/IEC 27001:2023 · certificate 02260301-01 · issued 5 June 2026 · valid until 4 June 2029

    The certifying body's document. Scope: development, operation and maintenance of cloud-based B2B solutions for organizational modelling, management and analysis.

    Download PDFDirect download
  • Operations and IT security conceptPDF · German · version 3.0 · as of 14 August 2025 · 17 pages

    Architecture, roles and permissions, data backup, deletion concept, tenant separation, encryption, logging, contingency plan. Answers most security questionnaires.

    Download PDFDirect download
  • Data processing agreement (DPA)PDF · DE/EN · Art. 28 GDPR

    The annex under Art. 28(3) GDPR in the version aiio signs. Includes the technical and organizational measures as an annex.

    Download PDFDirect download
  • List of sub-processorsPDF · DE/EN · valid from 1 August 2026

    Who is involved, for what, in which country and on what legal basis. New sub-processors are announced with a four-week objection period.

    Download PDFDirect download
  • General SaaS termsPDF · DE/EN · as of 1 June 2025

    Scope of service, availability, terms, remuneration. Plus return and deletion of the data at the end of the contract.

    Download PDFDirect download
  • Functional specificationPDF · German · as of 15 June 2026

    Which functions belong to the product — the contractual basis for what is owed.

    Download PDFDirect download
  • General terms of engagementPDF · DE/EN · 8 pages

    For rollout, training and workshops. Independent of the SaaS contract.

    Download PDFDirect download
  • Supplier self-disclosure

    The procurement questionnaire gets filled in and countersigned. For the common catalogues the answers are already on file.

  • Privacy policy

    Processing on this website: purposes, legal bases, retention, data subject rights.

    OpenPublic
  • Register details and representation

    Company name, address, register court, HRB number, VAT ID, management.

    OpenPublic

A document missing? ask for it →

Where the data sits.

Hosting and storage are in the EU. Three things process in the USA: sign-in depending on the product, error logging, the AI providers only by choice. Operations, development and support run out of one company in Magdeburg — no chain of holdings, no reseller, no offshore provider in between.

Platform
Microsoft Azure and AWS, regions within the EUThe tools do not all run in the same environment: depending on the product, Microsoft or AWS operates the data centre environment. Both are listed as sub-processors — Microsoft Ireland Operations and AWS EMEA SARL, place of processing EU. The Azure environment is a dedicated tenant with a Kubernetes cluster, MySQL and Redis in a closed virtual network. Which environment applies to a given product is stated in the hosting and infrastructure data sheet.
Storage location
Servers within the European UnionThree exceptions, and they carry different weight: sign-in processes in the USA depending on the product (see the “Sign-in” row below), error logging sits in a European data region controlled by a US company (see “Error logging”), the optional AI functions only where the organization picks a provider outside the EU.
Encryption
AES-256 at rest, TLS 1.2+ in transitVirtual disks, backups and snapshots are encrypted — so is internal communication between the services.
Backup
Daily, 30 days, geo-redundantAutomatic database backups, replicated into a geographically separate partner region. Backup files are deleted after 30 days, earlier on request.
Tenant separation
Every record belongs to exactly one tenantEvery request is filtered on the tenant identifier. The identifier is issued by the authentication service — by Microsoft Entra in the Azure environment — and cannot be altered from within the application.
Sign-in
SSO and multi-factor via Entra ID or Clerk — Clerk processes in the USAWhich service applies depends on the product. Clerk Inc. processes sign-in data in the USA, on the basis of the Data Privacy Framework — Clerk is certified — and standard contractual clauses under Art. 46 GDPR; listed that way in Annex 1, section 1.5. Unlike the AI functions there is nothing to switch off here: no sign-in, no use. Password policies and multi-factor stay in the hands of the organization — aiio enforces whatever is configured in its own directory, and stores no credentials.
Error logging
Sentry — European data region, controlled from the USAWhat gets recorded is technical error and performance data of the application; user and organization identifiers, IP addresses and requested URLs can occur in it. Content of the process documentation is not transmitted — server-side filtering limits the transfer to what error analysis requires. The operator is Functional Software, Inc. d/b/a Sentry, San Francisco, listed in Annex 1 under section 1.6; the basis is the Data Privacy Framework and standard contractual clauses under Art. 46 GDPR.
Deletion
At any time, with a recordAfter deletion, a deletion record goes to the organization. At the end of a contract the data is deleted at the latest on uninstallation, immediately where instructed.
Export
PDF, SVG, CSV, Excel, APIProcesses, org charts, process lists, requirements, resources, sites and staff. A change of provider does not founder on the format.

All details in the operations and IT security concept: Download PDF →

What the AI does with the data.

The AI functions are off by default. Only once they have been switched on and a provider selected is any content transmitted — until then nothing leaves the environment.

Choice of provider
Made by the organization, not by aiioThe options are OpenAI, OpenAI via Azure, Anthropic, Google Vertex AI, Groq and Mistral. Without an explicit selection, no data goes to any of them. A newly added provider does not change an existing configuration.
Model training
Does not happen on customer contentContractually assured for every listed provider: no use of the transmitted content for training or model improvement purposes.
Personal data
Is not transmitted to the AI servicesProcessing personal data is not the purpose. Where uploaded documents contain it, it is processed incidentally — aiio recommends pseudonymizing beforehand.
Data residency
Frankfurt selectableOpenAI via Azure runs in the Germany West Central region, Google Vertex AI in europe-west3 — both without third-country transfer. Mistral processes within the EEA. OpenAI directly, Anthropic and Groq process in the USA under standard contractual clauses.
Retention at the provider
Zero data retention configurableWhere the provider offers it, it is used. Otherwise the contractually agreed period applies — with OpenAI and Mistral up to 30 days for abuse monitoring, with Groq no retention of inference data.
Transparency
Its use is visible in the productWherever an AI function is at work, that is apparent to the user. Every statement in a representation leads back to the document it came from.
Role under the AI Act
Provider of an AI systemProcess analysis, summarization and versioning fall, by our own assessment, into none of the high-risk categories of the AI Act. The underlying foundation models are subject to the GPAI requirements at their own providers.

Sub-processor agreements.

Every data processing agreement aiio has concluded with a sub-processor is published — including those with the AI providers.

  • Amazon Web ServicesDPA · as of 16 February 2026

    Hosting and data centre environment. AWS EMEA SARL, Luxembourg, place of processing EU.

    Download PDFDirect download
  • MicrosoftData Protection Addendum

    Hosting, authentication and Azure OpenAI services. Microsoft Ireland Operations, Dublin.

    OpenPublic
  • OpenAIDPA · signed

    AI provider, usable directly. OpenAI Ireland Ltd., processing in the USA under standard contractual clauses.

    Download PDFDirect download
  • AnthropicDPA · as of 22 September 2023

    AI provider. Anthropic Ireland Ltd., processing in the USA under standard contractual clauses, no training on customer content.

    Download PDFDirect download
  • GoogleData Processing Addendum

    AI provider Vertex AI. Google Cloud EMEA, processing in the Frankfurt data centre.

    OpenPublic
  • GroqDPA

    AI provider. Groq Inc., processing in the USA under standard contractual clauses, inference data is not retained.

    Download PDFDirect download
  • MistralData Processing Addendum

    AI provider. Mistral AI SAS, Paris, processing within the EEA.

    OpenPublic
  • ClerkDPA

    Authentication platform. Clerk Inc., USA, Data Privacy Framework and standard contractual clauses.

    OpenPublic
  • Aikido SecurityDPA · v1.3 · valid from 1 August 2025

    Security monitoring of the cloud infrastructure and of software development. Aikido Security bv, Ghent, Belgium, place of processing EU. What is processed is configuration, source code and telemetry data of the platform; incoming requests are inspected for injection and events are reported to the Aikido cloud with IP addresses. Processing personal data of the client is not the purpose.

    Download PDFDirect download
  • SentryDPA · signed 12 August 2026

    Application monitoring and error logging. Functional Software, Inc. d/b/a Sentry, San Francisco, European data region and USA, Data Privacy Framework and standard contractual clauses. User and organization identifiers, IP addresses and requested URLs can occur; content of the process documentation is not transmitted.

    Download PDFDirect download
  • ZohoDPA · signed

    Customer data management. Zoho Corporation GmbH, Düsseldorf, processing in Amsterdam and Dublin.

    Download PDFDirect download
  • DATEVDPA · as of 1 January 2025

    Customer data management for accounting. DATEV eG, Nuremberg, processing in Germany.

    Download PDFDirect download

The complete list with purpose, location and legal basis: Download PDF →

Commitments and limits.

Every commitment here also stands in the contract. Beside it stands where it ends.

Hosting and storage are in the EU.Three things process in the USA. Sign-in, wherever it runs through Clerk — it cannot be switched off, on the basis of the Data Privacy Framework and standard contractual clauses; which service applies depends on the product. Error logging through Sentry, likewise not optional: the data sits in the European data region, the controller is a US company, the basis is the same set of instruments. The AI providers only by choice: anyone switching on OpenAI directly, Anthropic or Groq processes there. For processing exclusively in Germany there are Azure OpenAI and Google Vertex, both Frankfurt.
Customer content trains no models.Contractually assured, not technically enforced. What that assurance is worth depends on the provider — which is why their agreements are published and the choice sits with the organization.
Sub-processors are named in advance.Four weeks to object from the announcement in text form. The right comes from the contract, not from goodwill.
The audit right under Art. 28 applies in full.With four to six weeks' notice. Unannounced audits are not admissible, and the audit must not endanger business operations.
The data can be taken along.Including when the contract ends because another tool won. Export in open formats is part of the service, not one of the extras.
Questionnaires get filled in.On the procurement templates. Whatever cannot be answered is marked open rather than left out.

Reporting channels.

Someone answers who knows the installation. No outsourced first level in between.

Security incident
support@aiio.de · 0391 251 948 63A suspicion is enough. Where personal data is affected, the route from the DPA runs in parallel.
Vulnerability
support@aiio.deFrom outside as well. Receipt is confirmed before the finding is resolved.
Data protection
via the contact formAccess, rectification and erasure under Art. 15 to 17 GDPR. For existing customers additionally via the body named in the DPA.
Service disruption
Monday to Friday, business hoursMonitoring catches most disruptions before they are noticed. Resolution time follows the agreed SLA; whoever reported it is kept informed.

The contracting party.

One company, one register entry, one location — no chain of holding, sales and operating entities.

aiio GmbH

Klausenerstraße 10a, 39112 Magdeburg. Amtsgericht Stendal, HRB 6552. VAT ID DE 254461500.

Management

Dr. Christian Graup, Knut Köchli, Jobst von Heintze, Lars Bendler. The representation arrangements are recorded in the commercial register.

ISO/IEC 27001

Certificate 02260301-01, valid until 4 June 2029. The document and its scope are in the documents section.

Registered in 2007

Entered on 18 June 2007, trading under the name aiio since March 2022. Register entry, location and team unchanged.

Operated in the EU

Hosting and storage within the European Union, sign-in and error logging partly in the USA. Seat, development and support in Magdeburg.

Series A funded

Institutionally funded since 2024, eight-figure valuation. For the credit check.

Origins, management and advisory board: to the company →

Something missing?

Whatever is not here is either confidential or does not exist. Ask, and you get told which of the two.

Twenty minutes, no pitch.

Get in touch