Security and compliance

ISO 27001, DPA, hosting in the EU.

The contracting party is aiio GmbH in Magdeburg. Certified to ISO/IEC 27001, certificate 02260301-01, valid until 4 June 2029. All customer data sits on servers within the European Union. Data processing under Art. 28 GDPR, including technical and organizational measures.

Documents and agreements.

All of it without a form, without a sales conversation, downloadable directly.

  • ISO/IEC 27001 certificateCertificate 02260301-01 · valid until 4 June 2029

    The certifying body's document, with the scope: which sites and which processes are certified.

    RequestOn request
  • Operations and IT security conceptPDF · German · version 3.0 · as of 14 August 2025 · 17 pages

    Architecture, roles and permissions, data backup, deletion concept, tenant separation, encryption, logging, contingency plan. Answers most security questionnaires.

    Download PDFDirect download
  • Data processing agreement (DPA)PDF · DE/EN · Art. 28 GDPR

    The annex under Art. 28(3) GDPR in the version aiio signs. Includes the technical and organizational measures as an annex.

    Download PDFDirect download
  • List of sub-processorsPDF · DE/EN · valid from 15 June 2026

    Who is involved, for what, in which country and on what legal basis. New sub-processors are announced with a four-week objection period.

    Download PDFDirect download
  • General SaaS termsPDF · DE/EN · as of 1 June 2025

    Scope of service, availability, terms, remuneration. Plus return and deletion of the data at the end of the contract.

    Download PDFDirect download
  • Functional specificationPDF · German · as of 15 June 2026

    Which functions belong to the product — the contractual basis for what is owed.

    Download PDFDirect download
  • General terms of engagementPDF · DE/EN · 8 pages

    For rollout, training and workshops. Independent of the SaaS contract.

    Download PDFDirect download
  • Supplier self-disclosure

    The procurement questionnaire gets filled in and countersigned. For the common catalogues the answers are already on file.

  • Privacy policy

    Processing on this website: purposes, legal bases, retention, data subject rights.

    OpenPublic
  • Register details and representation

    Company name, address, register court, HRB number, VAT ID, management.

    OpenPublic

A document missing? ask for it →

Where the data sits.

All customer data sits on servers in the EU. Operations, development and support run out of one company in Magdeburg — no chain of holdings, no reseller, no offshore provider in between.

Platform
Microsoft Azure, West Europe regionA dedicated Azure tenant with a Kubernetes cluster, MySQL and Redis in a closed virtual network. The data centre environments are operated by Microsoft Ireland Operations and AWS EMEA, place of processing EU.
Storage location
Servers within the European UnionThe exception is the optional AI functions: depending on the provider chosen, a transfer to a third country can take place there. The organization makes that choice itself.
Encryption
AES-256 at rest, TLS 1.2+ in transitVirtual disks, backups and snapshots via Azure Storage Service Encryption. Internal communication between the services is encrypted as well.
Backup
Daily, 30 days, geo-redundantAutomatic database backups, replicated into a geographically separate partner region. Backup files are deleted after 30 days, earlier on request.
Tenant separation
Via the tenant ID from Microsoft EntraEvery record is assigned to a tenant, and every request is filtered on it. The tenant information is issued by the Microsoft authentication servers and cannot be altered.
Sign-in
Microsoft Entra ID, SSOPassword policies and multi-factor stay in the hands of the organization: aiio enforces whatever is configured in its own tenant, and stores no credentials.
Deletion
At any time, with a recordAfter deletion, a deletion record goes to the organization. At the end of a contract the data is deleted at the latest on uninstallation, immediately where instructed.
Export
PDF, SVG, CSV, Excel, APIProcesses, org charts, process lists, requirements, resources, sites and staff. A change of provider does not founder on the format.

All details in the operations and IT security concept: Download PDF →

What the AI does with the data.

The AI functions are off by default. Only once they have been switched on and a provider selected is any content transmitted — until then nothing leaves the environment.

Choice of provider
Made by the organization, not by aiioThe options are OpenAI, OpenAI via Azure, Anthropic, Google Vertex AI, Groq and Mistral. Without an explicit selection, no data goes to any of them. A newly added provider does not change an existing configuration.
Model training
Does not happen on customer contentContractually assured for every listed provider: no use of the transmitted content for training or model improvement purposes.
Personal data
Is not transmitted to the AI servicesProcessing personal data is not the purpose. Where uploaded documents contain it, it is processed incidentally — aiio recommends pseudonymizing beforehand.
Data residency
Frankfurt selectableOpenAI via Azure runs in the Germany West Central region, Google Vertex AI in europe-west3 — both without third-country transfer. Mistral processes within the EEA. OpenAI directly, Anthropic and Groq process in the USA under standard contractual clauses.
Retention at the provider
Zero data retention configurableWhere the provider offers it, it is used. Otherwise the contractually agreed period applies — with OpenAI and Mistral up to 30 days for abuse monitoring, with Groq no retention of inference data.
Transparency
Its use is visible in the productWherever an AI function is at work, that is apparent to the user. Every statement in a representation leads back to the document it came from.
Role under the AI Act
Provider of an AI systemProcess analysis, summarization and versioning fall, by our own assessment, into none of the high-risk categories of the AI Act. The underlying foundation models are subject to the GPAI requirements at their own providers.

Sub-processor agreements.

Every data processing agreement aiio has concluded with a sub-processor is published — including those with the AI providers.

  • Amazon Web ServicesDPA · as of 16 February 2026

    Hosting and data centre environment. AWS EMEA SARL, Luxembourg, place of processing EU.

    Download PDFDirect download
  • MicrosoftData Protection Addendum

    Hosting, authentication and Azure OpenAI services. Microsoft Ireland Operations, Dublin.

    OpenPublic
  • OpenAIDPA · signed

    AI provider, usable directly. OpenAI Ireland Ltd., processing in the USA under standard contractual clauses.

    Download PDFDirect download
  • AnthropicDPA · as of 22 September 2023

    AI provider. Anthropic Ireland Ltd., processing in the USA under standard contractual clauses, no training on customer content.

    Download PDFDirect download
  • GoogleData Processing Addendum

    AI provider Vertex AI. Google Cloud EMEA, processing in the Frankfurt data centre.

    OpenPublic
  • GroqDPA

    AI provider. Groq Inc., processing in the USA under standard contractual clauses, inference data is not retained.

    Download PDFDirect download
  • MistralData Processing Addendum

    AI provider. Mistral AI SAS, Paris, processing within the EEA.

    OpenPublic
  • ClerkDPA

    Authentication platform. Clerk Inc., USA, Data Privacy Framework and standard contractual clauses.

    OpenPublic
  • ZohoDPA · signed

    Customer data management. Zoho Corporation GmbH, Düsseldorf, processing in Amsterdam and Dublin.

    Download PDFDirect download
  • DATEVDPA · as of 1 January 2025

    Customer data management for accounting. DATEV eG, Nuremberg, processing in Germany.

    Download PDFDirect download

The complete list with purpose, location and legal basis: Download PDF →

Commitments and limits.

Every commitment here also stands in the contract. Beside it stands where it ends.

All customer data sits in the EU.Anyone switching on an AI function and choosing OpenAI directly, Anthropic or Groq processes in the USA. For processing exclusively in Germany there are Azure OpenAI and Google Vertex, both Frankfurt.
Customer content trains no models.Contractually assured, not technically enforced. What that assurance is worth depends on the provider — which is why their agreements are published and the choice sits with the organization.
Sub-processors are named in advance.Four weeks to object from the announcement in text form. The right comes from the contract, not from goodwill.
The audit right under Art. 28 applies in full.With four to six weeks' notice. Unannounced audits are not admissible, and the audit must not endanger business operations.
The data can be taken along.Including when the contract ends because another tool won. Export in open formats is part of the service, not one of the extras.
Questionnaires get filled in.On the procurement templates. Whatever cannot be answered is marked open rather than left out.

Reporting channels.

Someone answers who knows the installation. No outsourced first level in between.

Security incident
support@aiio.de · 0391 251 948 63A suspicion is enough. Where personal data is affected, the route from the DPA runs in parallel.
Vulnerability
support@aiio.deFrom outside as well. Receipt is confirmed before the finding is resolved.
Data protection
via the contact formAccess, rectification and erasure under Art. 15 to 17 GDPR. For existing customers additionally via the body named in the DPA.
Service disruption
Monday to Friday, business hoursMonitoring catches most disruptions before they are noticed. Resolution time follows the agreed SLA; whoever reported it is kept informed.

The contracting party.

One company, one register entry, one location — no chain of holding, sales and operating entities.

aiio GmbH

Klausenerstraße 10a, 39112 Magdeburg. Amtsgericht Stendal, HRB 6552. VAT ID DE 254461500.

Management

Dr. Christian Graup, Knut Köchli, Jobst von Heintze, Lars Bendler. The representation arrangements are recorded in the commercial register.

ISO/IEC 27001

Certificate 02260301-01, valid until 4 June 2029. Document and scope on request.

Registered in 2007

Entered on 18 June 2007, trading under the name aiio since March 2022. Register entry, location and team unchanged.

Operated in the EU

Customer data on servers within the European Union. Seat, development and support in Magdeburg.

Series A funded

Institutionally funded since 2024, eight-figure valuation. For the credit check.

Origins, management and advisory board: to the company →

Something missing?

Whatever is not here is either confidential or does not exist. Ask, and you get told which of the two.