Data Processing Agreement
Version of 4 August 2026 · applies to all plans, including Free.
This Data Processing Agreement (DPA) under Art. 28 GDPR forms part of the Terms and governs every processing of personal data that Compliance Concierge carries out on your behalf. Where it conflicts with the Terms, this DPA prevails for such processing.
Who is who, and when this applies
You (the customer) are the controller. Kristian Hoffmann, Karl-Kraut-Straße 15, 30177 Hannover, Germany, operating as Compliance Concierge, is the processor. This DPA takes effect when you create an account — no separate request is required, and it is not tied to a paid plan. If your organisation needs a countersigned copy, ask and you will get one.
1. Subject matter, nature, purpose and duration
Subject and purpose: provision of the Compliance Concierge SaaS — processing the documents you upload (policies, evidence) and the security questionnaires you receive, in order to produce evidence-cited draft answers.
Nature of processing: storage, chunking, embedding and vector search, LLM-assisted drafting, display in the review workspace, and export.
Duration: for the term of the main contract, plus the deletion periods set out in section 8.
2. Types of data and categories of data subjects
Types of data: determined by what you upload. Typically names, business contact details, roles, and technical or organisational statements contained in policies and questionnaires. You decide what the uploaded files contain and remain responsible for that choice.
Categories of data subjects: your employees, your contact persons, and third parties named in your documents or in your customers' questionnaires.
Special categories under Art. 9 GDPR are not intended to be processed. You undertake not to upload such data without a separate written agreement.
3. Instructions and confidentiality
We process personal data only on your documented instructions. Using the product as intended constitutes such an instruction. If we consider an instruction to infringe data protection law, we will inform you.
Every person authorised to process your data is bound to confidentiality. Access is limited to what is required to operate and support the service.
4. Technical and organisational measures (Art. 32 GDPR)
We state only measures that are actually implemented. Nothing in this section is aspirational.
- Transport encryption: TLS for all external connections; HSTS with preload; a strict Content Security Policy.
- Tenant isolation: Postgres Row-Level Security is enabled on every application table, restricting reads and writes to your own rows. Vector similarity search is additionally filtered by user id at query time, so evidence retrieval cannot cross tenants even if a query were malformed.
- Access control: authentication via Supabase; the privileged service-role credential is confined to a small number of server-side paths (payment webhook, background analysis worker, account deletion) and is never reachable from the browser.
- Data minimisation: only the minimum context required is sent to the language model (Mistral AI). Deleting a document cascade-deletes its source file and all embedded chunks.
- Backups: the database is backed up daily, encrypted at rest in the backup store and checksum-verified. Backups are held on infrastructure in Frankfurt, Germany.
Honest limitation: full-disk encryption of the production volume is not currently in place. Your data is encrypted in transit and in backups, but the live database volume is not encrypted at rest. We would rather tell you this than assure you of something we have not implemented. This page will be updated when that changes.
5. Subprocessors
You approve the following subprocessors on conclusion of the contract. Each processes only what its purpose requires; none of them receives your documents except where stated.
| Subprocessor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Hostinger International Ltd. | Server hosting for the application and the self-hosted database, authentication and file storage | Frankfurt, Germany | EU |
| Mistral AI SAS | Evidence search, embeddings and draft generation | Paris, France | EU |
| Stripe Payments Europe, Ltd. | Subscription billing. Never receives document or questionnaire content | Ireland / USA | DPF and/or SCC |
| Sendinblue GmbH (Brevo) | Account and product emails | Germany / France | EU |
| Google, GitHub, Apple | Optional social sign-in, if you choose to use it | USA | DPF and/or SCC |
We will inform you of any intended addition or replacement of a subprocessor with reasonable notice. You may object to the change; if we cannot accommodate the objection, you may terminate the affected part of the contract.
6. Third-country transfers
For recipients in the United States we rely on the EU-US Data Privacy Framework where the recipient is actively certified, and otherwise on the EU Standard Contractual Clauses in the appropriate module. A copy of the applicable safeguards is available on request.
7. Assistance
We assist you in responding to data subject requests (Art. 12–23 GDPR) and in meeting your obligations under Art. 32–36 GDPR, within what is technically possible and taking the nature of processing into account.
We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own reporting obligations.
8. Deletion and return
On termination we delete or return your personal data at your choice. Unless you request return, live data is deleted within 30 days of the end of the contract; encrypted backups roll off within a further 35 days. Statutory retention obligations remain unaffected.
You do not have to wait for us: Account & privacy lets you export your data (Art. 20) and permanently delete your account at any time, including storage objects, projects, questionnaires, answers, documents, embeddings and trust-center data.
9. Evidence and audits
We provide the information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by you or an auditor you mandate, at reasonable notice and without disproportionate disruption to operations.
10. Contact and countersigned copies
For a countersigned copy, questions about this DPA, or a copy of the transfer safeguards, write to moin@kristianhoffmann.de. We answer DPA requests before you buy, not after.