Skip to content

Security & GDPR

Your data. Under European law.

rinqo doesn't store data on US servers. We don't use US tracking pixels or US CDNs. When you work with us, you stay inside the EU, on every layer.

Four pillars. No compromises.

Hosted in Germany

All data sits on Hetzner servers in Falkenstein and Nuremberg. Hetzner is a German company; every contract runs under European law and European jurisdiction.

Encryption by default

Customer data is encrypted with AES-256-GCM. API keys are bcrypt-hashed. TLS 1.3 for every connection. Backups are stored encrypted.

Processing in the EU

Our primary AI sub-processor processes all content within the EU, contractually guaranteed, and does not use it for training. Speech recognition and speech synthesis run through services with EU processing, and a purely European fallback provider stands by. The named provider list is available to customers in the dashboard.

DPA included

Every customer automatically receives a signed Data Processing Agreement (DPA) under Art. 28 GDPR. No manual follow-up, no extra package.

The hard facts.

Server locationGermanyFalkenstein + Nuremberg (Hetzner Cloud)
EncryptionAES-256-GCMAt rest + TLS 1.3 in transit
Authenticationbcrypt-12Account lock after 5 failed attempts
RetentionConfigurable30 days default, adjustable up to 365 days depending on your package
Data exportGDPR Art. 20On request, within 14 days
Data deletionGDPR Art. 17Full deletion on request

Shadow AI: You probably already have the problem.

If your team has no approved AI tool, it uses its own. Four in ten companies in Germany assume their employees use private AI accounts at work. Only about a quarter have any rules for it at all (Bitkom, October 2025). Company data then ends up with US services, without a contract, without control.

This is not a discipline problem, it is a supply problem. Whoever provides an approved, GDPR-compliant alternative solves it. With rinqo, every team member gets a Personal Agent on European infrastructure, without US providers, with access to your company knowledge instead of the open web. Shadow AI loses its reason to exist.

Read the study: Shadow AI in SMEs

Data ProcessingAgreement (DPA).

Every rinqo customer automatically enters a DPA under Art. 28 GDPR. We integrate the EU Commission's Standard Contractual Clauses (SCC) and document all subprocessors. You need the DPA for your own documentation, we deliver it included. After the contract ends, we provide everything as a ZIP (Art. 20 GDPR); we delete your data completely within 30 days, or immediately on request.

EU AI Act. Met by default.

From 02.08.2026, Article 50 of the EU AI Act requires AI-generated content to be marked as such. rinqo already implements this: every automatically generated content (e.g. preview summaries, draft emails) carries an `ai-generated` flag in the response header, and we provide ready-made disclosure snippets for your website.

Open AI transparency page

Information pursuant to Art. 28 of Regulation (EU) 2023/2854 (Data Act)

The ICT infrastructure used to provide our data processing services is subject to the jurisdiction of the Federal Republic of Germany and the European Union; hosting takes place exclusively in data centres in Germany. Against unlawful governmental access from third countries, we take in particular the following measures: contractual partners established in the EU, data processing exclusively within the EU (contractually guaranteed), encryption of data in transit (TLS 1.3) and at rest (AES-256), access on a need-to-know basis, and legal review of every official disclosure request before any information is released.

When the agent gets it wrong

The agent answers only from your approved knowledge base, what is not in there, it does not say. If it does not know something, it says so honestly and hands over to your team instead of guessing. Every conversation is logged: you can see at any time what was said and correct the knowledge in one place. For regulated matters (medicine, law, tax): the agent records and forwards, it does not advise. rinqo staff access conversation content only at your request in a support case; access is logged and subject to the confidentiality obligation under § 203 (4) StGB. You are responsible for the content of your knowledge base, we are responsible for the technology, the details are governed by the DPA.

Oursubprocessors.

All subprocessors are based in the EU or have EU subsidiaries with their own DPAs. Transparently documented. On request, we provide the complete named list together with the DPA template before the contract is signed. Transparently documented:

Hosting & databasesServers, databases and voice infrastructure in German data centres (ISO 27001)Germany
AI models (speech & text)Processing contractually within the EU; no training on customer dataEU
TelephonyCall infrastructure via an EU telephony providerEU
Payment processingHandled via an EU payment provider (PCI-DSS)EU
Transactional emailsSent via a European providerEU

As a customer, you get the complete list with company names, legal entities and legal bases directly in the dashboard. Prospective customers receive it on request as part of the contract process.

Certifications. Documented honestly.

We don't believe in marketing badges that mean nothing. Here's the current status, open and without greenwashing. All artefacts go to customers who need them for their own vendor review.

GDPR compliance

Implemented

DPA under Art. 28, data export (Art. 20), deletion concept (Art. 17), records of processing activities maintained.

ISO 27001 (information security)

In preparation

Internal TOMs align with the standard. External certification planned for 2026/2027, status shared quarterly on this page.

SOC 2 Type II

Roadmap

Relevant for US customers with enterprise requirements. Evaluation in 2027 after the ISO 27001 certificate.

EU AI Act (Art. 50 transparency)

Implemented

AI-generated content is marked, agent transparency announcement at the start of the call, disclosure snippets for your website.

Penetration test (external)

Planned 2026

First pen-test after stable launch by an independent EU security firm. Report available to customers under DPA on request.

Privacy questions?

Write directly to our data protection contact. We answer within 24 hours.