Security & GDPR
Your data. Under European law.
Rinqo doesn't store data on US servers. We don't use US tracking pixels or US CDNs. When you work with us, you stay inside the EU, on every layer.
Four pillars. No compromises.
Hosted in Germany
All data sits on Hetzner servers in Falkenstein and Nuremberg. No US cloud, no CLOUD Act exposure. Every contract: European law, European jurisdiction.
Encryption by default
Customer data is encrypted with AES-256-GCM. API keys are bcrypt-hashed. TLS 1.3 for every connection. Backups are stored encrypted.
Processing in the EU
We use Microsoft Azure OpenAI Service as our primary AI sub-processor — contracting party is Microsoft Ireland Operations Ltd. (Dublin), processing happens within the Microsoft EU Data Boundary in the Sweden region. Microsoft contractually does not train on customer data. Text-to-speech comes from KugelAudio, a German company with EU hosting. Deepgram (speech-to-text) runs in an EU setup — Deepgram is a US corporation with its own EU setup, the processing region stays EU. OVHcloud Roubaix stands by as an opt-in Pure-EU failover provider and only becomes a sub-processor once actually activated.
DPA included
Every customer automatically receives a signed Data Processing Agreement (DPA) under Art. 28 GDPR. No manual follow-up, no extra package.
The hard facts.
Data ProcessingAgreement (DPA).
Every Rinqo customer automatically enters a DPA under Art. 28 GDPR. We integrate the EU Commission's Standard Contractual Clauses (SCC) and document all subprocessors. You need the DPA for your own documentation, we deliver it included.
View DPA sampleEU AI Act. Already implemented.
From 02.08.2026, Article 50 of the EU AI Act requires AI-generated content to be marked as such. Rinqo already implements this: every automatically generated content (e.g. preview summaries, draft emails) carries an `ai-generated` flag in the response header, and we provide ready-made disclosure snippets for your website.
Open AI transparency pageOursubprocessors.
All subprocessors are based in the EU or have EU subsidiaries with their own DPAs. Transparently documented:
Certifications. Documented honestly.
We don't believe in marketing badges that mean nothing. Here's the current status, open and without greenwashing. All artefacts go to customers who need them for their own vendor review.
GDPR compliance
ImplementedDPA under Art. 28, data export (Art. 20), deletion concept (Art. 17), records of processing activities maintained.
ISO 27001 (information security)
In preparationInternal TOMs align with the standard. External certification planned for 2026/2027, status shared quarterly on this page.
SOC 2 Type II
RoadmapRelevant for US customers with enterprise requirements. Evaluation in 2027 after the ISO 27001 certificate.
EU AI Act (Art. 50 transparency)
ImplementedAI-generated content is marked, agent transparency announcement at the start of the call, disclosure snippets for your website.
Penetration test (external)
Planned 2026First pen-test after stable launch by an independent EU security firm. Report available to customers under DPA on request.
Privacy questions?
Write directly to our privacy contact. We respond within 48 hours, usually the same day.