Security & data
Before you share information about your company with us, this is what we do with it. The summary you need to decide is here; the full technical detail, aimed at a CTO or security lead, is in the Trust Center.
Territory: European Union, always
Section titled “Territory: European Union, always”All the infrastructure the flows and agents we build run on lives in European territory. Nothing is replicated outside the EU without your explicit written consent. GDPR compliance is designed in from day one of every project, not bolted on at the end.
What data gets handled in a typical project
Section titled “What data gets handled in a typical project”- Contact and CRM data of your customers or leads, so the flow or agent can carry out the process you ask for.
- Work content (emails, documents, tickets, transcripts) that the automation needs to read or generate.
- Credentials for the tools we connect (CRM, accounting, messaging), only the ones essential for the integration to work.
Your data is used to run your processes, never to train third-party public models or to benefit another client.
The self-hosting criterion
Section titled “The self-hosting criterion”Whenever data is sensitive, we prioritize self-hostable tools (starting with our automation platform) so the information doesn’t leave where it should stay. For the most demanding case, we work with local AI models that run on your own infrastructure: the data never leaves your perimeter.
Commitments in writing
Section titled “Commitments in writing”- Data in the EU, not replicated outside without your explicit consent.
- Real confidentiality: we sign an NDA if you ask; projects are not referenced publicly without authorization (see Confidentiality).
- GDPR compliance by design (see Privacy Policy).
- Vulnerability reporting: security@aiginer.com (ES) / security@aiginer.com (EN), acknowledged in under 24 business hours.
The full technical detail
Section titled “The full technical detail”If you’re evaluating us from IT or security, the How we protect your data page is designed so you can evaluate us without asking for a call: authentication and access, encryption in transit and at rest, per-client data isolation with Row-Level Security, cryptographic traceability of sensitive actions, backups with the 3-2-1 rule, network protection and incident response, and an honest roadmap of what we don’t have yet.
| You need | Resource |
|---|---|
| A single starting point for procurement/legal | Trust Center |
| The technical security detail | How we protect your data |
| How we handle personal data | Privacy Policy |
| Confidentiality and NDA | Confidentiality |
| Responsible AI principles and the AI Act | AI Policy |
Your rights
Section titled “Your rights”To exercise any GDPR right (access, rectification, erasure, portability) write to dpo@aiginer.com. For general privacy questions, privacy@aiginer.com.