AUVYTrust Center

Trust you can review

EU-hosted workspaces, public processor disclosures, and the contracts buyers need — written for security, legal, and procurement review.

  • Core EU hosting
  • Public AVV / DPA
  • Processor register
  • AI transparency

Data handling

Where customer data lives, who can access it, how it is encrypted, and how long it is kept.

Last updated: 2026-08-03

Where is data stored?

Core workspace and account data is stored in the EU. Optional parsing and sandbox paths may use provider-managed regions when invoked.

CategoryDetail
Workspace contentEU (Helsinki) — documents, files, and product data for your organisation
Accounts & accessEU (Helsinki) — sign-in, sessions, and workspace membership
Web applicationEU (Frankfurt) — product website and app delivery
AI featuresEU — approved model providers in EU regions (for example Frankfurt and Sweden)
VoiceEU — speech-to-text for voice features (Microsoft Azure)
Web searchEU — Linkup for product web_search / web_read
Realtime collaborationEU (Helsinki) — OpenPulse is operated by AUVY on internal infrastructure, not a separate third-party processor

Who has access?

Only people in your workspace — and AUVY staff with a need to operate the service.

CategoryDetail
Your teamAccess follows workspace roles for signed-in users
Workspace ownersCan export or delete workspace data; those actions are logged
AUVY staffLimited production access for support and operations
Professional secrecy (§ 203)Available for Enterprise under the AVV — activation is contractual, not automatic

Security-relevant actions, exports, and deletions are recorded in your workspace activity log (typically kept about 12 months).

How is data encrypted?

Data is protected in transit and at rest.

CategoryDetail
In transitTLS 1.2 or higher for connections to AUVY and our providers
At restEncryption for production databases and file storage
Sensitive fieldsExtra protection for document contents and connected-account secrets

Full technical measures are described in the AVV and Product Privacy Notice.

Retention and deletion

You can export anytime. After the contract ends, we delete on the published timelines.

CategoryDetail
Account dataWhile the identity exists; a valid identity-erasure request removes or anonymizes controller data where legally possible
Workspace contentExport anytime; owner-authorized workspace deletion or final deletion typically 30 days after contract end. Removing one identity does not automatically delete a shared workspace
Activity logsTypically about 12 months
Product analyticsUp to 90 days in identifiable form, then aggregated or anonymized
Invoices & accounting vouchersGenerally 8 years under German commercial and tax law
Books & annual accountsMay require 10 years; commercial correspondence is generally 6 years
AI processingProvider-side handling follows the applicable service contract and configuration; AUVY does not designate customer data for model training

Tax, audit, litigation, limitation, or other legal holds can extend the applicable category period. Restricted records are not reused for incompatible purposes.

Related