Trust Center
What your procurement team wants to know.
Where the project data is stored, which processors are involved, what happens with the AI and where our limits are. All on one page, so you do not have to chase supplier questionnaires.
Last reviewed 9 August 2026 · This page summarises the privacy policy; the German privacy policy is the legally binding version.
Answered briefly
The six questions that always come up.
Where is our project data stored?
Does the AI train on our data?
Will we get a data processing agreement?
Are you certified to ISO 27001 or SOC 2?
What happens to our data if we cancel?
Is CE-Copilot a high-risk AI system under the EU AI Act?
Processors
Who processes data alongside us.
Complete list under Art. 28 GDPR. Data processing agreements are in place with all service providers listed. Where processing takes place outside the EU, the legal basis is stated alongside.
| Service provider | Purpose | Processing location |
|---|---|---|
| Supabase Inc. | Database, file storage, authentication | Servers in the EU or EEA |
| Anthropic, PBC | AI processing (Claude) for suggestions and drafts | USAData Processing Addendum, EU Standard Contractual Clauses |
| Railway Corp. | Hosting and delivery of the web application | USA (delivery preferably via data centres in the EU)Data processing agreement, EU-US Data Privacy Framework or Standard Contractual Clauses |
| IONOS SE | Sending transactional e-mails (SMTP) | Germany |
| Stripe Payments Europe, Ltd. | Payment processing | Dublin, Ireland (partly Stripe, Inc., USA)EU-US Data Privacy Framework or Standard Contractual Clauses |
| PostHog, Inc. | Audience measurement, only with consent | EU cloud, servers in the EU |
Art. 32 GDPR
Technical and organisational measures.
Every item describes something that is built in and can be verified. Statements of intent are deliberately left out.
Encrypted transmission
All connections to the application run over TLS. The Strict-Transport-Security header instructs browsers to access the domain exclusively over HTTPS from then on.
Tenant separation in the database
Account separation is enforced by the database itself (Row Level Security in PostgreSQL), not only by the application. An account sees exclusively the rows assigned to it, regardless of the query the application issues.
Files only via time-limited links
Uploaded files (photos, technical documents, full texts of standards) are held in non-public storage. Access runs through signed links with a short validity that are generated per retrieval.
Sign-in and sessions
Sign-in is handled by Supabase Auth (password or Google account); passwords are hashed there and are not visible to us. Sessions are registered server-side, so an account cannot remain open unnoticed on any number of devices in parallel.
AI calls limited to their purpose
Only the project content needed for the respective work step (for example the machine description and the hazard) is sent to the AI. Anthropic does not use this data to train its models; the processing is governed by a Data Processing Addendum.
Deletion in your hands
Projects, documents and files can be deleted in the application at any time; deleting an item also removes the associated file from storage. After the contract ends, the data is deleted unless a statutory retention obligation applies (German Commercial Code six years, German Fiscal Code ten years for accounting records).
Documents
What you receive.
- Data processing agreement under Art. 28 GDPR, including sub-processors and the annex on technical and organisational measures.
- Completed supplier or IT security questionnaire in your format.
- This page as a dated snapshot, if your process requires evidence as at the time of approval.
Request the DPA or send us your questionnaire
An e-mail to info@sh-eng.de is all it takes. Please report security vulnerabilities to the same address; we confirm receipt and come back to you with an assessment before we publish anything.
Limits
What we do not have.
- No ISO 27001 or SOC 2 certification. We work with a data processing agreement, documented technical and organisational measures and questionnaires instead of a certificate.
- No two-factor authentication in the application. If you need it, sign in with a Google account and use the protection available there.
- No guaranteed availability. The terms of service name no availability guarantee, and we do not promise one that we do not measure.
This list is here because these points come up in the questionnaire anyway. If one of them is a knock-out criterion for you, say so early and we both save ourselves the meeting.
Ready for the new Machinery Regulation?
Move your CE documentation to a guided workflow: from the risk assessment to the Declaration of Conformity, before the Machinery Regulation takes effect on 20 January 2027.
What changes on the cut-over date in concrete terms: for six machinery categories in Annex I Part A of the Machinery Regulation (including removable mechanical transmission devices with their guards, vehicle servicing lifts, cartridge-operated fixing tools and safety-related AI components), self-assessment via harmonised standards is no longer sufficient; there, the notified body becomes mandatory. Check whether your machine is affected
No credit card required · trial with the Starter feature set
The personal demo: 30 minutes, free of charge and without obligation.