Trust Center

What your procurement team wants to know.

Where the project data is stored, which processors are involved, what happens with the AI and where our limits are. All on one page, so you do not have to chase supplier questionnaires.

Last reviewed 9 August 2026 · This page summarises the privacy policy; the German privacy policy is the legally binding version.

Answered briefly

The six questions that always come up.

Where is our project data stored?
The database and file storage are operated by Supabase on servers in the EU or EEA. The application is delivered via Railway, preferably through data centres in the EU; Railway is based in the USA, which is why a data processing agreement with the usual safeguards is in place for it.
Does the AI train on our data?
No. AI processing runs through Claude by Anthropic. Anthropic does not use the submitted content to train its models. We do not pass customer data to third parties for training or analysis purposes.
Will we get a data processing agreement?
Yes. We provide the data processing agreement under Art. 28 GDPR on request, including the list of sub-processors and the technical and organisational measures. An e-mail is all it takes.
Are you certified to ISO 27001 or SOC 2?
No, and we do not claim to be. CE-Copilot is run by a small team; we have not gone through a certification of this kind. What we deliver is what procurement actually needs for approval: a data processing agreement, documented technical and organisational measures, the list of processors and completed supplier questionnaires.
What happens to our data if we cancel?
You export your projects yourself at any time: the complete dossier as PDF and as a Word file, and on the Professional plan additionally as re-importable JSON or Excel. After the contract ends, the data is deleted unless a statutory retention obligation applies. The export therefore never depends on our involvement.
Is CE-Copilot a high-risk AI system under the EU AI Act?
No. CE-Copilot is a documentation tool for CE marking; it falls into none of the high-risk categories of Annex III and is not a safety component of a product under Annex I either. It does not become part of your machine, it helps you document it. Wherever an AI is involved, we say so, and every AI suggestion remains a suggestion until you approve it.

Processors

Who processes data alongside us.

Complete list under Art. 28 GDPR. Data processing agreements are in place with all service providers listed. Where processing takes place outside the EU, the legal basis is stated alongside.

Service providerPurposeProcessing location
Supabase Inc.Database, file storage, authenticationServers in the EU or EEA
Anthropic, PBCAI processing (Claude) for suggestions and draftsUSAData Processing Addendum, EU Standard Contractual Clauses
Railway Corp.Hosting and delivery of the web applicationUSA (delivery preferably via data centres in the EU)Data processing agreement, EU-US Data Privacy Framework or Standard Contractual Clauses
IONOS SESending transactional e-mails (SMTP)Germany
Stripe Payments Europe, Ltd.Payment processingDublin, Ireland (partly Stripe, Inc., USA)EU-US Data Privacy Framework or Standard Contractual Clauses
PostHog, Inc.Audience measurement, only with consentEU cloud, servers in the EU

Art. 32 GDPR

Technical and organisational measures.

Every item describes something that is built in and can be verified. Statements of intent are deliberately left out.

Encrypted transmission

All connections to the application run over TLS. The Strict-Transport-Security header instructs browsers to access the domain exclusively over HTTPS from then on.

Tenant separation in the database

Account separation is enforced by the database itself (Row Level Security in PostgreSQL), not only by the application. An account sees exclusively the rows assigned to it, regardless of the query the application issues.

Files only via time-limited links

Uploaded files (photos, technical documents, full texts of standards) are held in non-public storage. Access runs through signed links with a short validity that are generated per retrieval.

Sign-in and sessions

Sign-in is handled by Supabase Auth (password or Google account); passwords are hashed there and are not visible to us. Sessions are registered server-side, so an account cannot remain open unnoticed on any number of devices in parallel.

AI calls limited to their purpose

Only the project content needed for the respective work step (for example the machine description and the hazard) is sent to the AI. Anthropic does not use this data to train its models; the processing is governed by a Data Processing Addendum.

Deletion in your hands

Projects, documents and files can be deleted in the application at any time; deleting an item also removes the associated file from storage. After the contract ends, the data is deleted unless a statutory retention obligation applies (German Commercial Code six years, German Fiscal Code ten years for accounting records).

Documents

What you receive.

  • Data processing agreement under Art. 28 GDPR, including sub-processors and the annex on technical and organisational measures.
  • Completed supplier or IT security questionnaire in your format.
  • This page as a dated snapshot, if your process requires evidence as at the time of approval.

Request the DPA or send us your questionnaire

An e-mail to info@sh-eng.de is all it takes. Please report security vulnerabilities to the same address; we confirm receipt and come back to you with an assessment before we publish anything.

Limits

What we do not have.

  • No ISO 27001 or SOC 2 certification. We work with a data processing agreement, documented technical and organisational measures and questionnaires instead of a certificate.
  • No two-factor authentication in the application. If you need it, sign in with a Google account and use the protection available there.
  • No guaranteed availability. The terms of service name no availability guarantee, and we do not promise one that we do not measure.

This list is here because these points come up in the questionnaire anyway. If one of them is a knock-out criterion for you, say so early and we both save ourselves the meeting.

124days until EU Machinery Regulation 2027Readiness check

Ready for the new Machinery Regulation?

Move your CE documentation to a guided workflow: from the risk assessment to the Declaration of Conformity, before the Machinery Regulation takes effect on 20 January 2027.

What changes on the cut-over date in concrete terms: for six machinery categories in Annex I Part A of the Machinery Regulation (including removable mechanical transmission devices with their guards, vehicle servicing lifts, cartridge-operated fixing tools and safety-related AI components), self-assessment via harmonised standards is no longer sufficient; there, the notified body becomes mandatory. Check whether your machine is affected

No credit card required · trial with the Starter feature set

The personal demo: 30 minutes, free of charge and without obligation.