Trust Center · updated 2026-07-23

Data protection, in the open

GDPR, EU data residency & your data

AgentWorks is built for European teams that treat GDPR, the EU AI Act and data residency as requirements, not nice-to-haves. Here is exactly how we handle your data — and who we work with.

  • Fully hosted in the EU
  • Zero-retention model contracts
  • DPA available on request

01 — Commitments

What we commit to

Fully hosted in the EU

AgentWorks runs on our own infrastructure in Germany (Hetzner) — application, database, authentication and file storage all live there. Large language model calls use EU endpoints where the provider offers them.

Zero-retention model contracts — the guarantee

The guarantee we build on is architectural: EU hosting plus model providers engaged on a no-training, zero-retention basis. That is what actually keeps your content from being retained or used for training — not a text-scanning layer, which can never be fully watertight.

Optional PII-detection layer

An additional layer can detect and mask common personal-data patterns before content reaches a model. It reduces exposure — we do not market it as a guarantee, because free-text detection always has a miss rate.

Audit trail + human oversight

Every state-mutating action is recorded to an append-only audit log, and high-risk actions can require human-in-the-loop approval before they run.

02 — Sub-processors

The vendors behind the platform

The third parties that process data on our behalf. We work with each on a Data Processing Agreement and inform customers of material changes.

Sub-processorPurposeRegionData-processing terms
EU infrastructure hosting (self-hosted)Infrastructure hosting for the application (frontend & backend) and database — self-hosted on our own serversEU (Germany)Infrastructure provider; data processed under our own operational control
AWS (Bedrock)Large language model inference — hosts Anthropic (Claude) and OpenAI open-weight (GPT-OSS) modelsEU (eu-north-1)No-training, zero-retention
Google Cloud (Vertex AI)Large language model inference — hosts Google (Gemini) modelsEUNo-training, zero-retention
OpenAILarge language model inference (GPT chat models) & text-embedding generationUS (direct API — no EU-hosted OpenAI endpoint in production today)No-training, zero-retention
MistralLarge language model inferenceEU (France-domiciled provider)No-training, zero-retention
StripePayment & subscription processingEU + USPCI-DSS certified (Stripe)
Transactional e-mail serviceTransactional email deliveryEUCovered by DPA

Optional integrations

Present in the platform but only active where explicitly configured. Listed for completeness — ask us for current production status for your account.

Sub-processorPurposeRegionData-processing terms
xAI (Grok)LLM inference — optional fallback providerEUConfigured per account
PerplexityWeb-search tool called by agents (not chat inference)EUConfigured per account
Error monitoring serviceError monitoringEUConfigured per account

A complete, named sub-processor list is available under our DPA — request it via contact.

03 — Security

Built to keep tenants apart

How the platform itself is built to keep tenants apart and credentials safe.

Tenant isolation by design

Every database query the backend makes is explicitly scoped to your organization at the application layer, not left to a database policy alone. Realtime updates (live chat/task streams) get their own row-level security scoped to what each person is actually allowed to see.

Encryption of credentials & keys

Integration tokens and platform model-provider keys are encrypted at rest. Nothing is stored as plain text.

Security headers by default

The application ships a Content-Security-Policy, HSTS, and standard anti-clickjacking / MIME-sniffing headers.

Dependency hygiene

Automated dependency scanning runs in CI, with Renovate/Dependabot keeping libraries current. Critical vulnerabilities block merges.

04 — Retention

How long we keep data

If you close your workspace subscription

A 30-day grace period follows workspace closure, after which a purge sweep anonymizes your tenant record. (This is separate from the personal "delete my account" action above, which is immediate — see Data subject rights.) Money-ledger and audit-log rows are retained for roughly 7 years to meet standard bookkeeping rules — they stay linked to the anonymized record, not to identifying information.

Operational log retention (policy)

Our data retention policy sets chat-interaction logs at 30 days, dispatch/action audit logs at 6 months, and the compliance audit trail at 7 years. Chat messages themselves are never automatically deleted. Automated enforcement of these windows is rolling out.

05 — GDPR

Our GDPR commitments

Data Processing Agreement (Art. 28)

AgentWorks acts as processor and your organisation as controller. Request a DPA using the button below and we will work through it with you directly.

Data subject rights

Every user can self-service their own access, portability and erasure rights from Settings — a one-click data export (Art. 15/20) and immediate account deletion (Art. 17: your data is anonymized and wiped on confirmation, not scheduled for later), no ticket required. Rectification is a normal profile edit. Anything else (e.g. a request about someone else’s data) we handle per-request by email.

Records of processing (Art. 30)

We maintain a record of processing activities, available to supervisory authorities and to customers under their DPA.

Breach notification

Our commitment is to notify affected customers without undue delay after becoming aware of a personal-data breach.

International transfers

Where a sub-processor processes data outside the EU, we cover the transfer with Standard Contractual Clauses via the provider’s own DPA.

Privacy policy

Our privacy policy covers cookies and how to control them in your browser — see it for full detail.

06 — EU AI Act

EU AI Act: ready, not a blanket claim

No platform is automatically "EU AI Act compliant" — the Act classifies risk by use case, so whether a given agent is high-risk depends on how you deploy it (for example, HR screening or credit scoring can be high-risk). AgentWorks gives you the controls the Act expects, so you can deploy responsibly:

  • Per-agent risk classification
  • Append-only audit trail of every action
  • Human-in-the-loop approval on high-risk actions
  • Article 50 transparency — clear AI-interaction disclosure
  • An optional PII-detection layer to reduce exposure
Read our EU AI Act guide

Certifications roadmap

Today we operate on infrastructure fully hosted in the EU (Germany), zero-retention model contracts, a published sub-processor list, and a privacy policy; a DPA is available on request. We are evaluating third-party security certifications (for example SOC 2 or ISO 27001) as we grow into larger enterprise and agency deployments. Talk to us about your specific assurance requirements.

07 — FAQ

Frequently asked questions

Where is my data stored?

AgentWorks is fully hosted in the EU on our own infrastructure: the application, database, authentication and file storage all run on servers we operate in Germany, and large language model calls use EU endpoints where the provider offers them. The guarantee we rely on is EU hosting plus zero-retention model contracts — not a redaction layer. An optional PII-detection layer can further reduce what reaches a model, but it is a complement to that guarantee, not a substitute for it.

Do you train AI models on my data?

No — the model providers we use are engaged on a no-training, zero-retention basis for API traffic, and that architectural guarantee is what we rely on, not a redaction promise. Free-text personal-data detection can never be 100% complete, so we do not market our optional PII-detection layer as a guarantee that personal data never reaches a model — only that it reduces exposure.

Do you sign a Data Processing Agreement (DPA)?

Yes — under GDPR Article 28, AgentWorks acts as processor and your organisation as controller, and we work through a DPA directly with business customers on request, covering any non-EU sub-processor transfers via Standard Contractual Clauses.

Is AgentWorks EU AI Act compliant?

AgentWorks is AI Act-ready rather than blanket "compliant" — whether a specific use case is high-risk depends on how you deploy the agent. We provide the building blocks the Act expects: per-agent risk classification, an append-only audit trail, human-in-the-loop oversight for high-risk actions, and Article 50 transparency (making clear when you are interacting with AI).

Who are your sub-processors?

Our core sub-processors are Hetzner (EU infrastructure — application and database, self-hosted on our own servers in Germany), AWS Bedrock and Google Vertex AI (EU-hosted LLM inference for Anthropic, OpenAI open-weight, and Google models), OpenAI (US-hosted GPT chat models and text embeddings) and Mistral (LLM inference), a transactional email service, and Stripe (payments). See the sub-processor table above — including optional integrations — for the full category breakdown, and request our DPA for the complete named list.

How do I exercise GDPR data subject rights?

Access and portability (Art. 15/20): download your own data any time from Settings → Account. Erasure (Art. 17): delete your account from the same page — your personal data is anonymized and your content wiped immediately on confirmation, not scheduled for later. Rectification is a normal profile edit. For anything else, contact us and we handle it per-request.

Talk to us

Need a DPA or security review?

Request our Data Processing Agreement, the sub-processor list, or a security questionnaire — or start free and see the compliance controls in the product.