Convenience translation for information purposes only. The legally binding version is the German original („Technische und organisatorische Maßnahmen", Anlage 2 zum AVV). In case of any discrepancy, the German version prevails.
Annex 2 to the Data Processing Agreement — measures under Art. 32 GDPR. Contractor (processor): Artur Parutkin (sole proprietorship), Isestraße 35, 20144 Hamburg, Germany. Version: July 2026.
Physical access control — Servers are operated exclusively in ISO 27001-certified data centres of Hetzner (Germany) and Scaleway (France); physical security is the contractual responsibility of these sub-processors. No own hardware.
System access control - End-user login via passwordless email-code authentication (short-lived, single-use digit code bound to a cryptographically secure 256-bit session secret held by the requesting browser; expires after a few wrong entries). - Rate limiting per email and per IP against brute force; honeypot and timing checks against bots. - Admin access separate, IP rate-limited, constant-time password comparison. - Server access (SSH) only for the operator; credentials stored separately.
Data access control - API keys are stored exclusively as SHA-256 hashes (plaintext is displayed once upon creation and never persisted) → database access does not reveal usable keys. - Tenant separation at application level: every access is bound to the session user identity. - Database (PostgreSQL) and cache (Redis) run in a private Docker network, not publicly reachable. - Budget/spend controls per account and a global spending limit against abuse.
Separation control — Separate environments (production / test) with separate databases. Processing separated by purpose (account, usage, content data).
Transfer/transport control - Encryption in transit throughout via TLS; HSTS enforced; modern security headers (CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy). - CSRF protection (same-origin checks + SameSite=Lax cookies, Secure + HttpOnly). - Inference transmission to Scaleway TLS-encrypted; Inputs are not stored, not logged and not used for training at Scaleway (Scaleway Specific Conditions for AI Services; except for the temporary retention of individual requests for abuse/malfunction analysis provided for therein). Scaleway's batch processing feature (with up to 24-hour intermediate storage) is not used.
Input control — Application logs without content data of Inputs/Outputs. IP addresses are stored only in pseudonymized form (salted SHA-256 hash). Exception: two security alerts to the operator (admin login, blocked mass cancellation) contain the raw IP address — Art. 6(1)(f) GDPR with Recital 49; a hashed address cannot be blocked. Only operational and security data is logged (timestamp, pseudonymized IP, route/endpoint, HTTP status, response time, model name, token/usage counters, user identifier, error messages) — no Input/Output content. Application and container logs are size-limited, rotating and deleted at the latest after 30 days; host/nginx access logs (with IP) are deleted after 14 days.
ssh → tar → gpg), so that unencrypted message data is at no point written to the target medium, not even temporarily. Each run is decrypted and message-counted before it is promoted; access is restricted to the operator. Regular restore testing.Data protection by design and by default (Art. 25) — Data minimization as a core principle: no storage of Inputs/Outputs, pseudonymized IPs, minimal logging, hashed keys, self-hosted analytics (no third-party trackers).
Vulnerability/patch management — Operating system and container images are updated regularly; security-critical updates are applied with priority.
Encryption at rest — Corrected 2026-08-17: the earlier wording ("The database is encrypted at rest") was inaccurate. The server uses no full-disk encryption (no LUKS) and PostgreSQL no TDE. What is in fact encrypted: backups with gpg (AES-256), both on the server and off-site; the identity fields of DPA acceptances (company, address, signer name and role) field-wise with Fernet (AES-128-CBC + HMAC); API keys as SHA-256 hashes only; IP addresses as salted SHA-256 hashes. The database is not publicly reachable (no published port, internal Docker network only).
Sub-processor control — All sub-processors under DPAs pursuant to Art. 28 (Hetzner, Scaleway – inference and email delivery –, Stripe); EU Standard Contractual Clauses for non-EU providers. Changes with 30 days' notice (§ 5 DPA).
Incident response / data breaches — Documented procedure: detection via monitoring/alerts and the sub-processors' notification chains; assessment of severity and affected data; containment (blocking of access/keys, isolation); notification of the affected controller without undue delay, as a rule within 48 hours (or of the supervisory authority within 72 hours where the Contractor is itself the controller); documentation of every incident.
Review — Regular review of the security measures; an external penetration test is planned. Email is received on our own infrastructure; for outbound delivery Scaleway is the processor (France/EU).
Your message goes straight to Artur's inbox — no queue, no ticket number.
We use your address only to reply. More in our privacy notice.
Received. Artur will reply personally, usually within one business day.
Sending failed. Please write to us directly at artur@privatai.com.
You've just sent several messages. Please wait a moment.