As of 26 May 2026
Compliance
and sovereignty.
This page states the platform's posture plainly: what is in place today, what is in preparation and where we deliberately are not yet. No marketing promises and no wall of certificates we do not hold.
1. GDPR: what is in place and how it is evidenced
Our own assessment, not an external audit. We do not put a percentage on it: nobody outside could recheck a figure like that. What follows are the points that actually matter.
A data processing agreement under Article 28 is provided on request as a customized template; the terms are set out on its own page.
- Eight active sub-processors, documented, with four weeks' notice before any change, as Article 28(2) requires.
- Operations in the EU: compute and backups at Hetzner in Germany, model inference at Modal Labs in Frankfurt.
- Data subject rights under Articles 15 to 22: self-service export in the tenant workspace plus a documented deletion matrix.
- A data protection impact assessment under Article 35 exists for analytics; every new AI feature gets its own before it goes live.
2. EU AI Act: which duties apply and how they are met
Risk classification is predominantly minimal to limited, with individual workflows carrying the Article 50 transparency obligation.
SIMO GmbH is both: provider of the platform and deployer of third-party general-purpose models, namely Apertus 8B and the Mistral family.
- The Article 50 transparency obligation is live: every answer is marked as AI-generated through a dedicated response header and a visible notice.
- Model cards for Apertus 8B and the Mistral family, with provider, license, knowledge cutoff and usage limits.
- Every model call is logged for thirty days with model ID, tenant hash, token count and response hash.
- No high-risk system: no feature falls under Annex III today, so no biometric scoring, no candidate screening, no education ranking.
3. ISO/IEC 27001: in preparation
Work on Annex A is under way and some measures are still outstanding. The certification audit is planned for 2027; there is no certificate today.
Asset inventory, risk register, statement of applicability and incident response are being built out; document control runs through the repository.
Hetzner, who runs the infrastructure, is certified to ISO/IEC 27001. At that layer the benefit already applies.
4. BSI C5: preparation from Q4 2026
Mapping the C5:2020 controls onto existing measures is under way, starting with operations, identity management and key management.
No attestation has been issued to date.
5. Accessibility: partially compliant
Partially compliant with WCAG 2.2 at level AA and with EN 301 549 V3.2.1.
The statement of accessibility under section 14 of the German Accessibility Strengthening Act is published. A bilingual VPAT 2.5 Rev INT serves as the detail report and is issued on request via [email protected].
6. Schrems II and third-country transfers
The transfer impact assessment methodology is documented; the EU standard contractual clauses 2021/914 are in place for every US sub-processor wherever US processing occurs.
The default path is processing inside the EU. A transfer to the United States happens only when a tenant deliberately switches on the relevant connector, such as Tavily, Stripe or Microsoft Graph.
Stripe and Microsoft are certified under the EU-US Data Privacy Framework.
7. Data sovereignty: where everything lives
| Storage location | Encryption | |
|---|---|---|
| Tenant databases (PostgreSQL) | Hetzner, Germany | TLS in transit, LUKS at rest, column encryption for secrets with a rotating master key |
| Backups, daily, thirty days | Hetzner Storage Box, Germany | AES-256 on a separate key path |
| Language model prompts and responses | Modal Labs, Frankfurt | TLS in transit, no retention at the model backend |
| Uploaded files | Hetzner and Cloudflare R2 in EU buckets | TLS in transit, AES-256 at rest |
| Authentication secrets | Hetzner, Germany | Argon2id for passwords, master key held apart from the signing key |
| Payment data | Stripe, EU and United States, DPF certified | PCI-DSS level 1 at Stripe |
| Support tickets | Hetzner, Germany | TLS in transit, LUKS at rest |
8. Sub-processors: all eight of them
Role, region and contractual basis per provider. Existing customers are told about any change by email four weeks in advance, as Article 28(2) requires.
| Role | Region | Safeguard | |
|---|---|---|---|
| Hetzner Online GmbH | Servers, storage, backups | Germany | Processing agreement, ISO 27001 |
| Cloudflare, Inc. | DDoS mitigation, firewall, DNS, tunnel | Global, EU-fronted | Processing agreement, EU standard contractual clauses, ISO 27001 |
| Modal Labs, Inc. | Compute for language models | EU (Frankfurt) | Processing agreement, EU standard contractual clauses, no retention |
| Stripe, Inc. | Payment processing | EU and United States | Processing agreement, EU standard contractual clauses, EU-US Data Privacy Framework |
| Tavily, Inc. | Web search, only on tenant opt-in | United States | Processing agreement, EU standard contractual clauses |
| Microsoft Corporation | Microsoft 365 connector, only on tenant opt-in | EU at the tenant's choice | Processing agreement, EU standard contractual clauses, EU-US Data Privacy Framework |
| GitHub, Inc. | Source code hosting, no tenant data | United States | Processing agreement, EU-US Data Privacy Framework |
| GitGuardian, Inc. | Secret scanning, no tenant data | EU | Processing agreement |
9. Certificates: only what genuinely exists
This section lists what we actually hold. External audit certificates are not among them yet. The slots stay visible as an honest signal.
- ISO/IEC 27001: targeted for 2027.
- BSI C5: preparation from the fourth quarter of 2026.
- TISAX: on request.
10. Contact and requests
For compliance inquiries, obtaining the processing agreement, vendor reviews or auditor access.
Postal address: SIMO GmbH, attn. Compliance, Würzburger Straße 152, 63743 Aschaffenburg, Germany.
This page is reviewed at least quarterly, and additionally whenever the platform changes materially.
- Compliance: [email protected]
- Data protection: [email protected]
- Accessibility: [email protected]