Datenmaske

Trust

Security & Data Protection

Datenmaske supports GDPR-compliant processes for detecting and permanently redacting personal data in PDF documents. This page provides an overview of the technical and organisational measures. The full privacy policy can be found under Privacy Policy .

Hosting & Server Location

Location: European Union (Germany).

AI detection (Named Entity Recognition, rule-based patterns) runs on self-hosted servers — no data is sent to US AI services such as OpenAI or Google. Which models are used in detail, where inference runs and how we handle the EU AI Act is documented transparently on the AI Explainability & AI Act Posture page.

The application infrastructure (application, database, AI detection, document processing) is operated by us and hosted with our hosting partner netcup (data centre in Nuremberg) in Germany. The netcup data centre is certified according to ISO/IEC 27001 (Data-Center-only; not a certification of the Datenmaske application).

Processors (Sub-Processors)

The following service providers process data on our behalf, exclusively within the EU and on the basis of a Data Processing Agreement (Art. 28 GDPR):

netcup GmbH — Hosting Infrastructure

Purpose: Server infrastructure for application, database, AI detection (NER) and document processing (Convex). Location: data centre Nuremberg (Germany). netcup (Anexia group) is certified for its data centre according to ISO/IEC 27001, ISO 9001 and ISO 27701 (Data-Center-only; no ISO certification of the Datenmaske application). DPA available.

Microsoft Azure Document Intelligence — OCR Text Recognition

Purpose: OCR for scanned pages (only for scanned documents; digital PDFs are not transmitted). Location: Germany (Azure region Germany West Central). Provider: Microsoft Ireland Operations Ltd., Ireland. DPA available.

Stripe — Payment Processing

Purpose: Billing of paid plans (only when booking). Location: EU. DPA available.

Rybbit — self-hosted, cookie-free analytics

Purpose: Aggregated, anonymous usage statistics. Self-hosted, without cookies, without personal data, without profiling. No consent required.

Encryption

Transit: TLS-encrypted (HTTPS).

Storage: Processing on EU servers; encryption by the infrastructure of the hosting partner (netcup).

Data Processing

  1. Upload over an encrypted connection to an EU server.
  2. Detection of personal data through self-hosted AI and rule-based patterns.
  3. OCR exclusively for scanned pages via Azure (EU) — digital PDFs never leave our servers.
  4. Irreversible redaction followed by verification that the text has actually been removed.
  5. Export of the redacted PDF; automatic deletion after the retention period expires.

Retention & Deletion

The standard period is 30 days from upload. Depending on the plan, a shorter period or a maximum of 90 or 365 days can be selected. Audit logs of the actions are retained without document contents. Audit logs are retained per plan for 30/180/180/365 days (Starter/Solo/Professional/Business).

Content Removal and Verification

The redaction is irreversible: the original text is physically removed from the PDF, not merely covered. After each redaction, the system verifies that the text has actually been removed. For OCR-based pages, only the text layer can be verified — such pages are marked accordingly and should additionally be checked manually.

Detection Quality Measurably Demonstrated

The detection and redaction quality is measured reproducibly — methodology, corpus hash, irreversibility proof and competitor status (each with a vendor statement or dated self-measurement) are publicly available under Research — Reproducible Detection Quality . The figures published there refer to a synthetic laboratory corpus and are not representative of arbitrary third-party documents.

Technical and Organisational Measures (Art. 32 GDPR)

Datenmaske implements a multi-layered security concept according to Art. 32 GDPR — divided into application-related measures and the infrastructure-related measures of our hosting partner netcup (data centre Nuremberg; the data centre is certified according to ISO/IEC 27001 — Data-Center-only). In overview:

Note: A dedicated ISO/IEC 27001-certified Information Security Management System (ISMS) for the Datenmaske application is in preparation (target 2027). The ISO/IEC 27001 certification mentioned here applies exclusively to the data centre of our hosting partner netcup.

  • Confidentiality: EU hosting, role-based and locally restricted admin access, API authentication via hashed keys, seamless audit logging.
  • Integrity & Transit: TLS-encrypted transit, processing exclusively on the instructions of the controller.
  • Availability: redundant data centre infrastructure (netcup, ISO/IEC 27001 Data-Center-only) including a backup concept.
  • Privacy by Design: 30-day deletion period by default, human-in-the-loop review of every redaction.
  • Redaction-specific: irreversible content-stream removal with post-redaction verification and metadata stripping.

The complete and versioned TOM catalogue according to Art. 32 GDPR is publicly available on the Technical and Organisational Measures (Art. 32 GDPR) page; the DPA template draft including the annex on the Data Processing Agreement (DPA) page.

For individual security questionnaires (CAIQ, customer-specific audits, extended TOM self-disclosures) please contact us on request : info@datenmaske.de .

Data Processing Agreement (DPA)

For business customers we provide a DPA according to Art. 28 GDPR. The template draft including the annex on the technical and organisational measures can be found on the Data Processing Agreement (DPA) page. Every change to the DPA template is documented publicly and versioned — the DPA Change History shows what has changed since an earlier version, with deep links to the respective paragraph. For a binding agreement and for security questionnaires, please contact us.

Support & Service Level

Our support channels, target response times per plan and availability notes can be found on the Support & Service Level page. During the beta phase, the target response times are purely indicative and provisional; binding SLAs are agreed in Business plans (and individual team/volume solutions on request).

Your Rights

Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and complaint to a supervisory authority. Details in the privacy policy.