GDPR-compliant, hosted in Germany
Your project data is hosted on servers in Germany. This page discloses which providers we use to run the service and with what safeguards – so your privacy and legal teams find everything in one place.
Data Location & Hosting
Your project data – descriptions, tasks, budgets, risks, stakeholders and AI chat histories – is stored and processed in a database on servers in Germany (EU).
- Primary hosting: Germany (EU)
- Encryption: TLS in transit, AES-256 at rest
- Daily automatic backups
Subprocessors
To operate the service we use a small number of carefully selected providers. Each is bound by a data processing agreement (DPA); where processing takes place outside the EU, we additionally rely on EU Standard Contractual Clauses (SCCs).
| Provider | Purpose | Data processed | Location | Safeguard |
|---|---|---|---|---|
| Hetzner | Hosting & database | Project data | Germany (EU) | DPA |
| Cloudflare | DNS & network security | Technical access data (e.g. IP) | EU / global | DPA, SCCs |
| Resend | Transactional email (e.g. verification) | Email address | USA | DPA, SCCs |
| OpenAI | AI processing | Context of the specific request | USA / EU | DPA, SCCs, no training |
| Anthropic | AI processing | Context of the specific request | USA / EU | DPA, SCCs, no training |
Changes to subprocessors are communicated to business customers in advance on request.
AI Data Processing
PathHub AI uses language models from OpenAI and Anthropic. For each AI feature, only the context needed for that specific request is passed to the model.
- Your content is not used to train public models.
- Processing runs under the providers' business API terms, not consumer services.
- No advertising profiles, no selling of data.
Access Control & Accountability
Role-based access
Owner, editor and viewer per workspace.
Two-factor authentication
Optional, for additional account protection.
Audit logs
Security-relevant events are logged.
IP restrictions
For Enterprise: limit access to approved networks.
Certifications & Audits
We align our information security management with recognized standards and have it independently assessed.
- ISO 27001: certification in preparation.
- SOC 2 Type II: planned.
- Regular penetration tests and vulnerability management.
- The data centers we use are ISO 27001-certified.
Data Processing & Your Rights
For business customers we provide a data processing agreement (DPA) including EU Standard Contractual Clauses. You may request access, rectification and deletion at any time. On account deletion, your project data is removed from live systems; backups expire after their retention period.
Full details: Privacy Policy · Security