SovrGPT Docs

GDPR & compliance

Data processing agreement, hosting, sub-processors, data flows.

SovrGPT was built to be operable in a GDPR-compliant way without workarounds. We do not use hyperscalers (AWS, Azure, Google Cloud) directly. The sub-processors we do use are operated exclusively in their EU regions — the processing path stays physically inside the EU. A data processing agreement under Art. 28 GDPR and standard contractual clauses are in place.

In short

QuestionAnswer
Where is data stored?In an EU region (encrypted at rest and in transit).
Where does model inference run?On GPU hardware in EU data centres across several EU member states.
Where does the frontend run?On an edge platform with a pinned EU region.
Are hyperscalers used?Not directly. Individual sub-processors operate their EU regions on hyperscaler infrastructure inside the EU, so hyperscalers are indirectly in the path, but not as a default chosen by us. For AI inference we use our own GPU hardware in EU co-location facilities, no hyperscaler.
Who is the controller?You (your organisation) for the content; eNetworkers GmbH (Jena, Germany) is the processor.
Who are the sub-processors?Categories are listed below. We provide the full list with legal entity, address and location on request.
Is data used for training?No. None of your data is used for training purposes — neither by us nor by the model providers (all self-hosted).

Data processing agreement (DPA)

Standard onboarding for team orgs includes a data processing agreement under Art. 28 GDPR. It is presented for acceptance when the org is created.

For enterprise contracts, eNetworkers adapts the DPA to the individual contractual situation.

Data flows

Browser (user, EU)


Web frontend (EU edge)

   ├── Database & storage (EU) — auth, chats, org data, encrypted tokens, attachments
   ├── GPU inference (EU data centres) — model inference
   ├── Transactional e-mail delivery (EU) — magic-link mails, system notifications
   └── Error telemetry (DE) — technical stack traces (no plain-text PII)

No data flow leaves the EU at any point.

Sub-processors (categories)

We publish only the categories of recipients here, in line with Art. 13(1)(e) GDPR. We provide the full list with legal entity, address, processing location and contractual basis on written request to dsb@landgraf-datenschutz.de — typically within 1–2 working days.

CategoryLocationPurposeContractual basis
Hosting, CDN, serverless functionsEU regionDelivery of the web app + API routesDPA + SCC
Database, authentication, file storageEU regionPersistence, login, attachmentsDPA + SCC
GPU inference (serverless)EU data centres in several EU member statesAI model inferenceDPA + SCC
Transactional e-mail deliveryEU regionMagic-link and system mailsDPA + SCC
Error telemetryGermanyTechnical error loggingDPA + SCC
Web search (optional, opt-in per chat)🔴 USA — Brave Software, Inc. (Delaware), based in San FranciscoBrave Search backendDPA with a zero-data-retention commitment

🔴 Web search is the only building block outside the EU — which is why it can be switched off. It is opt-in per chat and off by default; without the switch in the composer, no request leaves the European setup. What is transmitted is the search query the model wrote — not your conversation, not your attachments. Because the model derives that query from the conversation, it can contain material from it; if you have to rule that out, leave the switch off. For the Search API, Brave commits to zero data retention in its data processing addendum and takes the position that search query data falls outside the material scope of the GDPR. That assessment is Brave's own, not ours — it does not replace a transfer mechanism.

(This row said "EU" until 2026-09-12. That was wrong: Brave Software, Inc. is a US company and appoints an EU representative under the GDPR — which is what you do when you are not established in the EU. Corrected once the contradiction surfaced.)

Which data is processed?

  • Account data: e-mail, profile fields.
  • Chat content: user prompts, model answers, attachments.
  • Connector data: only what the respective connector explicitly loads (e.g. Notion page contents, GitHub issues).
  • Telemetry: anonymised performance and error telemetry without plain-text PII.
  • Logs: request logs (method, path, status, duration) for 30 days. No body content in logs.

Deletion

  • Delete a chat: hard delete in the database, attachments removed from storage at the same time.
  • Delete an org: cascading delete of all chats, connectors, tokens and API keys. The residual backup table is cleaned up within 30 days as well.
  • Delete an account: on request by e-mail to kontakt@e-networkers.de; the auth user is deleted and the deletion cascades into profiles and org memberships.

Rights of the data subject

Access, rectification, erasure and data portability under Art. 15–20 GDPR can be exercised through the self-service profile (/settings/profile) or requested by e-mail to kontakt@e-networkers.de. We respond within 30 days.

GDPR & compliance