Your data stays your data.
AI is only useful if you can trust it with your real documents. So here it is, without the marketing fog: where your data is stored, who sees it, and what happens to it – and what we deliberately don’t claim.
Four commitments you can hold us to
None of them is a statement of intent. All four are written into the contract.
Processing in Germany
The platform runs by default in a German data center. Not “on request,” not as a paid add-on – that’s the default for every customer.
No model training
Your inputs, documents, and chat history are never used to train AI models – neither ours nor anyone else’s.
Zero Data Retention with the models
We only enable models that run in the EU and that are contractually guaranteed not to store requests after they’ve been answered.
Encrypted transmission and access protection
All connections run over TLS. Passwords are stored exclusively as hashes, and credentials for your connected systems are encrypted. Internal services aren’t reachable from outside, and administrative access runs exclusively through a dedicated VPN.
What actually happens to a request
The most common objection in data-protection conversations is: “Where does all of this actually end up?” Here’s the path, stop by stop.
Your browser
You ask a question or upload a document. The connection is TLS-encrypted before the first character leaves your computer.
novendix.AI in Germany
Your request runs through the platform in the German data center. Connected systems – ERP, CRM, database – are only queried where your permissions allow it.
Model in the EU
The selected language model runs in a European data center, answers the request, and retains none of it.
What doesn’t happen: No training dataset is built from your content, no copy stays with the model provider, and nothing leaves the EU.
Technical and organizational measures
The excerpt that’s relevant for most audits. The full TOMs are an appendix to the Data Processing Agreement.
Data processing under Art. 28 GDPR
As soon as we process personal data on your behalf, you are the controller and we are the processor. That isn’t a formality – it’s what lets you keep control: we only process what you instruct us to.
The Data Processing Agreement governs the location of processing, the subprocessors used, the technical and organizational measures, and our obligations to you. It is anchored in § 6 of our Terms & Conditions and takes precedence over them in case of conflict.
When you book access, you conclude the DPA with its own separate mandatory checkbox – apart from the Terms & Conditions and this privacy notice. If you need a signed copy or your own group-wide template, you’ll get the agreement separately on request, usually the same business day. What the agreement covers in detail is on the Data Processing Agreement (DPA).
Your rights as a data subject
Regardless of the contract, you and your employees are entitled to the rights under the GDPR. We support you in exercising them.
- Access to information about which data is processed (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure and restriction of processing (Art. 17, 18)
- Data portability in a common format (Art. 20)
- Objection to certain types of processing (Art. 21)
Send inquiries to info@novendix.AI. We respond personally, not through a ticketing system.
EU AI Act: we’ll also tell you when things get complicated
Data protection is one half, AI law is the other. Since August 2026, parts of the EU AI Act have applied; for high-risk applications, the larger part follows later. Before we build anything, we work out together which category your use case falls into – and say openly when a project would cost more effort than it’s worth.
What has applied since August 2026
Obligations, deadlines, and the actual fine ranges under Art. 99 – including the special rule for SMEs.
High risk in HR
Why selecting applicants and specifically targeting job ads falls under Annex III.
When AI acts on its own
What changes once an agent no longer just answers but triggers processes – and what limits are then needed.
The questions data protection officers ask us
Sorted by frequency, answered without dodging.
Are our inputs used to train AI models?
No. We only enable models for which it’s contractually guaranteed that requests are neither used for training nor stored after being answered. That guarantee is why our model selection is smaller than with freely accessible chat services – we only enable what meets this condition.
Where is the data processed?
The platform runs by default in a German data center. The language models run in European data centers. There is no processing outside the EU.
Who at novendix can see our content?
No one, during normal operation. Access to systems containing customer data only happens when you bring us in for a specific issue or a connection – and then only by the people already handling your project. You have a dedicated point of contact with us, not a rotating support queue.
Can we delete chat history?
Yes. You delete individual conversations directly in the platform. No copy is created at the model provider that would need deleting anyway. Full deletion of an account or all data at the end of the contract follows what’s agreed in the Data Processing Agreement.
Are you certified to ISO 27001?
The infrastructure the platform runs on is certified to ISO 27001 – the infrastructure provider holds that certificate. We’re currently building our own information security management system. As long as we don’t have a certificate for that, we won’t put it on our website either.
Do we get a Data Processing Agreement?
Yes, it’s part of every contract and is anchored in § 6 of our Terms & Conditions. Currently, we send it on request; in the future it will be included automatically when the package is booked.
What happens to the data in our connected systems?
It stays where it is. The connection to your ERP, CRM, or database is an encrypted, access-controlled interface – the AI reads what it needs for the answer at the moment of the request. No second copy of your data is created with us.
What if we want to switch again later?
Then you take your data with you. Content and connections stay traceable and exportable – we deliberately don’t build in hurdles that make switching artificially expensive.
Does your data protection team still have questions?
Then let’s talk to them directly. We’ll put together the documents you need for your review, and we’ll also tell you where we can’t yet provide evidence for something.
Your secure AI platform for the Mittelstand. Secure. Intelligent. Integrated. Custom database integration, personally supported.
novendix GmbH · Industriestraße 6 · 91126 Schwabach
Locations: Schwabach · Weißenburg · Nuremberg
A company of the L&S Lange & Schermer Group
