Privacy & Security

Privacy & Security

Your data stays your data.

AI is only useful if you can trust it with your real documents. So here it is, without the marketing fog: where your data is stored, who sees it, and what happens to it – and what we deliberately don’t claim.

Server location: GermanyNo training on your dataEncrypted transmissionData processing under Art. 28 GDPR

Four commitments you can hold us to

None of them is a statement of intent. All four are written into the contract.

Processing in Germany

The platform runs by default in a German data center. Not “on request,” not as a paid add-on – that’s the default for every customer.

No model training

Your inputs, documents, and chat history are never used to train AI models – neither ours nor anyone else’s.

Zero Data Retention with the models

We only enable models that run in the EU and that are contractually guaranteed not to store requests after they’ve been answered.

Encrypted transmission and access protection

All connections run over TLS. Passwords are stored exclusively as hashes, and credentials for your connected systems are encrypted. Internal services aren’t reachable from outside, and administrative access runs exclusively through a dedicated VPN.

What actually happens to a request

The most common objection in data-protection conversations is: “Where does all of this actually end up?” Here’s the path, stop by stop.

01 · Input

Your browser

You ask a question or upload a document. The connection is TLS-encrypted before the first character leaves your computer.

02 · Processing

novendix.AI in Germany

Your request runs through the platform in the German data center. Connected systems – ERP, CRM, database – are only queried where your permissions allow it.

03 · Response

Model in the EU

The selected language model runs in a European data center, answers the request, and retains none of it.

What doesn’t happen: No training dataset is built from your content, no copy stays with the model provider, and nothing leaves the EU.

Technical and organizational measures

The excerpt that’s relevant for most audits. The full TOMs are an appendix to the Data Processing Agreement.

Transport encryptionAll connections run over TLS – to the platform and to every connected interface.

Protection of stored dataPasswords are stored exclusively as hashes, and credentials for connected systems are encrypted.

Two-factor authenticationAvailable for every user account and included in every package.

Access control at the interfacesEvery connection to your systems gets its own credentials and a defined scope of permissions – no more than the task requires.

Certified infrastructureOperations run on cloud infrastructure certified to ISO 27001. The certification is held by the infrastructure provider.

Our own certification in progressWe’re currently building our own information security management system to ISO 27001. As long as we don’t hold the certificate, we don’t claim one either.

Data processing under Art. 28 GDPR

As soon as we process personal data on your behalf, you are the controller and we are the processor. That isn’t a formality – it’s what lets you keep control: we only process what you instruct us to.

The Data Processing Agreement governs the location of processing, the subprocessors used, the technical and organizational measures, and our obligations to you. It is anchored in § 6 of our Terms & Conditions and takes precedence over them in case of conflict.

When you book access, you conclude the DPA with its own separate mandatory checkbox – apart from the Terms & Conditions and this privacy notice. If you need a signed copy or your own group-wide template, you’ll get the agreement separately on request, usually the same business day. What the agreement covers in detail is on the Data Processing Agreement (DPA).

No email program configured?

Your rights as a data subject

Regardless of the contract, you and your employees are entitled to the rights under the GDPR. We support you in exercising them.

  • Access to information about which data is processed (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure and restriction of processing (Art. 17, 18)
  • Data portability in a common format (Art. 20)
  • Objection to certain types of processing (Art. 21)

Send inquiries to info@novendix.AI. We respond personally, not through a ticketing system.

EU AI Act: we’ll also tell you when things get complicated

Data protection is one half, AI law is the other. Since August 2026, parts of the EU AI Act have applied; for high-risk applications, the larger part follows later. Before we build anything, we work out together which category your use case falls into – and say openly when a project would cost more effort than it’s worth.

The questions data protection officers ask us

Sorted by frequency, answered without dodging.

Are our inputs used to train AI models?

No. We only enable models for which it’s contractually guaranteed that requests are neither used for training nor stored after being answered. That guarantee is why our model selection is smaller than with freely accessible chat services – we only enable what meets this condition.

Where is the data processed?

The platform runs by default in a German data center. The language models run in European data centers. There is no processing outside the EU.

Who at novendix can see our content?

No one, during normal operation. Access to systems containing customer data only happens when you bring us in for a specific issue or a connection – and then only by the people already handling your project. You have a dedicated point of contact with us, not a rotating support queue.

Can we delete chat history?

Yes. You delete individual conversations directly in the platform. No copy is created at the model provider that would need deleting anyway. Full deletion of an account or all data at the end of the contract follows what’s agreed in the Data Processing Agreement.

Are you certified to ISO 27001?

The infrastructure the platform runs on is certified to ISO 27001 – the infrastructure provider holds that certificate. We’re currently building our own information security management system. As long as we don’t have a certificate for that, we won’t put it on our website either.

Do we get a Data Processing Agreement?

Yes, it’s part of every contract and is anchored in § 6 of our Terms & Conditions. Currently, we send it on request; in the future it will be included automatically when the package is booked.

What happens to the data in our connected systems?

It stays where it is. The connection to your ERP, CRM, or database is an encrypted, access-controlled interface – the AI reads what it needs for the answer at the moment of the request. No second copy of your data is created with us.

What if we want to switch again later?

Then you take your data with you. Content and connections stay traceable and exportable – we deliberately don’t build in hurdles that make switching artificially expensive.

Does your data protection team still have questions?

Then let’s talk to them directly. We’ll put together the documents you need for your review, and we’ll also tell you where we can’t yet provide evidence for something.

No email program configured?

Legal basis in detail: Privacy Policy · Terms & Conditions · Legal Notice. Last updated: September 2026.

Your secure AI platform for the Mittelstand. Secure. Intelligent. Integrated. Custom database integration, personally supported.

novendix GmbH · Industriestraße 6 · 91126 Schwabach
Locations: Schwabach · Weißenburg · Nuremberg
A company of the L&S Lange & Schermer Group

© 2026 novendix GmbH — All rights reserved.A New Era of Thinking · Built for the German Mittelstand 🇩🇪