Skip to main content

Data protection & GDPR

Generect operates in line with the GDPR. Our public legal terms:

Data Processing Agreement (DPA)

A signed DPA is available for customers processing personal data through the API — request one at support@generect.com.

Infrastructure & security practices

  • Hosting: production systems run in EU data centers.
  • In transit: all API traffic is encrypted over HTTPS/TLS.
  • Payments: processed entirely by Stripe — card data never touches Generect servers.
  • API keys: scoped per token; every key can be paused, renamed, or revoked instantly from your settings, and usage and transaction history are visible via the account endpoints.
  • Billing transparency: every charge is itemized (meta.amount_charged, transactions, invoices) — see Pricing.

Certifications

We do not currently hold SOC 2 or ISO 27001 certification. If your security review needs a completed questionnaire (CAIQ/SIG or your own), contact support@generect.com.

Uptime & incidents

Live status, 90-day uptime history, and incident reports are public at status.generect.com. See also Reliability.