Skip to main content

Data protection & GDPR

Generect operates in line with the GDPR. Our public legal terms:

Data Processing Agreement (DPA)

Our Data Processing Agreement covers personal data processed through the API and the app. It is accepted together with the Terms of Service, so there is nothing to sign — send the link straight to your legal or security team. It includes the processing details (Annex I), the technical and organisational measures (Annex II) and the current sub-processor list with hosting locations (Annex III), which is usually what a security review asks for next. Need a countersigned copy, or have another data-protection question? Write to dpa@generect.com.

Infrastructure & security practices

  • Hosting: the application and database run in EU data centers; static web assets are served from our provider’s US location.
  • In transit: all API traffic is encrypted over HTTPS/TLS.
  • Payments: processed entirely by Stripe — card data never touches Generect servers.
  • API keys: scoped per token; every key can be paused, renamed, or revoked instantly from your settings, and usage and transaction history are visible via the account endpoints.
  • Billing transparency: every charge is itemized (meta.amount_charged, transactions, invoices) — see Pricing.

Certifications

We do not currently hold SOC 2 or ISO 27001 certification. If your security review needs a completed questionnaire (CAIQ/SIG or your own), contact dpa@generect.com — the same address as the DPA, so the whole review stays in one thread.

Uptime & incidents

Live status, 90-day uptime history, and incident reports are public at status.generect.com. See also Reliability.