> ## Documentation Index
> Fetch the complete documentation index at: https://docs.generect.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Compliance

> How Generect handles your data, privacy, and legal agreements

## Data protection & GDPR

Generect operates in line with the **GDPR**. Our public legal terms:

* [Privacy Policy](https://generect.com/privacy) — what we collect and why, including US state privacy rights
* [Terms of Service](https://generect.com/terms)
* [Legal Notices](https://generect.com/legal) and [Cookie Policy](https://generect.com/cookie-policy)

## Data Processing Agreement (DPA)

Our [Data Processing Agreement](https://generect.com/dpa) covers personal data processed through the API and the app. It is accepted together with the [Terms of Service](https://generect.com/terms), so there is nothing to sign — send the link straight to your legal or security team.

It includes the processing details (Annex I), the technical and organisational measures (Annex II) and the current sub-processor list with hosting locations (Annex III), which is usually what a security review asks for next.

Need a **countersigned copy**, or have another data-protection question? Write to [dpa@generect.com](mailto:dpa@generect.com).

## Infrastructure & security practices

* **Hosting:** the application and database run in **EU data centers**; static web assets are served from our provider's US location.
* **In transit:** all API traffic is encrypted over HTTPS/TLS.
* **Payments:** processed entirely by **Stripe** — card data never touches Generect servers.
* **API keys:** scoped per token; every key can be paused, renamed, or revoked instantly from [your settings](https://beta.generect.com/settings/api), and usage and transaction history are visible via the [account endpoints](/api-reference/endpoint/accounts/get-account-usage).
* **Billing transparency:** every charge is itemized (`meta.amount_charged`, transactions, invoices) — see [Pricing](/billing/pricing).

## Certifications

We do not currently hold SOC 2 or ISO 27001 certification. If your security review needs a completed questionnaire (CAIQ/SIG or your own), contact [dpa@generect.com](mailto:dpa@generect.com) — the same address as the DPA, so the whole review stays in one thread.

## Uptime & incidents

Live status, 90-day uptime history, and incident reports are public at [status.generect.com](https://status.generect.com). See also [Reliability](/api-reference/reliability).
