> ## Documentation Index
> Fetch the complete documentation index at: https://docs.generect.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Compliance

> How Generect handles your data, privacy, and legal agreements

## Data protection & GDPR

Generect operates in line with the **GDPR**. Our public legal terms:

* [Privacy Policy](https://generect.com/privacy) — what we collect and why, including US state privacy rights
* [Terms of Service](https://generect.com/terms)
* [Legal Notices](https://generect.com/legal) and [Cookie Policy](https://generect.com/cookie-policy)

## Data Processing Agreement (DPA)

A signed DPA is available for customers processing personal data through the API — request one at [support@generect.com](mailto:support@generect.com).

## Infrastructure & security practices

* **Hosting:** production systems run in **EU data centers**.
* **In transit:** all API traffic is encrypted over HTTPS/TLS.
* **Payments:** processed entirely by **Stripe** — card data never touches Generect servers.
* **API keys:** scoped per token; every key can be paused, renamed, or revoked instantly from [your settings](https://beta.generect.com/settings/api), and usage and transaction history are visible via the [account endpoints](/api-reference/endpoint/accounts/get-account-usage).
* **Billing transparency:** every charge is itemized (`meta.amount_charged`, transactions, invoices) — see [Pricing](/billing/pricing).

## Certifications

We do not currently hold SOC 2 or ISO 27001 certification. If your security review needs a completed questionnaire (CAIQ/SIG or your own), contact [support@generect.com](mailto:support@generect.com).

## Uptime & incidents

Live status, 90-day uptime history, and incident reports are public at [status.generect.com](https://status.generect.com). See also [Reliability](/api-reference/reliability).
