DocsGDPR & security

GDPR & security

Everything about how Custos AI processes your data, the legal framework, and the technical security measures we apply.

Our role under the GDPR

Custos AI acts as a data processor. You — the customer — are the data controller. We process personal data only on your documented instructions and in accordance with our Data Processing Agreement (DPA), which is included in our Terms of Service.

Data Processing Agreement (DPA)

Our DPA is Article 28 GDPR-compliant and covers all processing activities. It is automatically accepted when you accept our Terms of Service. You can download the current version at any time.

What data we process

CategoryExamplesRetention
Account dataName, email, hashed password, languageDuration of account + 12 months
Chat dataConversation history, model used365 days rolling, configurable
Uploaded filesPDF, DOCX, images30 days from upload (configurable)
Usage dataToken counts, cost estimates12 months rolling
Audit logsIP address, timestamps365 days
Billing recordsStripe references, plan info7 years (tax law)

LLM providers and the BYOK model

Under the BYOK model, you maintain a direct relationship with each LLM provider through your own API keys. LLM providers are not sub-processors of Custos AI — they are independent controllers or processors that you engage directly. You are responsible for ensuring appropriate legal basis and data processing agreements with each provider you use.

The four LLM providers currently supported in Custos AI — OpenAI, Anthropic, Google, and Mistral — all offer their own GDPR-compliant terms and DPAs which you agree to when creating an account with them.

Sub-processors

Supabase, Inc.Database, auth, file storageFrankfurt, DE
Vercel, Inc.Frontend hosting and edge computeEU edge
TransIP B.V.VPS for LiteLLM proxyAmsterdam, NL
LettermintTransactional emailEU
Stripe Payments EuropePayment processing and taxDublin, IE

Full list: custosai.eu/sub-processors

Security measures

Encryption at rest
AES-256 (data), AES-256-GCM (API keys)
Encryption in transit
TLS 1.2+ on all connections
Authentication
Email + TOTP MFA
Access control
Least-privilege, role-based
Backups
Daily encrypted, 30-day retention
Hosting
EU only — Frankfurt + Amsterdam
Privacy or DPA questions?

Our privacy team responds within 2 business days.