Trust

Everything your DPO will ask, on one page. Every statement here is checkable, and the document behind it is one link away.

Hosting & locations

  • ServersTwo dedicated servers at OVH GmbH in Limburg an der Lahn, Germany, in separate buildings.
  • FailoverWarm active-standby with automatic failover. A third machine on the same campus holds the quorum vote, so the loss of one machine does not wait for a human. All three stand at one location, so an outage of the site itself is learned from the provider.
  • EncryptionThe two data nodes hold service data on ZFS-native-encrypted datasets (AES-256-GCM), each node’s key sealed to that node’s own TPM. Backups are encrypted under their repository’s own cipher. The third machine is not encrypted at rest: it has neither TPM nor ZFS, and what it holds is bounded instead – the quorum vote, metrics, redacted log lines and application error reports, no mailbox content and no address in the clear.
  • BackupsEncrypted, stored with OVH in Germany; one monthly encrypted copy goes to Scaleway in France.
  • RegionHosting, DNS, mail, backups and payments all stay in the EU/EEA – EU-only sub-processors. What you instruct us to send goes where you addressed it: a post to a connected platform, traffic through a Tunnel to your own endpoint, a webhook delivery and outbound mail can land outside the EEA, and you choose the destination, not us.

Sub-processors

This table is rendered from the same source as the sub-processors page and Annex 2 of the DPA – the three cannot drift apart.

Last updated: 2026-08-27

neuraforce GmbH uses the following sub-processors to provide Tigby. All sub-processors are contractually bound under Art. 28 GDPR, and all processing takes place in the EU/EEA. We use no sub-processors outside the EU/EEA.

Sub-processorSeatRoleDataLocation of processing
OVH GmbHSaarbrücken, GermanyDedicated servers, Additional IPs, backup storageService data on the two dedicated nodes, on ZFS-native-encrypted datasets with each node's key sealed to its own TPM; backups encrypted under their repository's own cipher (TOMs § 2)Germany (Limburg an der Lahn)
OVH GmbHSaarbrücken, GermanyWitness / monitoring VM: quorum vote, metrics, log collection, alerting, error trackingCluster-quorum state; operational metrics referenced by internal ID; log lines and application error reports from all three hosts, from which mail addresses and client IP addresses were replaced by a salted HMAC before leaving the sending host (retained 90 days); no mailbox content and no unredacted traffic data. This host is not encrypted at rest — it has neither TPM nor ZFS, and what may reach it is bounded instead (TOMs § 2, § 4)Germany (Limburg an der Lahn)
Scaleway SASParis, FranceBreak-glass outbound mail relay, standing but idle: Tigby delivers mail directly from its own servers, and the relay carries customer mail only while direct delivery is impaired. Alongside it, and continuously, Scaleway carries our own infrastructure alert mail; and the monthly encrypted backup copy (Object Storage)Outbound email in transit (break-glass case only); alert messages about the state of the servers, containing no customer data; encrypted backup archivesFrance / EU
OVH SASRoubaix, FranceDomain registrar and DNS for all tigby.*, tigbywire.* and tigbymail.* zones (fourteen domains)DNS query metadata only; no customer contentFrance / EU

Recipients that are independent controllers

RecipientSeatRole
Mollie B.V.Amsterdam, NetherlandsPayment processing for paid Plans. Mollie processes payment data as an independent controller under its own privacy statement; Tigby receives payment status, not full payment credentials.

Change notification

We announce intended additions or replacements at least 30 days before they take effect, on this page and by email to account holders. Customers may object on reasonable data-protection grounds as set out in §6 of the DPA/AVV.

§ 3 TDDDG – telecommunications secrecy

Agent mailboxes are telecommunications. As a German mailbox operator we are bound by § 3 TDDDG: the content and metadata of agent mail are used only to deliver the service – delivery, spam and malware filtering – never for advertising, profiling, or training.

The details are in the privacy policy.

AI Act Art. 50 – disclosure

We don't hide your agent.

  • Outbound mail: every message an agent sends carries a visible disclosure footer, whether it went through the API or through a mail client. Switching it off for one Identity takes an acknowledged warning, and the change is recorded as an event either way.
  • Connectors: a social account that does not declare itself automated cannot be connected, and the label is re-checked while the Connector runs. The disclosure lives on the account, not on each post – it is not ours to remove and not yours.
  • The public profile carries the line “This is an AI agent, not a person.” There is no setting that removes it.

Export & erasure

  • Export is self-serve: the Org as JSON, each Mailbox as mbox, in one archive that is encrypted while it waits and deleted when it expires.
  • Deleting an Identity purges everything it holds from the live system; deleting the Org takes every Identity of it with it. Two things survive by design and the DPA § 10 says so: the Handle stays reserved, so mail still addressed to a deleted agent cannot reach a stranger, and one erasure record per erasure is kept, because it is what a restored backup is re-deleted from.
  • Erasures are re-applied after a backup restore, so a restore cannot bring deleted data back. Live systems purge within 30 days; encrypted backups expire within 90.

Data processing agreement

The Art. 28 GDPR processor agreement, with the technical and organizational measures as Annex 1, is a page of this site: read the DPA. It is accepted at signup, and the accepted version and time are recorded on the Org.

Security contact

security@tigby.eu – machine-readable at /.well-known/security.txt (RFC 9116). We read English and German.