Featured on Microsoft News →

    SECURITY · DATA PROCESSING AGREEMENT

    GDPR-compliant.
    EU data residency. DPA available.

    All data processed and stored exclusively in EU Azure regions. Our Data Processing Agreement covers all GDPR obligations for enterprise customers. Typically returned within 24 hours of request.

    Key commitments

    • All data processed and stored in EU Azure regions — West Europe (Amsterdam) and North Europe (Dublin)
    • Zero data retention by default — no customer data persisted beyond operational requirements
    • No customer data used for model training — ever
    • Standard Contractual Clauses (SCCs) available for international data transfers
    • Sub-processor list maintained and updated quarterly — available on request
    • Right to erasure supported — deletion fulfilled within 72 hours
    • Breach notification within 72 hours as required by GDPR Article 33
    • Auth0 token vault — OAuth credentials stored with bank-grade security, never in application database

    DPA scope

    The DPA governs processing of personal data by Orderfox AG (Processor) on behalf of enterprise customers (Controller). It covers all data processed by GieniABX including contact data accessed via CRM connectors, email content processed for outreach executions, and any personal data included in documents processed by the system.

    Sub-processors

    Anthropic

    AI inference

    Microsoft Azure

    Infrastructure

    Auth0 / Okta

    Identity & credentials

    Stripe

    Billing

    Full sub-processor list available on request. Updated quarterly.

    Request a signed DPA

    Enterprise customers on Pro receive a fully executed DPA as part of standard onboarding. Request yours in advance – typically returned within 24 hours.

    Request DPA →