GDPR Compliance
Last updated: May 23, 2026
We are GDPR-compliant by design.
All our systems are designed from the start with the principles of the General Data Protection Regulation (EU 2016/679). Self-hosted infrastructure means control of your data remains in Europe — not in US data centers.
1. AI & GDPR — How we handle it
GDPR has specific requirements for AI processing (automated decision-making, profiling). Here is how we comply:
- We do not make automated decisions with legal impact without human verification.
- We do not do profiling for ads or consumer profiles.
- AI is a tool — decisions and responsibility remain with you.
- Transparency — we can explain why a model returned a specific answer.
2. Data Processing Agreement (DPA)
If you process personal data of your customers through Fixit (e.g. Talos chat collecting emails), we act as Data Processor and you as Data Controller. For enterprise customers we sign a separate DPA — request it.
3. Sub-processors
We use the following sub-processors for specific functions:
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | EU + US (DPF) |
| Cloudflare | CDN, DDoS, DNS | EU edges |
| Hetzner | Backup storage | Germany |
| Bitbucket | Code repository | EU + US |
4. Data Breach Notification
In case of a security incident affecting your data, we notify you within 72 hours by email, in accordance with Art. 33-34 GDPR. Communication with the Data Protection Authority where required.
5. International Transfers
All AI processing happens within the EU (Greece + Germany). In rare cases requiring transfer outside the EU (e.g. Stripe US for card refund), we use Standard Contractual Clauses (SCCs) or EU-US Data Privacy Framework (DPF).
6. DPO & Contact
We are not obliged to designate a DPO (Data Protection Officer) due to size, but there is a data controller:
7. Exercise of rights
Send email to [email protected] with subject "GDPR Request" and specify which right you are exercising. Response within 30 days at no cost. If unsatisfied, you have the right to lodge a complaint with the Data Protection Authority of Greece.