Data Security
Last reviewed: 19 September 2026 · Version: 1.1
This page describes how Domicode protects the data of its customers and their clients, what our current limits are, and which laws we follow. It is written to be checked, not to reassure: every statement here reflects our systems as configured on the review date. The Privacy Policy describes what we collect and why; the Data Processing Agreement sets out our obligations as processor; this page describes the measures.
1. Where your data is
| Data | Location |
|---|---|
| Application database (accounts, workspaces, projects, conversations, extracted text, project memory, locations, billing) | Frankfurt, Germany, in the European Union |
| Vector search index (text chunks of your documents and their embeddings) | Sweden, in the European Union |
| Uploaded files (original documents) | The Eastern Europe region of our cloud storage provider |
| Conversation records for quality review | Frankfurt, Germany, in the European Union |
| Authentication (name, email, sign-in identifiers, sessions) | United States |
| Artificial-intelligence inference (question text, conversation, document content) | A broker in the United States that routes requests to model providers in the United States and other countries; routing is not currently restricted to a region |
| Mapping and geocoding (addresses you enter) | Global (primary), Germany (fallback) |
| Hosting, payments, secrets and email providers | United States companies; regions depend on the service (Privacy Policy, section 7) |
We do not claim that all customer data stays in the EU: authentication and AI inference are processed in the United States under the European Commission's Standard Contractual Clauses (Privacy Policy, section 7). Our regulatory corpus, the published Greek building regulations, contains no customer data.
2. Encryption
All data is encrypted at rest with AES-256 by our database, file-storage, authentication and vector-index providers, including database backups. All connections use TLS: between your browser and the application, between the application and every provider, and between our providers.
3. Access control
Your workspace. Every request to the application is checked against your workspace membership; you can only see projects, files and conversations shared with you within your workspace. A workspace administrator decides who is a member and what each member can see and do.
Uploads. Files go directly from your browser to encrypted storage using a credential that is valid for 15 minutes and for that one upload; they do not pass through our application servers.
Our team. There is no function in the application through which our team can read customer documents or conversations; our internal console manages organisations, plans and credits only. Conversation records are available to a small number of named team members through the quality-review tool described in the Privacy Policy, section 5. Separately, the administrators who hold production credentials have technical access to the database and file storage, and therefore to all customer content; that access is limited to a small number of named people bound by confidentiality. Their access is not currently recorded in an audit log; see section 9.
4. Backups and recovery
The application database is protected by continuous point-in-time recovery, stored encrypted in the same EU region. This protects against accidental deletion, corruption and provider incidents within the provider's rolling recovery window. Data you delete expires from the recovery history within that window and cannot be removed from it earlier.
Uploaded files are stored in encrypted object storage without a separate backup copy we control; keep your own copies of original documents.
5. Deletion and export
Deleting a file, a conversation or a project removes it from the live systems. Deleting an account removes the account and its content from the live systems on request; copies in backups expire within the recovery window. You can request an export of your content, outputs and project memory in a structured, machine-readable format at any time and for 30 days after your subscription ends; we provide it free of charge within 30 days (Terms of Service, clause 13.3). Deletion and export requests are currently handled by our team on request to hello@domicode.gr; a self-service function is planned.
6. Artificial intelligence and your content
Outputs are generated by AI models operated by providers that act as our processors. We do not use your content or outputs in identifiable form to train, fine-tune or evaluate models, and we have configured and contractually restricted our AI providers so that content submitted through the Service is not used to train their models. Every AI-generated output is labelled as such in the Service, and the Service tells you that you are interacting with an AI system, as Article 50 of Regulation (EU) 2024/1689 requires. Our providers' processing locations are stated in section 1.
7. Account security
Sign-in is by email or by a Google account; a Google sign-in inherits the two-factor protection you have set on that account. Multi-factor authentication for user accounts is not yet available; it is planned and will be announced on this page. Sessions expire and can be revoked by signing out; tell us at hello@domicode.gr immediately if you suspect unauthorised use of your account.
8. Incidents and vulnerability reports
If we become aware of a personal data breach, we assess it immediately, contain it, notify the Hellenic Data Protection Authority within 72 hours where required, and inform affected customers without undue delay with the facts, the likely consequences and the measures taken (GDPR Articles 33 and 34). As processor we inform the customer, as controller, without undue delay so that the customer can meet its own obligations.
To report a security vulnerability, write to hello@domicode.gr with "security" in the subject line. We acknowledge reports within three working days, keep you informed, and will not take legal action against good-faith research that respects users' data and does not disrupt the Service. We do not operate a paid bounty programme.
9. What we do not yet offer
We would rather state our limits than have you discover them. As at the review date:
- Our team's technical access to production systems is not recorded in an audit log. Audit logging is planned.
- AI inference routing is not restricted to a region; a region-restricted, contractually guaranteed deployment is planned.
- We hold no ISO 27001 or SOC 2 certification and do not claim one. We will consider certification when our customer base requires it.
- Self-service account deletion and export are planned; both are available on request today.
- Multi-factor authentication for user accounts is not yet available, and its enforcement across our team's production consoles is being completed.
Each item will be updated here when it changes.
10. Legal framework we follow
- Regulation (EU) 2016/679 (GDPR) and Law 4624/2019, as controller for user data and as processor for the data in customer documents, with a Data Processing Agreement available to every business customer and a sub-processor list available on request.
- Law 3471/2006 on privacy in electronic communications: strictly necessary cookies in the application, and on the website traffic analytics that load only after you accept them, with no advertising or cross-site tracking either way.
- Presidential Decree 131/2003 on electronic commerce and Law 4919/2022 on the General Commercial Registry: provider information published on every page.
- Regulation (EU) 2024/1689 (AI Act), Article 50: AI disclosure and labelling of AI-generated outputs.
- Regulation (EU) 2023/2854 (Data Act): switching and export terms without fees or obstacles.
- Regulation (EU) 2022/2065 (Digital Services Act), to the extent it applies to the Service: a single point of contact and transparent content restrictions in the Terms of Service.
11. Contact
Security and privacy questions, data processing agreements and sub-processor lists: hello@domicode.gr. DOMICODE P.C., 75 Thessalonikis Street, 183 45 Moschato, Attica, Greece.