Security & privacy
Your data. Your results. Your control.
EU hosting in Frankfurt and Amsterdam, no training on your data, a DPA built into every contract, every result yours. Each commitment on this page is written into our terms or our privacy policy — with the clause, so you can check it.
What every customer gets — from day one.
No enterprise tier, no negotiation. These four points are part of the contract for every account, from the free trial to the agency plan.
EU hosting in Frankfurt & Amsterdam
Your database, your login and your files sit in an EU region in Frankfurt. The applications run in an EU region in Amsterdam.
Terms § 20.2 · Privacy § 3 & 9
No training on your data
Your inputs and results are never used to train general AI models — ours or anyone else's. Our AI providers have committed to the same contractually.
Terms § 13.3 · Privacy § 9
DPA built into the contract
The Art. 28 GDPR data processing agreement becomes part of your contract at signup and sits in your account. A signed copy is one email away.
Terms § 20.3
Every result is yours
Listings, images, translations: the outputs belong exclusively to you. We reserve no exploitation rights and no promotional rights in them.
Terms § 14.1
Two EU regions for your data. And full transparency on where AI runs.
We name cities, not labels — and say which part of the processing goes where.
Frankfurt · EU
Account, data & files
Database, authentication and file storage are pinned to an EU region in Frankfurt.
Amsterdam · EU
Website & applications
All Torch application services are deployed in an EU region in Amsterdam — server logs included.
USA · EU Standard Contractual Clauses
AI generation
For text and image generation, prompts, product data and images go to our AI processors in the US. No training on your content, no prompt retention by default, storage bounded by the contract term.
Transfers to third countries take place only on the basis of appropriate safeguards under Art. 44 et seq. GDPR and are listed individually in the privacy policy (Terms § 20.2).
What applies to you, concretely.
Six points procurement and data protection officers usually ask about — each with its clause.
Payments through Stripe
Card and bank details go through Stripe Payments Europe (Ireland). We never receive full card or account data.
Privacy § 6
Zero tracking cookies
Our website sets no cookies for tracking or analytics. Web analytics runs cookieless and exclusively on EU servers; we use no advertising services.
Privacy § 7 & 8
No selling, no advertising
We do not sell personal data and do not use customer content for advertising.
Privacy § 9
30-day export after the contract ends
After the contract ends you can export your inputs and results in a common format for 30 days. After that, the data is deleted.
Terms § 19.5
Provenance record for every AI output
A provenance record identifying the content as AI-generated is stored with each generated version. A human stays in control of what gets published.
Privacy § 13
Reference only with your consent
We name you as a customer only after you have agreed in text form. No logo on our site without your yes.
Terms § 14.1
Every provider is listed in the privacy policy.
Whoever processes data on our behalf is listed there with location, role and transfer safeguard — as of 9 August 2026. If we swap a provider, that list changes.
Business customers can request our data processing agreement, including subprocessor flow-down terms, at hello@torchtechnology.de.
We show what we do — not what we bought.
You won't find a purchased seal or a self-made badge on this page. Every statement is a contractual commitment or documented in our privacy policy — checkable, with its clause. We do not hold an ISO 27001 or SOC 2 certification today; if your procurement has a security questionnaire, we answer it directly and in full.
Questions about security & privacy
See your catalog in the system
Bring your product and 20 minutes — we'll show you live how Listings and Studio work on your own data.