Skip to content

// security

GDPR

Applies to

Product: Demo · Cloud · Server · Audience: Security / Compliance reviewer · Data protection officers

Roles (controller/processor) per deployment model, availability of a data processing agreement (DPA), data location, data subject rights and how basebox supports them. Not legal advice – the assessment of your processing lies with you as controller.

Roles per deployment model

Controller basebox's role DPA
basebox Cloud Your organization Processor – basebox operates the infrastructure your data sits on and has technical access Yes, prerequisite for production (Go-live checklist)
basebox Server, self-operated Your organization None – basebox has no access, no telemetry; no processing by basebox takes place Not required
basebox Server, operated by basebox Your organization To be regulated contractually – the maintenance access technically enables access to personal data Usually yes, as part of the operations contract
basebox Server, hosted at basebox Your organization Housing alone is not processing; physical access must be regulated contractually Housing contract; DPA only under an operations contract
Demo User or organization Processor, with Hetzner and Google as sub-processors DPA in place; real personal data still does not belong in the Demo

Application administration and data sit with you in every model (Shared responsibility).

Data location

  • Cloud: platform and language model run on basebox's own server in the Noris data center in Munich; no third party processes data. basebox GmbH is based in Germany (Infrastructure).
  • Demo: platform at Hetzner, language model Claude via Google Vertex AI; both are sub-processors of basebox with their own DPA.
  • Server: your data center or the basebox data center – the server is dedicated, the data sits there and only there.
  • External services: web search queries go to the configured provider – Staan (default) processes in EU data centers with a DPA available; DuckDuckGo is a US company. Connectors reach your own systems. Both are off by default and your decision (External services).
  • Cloud and Server: no third-country transfer by the architecture; it arises only if you enable an external service outside the EU.
  • Demo: Google is a US company. Whether using Vertex AI involves a third-country transfer depends on region and contract. Real data does not belong in the Demo anyway.

Which data is processed

Category Examples Where
User master data Name, e-mail, role, groups Application and identity database
Usage data Sign-ins, actions, client addresses, tool calls Audit log
Content data Uploads, knowledge base documents, embeddings – depending on what users enter, potentially special categories (Art. 9) Databases, media volume
Chat history Users' conversations Locally in the user's browser, not on the server
Conversation content in the audit log Only at the corresponding detail level, with a notice in the chat Audit log
Credentials Per-user connector credentials (write-only), password hashes of local accounts Application and identity database

Complete: Storage. Whether special categories are processed depends on your use – with patient data a data protection impact assessment is usually indicated.

Data subject rights

Right How basebox supports What sits with you
Access (Art. 15) User management shows master data; audit export delivers usage data per user; users see their chats themselves Compilation and answer
Rectification (Art. 16) Master data in user management or in the directory (LDAP/SSO) Execution
Erasure (Art. 17) Delete account, remove documents; chats sit in the user's browser. Audit entries are currently not deleted automatically Process per Deletion; factor in backup rotation
Restriction (Art. 18) Deactivate account Decision
Data portability (Art. 20) Chat export by the user (Back up chats); audit export CSV Format and handover
Objection (Art. 21) – Assessment

Technical and organizational measures

The TOMs you can describe in your record or DPA annex, with references:

  • Access control: roles administrator/user, groups, OIDC/LDAP, API keys (Roles & permissions)
  • Tenant separation: Cloud isolated environment per organization (Isolation); Server dedicated hardware
  • Transport encryption: TLS on all paths; storage encryption at the storage layer (Encryption)
  • Logging: audit log with configurable retention and detail level; notice in the chat (Audit & logging)
  • Data minimization: web search without user identity, audit without query text, prompt logging off by default
  • Deletability: by users and administrators (Deletion)
  • Availability: backups (Backup · Backup & restore)
  • Control of processing on behalf: maintenance access time-limited, approved, logged (Remote maintenance)
  • Secure development: security tests before release, four-eyes principle (Infrastructure policy)

Openly named: no encryption at rest by the application; image signatures in preparation.

Incidents

In case of security-relevant incidents basebox informs affected customers without delay (Compliance document); notification of supervisory authorities and data subjects under Art. 33/34 lies with the controller. Reports to basebox: datenschutz@basebox.ai.

For the review

  • Determine the deployment model and thus basebox's role unambiguously.
  • Cloud: DPA before go-live; take subcontractors and data center location from the DPA.
  • Document policies: audit detail level, retention, web search, connectors (Policies).
  • Set a usage rule for users (which data may go into basebox, which not into web searches).
  • Check for a DPIA if special categories are processed.

Next step: ISO 27001