Licensed to be used in conjunction with basebox, only.
// security
GDPR
Applies to
Product: Demo · Cloud · Server · Audience: Security / Compliance reviewer · Data protection officers
Roles (controller/processor) per deployment model, availability of a data processing agreement (DPA), data location, data subject rights and how basebox supports them. Not legal advice – the assessment of your processing lies with you as controller.
Roles per deployment model
| Controller | basebox's role | DPA | |
|---|---|---|---|
| basebox Cloud | Your organization | Processor – basebox operates the infrastructure your data sits on and has technical access | Yes, prerequisite for production (Go-live checklist) |
| basebox Server, self-operated | Your organization | None – basebox has no access, no telemetry; no processing by basebox takes place | Not required |
| basebox Server, operated by basebox | Your organization | To be regulated contractually – the maintenance access technically enables access to personal data | Usually yes, as part of the operations contract |
| basebox Server, hosted at basebox | Your organization | Housing alone is not processing; physical access must be regulated contractually | Housing contract; DPA only under an operations contract |
| Demo | User or organization | Processor, with Hetzner and Google as sub-processors | DPA in place; real personal data still does not belong in the Demo |
Application administration and data sit with you in every model (Shared responsibility).
Data location
- Cloud: platform and language model run on basebox's own server in the Noris data center in Munich; no third party processes data. basebox GmbH is based in Germany (Infrastructure).
- Demo: platform at Hetzner, language model Claude via Google Vertex AI; both are sub-processors of basebox with their own DPA.
- Server: your data center or the basebox data center – the server is dedicated, the data sits there and only there.
- External services: web search queries go to the configured provider – Staan (default) processes in EU data centers with a DPA available; DuckDuckGo is a US company. Connectors reach your own systems. Both are off by default and your decision (External services).
- Cloud and Server: no third-country transfer by the architecture; it arises only if you enable an external service outside the EU.
- Demo: Google is a US company. Whether using Vertex AI involves a third-country transfer depends on region and contract. Real data does not belong in the Demo anyway.
Which data is processed
| Category | Examples | Where |
|---|---|---|
| User master data | Name, e-mail, role, groups | Application and identity database |
| Usage data | Sign-ins, actions, client addresses, tool calls | Audit log |
| Content data | Uploads, knowledge base documents, embeddings – depending on what users enter, potentially special categories (Art. 9) | Databases, media volume |
| Chat history | Users' conversations | Locally in the user's browser, not on the server |
| Conversation content in the audit log | Only at the corresponding detail level, with a notice in the chat | Audit log |
| Credentials | Per-user connector credentials (write-only), password hashes of local accounts | Application and identity database |
Complete: Storage. Whether special categories are processed depends on your use – with patient data a data protection impact assessment is usually indicated.
Data subject rights
| Right | How basebox supports | What sits with you |
|---|---|---|
| Access (Art. 15) | User management shows master data; audit export delivers usage data per user; users see their chats themselves | Compilation and answer |
| Rectification (Art. 16) | Master data in user management or in the directory (LDAP/SSO) | Execution |
| Erasure (Art. 17) | Delete account, remove documents; chats sit in the user's browser. Audit entries are currently not deleted automatically | Process per Deletion; factor in backup rotation |
| Restriction (Art. 18) | Deactivate account | Decision |
| Data portability (Art. 20) | Chat export by the user (Back up chats); audit export CSV | Format and handover |
| Objection (Art. 21) | – | Assessment |
Technical and organizational measures
The TOMs you can describe in your record or DPA annex, with references:
- Access control: roles administrator/user, groups, OIDC/LDAP, API keys (Roles & permissions)
- Tenant separation: Cloud isolated environment per organization (Isolation); Server dedicated hardware
- Transport encryption: TLS on all paths; storage encryption at the storage layer (Encryption)
- Logging: audit log with configurable retention and detail level; notice in the chat (Audit & logging)
- Data minimization: web search without user identity, audit without query text, prompt logging off by default
- Deletability: by users and administrators (Deletion)
- Availability: backups (Backup · Backup & restore)
- Control of processing on behalf: maintenance access time-limited, approved, logged (Remote maintenance)
- Secure development: security tests before release, four-eyes principle (Infrastructure policy)
Openly named: no encryption at rest by the application; image signatures in preparation.
Incidents
In case of security-relevant incidents basebox informs affected customers without delay (Compliance document); notification of supervisory authorities and data subjects under Art. 33/34 lies with the controller. Reports to basebox: datenschutz@basebox.ai.
For the review
- Determine the deployment model and thus basebox's role unambiguously.
- Cloud: DPA before go-live; take subcontractors and data center location from the DPA.
- Document policies: audit detail level, retention, web search, connectors (Policies).
- Set a usage rule for users (which data may go into basebox, which not into web searches).
- Check for a DPIA if special categories are processed.
Next step: ISO 27001