Access only to what you grant.
ProcessMagnet connects through your systems’ own interfaces (APIs) — and reads only what the permissions set there allow. This page states how far that access reaches and where the data sits.
The access in detail
The four statements your IT needs for a first assessment.
ProcessMagnet connects to your systems’ interfaces (APIs) and works with exactly the permissions set there. What a granted account may not see, ProcessMagnet does not see either — existing rights are never bypassed. For each source you additionally decide how deeply it is read and who sees the results.
No second, uncontrolled data store appears alongside your systems. ProcessMagnet reads what process recognition requires and files the result — the identified processes, roles and requirements — in your organization system.
Your process data is processed and stored on servers within the European Union. Exactly three things process outside the EU: sign-in, depending on which service applies to the product; error logging, which sits in a European data region but is operated by a US company and receives no content from your process documentation; and the AI providers, but only the ones you select yourself. The hosting and infrastructure data sheet with the specifics is available on request.
Your process knowledge never becomes training material — neither for us nor for the models in use. What you bring in stays in your context.
How the AI processing works
With an AI product this question comes first: which provider reads our content, where does it run, and does anything leave the EU? Here is the answer. It is contractually governed in the list of sub-processors — which forms part of the data processing agreement.
Which AI providers are permitted for your use is your choice — made on a per-provider basis. Without your explicit selection, no data is transmitted to the provider concerned. If a provider is added to the list later, that does not change your existing configuration: it only takes effect once you select it.
For OpenAI via Microsoft Azure the place of processing is Germany (Azure region Germany West Central, Frankfurt); for Google Vertex AI likewise Germany (region europe-west3, Frankfurt) — both without third-country transfer. Mistral processes in the EEA. Providers processing in the USA — OpenAI directly, Anthropic, Groq — operate under standard contractual clauses per Art. 46 GDPR. Where providers offer it, we use EU/DE data centres and data-minimising settings such as zero data retention to avoid third-country transfers.
For every listed provider the following applies under the data processing agreements in place: no use of the transmitted content for training or model improvement purposes, and storage only to the extent contractually agreed and technically necessary.
The AI providers are used exclusively to analyse content you generate and documents you upload. Processing personal data is not the intention. Where that content does contain personal data — hard to avoid in email, tickets or documents — it is incidentally transmitted and processed. As the controller you decide which content is collected; we recommend minimising or pseudonymising personal content beforehand.
Operations, deletion, exit
The checklist every IT sign-off and every procurement team works through. The statements below are contractually assured — they govern working with aiio GmbH, whichever product you run.
Single sign-on and multi-factor authentication run through Microsoft Entra ID or Clerk — which service applies depends on the product and is stated in the hosting and infrastructure data sheet. Clerk processes sign-in data in the USA, on the basis of the Data Privacy Framework and standard contractual clauses per Art. 46 GDPR. Password policies and multi-factor stay in your directory: what is enforced is what you configured there — we store no credentials.
Data at rest is encrypted with AES-256, data in transit with TLS 1.2 or higher — including between internal services. Every record belongs to exactly one tenant; every request is filtered on the tenant identifier, which the authentication service issues and which cannot be altered from within the application. Backups run daily, geo-redundantly into a separate region.
You can delete all data yourself, first and foremost, whenever you see fit. The procedure follows a binding work instruction, and after deletion you receive a deletion record. Backup files from the automatic data protection are deleted after 30 days — earlier on request.
On termination you hold the unrestricted right to have your data handed over or deleted immediately under Art. 28 GDPR — you choose which. On your instruction the data is deleted immediately at the end of the contract; at the latest it happens when the tenant is decommissioned. What you take with you sits in ProcessCollector and exports from there as BPMN and PDF — a switch does not fail on the file format.
Support is reachable Monday to Friday during normal business hours, at support@aiio.de. Automatic monitoring usually catches incidents before they reach you; whoever reports one is kept informed about the state of the fix. Resolution times follow the contractually agreed SLA.
The audit rights assured under Art. 28 GDPR are yours in full. Audit rights arising from other regulations — your own certification requirements, for instance — we grant provided a planned audit is announced four to six weeks in advance. Unannounced audits are not provided for.
Documents you get from us
The contracting party is aiio GmbH; the core documents are openly available in its Trust Center, no form. What is marked “on request” here we’ll send on a short email to support@aiio.de.
- Data processing agreement (DPA) Direct download
- List of sub-processors Direct download
- Operations & security concept (architecture, encryption, authentication) Direct download
- Technical and organizational measures (TOM) Part of the DPA
- ISO/IEC 27001 certificate with scope and certificate number Direct download
- General SaaS terms (availability, terms of contract, return and deletion on termination) Direct download
- Functional description — what is contractually owed Direct download
- Supplier self-disclosure — we fill in and counter-sign your questionnaire On request
- Hosting & infrastructure data sheet On request
When the works council or privacy office has a say
ProcessMagnet reads systems people work in — mailboxes, tickets, call notes. In Germany that belongs on the table early, not in the week before rollout. What follows is not legal advice. It is what is contractually assured, so the other side can build their template on it.
- You set the scope. Which sources get connected and how deeply they are read is your call, per source — as is who sees the results.
- Existing permissions still apply. ProcessMagnet works with the permissions of the account you grant. What that account may not see, ProcessMagnet does not see.
- No second data store. No shadow copy appears alongside your systems that would escape your own control.
- What comes out are processes. The result is identified flows, roles and requirements — filed in your organization system.
- Personal data is not the aim — and not glossed over. Where the content read does contain personal data, it is incidentally processed. As the controller you decide which content is collected; we recommend minimising or pseudonymising it beforehand.
- The conversation happens first. We go through sources, access depth and the permission model with you before anything is connected — with IT, the privacy office and the works council alike.
The documents a works agreement usually calls for — DPA, TOM, the list of sub-processors and the operations & security concept — are openly downloadable above.
Before anything gets connected
On request, your IT goes through the sources, the access depth and the permission model with us beforehand — before the demo, not after. Whoever signs off system access should know what gets read first.
Arrange a call with your ITConnect your whole organization into one system.
In a short demo, ProcessMagnet pulls your systems together live — and you see, for the first time, how your company really runs.
- Hosted in the EU
- ISO/IEC 27001
- No AI training on your data