Zum Inhalt springen
Core infrastructure in Germany · Made in Germany

Your Data Stays in the EU

The core app, database and media storage are processed and stored on German servers. Required external providers and consent-gated analytics may process data elsewhere.

View DPA
Hetzner, Germany
ISO 27001 certified
GDPR-compliant
DPA on request
Transparent providers

Server Location: Germany

Content Mate runs the core app, database and media storage in German data centers of Hetzner Online GmbH.

Nuremberg & Falkenstein Data Centers

Core application servers, databases (PostgreSQL), caches (Redis) and media storage are operated in Hetzner data centers in Nuremberg and Falkenstein, Germany.

ISO 27001 Certified (Hetzner)

Hetzner Online GmbH is certified to ISO 27001. Data centers feature physical access control, CCTV and redundant power supply.

Encrypted Transmission

All data transmissions are encrypted via TLS 1.2+. Passwords are hashed with bcrypt. OAuth tokens are stored encrypted. Media files are secured with server-side encryption.

Transparent External Providers

Required external providers, payment processing and consent-gated analytics may process data elsewhere. Details are listed in the privacy policy.

Workspace-Based Data Isolation

Each workspace is separated by strict database isolation. All database queries are filtered by workspace ID. Multi-tenant architecture following the principle of least privilege.

Automated Backups

Regular encrypted database backups with a backup rotation of max. 90 days. Redis persistence for queue data. Full data deletion within 30 days after contract termination.

Sub-Processors

A complete list of all sub-processors handling personal data within Content Mate.

ProviderPurposeProcessing LocationCertification
Hetzner Online GmbHCloud hosting: application servers, PostgreSQL, Redis, object storage (S3-compatible)Germany (EU)ISO 27001
Stripe, Inc.Payment processing and subscription management (email, name, payment data)EU & USAPCI DSS Level 1, EU-US DPF (Art. 45 GDPR)

Changes to this list are communicated at least 4 weeks in advance in writing (per §8 DPA). Social media platforms (Meta, TikTok, LinkedIn) are independent controllers, not sub-processors.

Compliance at a Glance

Content Mate is built for organizations that require the highest level of data protection.

DE
Core Infrastructure
Core app, database and media storage in Germany
ISO 27001
Hosting Certification
Hetzner Online GmbH
Art. 28
GDPR DPA
Based on official BfDI template v2.1
TLS 1.2+
Encryption
For all client & API connections
DPA per Art. 28 GDPR

Data Processing Agreement (DPA) on Request

A Data Processing Agreement under Art. 28 GDPR can be requested. Details about processing, providers and safeguards are listed in the privacy policy.

Request DPA

Frequently Asked Questions about Data Residency

Core application data (database, media files, cache) is stored on servers of Hetzner Online GmbH in Germany — specifically in the Nuremberg and Falkenstein data centers. Required external providers and consent-gated analytics may process data elsewhere.

Payments are processed via Stripe, Inc. (USA). Stripe is certified under the EU-US Data Privacy Framework (DPF), making the data transfer lawful under Art. 45 GDPR (adequacy decision). Content Mate itself does not store full credit card details.

Yes. A Data Processing Agreement under Art. 28 GDPR can be requested.

Hetzner Online GmbH's data center infrastructure is certified to ISO 27001. The certification documents an audited information security management system (ISMS).

After subscription termination, personal data is deleted under the applicable deletion processes — including database entries, media files (S3), cache (Redis), and backups within the 90-day rotation cycle. A deletion certificate is available on request.

Yes, you can export your data through the app. Upon contract termination, we also provide a data export on request.