Your Data Stays in the EU
The core app, database and media storage are processed and stored on German servers. Required external providers and consent-gated analytics may process data elsewhere.
Server Location: Germany
Content Mate runs the core app, database and media storage in German data centers of Hetzner Online GmbH.
Nuremberg & Falkenstein Data Centers
Core application servers, databases (PostgreSQL), caches (Redis) and media storage are operated in Hetzner data centers in Nuremberg and Falkenstein, Germany.
ISO 27001 Certified (Hetzner)
Hetzner Online GmbH is certified to ISO 27001. Data centers feature physical access control, CCTV and redundant power supply.
Encrypted Transmission
All data transmissions are encrypted via TLS 1.2+. Passwords are hashed with bcrypt. OAuth tokens are stored encrypted. Media files are secured with server-side encryption.
Transparent External Providers
Required external providers, payment processing and consent-gated analytics may process data elsewhere. Details are listed in the privacy policy.
Workspace-Based Data Isolation
Each workspace is separated by strict database isolation. All database queries are filtered by workspace ID. Multi-tenant architecture following the principle of least privilege.
Automated Backups
Regular encrypted database backups with a backup rotation of max. 90 days. Redis persistence for queue data. Full data deletion within 30 days after contract termination.
Sub-Processors
A complete list of all sub-processors handling personal data within Content Mate.
| Provider | Purpose | Processing Location | Certification |
|---|---|---|---|
| Hetzner Online GmbH | Cloud hosting: application servers, PostgreSQL, Redis, object storage (S3-compatible) | Germany (EU) | ISO 27001 |
| Stripe, Inc. | Payment processing and subscription management (email, name, payment data) | EU & USA | PCI DSS Level 1, EU-US DPF (Art. 45 GDPR) |
Changes to this list are communicated at least 4 weeks in advance in writing (per §8 DPA). Social media platforms (Meta, TikTok, LinkedIn) are independent controllers, not sub-processors.
Compliance at a Glance
Content Mate is built for organizations that require the highest level of data protection.
Data Processing Agreement (DPA) on Request
A Data Processing Agreement under Art. 28 GDPR can be requested. Details about processing, providers and safeguards are listed in the privacy policy.
Frequently Asked Questions about Data Residency
Core application data (database, media files, cache) is stored on servers of Hetzner Online GmbH in Germany — specifically in the Nuremberg and Falkenstein data centers. Required external providers and consent-gated analytics may process data elsewhere.
Payments are processed via Stripe, Inc. (USA). Stripe is certified under the EU-US Data Privacy Framework (DPF), making the data transfer lawful under Art. 45 GDPR (adequacy decision). Content Mate itself does not store full credit card details.
Yes. A Data Processing Agreement under Art. 28 GDPR can be requested.
Hetzner Online GmbH's data center infrastructure is certified to ISO 27001. The certification documents an audited information security management system (ISMS).
After subscription termination, personal data is deleted under the applicable deletion processes — including database entries, media files (S3), cache (Redis), and backups within the 90-day rotation cycle. A deletion certificate is available on request.
Yes, you can export your data through the app. Upon contract termination, we also provide a data export on request.