Trust, by default.

Legal data is sensitive. We build Harmonity so that security, privacy, and compliance are part of the design from day one.

Data location
EU · Stockholm
Encryption
At rest + in transit
Model training
Your data isn’t used
Compliance
KVKK & GDPR

Four foundations

Data protection

Your data is yours — protected with least-privilege access and never used to train models.

Encryption & access

Encryption at rest and in transit, role-based access, and full audit logs.

KVKK & GDPR compliance

End-to-end compliance including notices, explicit consent, data subject requests, and İYS.

Infrastructure & resilience

EU-region hosting, regular backups, and incident response plans.

Our approach

Data protection & KVKK

We process personal data in line with KVKK and GDPR principles: purpose limitation, data minimization, and retention discipline.

We have built-in processes to handle data subject requests (access, rectification, erasure) and respond within statutory timeframes.

Infrastructure & hosting

Production data is hosted in the EU region (Stockholm). Encryption is the default at rest and in transit.

Resilience is ensured through regular backups, monitoring, and incident response plans.

Access & auditability

We apply role-based access control and the principle of least privilege. Critical operations are audit-logged.

Sub-processors are carefully selected and governed by contractual safeguards.

Compliance & documentation

We run our processes in line with KVKK and GDPR principles, managing notices, explicit consent, and data subject rights end to end.

For a data processing agreement (DPA), the current sub-processor list, or security documentation, write to our security team.

Our security practices

We treat security not as a single feature but as part of our engineering discipline.

  • Role-based access control (RBAC) and least privilege

  • Encryption at rest and in transit

  • Audit logging for critical operations

  • Separation of production and staging environments

  • Regular backups and disaster recovery

  • Incident response plan and responsible disclosure

  • Sub-processor due diligence and contractual safeguards (DPA)

  • Data minimization and retention discipline

Sub-processors

We work with a carefully selected set of service providers to run Harmonity. Each is governed by contractual data-protection safeguards.

Supabase
Database, authentication, and storage
EU (Stockholm)
Vercel
Application hosting and content delivery network (CDN)
Global CDN
Resend
Transactional email delivery
USA
AI model providers
Language model inference — your data isn’t used for training
Provider-dependent

For the current sub-processor list and a data processing agreement (DPA), contact our security team.

Our commitments

  • Your data is never used to train models.

  • Encryption at rest and in transit.

  • Least-privilege access.

  • KVKK/GDPR-compliant processes and data subject requests.

  • Regular backups and an incident response plan.

FAQ

Is my data used to train models?

No. Customer content is never used to train foundation models.

Where is data hosted?

Production data is hosted in the EU region (Stockholm).

How long is my data retained?

We keep data only as long as needed to provide the service and within legal retention obligations. On account closure we apply deletion or anonymization.

Can I get a data processing agreement (DPA)?

Yes. Email security@harmonity.ai to request a DPA and the current sub-processor list.

How do I file a KVKK data subject request?

Email security@harmonity.ai or use the form on our privacy page. We respond within statutory timeframes.

How do I report a security vulnerability?

Report vulnerabilities to security@harmonity.ai. We follow responsible disclosure and respond promptly.

Contact the security team

For questions about security, privacy, or compliance — or to request a DPA, sub-processor list, or security documentation — reach our team directly.