
Trust, by default.
Legal data is sensitive. We build Harmonity so that security, privacy, and compliance are part of the design from day one.
Four foundations
Data protection
Your data is yours — protected with least-privilege access and never used to train models.
Encryption & access
Encryption at rest and in transit, role-based access, and full audit logs.
KVKK & GDPR compliance
End-to-end compliance including notices, explicit consent, data subject requests, and İYS.
Infrastructure & resilience
EU-region hosting, regular backups, and incident response plans.
Our approach
Data protection & KVKK
We process personal data in line with KVKK and GDPR principles: purpose limitation, data minimization, and retention discipline.
We have built-in processes to handle data subject requests (access, rectification, erasure) and respond within statutory timeframes.
Infrastructure & hosting
Production data is hosted in the EU region (Stockholm). Encryption is the default at rest and in transit.
Resilience is ensured through regular backups, monitoring, and incident response plans.
Access & auditability
We apply role-based access control and the principle of least privilege. Critical operations are audit-logged.
Sub-processors are carefully selected and governed by contractual safeguards.
Compliance & documentation
We run our processes in line with KVKK and GDPR principles, managing notices, explicit consent, and data subject rights end to end.
For a data processing agreement (DPA), the current sub-processor list, or security documentation, write to our security team.
Our security practices
We treat security not as a single feature but as part of our engineering discipline.
Role-based access control (RBAC) and least privilege
Encryption at rest and in transit
Audit logging for critical operations
Separation of production and staging environments
Regular backups and disaster recovery
Incident response plan and responsible disclosure
Sub-processor due diligence and contractual safeguards (DPA)
Data minimization and retention discipline
Sub-processors
We work with a carefully selected set of service providers to run Harmonity. Each is governed by contractual data-protection safeguards.
For the current sub-processor list and a data processing agreement (DPA), contact our security team.
Our commitments
Your data is never used to train models.
Encryption at rest and in transit.
Least-privilege access.
KVKK/GDPR-compliant processes and data subject requests.
Regular backups and an incident response plan.
FAQ
Is my data used to train models?
No. Customer content is never used to train foundation models.
Where is data hosted?
Production data is hosted in the EU region (Stockholm).
How long is my data retained?
We keep data only as long as needed to provide the service and within legal retention obligations. On account closure we apply deletion or anonymization.
Can I get a data processing agreement (DPA)?
Yes. Email security@harmonity.ai to request a DPA and the current sub-processor list.
How do I file a KVKK data subject request?
Email security@harmonity.ai or use the form on our privacy page. We respond within statutory timeframes.
How do I report a security vulnerability?
Report vulnerabilities to security@harmonity.ai. We follow responsible disclosure and respond promptly.
Contact the security team
For questions about security, privacy, or compliance — or to request a DPA, sub-processor list, or security documentation — reach our team directly.