Trust Center
Trust for legal work is part of how the product operates.
We explain where data is held, who can access it, and which controls govern the use of AI.
Request a demoSecurity, privacy, and human control are parts of the same system.
Access, data processing, and assessment of AI output are governed together. The information here reflects current product and provider configurations; supporting security documents are available through our review process.
We address data protection through visible controls.
We prioritize the approach in operation today and documentation that can be reviewed.
KVKK and GDPR principles
Personal-data processes consider purpose limitation, data minimization, and data-subject rights.
Notice · requests · retentionEncryption
Application traffic uses encryption in transit and supported data services use encryption at the storage layer.
In transit · at restAccess management
User and administrator access is limited according to authorization needs, with additional protection for sensitive administration.
Role · permission · admin accessModel use
The exclusion of customer content from foundation-model training is governed through enterprise provider terms and contracts.
Enterprise provider termsData lifecycle
Data is processed for a defined purpose and for as long as the service requires.
- 01
Received
Documents and work inputs are received to provide the product function selected by the user.
- 02
Processed
Only the relevant work surface and authorized service components process the data.
- 03
Protected
Access and storage are limited through the controls available in the current infrastructure.
- 04
Retained or deleted
Retention and deletion requests are managed with contractual and legal obligations in mind.
Product and operational controls
Trust should be visible during the work, not only in the infrastructure.
The published control set is limited to current system behavior.
Permission-based access
Users access content within their role and workspace permissions.
Operational visibility
Supported administrative and product operations are recorded for review and operational needs.
Environment separation
Production and development/test processes use distinct configurations and access rules.
Incident and continuity approach
Monitoring, backup, and incident-response processes are operated within the scope of the infrastructure in use.
Human assessment
AI output is presented for user assessment together with available sources and relevant work information.
Service providers
The core infrastructure behind Harmonity.
The current contractual list and data-processing details can be requested from the security team.
Contact security@harmonity.ai for sub-processor or data-processing agreement requests.
Questions about trust
Is customer content used for model training?
Excluding customer content from foundation-model training is governed through enterprise provider terms and contractual controls. The security team can confirm the current scope.
Where is production data hosted?
The current primary data infrastructure is configured in Supabase’s Stockholm region. Content delivery and some supporting services may operate in other regions.
How can I make a data-subject request?
KVKK or GDPR access, correction, and deletion requests can be submitted through the data request form or security@harmonity.ai.
Can we request security documentation?
Yes. Contact our team for data-processing or security materials within the appropriate confidentiality and assessment process.
Security team
Contact us for your technical or legal security assessment.
Request details about data processing, sub-processors, security controls, or data-subject rights.