Trust Center

Trust for legal work is part of how the product operates.

We explain where data is held, who can access it, and which controls govern the use of AI.

Request a demo

Security, privacy, and human control are parts of the same system.

Access, data processing, and assessment of AI output are governed together. The information here reflects current product and provider configurations; supporting security documents are available through our review process.

We address data protection through visible controls.

We prioritize the approach in operation today and documentation that can be reviewed.

KVKK and GDPR principles

Personal-data processes consider purpose limitation, data minimization, and data-subject rights.

Notice · requests · retention

Encryption

Application traffic uses encryption in transit and supported data services use encryption at the storage layer.

In transit · at rest

Access management

User and administrator access is limited according to authorization needs, with additional protection for sensitive administration.

Role · permission · admin access

Model use

The exclusion of customer content from foundation-model training is governed through enterprise provider terms and contracts.

Enterprise provider terms

Data lifecycle

Data is processed for a defined purpose and for as long as the service requires.

  1. 01

    Received

    Documents and work inputs are received to provide the product function selected by the user.

  2. 02

    Processed

    Only the relevant work surface and authorized service components process the data.

  3. 03

    Protected

    Access and storage are limited through the controls available in the current infrastructure.

  4. 04

    Retained or deleted

    Retention and deletion requests are managed with contractual and legal obligations in mind.

Product and operational controls

Trust should be visible during the work, not only in the infrastructure.

The published control set is limited to current system behavior.

01

Permission-based access

Users access content within their role and workspace permissions.

02

Operational visibility

Supported administrative and product operations are recorded for review and operational needs.

03

Environment separation

Production and development/test processes use distinct configurations and access rules.

04

Incident and continuity approach

Monitoring, backup, and incident-response processes are operated within the scope of the infrastructure in use.

05

Human assessment

AI output is presented for user assessment together with available sources and relevant work information.

Service providers

The core infrastructure behind Harmonity.

The current contractual list and data-processing details can be requested from the security team.

ServicePurposeRegion
SupabaseDatabase, authentication, and file storageEU · Stockholm
VercelWeb application hosting and content deliveryGlobal network
ResendTransactional email deliveryUSA
AI providersModel inference for selected product functionsProvider-dependent

Contact security@harmonity.ai for sub-processor or data-processing agreement requests.

Questions about trust

Is customer content used for model training?

Excluding customer content from foundation-model training is governed through enterprise provider terms and contractual controls. The security team can confirm the current scope.

Where is production data hosted?

The current primary data infrastructure is configured in Supabase’s Stockholm region. Content delivery and some supporting services may operate in other regions.

How can I make a data-subject request?

KVKK or GDPR access, correction, and deletion requests can be submitted through the data request form or security@harmonity.ai.

Can we request security documentation?

Yes. Contact our team for data-processing or security materials within the appropriate confidentiality and assessment process.

Security team

Contact us for your technical or legal security assessment.

Request details about data processing, sub-processors, security controls, or data-subject rights.