Meet us at secIT digital on September 29 + 30

Read the article
Start for free now
Data protection

GDPR

migRaven.MAX processes your data exclusively within the EU — on certified enterprise infrastructure, with strict tenant separation and no model training on customer data.

  • 100% EU data processing
  • GDPR- and ISO-certified AI infrastructure
  • Strict tenant separation
  • Azure & AWS enterprise services
  • Transparent data processing agreement
  • No model training on customer data
  • Complete data control
Architecture

Privacy-friendly architecture

migRaven.MAX is built from the ground up for maximum data security. Every processing step follows clear GDPR principles.

  • Strict tenant separation

    Every environment is logically isolated, guaranteeing complete data separation between tenants.

  • Data minimization

    MAX only processes the data that is technically necessary — no unnecessary data storage.

  • Automatic masking

    Recognizable personal references are automatically redacted, protecting sensitive information.

  • Configurable deletion rules

    Data is automatically removed once its purpose has been fulfilled, meeting the GDPR's storage limitation requirement.

This lets MAX meet key requirements of Art. 25 GDPR without additional effort.

Your rights

Your data. Your control.

You retain control over your information at all times. Through MAX, you can conveniently exercise all your rights under the GDPR.

  • Access

    Transparent insight into all processed data, with complete documentation of processing purposes.

  • Rectification

    Correction of technical data is possible at any time — simply and traceably.

  • Erasure

    Complete removal once the purpose has been fulfilled, with automatic logging of the deletion process.

  • Restriction

    Reduced processing on request — full control over the scope of data use.

  • Export

    Provided in standardized formats for seamless data portability.

  • Auditable processes

    Traceable data flows and clear responsibilities for maximum transparency.

Data processing agreement

Responsibilities & data processing agreement

migRaven acts as the processor — your organization always remains the controller within the meaning of the GDPR.

Legally compliant data processing agreement under Art. 28 GDPR

  • Documented technical & organizational measures
  • Guaranteed data processing exclusively within the EU
  • Complete transparency about Microsoft and AWS enterprise services
  • Audit and control options for your compliance teams

Technical & organizational measures

  • Encrypted transmission & storage
  • Data processing in EU data centers
  • Logging & monitoring mechanisms
  • No prompt storage
  • Strict access controls

Our commitments

  • No use of your data for AI training
  • No sharing with third-party providers
  • Data processing agreement under Art. 28 GDPR
  • Auditability & transparency
  • User rights: access, rectification, erasure

MAX does not process any data for training purposes and uses exclusively certified enterprise infrastructure.