Security, Data Protection and Compliance
What procurement, IT security and QA need to know about working with us – before the first conversation.
We develop data science and AI solutions for research and development in pharma and crop science. Projects in this environment rarely begin with the technical question – they begin with a supplier review. This page summarises what that review covers. The full documentation is available on request.
Information security
We are certified to ISO/IEC 27001:2022.
- Certification body · TÜV Rheinland Cert GmbH
- Certificate number · 01 153 2300149
- Valid until · 27 August 2029
- Scope · Development of solutions in machine learning, artificial intelligence, process optimisation and digital transformation
Responsibility for information security sits with a named role (CISO) with a direct escalation path to the management board. The information security management system is audited internally each year, certified externally, and reviewed by management in a formal management review. In addition, an external provider carries out annual penetration tests.
All staff complete mandatory annual training on data protection and information security.
Data protection
In most of our projects, processing involves no personal data at all. Where a project does include it, the contractual arrangement, the encryption and the storage location follow the protection level that data requires.
- An external data protection officer is appointed.
- Data processing agreement under Art. 28 GDPR – a template is in place and can be concluded at any time.
- Technical and organisational measures under Art. 32 GDPR documented and available for inspection on request.
- A documented deletion procedure, with the deletion operations logged, applies after the contract ends.
- Processing in Germany and the EU. As a rule, no client data is transferred to a third country. Where this is necessary in an individual case, it takes place solely on a valid legal basis.
- A dedicated project environment per client, with logical separation of databases, storage and directories.
- Access on the least-privilege principle. The permission model rules out cross-project access by staff.
- Data transfer through the channels you provide; alternatively through an encrypted transfer route we provide.
Data processing and hosting
We work on AWS, Microsoft Azure and Google Cloud. Which platform we use follows your requirements first – not our preferences.
External staff, freelancers and sub-contractors sign a non-disclosure agreement before the work begins. Project-specific sub-processors are named individually in the data processing agreement.
How we handle your data and models
The point that is scrutinised most often in AI projects – and the one we answer without being asked:
We do not use client data to train our own models or models for other projects. No exceptions, no anonymisation caveat.
Client data is processed solely for the agreed purpose of the project. Where external AI services and LLM interfaces are involved:
- If your company mandates its own or an approved AI service, we work exclusively on that.
- Otherwise we process only anonymised or pseudonymised data there.
- Opting out of the provider's model training is contractually assured.
Rights to the work results transfer to you in full. Publications and use as a reference happen only with prior written approval.
Regulatory context
GxP. We are not a validated GxP provider and do not present ourselves as one. In regulated applications we work in support of your QA and validation function; system validation itself stays with you. We would rather settle that boundary before a project starts than during an audit.
EU AI Act. We define the allocation of roles per project. As a rule you are the provider within the meaning of the regulation, while we deliver the development work and support the documentation requirements. For a structured assessment we offer the AI Compliance Check.
Business continuity
Every project role has a designated deputy. Code is kept in your repositories throughout, and documentation follows a defined standard. Backups run in multiple stages and encrypted across all core systems, separated from the production systems, with periodic restore tests.
At the end of a project you receive a full handover of code, models and documentation, together with a certificate of deletion.
Documentation on request
For your supplier qualification we provide:
- The full supplier qualification document
- A copy of the ISO/IEC 27001 certificate
- A summary of the Statement of Applicability
- A summary of the most recent audit report
- Documentation of the technical and organisational measures under Art. 32 GDPR
- Templates for the data processing agreement and the non-disclosure agreement
- Proof of public liability and professional indemnity insurance
We are happy to sign a non-disclosure agreement before the first substantive assessment – not only before the project starts.