ShinrAI Dashboard
Innovius · ShinrAI

Data processing

Data processing agreement under Article 28 GDPR for the managed ShinrAI service.

Last updated: 9 September 2026

Parties, subject matter and duration

The business customer identified in checkout or the order is the controller or commissioning processor. Innovius UG (haftungsbeschränkt), Elbestraße 1A, 14513 Teltow, Germany, is the processor of content submitted to the cloud API. This agreement applies for the service contract’s duration, including necessary return or deletion. Independent management of customer accounts and billing is described in the privacy notice.

Processing and affected data

The customer determines the purposes and lawful basis. Innovius processes content to provide the ordered detection, categorization, replacement, redaction and related documented API functions. Processing covers submitted text and supported images/documents, temporary asynchronous jobs and reusable templates or dictionaries the customer explicitly saves. Data subjects can include employees, customers, prospects, suppliers and communication partners. Data categories follow the input and can include names, contact details, identifiers, addresses, financial references and sensitive information. Special-category data requires the customer’s lawful documented instructions and suitable safeguards.

Instructions and confidentiality

The customer instructs processing through their order and API requests. Further documented instructions may be sent to info@innovius.ai. Innovius processes content only on documented instructions, including third-country transfers, unless legally required otherwise. We inform the customer beforehand where permitted. We promptly flag instructions we consider contrary to data protection law. Authorized personnel are bound by confidentiality or an equivalent statutory obligation.

Technical and organizational measures

Public API connections use TLS. Access uses revocable API keys, ownership checks and restricted administrative access; key secrets are stored as verification hashes rather than plaintext account records. Backend services use private networks. Synchronous content is processed in memory. Temporary job data and saved configurations use authenticated encryption; operational backups are protected and off-site copies are encrypted. Input/output content is excluded from routine service logs. Access boundaries, accounting integrity and recovery procedures are tested. Measures are maintained and may be improved without materially reducing protection.

Subprocessing

The authorized infrastructure subprocessor is STACKIT, operated by Schwarz Digits Cloud GmbH & Co. KG, Am Campus 1, 74177 Bad Friedrichshall, Germany, for managed processing and storage in Germany. The customer grants general authorization for subprocessors. Innovius informs the customer before adding or replacing a content subprocessor, with sufficient time to object on data-protection grounds before the change. We address justified objections through an alternative arrangement or termination of the affected service if no solution is possible. Equivalent contractual obligations apply to subprocessors and Innovius remains responsible for their performance.

Stripe, RevenueCat and the email provider process account, billing or correspondence data under the privacy notice; they are not routine inference-content subprocessors. Customer-directed external storage and key-management connections follow the documented instruction and applicable transfer safeguards. Innovius does not transfer managed content outside the EEA on its own initiative.

Assistance and incidents

Innovius assists the customer, taking account of the nature of processing and information available, with data subject rights, security, breach notifications, impact assessments and supervisory consultations. We notify the customer without undue delay after becoming aware of a personal data breach affecting customer content, provide available information and supplement it as findings emerge. Requests from data subjects about customer content are forwarded to the customer and answered only on their instructions or as legally required.

Return, deletion and audit

Results are returned through the API. Synchronous inputs and mappings are not kept for later retrieval. Asynchronous source content is removed when processing ends; the remaining job data expires 24 hours after submission and is automatically purged. Saved templates and dictionaries persist until deleted or removal is requested, with residual copies aging out through the 14-day operational backup rotation. At the end of the service, Innovius returns or deletes remaining customer content at the customer’s choice, unless law requires storage, and confirms completion on request. The customer retrieves needed results before expiry and controls copies in its own storage.

Innovius provides information necessary to demonstrate compliance with this agreement and permits audits, including inspections, by the customer or its mandated independent auditor. Scheduling and confidentiality arrangements protect other customers and service security without preventing the statutory audit right. The data processing agreement takes precedence over conflicting service terms for the processing it covers.

Offline operation

For entirely local offline operation, Innovius processes no inference content. The customer operates and secures the installation. Where a separate support order requires access to personal content, purpose, access rights and safeguards must be agreed separately beforehand.