Sovereignty and data protection
No software is "GDPR compliant" on its own – that always depends on how it is used. So we say concretely what Kundrio does and where the data is.
Where the data is
- Hosting: STACKIT, region EU01, data centres in Germany. STACKIT is part of the Schwarz Group.
- Database and files: STACKIT PostgreSQL Flex and STACKIT Object Storage.
- Backups: daily, encrypted, also at STACKIT. The decryption key is not stored at STACKIT.
- AI: language models via STACKIT AI Model Serving in Germany. Self-hosters can use local models through Ollama.
What leaves the system
The sovereignty cockpit in Kundrio lists every outbound connection with provider, location and possible replacement. Each client account can be pinned to a region (Germany or EU). The cockpit warns if a connection in use doesn't match.
Services such as payment providers, social channels or calendars are only used if you connect them yourself.
Data subject rights
- Access requests (Art. 15 GDPR) per contact as a file
- Erasure (Art. 17 GDPR) – contacts with invoices are anonymised because records must be retained
- Full export of all data of an account as a ZIP file
No cookies
The analytics feature works without cookies and does not store IP addresses. Bots are detected on the server.
For regulated industries
If you need your own environment, you can run Kundrio yourself or in your own STACKIT project. The source code is open, and deployment with Docker Compose or Kubernetes is documented. Talk to us if you need help.
Data processing agreement: For the hosted service at app.kundrio.de we sign a data processing agreement under Art. 28 GDPR with you. The list of sub-processors is available on request.