Security & Data Protection
Last updated: 29 September 2026
How we host, protect and hand over the systems we build, especially AI automations that touch your ERP, CRM, inboxes and documents. If your IT or data protection team needs more detail, ask us and we answer in writing.
Where your data is processed
- Automations run on n8n, either on our server in the EU (Hetzner) or on your own infrastructure. We agree this per project.
- On our server, workflow data is stored in a Postgres database on Supabase in Ireland, and run logs are deleted automatically after 7 days unless your project needs them longer.
- Websites and web apps are hosted on Vercel.
- AI models are chosen per project, for example OpenAI, Anthropic or Azure OpenAI in the EU. Before launch we tell you which provider sees which data. We use API access, which these providers do not use to train their models by default.
Who has access
- Only the engineers working on your project, each with their own account. No shared logins.
- Two-factor authentication on every admin account: hosting, databases, code and CMS.
- Server access by SSH key only, never by password.
- Credentials for your systems are stored encrypted in n8n, limited to what each workflow needs, and removed when the project ends.
Backups
- On our infrastructure: daily backups of workflows, configuration and databases, kept for 7 days and stored in the EU.
- On your infrastructure: backups follow your policy. We set them up for you if you want us to.
Updates and monitoring
- Critical security updates for n8n and its dependencies within 72 hours of release on systems we run. Routine updates monthly.
- Every workflow logs its runs, and a failed run sends us an alert.
Contracts and GDPR
- On request we sign a data processing agreement (DPA, in German AVV) under Art. 28 GDPR before any personal data is processed.
- We process your data only to deliver the agreed work, and delete or return it when the project ends.
- The processors behind our own website are listed in our privacy policy.
Security incidents
If we detect a security incident that affects your data, we notify you within 48 hours of becoming aware of it: what happened, which data is affected and what we are doing about it.
Reporting a vulnerability
Found a security issue in one of our sites or systems? Email info@nevioxdigital.com with the details, and give us reasonable time to fix it before you publish anything. Our security.txt lists the same contact.