Yura.to Deutsch

GDPR-Compliant AI Assistant – Data Protection at Yura.to

How to recognise a GDPR-compliant AI assistant: Art. 28 DPA, server location, third-country transfers, no training on your data, deletion deadlines and the EU AI Act.

Where is my data stored with Yura?

Application and database run in our hosting partner's data centres in Germany, and a data processing agreement is in place with the host. Requests to the language models may in addition be processed on servers in the USA, covered by the EU-US Data Privacy Framework and standard contractual clauses. The full wording is in our privacy policy.

Does Yura use my data to train AI models?

No. We use business and enterprise interfaces from the model vendors only, and it is contractually established that your inputs, documents and company data are not used to train global models.

Do I get a data processing agreement under Art. 28 GDPR?

A DPA belongs to every rollout that processes personal data. Raise it with us before the contract starts and we will settle the paperwork directly with your data protection officer.

How long are chat histories kept?

Chat logs are stored temporarily to handle the request in question. Unless law or contract says otherwise, logs that are no longer needed are deleted automatically after 30 days.

How do I request access to my stored data?

Write to us through the contact form. You will receive a complete copy of your data within 30 days in a structured, common format — as JSON, CSV or XML.

What happens to my data if I cancel?

You can export your data before cancelling. After that it is deleted, unless a statutory retention duty applies — commercial or tax deadlines for invoice data, for example.

Is Yura itself certified?

No, and we state that deliberately. The certificates shown on this page belong to our hosting partner and its data centres. We run the service on that audited infrastructure but are not the certificate holder ourselves.

Can we run Yura in our own data centre?

Yes. For organisations with stricter requirements there is operation on your own infrastructure, including complete audit logs and a connection to your own roles and permissions setup.

Does Yura make automated decisions about people?

Not in the default settings. Yura prepares replies, tasks and appointments; a person approves them. If you want to automate a process end to end, have it assessed under data protection law first.

What does the EU AI Act change for us?

The substantive obligations of the AI Regulation have applied since 2 August 2026. For office workflows the focus is on transparency and documentation. How your specific purpose is classified is decided by your data protection officer — we provide the technical details.

Your data security is our top priority. Learn how we collect, store, and protect your information in compliance with GDPR regulations.

Certified infrastructure

These certificates belong to our hosting partner and its data centres. Yura itself does not hold them – we run the service on this audited infrastructure.

Full compliance with EU data protection regulations

/images/gdpr/dsgvo.svg

Our hosting partner's data centres in Germany

/images/gdpr/hosted-in-germany.svg

Certified Datacenters

Certifications held by our hosting partner's data centres

/images/gdpr/certified-datacenters.svg

Encrypted transfer between your device and Yura

/images/gdpr/ssl-tls.svg

Application and database in the EU; model requests may run in the USA (DPF/SCC)

/images/gdpr/european-union.svg

CO2-neutral operation of the hosting infrastructure

/images/gdpr/seal_climate_friendly.svg

Cloud security certification held by our hosting partner

/images/gdpr/csa.svg

Under GDPR, you have comprehensive rights over your personal data

You have the right to request a copy of all personal data we hold about you.

We will provide you with a complete copy of your data in a structured, commonly used format within 30 days of your request.

Right to Rectification

You can request correction of inaccurate or incomplete personal data.

Simply contact us with the correct information, and we will update your data promptly.

You can request deletion of your personal data ("right to be forgotten").

We will delete your data unless we have a legal obligation to retain it. This process typically takes 30 days.

Right to Data Portability

You can receive your data in a portable format and transfer it to another service.

We provide data exports in JSON, CSV, or XML format for easy transfer to other platforms.

You can object to processing of your personal data for specific purposes.

This includes objecting to direct marketing, profiling, and processing based on legitimate interests.

Right to Restriction

You can request restriction of processing in certain circumstances.

We will mark your data and only process it with your consent or for legal claims.

Security Infrastructure

How we protect your data with enterprise-grade security

All data is encrypted at rest using AES-256 and in transit using TLS 1.3.

Role-based access control ensures only authorized personnel can access data.

Independent security audits conducted quarterly to ensure compliance.

Automated daily backups with 30-day retention and disaster recovery plan.

Book a demo