Security & privacy
AlmaOS holds your business memory: clients, contracts, calls and decisions. This is exactly where that data lives, how we protect it and what control you have over it. Facts only, no decorative badges.
Last updated: June 2026
EU data residency
Your data is hosted on servers located in the European Union (Hetzner, Germany). It is not transferred outside the European Economic Area nor processed through third parties subject to frameworks outside the GDPR. For sectors such as legal, healthcare or property management, this means your clients’ sensitive information never leaves Europe.
Encrypted in transit and at rest
All communications use TLS 1.3. Stored information is encrypted at rest. Access to your memory is restricted to your organisation and the people you authorise.
GDPR compliance
Processing is governed by the General Data Protection Regulation. We sign a data processing agreement (DPA) with every customer and honour your rights of access, rectification, export and erasure. In the event of a breach affecting you, we notify within a maximum of 72 hours.
We never train models on your data
Your information is never used to train AI models, ours or third parties’. AlmaOS is model-agnostic: your business knowledge stays isolated and feeds no shared system.
The engine underneath: MemoryFirst
AlmaOS runs on MemoryFirst, our own memory engine for AI. We do not rely on third-party memory services: the layer where your knowledge is stored and queried is ours and runs on our European infrastructure.
Compliance status
We are transparent about what is already in place and what is in preparation. We do not display certifications we do not hold.
- EU data residencyActive
- TLS 1.3 + at-rest encryptionActive
- Data processing agreement (DPA)Active
- GDPR rights (access, export, deletion)Active
- 72h breach notificationActive
- SOC 2 auditIn preparation
Privacy contact
For any question about how your data is handled or to exercise your rights, write to us: [email protected]