Security and data protection
What happens to your documents and tenders when your team uses Stazion: where they are kept, who can see them, what AI providers may do with them, and what you can ask us for in a vendor review. The legal documents behind it are linked at the bottom of this page.
Hosted in the EEA
Your account data, the documents you upload and the search indexes built from them are kept in the European Economic Area.
Encrypted throughout
TLS on every connection, and AES-256 at rest for the database and file storage.
Each organisation kept apart
The database itself keeps one customer’s data out of reach of every other customer.
No training on your content
Neither we nor our AI providers use your documents or questions to train AI models.
Roles for every person
Owners, admins and members, and every invitation, role change and removal is written to your organisation’s log.
Analytics only after a yes
No usage statistics or session recordings until you allow them, and error reports are sent only when something breaks.
Where your data lives
Your core data stays in the European Economic Area. Where a provider outside it takes part, the transfer is covered by the EU’s own safeguards.
- Your account data, the documents you upload and the search indexes built from them are hosted in the EEA. The database and file storage run on Supabase in the EEA, and the application runs on Vercel in Stockholm, Sweden.
- Scanned pages, and files that cannot be read directly, are read by Google Cloud Document AI in its EEA region, and the content is not kept there after it has been read.
- Some processing happens outside the EEA. In the United States: the AI models of Anthropic and OpenAI, Resend, which sends our own service emails (with the recipients’ addresses and what the email says), and Merge.dev, only if you connect one of its integrations. The optional search ranking by Cohere runs in the United States or Canada. These transfers are covered by the EU Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework, or for Canada the EU’s adequacy decision.
- The Microsoft 365 connection works inside your own Microsoft tenant, wherever your organisation has it hosted, which may be outside the EEA.
- Every provider that processes personal data on your behalf, with what it does, where and under which safeguard, is on our subprocessor list.
- A Transfer Impact Assessment of these transfers is available to customers on request at support@stazion.ai.
Encrypted in transit and at rest
Everything travels over encrypted connections, and what is stored is encrypted where it is stored.
- Every connection uses TLS: between your browser and Stazion, between Stazion and its database, and to every outside service, the AI providers included. HTTPS is enforced across the application.
- The database and the file storage are encrypted at rest with AES-256, and the automated backups are encrypted too.
- The tokens that connect Stazion to a person’s Microsoft 365 account are encrypted on their own with AES-256-GCM, and deleted when the connection is removed.
- Passwords are never stored in plain text. Sign-in is handled by our authentication provider, Supabase Auth, which keeps only a hash of each password.
Each organisation’s data kept apart
Stazion is one application shared by many companies. What keeps them apart is built into the database, not left to the screens.
- Your organisation’s records are marked as its own, and row-level security in the database refuses to show them to anybody outside it.
- The rules live in the database itself, so a request that goes around the app’s own screens meets exactly the same rules.
- Nobody can add themselves to an organisation. People join by accepting an invitation, or by the organisation’s email domain if it allows that.
Who can sign in, and what they can do
Roles decide what each person may change, and the important changes are logged.
- There are three roles: owner, admin and member. Organisation-wide switches that could cost somebody work, and moving a tender to the trash, are limited to owners and admins.
- People sign in with an email address and password, or with a Microsoft or Google account. Changing the sign-in address or password, or deleting an account, asks for the password again or a fresh sign-in.
- Invitations, role changes, removals and the organisation-wide switches are written to your organisation’s log with who made them.
- Owners and admins can read that log in Settings.
- When somebody asks a colleague a question by email from Stazion, their inbox is watched only while the question is open. Each new message is read one step at a time: its subject, then its sender only if the subject names an open question, then its text only if it is the colleague’s reply. Teams chats with no open question are dropped without being read.
- At Stazion, only authorised people with an operational need can reach production systems. They are bound by confidentiality, and their access is removed when it is no longer needed.
AI and your content
AI does the reading and the first draft. Your content is sent to AI providers only to do that work, and never to train their models.
- To read tenders, draft answers and search your documents, Stazion sends the relevant content to AI providers over TLS: Anthropic (Claude) for reading and drafting, OpenAI for building search indexes, Cohere for optional search ranking, and Google Document AI for scanned pages and files that cannot be read directly.
- Your content is not used to train AI models: not our own, and not our providers’. They are engaged under terms that prohibit using your content to train their models.
- The AI proposes and a person decides. Everything the AI writes is a draft for your team to accept or change, and Stazion never sends anything to your customers itself.
Error reports and analytics
We are told when something breaks. We learn how the app is used only if you say yes.
- Errors are reported to Sentry, hosted in the EEA. It receives a report only when an error happens, with limited technical context. Sentry records no sessions and does no performance tracing, and reports come only from our hosted deployments, never from a developer’s machine.
- Usage statistics (Amplitude, in its EU data region, and Google Analytics on this website only) start only after you choose Allow in the cookie banner. After that yes, Amplitude also records a sample of sessions in the app, to show us where people get stuck. If you reject them, or never answer, nothing is collected or recorded and Stazion works exactly the same.
- You can change your answer at any time under Cookie settings, at the bottom of Settings in the app or at the bottom of this website. Usage statistics are kept for up to 12 months.
- The cookie that keeps you signed in is always on, because Stazion cannot work without it. Analytics cookies are never set before you allow them.
Deleting and exporting your data
Your data is yours to remove, and to take with you when you leave.
- Documents can be deleted at any time, and their content and search indexes go with them. A member can delete the documents they uploaded; owners and admins can delete any document in the organisation.
- A deleted tender stays in the trash for 30 days, so it can be restored, and is then removed for good.
- People can delete their own account in Settings. What they made for the team is handed to an owner who stays; if they were the only member, the organisation is deleted with them. The only owner of an organisation that still has other members must make somebody else an owner first, so an organisation is never left without one.
- Personal data is deleted within 30 days of a verified request.
- At the end of your contract you choose: all personal data deleted within 30 days, or an export in a structured format. An export must be asked for within 30 days of the end of the contract.
- A copy of your personal data in a structured, machine-readable format is available on request at any time.
- Owners can also export the organisation’s data themselves in Settings: every uploaded document, every tender with its requirements and answers (those in the trash included), the Answer Library, the members and open invitations, and the activity log. It can be downloaded for 7 days, and a newer export replaces the one before.
Incidents and reporting a vulnerability
If something goes wrong, you hear it from us. If you find something, we want to hear it from you.
- If a security incident affects your data, we tell you without undue delay and no later than 48 hours after we become aware of it, and help with any notice to the authorities and the people affected.
- To report a vulnerability, write to support@stazion.ai with what you found, the steps to reproduce it and its likely impact. We acknowledge your report within 48 hours and keep you updated, we will not take legal action against research done in good faith, and with your permission we credit you.
- In scope are stazion.ai, app.stazion.ai, the Stazion application and its API, and sign-in. Please do not test denial of service or social engineering, and report a problem in a third-party service to that service directly.
What we provide for your vendor review
Stazion does not hold a SOC 2 report or an ISO 27001 certificate today. This is what we can give your reviewer instead.
- Our Data Processing Agreement under GDPR Article 28 applies to every customer from the moment the Terms of Service are accepted. A countersigned copy naming both parties is available on request.
- Annex A of the Data Processing Agreement lists our technical and organisational measures, and our security practices document describes them in more detail.
- On request at support@stazion.ai: the Transfer Impact Assessment, and a completed security questionnaire.
- Under the Data Processing Agreement you may audit us up to once every 12 months, with at least 30 days’ notice and at your own cost.
- Every provider that processes personal data on your behalf is listed on our subprocessor list, with what it does, where and under which safeguard. You are told at least 14 days before a new one is added, and may object.
- Stazion ApS is a Danish company (CVR 46244028) in Copenhagen, and processes personal data under the GDPR and the Danish Data Protection Act.
The documents behind this page
Where this page and a document differ, the document is what applies. Questions about any of them go to support@stazion.ai.
Privacy Policy
How Stazion collects, uses, stores, and protects personal data, and the rights you have under GDPR.
Terms of Service
The terms that govern your use of the Stazion.ai sales platform.
Data Processing Agreement
Our GDPR Article 28 commitments for processing personal data on your behalf, including our technical measures and subprocessors.
Security Practices
The technical and organizational measures we use to protect your data, from encryption to incident response.
Subprocessors
The third-party providers Stazion engages to process personal data, with their purpose, location, and transfer mechanism.
Questions from your security team?
Send us your security questionnaire, or ask for the Transfer Impact Assessment or a countersigned Data Processing Agreement.
SAME-DAY SETUP · NO CONSULTANTS · NO IT PROJECT