2 min read
Data security and privacy
Consultad is built with data security and privacy as foundational requirements, not afterthoughts. Here is how your data is protected.
Data residency
Your account infrastructure is stored and processed in the European Union:
- Region: EU data center (Poland)
- Services: application infrastructure - database, secure storage, and compute - run in this region.
AI processing follows the data-handling terms of each model provider. Analytics processing runs entirely within EU regions. The chat assistant is processed under strict data-protection terms that prohibit training on your data; regional pinning to the EU for chat is not guaranteed by default. See "AI and your data" below for details.
Encryption
- At rest - all data is encrypted using AES-256 encryption, managed by Google Cloud's default encryption layer.
- In transit - all connections use TLS 1.2 or higher. This applies to browser-to-server communication, server-to-server calls, and connections to ad platform APIs.
AI and your data
Consultad uses two AI models:
- An advanced language model for the chat assistant and account audits.
- A separate, dedicated analytics model for analytics reports.
Your data is never used to train AI models. The commercial terms governing every AI provider we use explicitly prohibit them from using your queries or campaign data to train their models. Data sent to AI models is used only to generate your response. Providers do not retain your data beyond that, except in cases flagged by their automated abuse-detection systems as a potential policy violation - a safeguard applied to all customers, not something specific to your data.
GDPR compliance
Consultad is fully GDPR compliant:
- You can request deletion of all your data at any time.
- Data processing is limited to what is necessary for the service.
- A Data Processing Agreement (DPA) is available upon request.
- Chat conversation history can be deleted by the user at any time.
Authentication and access control
- User authentication supports Google OAuth and email/password.
- All API requests are verified server-side - frontend tokens alone do not grant data access.
- Each tenant's data is isolated at the database level.
Related documents
If you have specific security questions or need documentation for your compliance review, contact support.