Fully in Germany
The Simple8 service and the KI- model are fully operated in an infrastructure operated by Simple8 in Germany.
Simple8 runs entirely in Germany and is GDPR compliant. You get 99.9% availability, no external AI models, and your data is never used for training.

The Simple8 service and the KI- model are fully operated in an infrastructure operated by Simple8 in Germany.
Automatic text processing.
Simple8 only processes data necessary for account, query, result, security, billing or support.
The production API includes a 99.9% monthly availability SLA.
The Simple8 service and its processing engine run in Simple8-operated infrastructure in Germany.
Simple8 uses a language-processing engine that is built, versioned, and operated as part of the Simple8 service.
Customer requests stay inside the Simple8 service and are not sent to an external model provider.
Customer content is not used to train or fine-tune models.
| Data | Purpose | Storage duration | Your control | Deletion |
|---|---|---|---|---|
| Account details | Contract and access | Contract duration and statutory deadlines | Account management | After the end of the contract, insofar as no obligation exists |
| Query contents | Create result | During processing; background tasks at most one hour | Agreed retention plan | Upon completion or expiration, unless no cache is agreed upon |
| Results in cache | Provide unchanged content faster | Agreed cache period | Clear cache or export content | In case of deletion, expiration, or end of contract |
| Security protocols | Protect service and investigate incidents | Agreed security period | Support and Incident Process | After expiration, except in the case of a documented incident |
| Usage data | Quota and Billing | Billing period and statutory deadlines | Usage overview | After the expiration of the statutory period |
| Backups | Recovery after a failure | Agreed security cycle | Retention plan | Automatically with the next backup cycle |
Examine how access is secured and permissions are granted. Multi-factor authentication, segregated roles, and traceable access logs should align with the intended use. For confidential content, it is important to know whether support staff have access by default or if access requires individual authorization. Encryption is valuable, but it does not address who is permitted to decrypt and edit content during day-to-day operations.
Encryption complements the location commitment but does not replace it. Keys can be managed in Germany while authorized personnel use them via an operations team in another country. Conversely, a global key management service can secure a German data region. Buyers should therefore know where keys are stored and managed, and which entities can authorize their use.
Many APIs require a secret access key. It indicates to the service which system is making a request and which permissions apply. This key should not appear in page content, screenshots, or browser code delivered to the public. If it were exposed, unauthorized parties could copy it and send requests on the company's behalf.
The product description, main contract, data processing agreement, and security documentation should align. Pay particular attention to permitted data usage, locations, retention, subcontractors, availability, and support. A marketing claim holds little value if the contract leaves it open or severely restricts it. Key requirements belong in binding documents, not merely in a presentation or a personal email from the sales team.
Before comparing providers, the intended task must be clearly defined. Is the service intended to generate initial translation drafts, convert texts into Plain Language, or flag passages that are difficult to understand? Content types, languages, monthly volumes, and the potential consequences of errors are equally important. A service for general product descriptions must meet different requirements than a tool used for medical instructions or binding service information.
A data processing agreement (often referred to as DPA or *AVV* in German) supplements the service contract. It becomes relevant when a provider processes personal data on behalf of its client-for instance, in cases of hosting, support, newsletter distribution, or cloud applications. What matters is the actual use of the data, not the document's title.
Individuals processing data on behalf of the provider must be bound by confidentiality obligations or subject to a corresponding statutory duty. For buyers, it is also important to understand how access is restricted in day-to-day operations. Does support staff have access to content by default, or is access granted only for a specific case? Roles, permissions, and logging mechanisms should align with the promised service.
Many providers do not deliver their services in isolation. They utilize data centers, email services, or support firms that may act as additional data processors. The data processing agreement should specify whether a specific or general authorization applies. In the case of a general authorization, customers must be informed of intended changes and given a genuine opportunity to object.
The promise that "data is deleted immediately" sounds reassuring but is ambiguous without further explanation. Does it apply to the active dataset, all caches, search indices, logs, and backups? A credible answer specifies the various levels and their respective timeframes. It also explains whether deletion occurs automatically or must be initiated by a support team.
Clarify explicitly whether inputs, outputs, and corrections are used to train or improve models. Terms such as "service improvement" can encompass a wide range of uses. The decisive factor is not merely whether a base model undergoes further training; human review, the creation of test data, or permanent inclusion in sample datasets also alter the purpose for which the submitted content is used.
A commitment of 99.9 percent sounds unambiguous but leaves key questions unanswered. Is the calculation based on a monthly or yearly basis? Does only the login page count, or must the word processing function as well? Are the API, web interface, and CMS connection all included in the assessment? Without a defined measurement point, the provider and the customer might evaluate the same outage differently.
A notification stating simply "We are investigating a problem" is rarely sufficient. The organization needs to know which functions, timeframes, and data may be affected. For an editorial team, it is important to know whether content versions already created can continue to be used or should be temporarily locked. Data protection and IT teams may require different details regarding access and protective measures.
A website is accessible if people can use it reliably, regardless of varying abilities or usage contexts. This includes blind and visually impaired individuals, deaf people, those with motor or cognitive impairments, and many older users. Temporary factors - such as a broken hand, a noisy environment, or a slow internet connection - can also make usage difficult. Accessibility is therefore not aimed at a small, niche group; rather, it improves access for a wide range of people.
No.
Simple8 processes customer content entirely in Germany.
The security pack lists the infrastructure and every relevant non-model service provider.
No.
This applies to all plans, languages, and language modes.
Learn more about processing and your controls in the Data Processing Terms.
Yes.
Production plans support documented retention controls, including shorter retention periods where workflow and operational requirements allow.
A full on-premise model deployment is not offered.
Enterprise architectures can keep selected cache or database components in the customer environment while the managed service and processing engine remain in Germany.
Create your free account and use up to 15,000 characters free every month.