Always know where your content is processed.

Simple8 runs entirely in Germany and is GDPR compliant. You get 99.9% availability, no external AI models, and your data is never used for training.

Security and Trust

Trust Summary

Fully in Germany

The Simple8 service and the KI- model are fully operated in an infrastructure operated by Simple8 in Germany.

No external AI-model APIs

Automatic text processing.

Only necessary data

Simple8 only processes data necessary for account, query, result, security, billing or support.

Production availability

The production API includes a 99.9% monthly availability SLA.

How Simple8 processes your content.

Infrastructure location

The Simple8 service and its processing engine run in Simple8-operated infrastructure in Germany.

Processing engine

Simple8 uses a language-processing engine that is built, versioned, and operated as part of the Simple8 service.

Inference operation

Customer requests stay inside the Simple8 service and are not sent to an external model provider.

Training policy

Customer content is not used to train or fine-tune models.

How we protect your data.

DataPurposeStorage durationYour controlDeletion
Account detailsContract and accessContract duration and statutory deadlinesAccount managementAfter the end of the contract, insofar as no obligation exists
Query contentsCreate resultDuring processing; background tasks at most one hourAgreed retention planUpon completion or expiration, unless no cache is agreed upon
Results in cacheProvide unchanged content fasterAgreed cache periodClear cache or export contentIn case of deletion, expiration, or end of contract
Security protocolsProtect service and investigate incidentsAgreed security periodSupport and Incident ProcessAfter expiration, except in the case of a documented incident
Usage dataQuota and BillingBilling period and statutory deadlinesUsage overviewAfter the expiration of the statutory period
BackupsRecovery after a failureAgreed security cycleRetention planAutomatically with the next backup cycle

Access and Encryption

TLS for data in transit

Examine how access is secured and permissions are granted. Multi-factor authentication, segregated roles, and traceable access logs should align with the intended use. For confidential content, it is important to know whether support staff have access by default or if access requires individual authorization. Encryption is valuable, but it does not address who is permitted to decrypt and edit content during day-to-day operations.

Encryption at rest

Encryption complements the location commitment but does not replace it. Keys can be managed in Germany while authorized personnel use them via an operations team in another country. Conversely, a global key management service can secure a German data region. Buyers should therefore know where keys are stored and managed, and which entities can authorize their use.

Role-based internal access

Many APIs require a secret access key. It indicates to the service which system is making a request and which permissions apply. This key should not appear in page content, screenshots, or browser code delivered to the public. If it were exposed, unauthorized parties could copy it and send requests on the company's behalf.

All the important documents for data protection, security, law and shopping in one place.

Security overview

The product description, main contract, data processing agreement, and security documentation should align. Pay particular attention to permitted data usage, locations, retention, subcontractors, availability, and support. A marketing claim holds little value if the contract leaves it open or severely restricts it. Key requirements belong in binding documents, not merely in a presentation or a personal email from the sales team.

Data-flow diagram

Before comparing providers, the intended task must be clearly defined. Is the service intended to generate initial translation drafts, convert texts into Plain Language, or flag passages that are difficult to understand? Content types, languages, monthly volumes, and the potential consequences of errors are equally important. A service for general product descriptions must meet different requirements than a tool used for medical instructions or binding service information.

AVV/DPA template

A data processing agreement (often referred to as DPA or *AVV* in German) supplements the service contract. It becomes relevant when a provider processes personal data on behalf of its client-for instance, in cases of hosting, support, newsletter distribution, or cloud applications. What matters is the actual use of the data, not the document's title.

Technical and organizational measures

Individuals processing data on behalf of the provider must be bound by confidentiality obligations or subject to a corresponding statutory duty. For buyers, it is also important to understand how access is restricted in day-to-day operations. Does support staff have access to content by default, or is access granted only for a specific case? Roles, permissions, and logging mechanisms should align with the promised service.

Subprocessor list

Many providers do not deliver their services in isolation. They utilize data centers, email services, or support firms that may act as additional data processors. The data processing agreement should specify whether a specific or general authorization applies. In the case of a general authorization, customers must be informed of intended changes and given a genuine opportunity to object.

Retention and deletion policy

The promise that "data is deleted immediately" sounds reassuring but is ambiguous without further explanation. Does it apply to the active dataset, all caches, search indices, logs, and backups? A credible answer specifies the various levels and their respective timeframes. It also explains whether deletion occurs automatically or must be initiated by a support team.

Model and training policy

Clarify explicitly whether inputs, outputs, and corrections are used to train or improve models. Terms such as "service improvement" can encompass a wide range of uses. The decisive factor is not merely whether a base model undergoes further training; human review, the creation of test data, or permanent inclusion in sample datasets also alter the purpose for which the submitted content is used.

SLA

A commitment of 99.9 percent sounds unambiguous but leaves key questions unanswered. Is the calculation based on a monthly or yearly basis? Does only the login page count, or must the word processing function as well? Are the API, web interface, and CMS connection all included in the assessment? Without a defined measurement point, the provider and the customer might evaluate the same outage differently.

Incident process

A notification stating simply "We are investigating a problem" is rarely sufficient. The organization needs to know which functions, timeframes, and data may be affected. For an editorial team, it is important to know whether content versions already created can continue to be used or should be temporarily locked. Data protection and IT teams may require different details regarding access and protective measures.

Accessibility statement

A website is accessible if people can use it reliably, regardless of varying abilities or usage contexts. This includes blind and visually impaired individuals, deaf people, those with motor or cognitive impairments, and many older users. Temporary factors - such as a broken hand, a noisy environment, or a slow internet connection - can also make usage difficult. Accessibility is therefore not aimed at a small, niche group; rather, it improves access for a wide range of people.

FAQ

Is content sent to an external AI provider?+

No.

Simple8 processes customer content entirely in Germany.

The security pack lists the infrastructure and every relevant non-model service provider.

Is customer content used to train models?+

No.

This applies to all plans, languages, and language modes.

Learn more about processing and your controls in the Data Processing Terms.

Can we set a shorter retention period?+

Yes.

Production plans support documented retention controls, including shorter retention periods where workflow and operational requirements allow.

Can Simple8 be operated on premises?+

A full on-premise model deployment is not offered.

Enterprise architectures can keep selected cache or database components in the customer environment while the managed service and processing engine remain in Germany.

Start using Simple8 for free.

Create your free account and use up to 15,000 characters free every month.