Skip to main content

Overview

Last updated: 09.09.2026·All documents current

Privacy isn't a checkbox. It's a commitment. Sally AI is built on the principle that your data belongs to you: it stays inside our own infrastructure in Germany at Hetzner, is processed by Sally's own LLM with no external AI providers involved, and is never used to train or improve language models. We hold ourselves to the highest European data protection standards so you can focus on getting value from AI, without compromise.

Compliance & certifications

GDPRGDPR
Compliant

Fully compliant with the EU General Data Protection Regulation. GDPR-compliant DPA under Art. 28 with every customer.

Germany HostingGermany Hosting
Active100% Germany

All meeting content, transcripts and metadata are stored and processed exclusively in German data centers at Hetzner. No third-country transfers, ever.

Own LLM in GermanyOwn LLM in Germany
Active

AI processing happens on Sally's own large language model, operated end-to-end in our own infrastructure in Germany. No external AI providers involved.

ISO 27001ISO 27001
Certified

Certified to ISO 27001:2022 for information security management, part of our independently audited integrated management system. Full details on our ISO Certifications page.

ISO 14001ISO 14001
Certified

Certified to ISO 14001:2015 for environmental management. Full details and the downloadable certificate on our ISO Certifications page.

ISO 9001ISO 9001
Certified

Certified to ISO 9001:2015 for quality management. Full details and the downloadable certificate on our ISO Certifications page.

SOC 2SOC 2
Compliant

Service organization controls aligned with SOC 2 principles for security, availability, and confidentiality.

No AI Training🚫
Guaranteed

Your data is never used to train or improve language models, guaranteed contractually and technically.

DORA🛡️
Compliant

Sally AI meets the requirements of the Digital Operational Resilience Act (DORA) for financial-sector resilience.

⚖️
EU AI Act
Regulation (EU) 2024/1689
Risk Classification
Limited Risk
Transparency
Auto-notice in meeting chat
AI processing
Sally's own LLM in Germany
Declaration
Available for download
Full details 
Roadmap
Achieved and planned compliance milestones
Dec 2026Accessibility self-declaration (EN 301 549 / WCAG 2.1 AA)

Self-declaration on accessibility aligned with EN 301 549 and WCAG 2.1 AA, including the mandatory disclosures required by BITV and BFSG. Provides public-sector buyers and customers with elevated accessibility requirements a solid basis.

Sep 2026Network segmentation & dedicated bastion host

Network-level separation of administration traffic and compute workload networks, including a dedicated jump/bastion host (per BSI C5:2026, controls COS-02.01B, COS-05.01B, COS-05.02B).

Sep 2026ISO 42001 certification (AI Management System)

AI governance at the heart of Sally AI. Our certified AI Management System to ISO/IEC 42001, independently audited, extends our ISO 27001 controls to the AI life cycle: transparency, accountability, and continuous risk management for every model in production.

Sept 2026✓ Own LLM, fully independent of external AI providers

Sally's own large language model runs in production. Every step of inference happens inside our own infrastructure in Germany, with no external AI providers involved.

Sept 2026✓ 100% Germany-only infrastructure

All meeting content, transcripts and metadata are stored and processed exclusively in German data centers at Hetzner. Zero dependency on non-German EU regions.


Security controls

Infrastructure
  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • ISO 27001-certified German data centers
  • DDoS protection & rate limiting
  • Geo-redundant backups
Access & Authentication
  • Multi-factor authentication (MFA) on all systems
  • Role-based access control (RBAC)
  • Principle of least privilege
  • Full audit logging of all access
  • Tenant-level data separation
AI & Data Privacy
  • Own LLM operated end-to-end in Germany, no external providers
  • No AI training on customer data, ever
  • AES-256 encryption at rest, TLS 1.3 in transit
  • Bring Your Own LLM option available
  • On-premises storage option available
Processes & Organisation
  • DPA with every customer & all subprocessors
  • Regular employee security training
  • Incident notification to customer < 24 hours
  • Annual penetration tests by external security firms
  • DPIA per Article 35 GDPR
  • Regular internal security reviews

Completing the DPA: Two options

RecommendedRequest online
1
Fill out the form: Enter your company details directly in the online form.
2
DPA is generated: Your personalized DPA is created automatically.
3
Sign digitally: You receive the DPA via email and can sign it directly online.
Complete manually
1
Download: Get the DPA in your preferred language.
2
Sign: Digitally or by hand. The signatory must be authorized to represent the company.
3
Email: Send the signed copy to privacy@sally.io. We countersign within 1–⁠3 business days.

Documents & resources

📄
Data Processing Agreement (DPA)

GDPR-compliant DPA under Art. 28, signed with every customer. Available in English and German.

Download DPA 
🔒
Technical & Org. Measures (TOMs)

Our full technical and organizational security measures. Annex 1 of the DPA.

Download TOMs 
🌐
Subprocessors List

All subprocessors with processing purpose and hosting location in Germany. Annex 3 of the DPA.

Download List 

Contact

Data Protection Officer
Norton Engele