Security & Compliance
For law firms, tax advisors and medical practices — GDPR-compliant, §203-compatible, DPA included. Your data lives technically isolated in Frankfurt — on a dedicated server on the Compliance plan. Not a single byte leaves the EU.
Provider comparison
A direct compliance comparison of the common AI platforms — for professions bound by statutory confidentiality, every detail counts.
| Criterion | ClapNClaw | ChatGPT Team | Copilot Business |
|---|---|---|---|
| Server location | Frankfurt (DE) | USA | USA / EU |
| CLOUD Act | ✓ No risk | ✗ Affected | ✗ Affected |
| §203 StGB | ✓ Compatible | ✗ Not possible | ✗ Not possible |
| DPA Art. 28 | ✓ Included | ~ On request | ~ On request |
| Dedicated VPS | ✓ On the Compliance plan | ✗ Shared cloud | ✗ Shared cloud |
| Audit logs | ✓ Complete | ~ Limited | ~ Limited |
| Price / user | from €29 | $30 | $30 |
Data flow architecture
From the browser to the AI model — every step stays in the EU.
Your team
End-to-end encrypted
Hetzner Frankfurt
Routing & cache
Frankfurt · eu-central-1
Professional confidentiality
§203 StGB protects the professional secrets of lawyers, doctors and tax advisors. ClapNClaw is built so that your data is technically separated from every other customer. Access by ClapNClaw is limited strictly to operations and maintenance — contractually restricted and logged (data processing under Art. 28 GDPR).
Data protection documentation
The GDPR requires documentation. ClapNClaw delivers it with the product — prepared and ready to use right away.
Every ClapNClaw contract includes a complete data processing agreement. Subject matter, duration, nature and purpose of processing as well as the TOMs are documented and ready to use right away.
When processing special categories of personal data, a DPIA may be required. ClapNClaw provides a DPIA template and technical documentation.
A complete overview: which data is processed, the legal basis, retention periods, sub-processors and TOMs — ready for your files.
Isolated environment
Your private AI runs in a technically isolated environment and is governed by declarative security policies (policy-as-code).
Security policy (YAML)
Security policies in YAML — versioned, auditable, reproducible. No manual intervention required.
Every file access, every network request, every token used is logged. 90-day retention.
Your data protection officer gets access to usage statistics, audit logs and the policy configuration.
Certifications & standards
ClapNClaw relies on infrastructure with recognized certifications — and delivers the compliance documents right along with it.
ISO 27001 certified data center. Isolated containers on the Team plan, a dedicated VPS with hypervisor isolation on the Compliance plan.
ISO 27001, BSI C5 and SOC 2 audited. AI inference in Frankfurt (eu-central-1), zero data retention.
Data processing agreement included in the contract. Ready to use right away.
Architecture designed for §203-compatible use. On the Compliance plan: a dedicated server plus the §203 addendum.
ISO 27001, BSI C5 and SOC 2 are certifications of our infrastructure providers (Hetzner, AWS). They attest to the security of the underlying data centers and AI infrastructure.
Frequently asked questions
ClapNClaw is built for GDPR compliance. All customer data is stored in technically isolated environments in the Hetzner data center in Frankfurt (ISO 27001 certified) — on a dedicated server on the Compliance plan. AI inference runs via AWS Bedrock eu-central-1 without data storage. A data processing agreement (DPA) under Art. 28 GDPR is included in the contract.
Your data lives at Hetzner in Frankfurt am Main — in a technically isolated container with its own database instance on the Team plan, on a dedicated VPS on the Compliance plan. AI inference runs via AWS Bedrock eu-central-1 (also in Frankfurt). Not a single byte leaves the EU.
No. AWS Bedrock does not store inputs or outputs and does not use them for model training. Your chat history stays exclusively in your isolated environment in Frankfurt.
A data processing agreement (DPA) under Art. 28 GDPR governs how we handle your data as a processor. Yes — every ClapNClaw contract includes a complete DPA.
Yes. ClapNClaw's architecture is designed to create the technical conditions for §203-compliant use: on the Compliance plan you get a dedicated VPS with hypervisor isolation. Access by ClapNClaw is limited strictly to operations and maintenance — contractually restricted and logged (DPA under Art. 28 GDPR plus the §203 addendum). The legal assessment remains the responsibility of the individual professional bound by confidentiality.
A DPIA (data protection impact assessment) under Art. 35 GDPR may be required if you process special categories of personal data (e.g. health data). ClapNClaw provides a DPIA template and technical documentation.
Your data belongs to you and your team. Every customer organization runs in a technically isolated environment — a container with a dedicated data volume and its own database instance on the Team plan, a dedicated VPS with hypervisor isolation on the Compliance plan. Access by ClapNClaw is limited strictly to operations and maintenance — contractually restricted and logged (data processing under Art. 28 GDPR). AWS Bedrock stores no data.
When the contract ends, your entire environment is deprovisioned and all data is permanently erased — the whole dedicated VPS on the Compliance plan; container, data volume and database instance on the Team plan. AWS Bedrock stores no data in the first place.
An isolated environment in Frankfurt — a dedicated server on the Compliance plan. DPA from day one. Not a single byte to the USA.
Start free for 7 days ↗Setup in 5 minutes · DPA included · Data in Frankfurt · Cancel anytime