DPA ANNEX · ART. 32 GDPR
Technical and organisational measures.
Effective: 21 August 2026
SilentChat operates no hardware of its own. The application runs on rented servers of Hetzner Online GmbH in Falkenstein (Vogtland); physical security of the data centres is governed by their certification and their data processing agreement.
Server access is by SSH key only; password authentication is disabled.
Sign-in with email and password. Passwords are hashed with Argon2id and never stored or logged in clear text.
In addition: two-factor authentication (TOTP) with recovery codes, passwordless sign-in via one-time link, plus SAML 2.0 and OpenID Connect for enterprise customers.
Sign-in attempts are rate limited (5 per minute per IP). Sessions can be revoked centrally — a suspended account loses access immediately, not when its token expires.
SilentChat is multi-tenant. Separation is enforced in the database layer, not merely in the interface: every query carries the tenant identifier as a filter, using reusable scopes rather than hand-written conditions.
Within a tenant, a role and permission model (owner, admin, agent and others) is checked server-side. The interface only hides — it decides nothing.
The cache separates too: keys carry the tenant identifier as a prefix.
In transit: TLS only. Certificate expiry is monitored automatically.
Backups: database and file backups are encrypted with age (a modern replacement for GPG) before they leave the server. The private key is not kept on the backed-up machine. Transfer to the offsite store uses SFTP.
Outbound requests: addresses originating from user input (for example when crawling a page into the knowledge base) pass a server-side request forgery filter; internal networks are blocked.
Every administrative action is recorded in the tenant audit log: who, when, what, from which address. This includes role changes, deletions, invitations and switching the AI provider.
On the provider side, every AI call is logged as well — with model, purpose, consumption and cost.
The database is backed up on a schedule, files once a day. Both backups are encrypted and transferred to an offsite store.
Retention: 30 days rolling — deliberately aligned with the deletion period in the DPA, so a deletion cannot survive in an older backup.
Restore has been rehearsed, not just described: on 6 July 2026 database and files were actually restored from the offsite backup. Recovery point and recovery time objectives are documented in the disaster recovery runbook.
Data of different tenants lives in the same tables, separated by the tenant identifier (see no. 3). In addition, the test environment and production are entirely separate installations with their own databases.
The only AI provider is IONOS, processing in Germany. Speech recognition for voice messages runs in our own container on our own server — recordings do not leave the machine.
Providers based in the US are technically blocked: the application does not connect to them, and the block cannot be lifted from the admin interface.
For emergencies there is a central kill switch that stops all AI calls immediately. Cost ceilings apply per tenant and for the installation as a whole.
The application exposes a health endpoint reporting database, cache, background workers and speech recognition separately. Connection failures to database and cache are absorbed with retries.
For maintenance there is a maintenance mode that shows visitors a message instead of producing errors.
Every release runs through an automated check chain: translations, route coverage, security headers, database migrations, browser-level interface checks, plus unit and integration tests against a real database.
Dependencies are scanned for known vulnerabilities; critical findings are fixed immediately.
These belong in an honest risk assessment:
- No point-in-time recovery (no WAL archive, no PITR). Potential data loss equals the interval between backups, not minutes. A deliberate decision, reasoned in the disaster recovery runbook.
- No 24/7 on-call rotation. SilentChat is run by a small team; response times outside business hours are not guaranteed.
- No ISO 27001 certification and no SOC 2 report.
- No separate database per tenant. Separation is logical (nos. 3 and 7).
Questions and audit requests to dsb@silentchat.de. Material changes to this annex are announced to controllers at least 30 days in advance.