Data and security
A reference document for technical teams and customer data protection departments. Here you'll find where we host data, how we protect it, in what legal framework we process it, and how we treat it in the context of AI features.
Your data stays in the European Union
We host GC.Platform exclusively in data centres located in the European Union. We use three cloud regions: Microsoft Azure in Poland, Microsoft Azure in Germany and Oracle Cloud in Germany.
We store transactional and configuration data in Azure SQL. Product data (the MDM layer) — in Oracle Cloud, where its structure and query performance are critical. Traffic from your customers is handled through Cloudflare — the edge layer, which provides DDoS protection, WAF filtering and content acceleration.
Data is not transferred outside the territory of the European Union — this also applies to backups.
Multi-layer protection in the Enterprise cloud standard
We use security mechanisms built into Microsoft Azure and Oracle Cloud — environments where data protection standards are certified and regularly audited.
Encryption in transit
All communication between the client and GC.Platform and inside the platform happens over TLS 1.2 or higher. Enforced at the infrastructure level — unencrypted connections are rejected.
Encryption at rest
Data in Azure SQL databases is encrypted automatically by Transparent Data Encryption (TDE). Cryptographic keys and secret values are stored in Azure Key Vault — a service that protects them from unauthorised access even within our own infrastructure.
Backups and business continuity
Regular, automatic Azure SQL backups with a retention policy. High availability (HA) is provided by Azure App Service and Azure SQL with the Zone Availability mechanism — allowing automatic scaling and resilience to failures of individual components.
Certified infrastructure
Microsoft Azure and Oracle Cloud, which GC.Platform runs on, are certified to ISO 27001, SOC 1, SOC 2 and SOC 3. The data centres meet the physical and logical protection standards required for enterprise infrastructure.
Limited, controlled, fully audited access
Access to production customer data is held by a narrow, dedicated team maintaining GC.Platform. Each access is individually authorised under the principle of least privilege.
The team logs in through Microsoft Entra ID with enforced multi-factor authentication (MFA). Permissions are managed through Azure Role-Based Access Control (RBAC). Every login, every production operation and every configuration change is recorded in Azure Log Analytics and Application Insights — with the ability to audit retroactively.
Each week, the team analyses Azure Advisor recommendations on security and plans the rollout of changes. This is a routine, not a reaction to an incident.
As a data processor, in accordance with Article 28 GDPR
In the SaaS model, you remain the controller of your data. GearCode is the data processor, processing data on your behalf and at your instruction, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).
Alongside the SaaS licence agreement, we sign a data processing agreement with you. It is based on the standard contractual clauses approved by the European Commission (Implementing Decision 2021/915 of 4 June 2021) — a template recognised by the regulator as meeting GDPR requirements.
The list of our sub-processors (infrastructure providers and other entities that have access to data as part of delivering the service) is available to you. We notify you of any planned change to this list — adding a new sub-processor or replacing an existing one — at least 14 days in advance, so that you have time to object.
How we treat data in AI features
You're reading this section because you're probably wondering what happens with the conversations between your customers and AI.Assistant. Here's a straight answer.
We review user conversations with AI.Assistant. Our team does this manually, to understand what the conversation flow between the customer and the assistant actually looks like — where the assistant does well, where it gets it wrong, where the user gets lost. Based on that, we improve the product: we fine-tune the conversation logic, fix edge cases, add support for new types of queries. That's how AI.Assistant gets better over time.
Your data does not feed external AI models. We work with language model providers who contractually commit that conversations with AI.Assistant will not be used to train their models — neither ours nor the ones publicly available. That means your data, your customers' data and your suppliers' data stay strictly within the service you use.
In other words: AI.Assistant learns to serve your customers better, but not at the cost of your data privacy or the risk that it will end up in models used by anyone else.
Vehicle identification database (VIN and registration numbers)
Some of our automotive catalogues — including the demonstration version at catalog-gearcode.eu — allow vehicles to be identified by registration number or VIN. Where access to public registries is unavailable or not viable for the client, we use our own GearCode identification database.
The database is built by AI.Assistant users. Before each addition, AI.Assistant asks the user for a conscious confirmation of linking the registration number or VIN to a specific vehicle. We store only technical vehicle data in the database; we do not correlate it with personal data of vehicle owners or users.
The shared database applies exclusively to catalogues in multitenant model provided under a GearCode subscription. Clients using a dedicated subscription have full data separation in this regard.
Exit without hostages
After the contract ends, your data is returned to you or permanently deleted — within 30 days of cooperation ending, according to the decision you make as the data controller. We confirm the deletion with a protocol within the following 14 days.
The procedure details are described in the data processing agreement we sign with every customer. The contractual terms for ending cooperation are laid out on the partnership model page.
Questions about data protection?
We have a dedicated data protection consultant at GearCode who answers questions from customers, compliance teams and legal departments.
Data Protection Consultant
Back to GC.Platform
There you'll find the full description of the platform, modules and implementation scenarios.