When we are the controller
We are the controller for information about website visitors, account holders, customer contacts and leads when we determine the purpose of processing.
Security and trust center
We combine technical controls, contractual safeguards and customer-controlled integrations to protect the business context and content you process through the service.
Sources last reviewed 10 August 2026
Our public policies commit to TLS 1.2 or higher in transit, encryption at rest where technically appropriate, least-privilege access, role-based controls, employee MFA for production access, logging, security reviews and an incident-response process. We do not use customer data to train AI models, and personal data is primarily stored in the EU/EEA.
This page summarizes our current contractual and privacy commitments. The DPA is the controlling source for processing terms where documents differ. Nothing on this page states that we hold SOC 2 or ISO 27001 certification.
The role depends on the data and purpose. Our Privacy Policy and DPA distinguish between our own business data and the content you process through the service.
We are the controller for information about website visitors, account holders, customer contacts and leads when we determine the purpose of processing.
For your content, connected-channel data and other personal data processed on your instructions, you are the controller and we act as processor under the DPA.
We use subprocessors for hosting, AI inference, publishing, analytics, support and integrations. Other providers can have a different legal role; for example, the DPA identifies Stripe as an independent controller for payment data.
The table summarizes statements in our current public Privacy Policy and Terms. “Committed” means the control is written in those documents. It does not mean an external auditor has independently certified it.
| Control area | Published commitment | Evidence status | Source |
|---|---|---|---|
| Data in transit | TLS 1.2 or higher for data transmitted to and from the service. | Committed in policy and DPA controls | Privacy §10; Terms §18.2 |
| Data at rest | AES-256 or equivalent encryption where technically appropriate. | Committed in policy and DPA controls | Privacy §10; Terms §18.2 |
| Access | Least privilege, role-based access and employee MFA for access to production data. | Committed in policy and DPA controls | Privacy §10; Terms §18.1 |
| Monitoring | Logging and monitoring of access, events and security incidents. | Committed in policy and DPA controls | Privacy §10; Terms §18.3 |
| Secure delivery | Environment separation, patching, vulnerability management and regular security reviews. | Committed in policy and DPA controls | Privacy §10; Terms §18.3 and §18.5 |
| Backups and continuity | Daily automated encrypted backups and documented incident and continuity procedures. | Committed; DPA sets the controlling retention maximum | Terms §18.4; DPA §16.10 |
| DPA and audit support | A binding DPA in the Terms, standalone copy on request and audit information under defined conditions. | Contractual commitment | Terms §16 and §16.9 |
We use AI providers to generate text and images for the service you request. The Privacy Policy states that we do not use customer data, user data or content to train or fine-tune AI models and that we hold contractual terms preventing providers from using service inputs and outputs for model training.
Our DPA states that personal data is stored primarily in the EU/EEA, mainly in Google Cloud regions in Ireland. The subprocessor inventory also lists AWS for cloud storage and operations.
The DPA says deletion normally occurs within 30 days after termination and no later than 90 days. Backups are deleted under standard routines and no later than 180 days. Legal retention duties, such as bookkeeping records, remain exceptions. Connected-service tokens are deleted after disconnection or account closure under the Privacy Policy.
Contractual source: DPA §16.10 is the controlling schedule for customer personal data where a shorter summary elsewhere differs.
Our DPA and privacy commitments describe a defined process for identifying, classifying, escalating and handling security incidents. Notification duties depend on our role and applicable law.
We do not claim on this page to hold SOC 2, ISO 27001 or another independent security certification. The Terms identify infrastructure certifications held by Google Cloud, not by us. You can request current security documentation and available audit evidence from us.
Request the current DPA, subprocessor information or answers to a security questionnaire. Include your organization, deadline and the areas your review needs to cover.
Request security informationNo. Our Privacy Policy states that customer data, user data and content are not used to train or fine-tune AI models and that AI providers are contractually restricted from using service inputs and outputs for training.
Our public documents state that personal data is primarily stored in the EU/EEA. Some subprocessors may process data elsewhere under an applicable transfer mechanism such as the Data Privacy Framework or Standard Contractual Clauses.
Yes. Sections 16 to 18 of the Terms form a binding DPA, and a standalone signable version is available on request.
We do not make that certification claim on this page. Cloud-provider certifications are not the same as a certification held by us.
The DPA says deletion normally occurs within 30 days and no later than 90 days, except where law requires retention. Backups are deleted under standard routines and no later than 180 days.