GuidesSecurity & PrivacyData Handling (GDPR, retention, regions)

Security is built into every processor and workflow.

Storage & encryption

  • Files are encrypted at rest with AES-256 and in transit via TLS 1.2+.
  • Processing occurs in the eu-west-1 region by default; contact support to enable additional regions.
  • Access is scoped to your workspace; every API key maps to a least-privilege role.

Retention controls

  • Default retention is 30 days for uploads and run outputs.
  • Override in https://app.algorythmos.fr/settings/security to shorten or extend retention (1–90 days).
  • Enable Auto-delete on success for sensitive documents and we purge outputs immediately after webhook delivery.

GDPR & compliance

  • Algorythmos acts as a data processor under GDPR; review the DPA in Settings → Legal.
  • Request data exports or deletion at any time by emailing dpo@algorythmos.fr with your workspace slug.
  • Audit trails and access logs are available to workspace admins.

Operational best practices

  • Rotate API keys quarterly.
  • Use dedicated service accounts for server-to-server calls.
  • Monitor suspicious activity in Console → Settings → Security → Activity Logs.