Built for your
vendor-security review
CrunchJunkie is built by a German company (Tiki-Taka Media GmbH) for agencies who hold their clients' data. Here is exactly where your data lives, who processes it, and the measures that protect it — everything an ISO-certified buyer needs to sign us off.
Data residency
Application compute
Frankfurt (fra1)
EUVercel — EU region
File storage
Frankfurt (fra1)
EUVercel Blob — EU region
Database
Frankfurt (eu-central-1)
EUNeon — EU region
Application compute, file storage and the database all run in the EU (Frankfurt). As a US-incorporated host, Vercel may be subject to the US CLOUD Act; for AI processing fully within your own jurisdiction, use your own AI key (BYOK), and your prompts are processed by your own provider account.
Customers can view and export a live Data Location & Sub-processor Report for their own workspace under Settings → Data & residency.
Sub-processors
We have Data Processing Agreements (Art. 28 GDPR) with every sub-processor that handles personal data on our behalf. AI providers are engaged only when you enable Managed AI or the feature that uses them.
| Sub-processor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
Vercel Vercel Inc. (USA) DPA → | Application hosting, CDN, serverless function execution (compute), and file/object storage | Frankfurt (fra1), EU | EU–US Data Privacy Framework + Standard Contractual Clauses |
Neon Neon Inc. (USA) DPA → | Managed PostgreSQL database (all application data at rest) | Frankfurt (eu-central-1), EU | Processed in the EU — no third-country transfer |
Stripe Stripe, Inc. (USA) DPA → | Payment processing & subscription management | United States | EU–US Data Privacy Framework + Standard Contractual Clauses |
Resend Resend Inc. (USA) DPA → | Transactional email delivery (password resets, report & alert emails) | United States | EU–US Data Privacy Framework + Standard Contractual Clauses |
SerpAPI SerpAPI, LLC (USA) | Reads Google AI Overviews & AI Mode for visibility scans | United States | No transfer mechanism published by the vendor — do not send personal data |
Tavily Tavily (USA) | Supplementary web-search retrieval in research & content-brief features | United States | No transfer mechanism published by the vendor — do not send personal data |
OpenAI OpenAI, L.L.C. (USA) DPA → | AI-visibility scans (ChatGPT) and CrunchJunkie AI features · Retention: 30-day default; Zero-Data-Retention available | United States (EU in-region processing available via EU Project) | EU–US Data Privacy Framework + Standard Contractual Clauses |
Anthropic (Claude) Anthropic, PBC (USA) DPA → | CrunchJunkie AI features (report summaries, assistant) and Claude visibility scans · Retention: 7-day default; Zero-Data-Retention available (enterprise) | United States | Standard Contractual Clauses (+ Transfer Impact Assessment) |
Google (Gemini) Google LLC (USA) DPA → | Gemini visibility scans and CrunchJunkie AI features · Retention: Not used to train models on paid API/Vertex | United States (EU regions available via Vertex AI) | EU–US Data Privacy Framework + Standard Contractual Clauses |
Perplexity Perplexity AI, Inc. (USA) DPA → | Perplexity visibility scans | United States | Standard Contractual Clauses (+ Transfer Impact Assessment) |
Grok (xAI) X.AI LLC (USA) DPA → | Grok visibility scans and (optionally) CrunchJunkie AI features · Retention: Deleted within ~30 days of a deletion request | United States | Standard Contractual Clauses (+ Transfer Impact Assessment) |
DeepSeek(opt-in) DeepSeek (China) | DeepSeek visibility scans | China | No transfer mechanism published by the vendor — do not send personal data |
Technical & organisational measures (Art. 32)
- Encryption at rest — AI keys & OAuth tokens with AES-256-GCM at the application layer, over provider disk encryption
- Encryption in transit — TLS 1.2+ with HSTS enforced
- Tenant isolation — every query scoped to the authenticated team; cross-tenant access architecturally prevented
- Access control — MFA required for production access; least-privilege; access logged and reviewed
- Passwords — bcrypt (cost factor 12), never stored in plain text
- Rate limiting — auth and critical API routes throttled per IP
- Incident response — documented process; breach notification within 72 hours (Art. 33 GDPR)
The full TOM annex is part of our Data Processing Agreement.
Certifications
We build to the controls behind ISO 27001 (encryption, access control, logging, incident response, resilience). Formal ISO 27001 certification is on our roadmap; in the meantime we support your vendor-security review with a signed DPA, this sub-processor list, our TOMs, and a completed security questionnaire on request.
International transfers
Where data reaches a third-country sub-processor (primarily the US), we rely on the EU–US Data Privacy Framework where the provider is certified, backed by EU Standard Contractual Clauses and a Transfer Impact Assessment. We keep SCCs in place even for DPF-certified providers, so transfers stay lawful if the framework changes.
Documents for your review
Everything your compliance team needs. Need a signed DPA (AVV) or our security questionnaire? Email hello@crunchjunkie.io.
Signed-in customers can export a live data-location report under Settings → Data & residency.