Trust & Compliance

Built for your
vendor-security review

CrunchJunkie is built by a German company (Tiki-Taka Media GmbH) for agencies who hold their clients' data. Here is exactly where your data lives, who processes it, and the measures that protect it — everything an ISO-certified buyer needs to sign us off.

Data residency

Application compute

Frankfurt (fra1)

EU

Vercel — EU region

File storage

Frankfurt (fra1)

EU

Vercel Blob — EU region

Database

Frankfurt (eu-central-1)

EU

Neon — EU region

Application compute, file storage and the database all run in the EU (Frankfurt). As a US-incorporated host, Vercel may be subject to the US CLOUD Act; for AI processing fully within your own jurisdiction, use your own AI key (BYOK), and your prompts are processed by your own provider account.

Customers can view and export a live Data Location & Sub-processor Report for their own workspace under Settings → Data & residency.

Sub-processors

We have Data Processing Agreements (Art. 28 GDPR) with every sub-processor that handles personal data on our behalf. AI providers are engaged only when you enable Managed AI or the feature that uses them.

Sub-processorPurposeRegionTransfer mechanism
Vercel
Vercel Inc. (USA)
DPA →
Application hosting, CDN, serverless function execution (compute), and file/object storageFrankfurt (fra1), EUEU–US Data Privacy Framework + Standard Contractual Clauses
Neon
Neon Inc. (USA)
DPA →
Managed PostgreSQL database (all application data at rest)Frankfurt (eu-central-1), EUProcessed in the EU — no third-country transfer
Stripe
Stripe, Inc. (USA)
DPA →
Payment processing & subscription managementUnited StatesEU–US Data Privacy Framework + Standard Contractual Clauses
Resend
Resend Inc. (USA)
DPA →
Transactional email delivery (password resets, report & alert emails)United StatesEU–US Data Privacy Framework + Standard Contractual Clauses
SerpAPI
SerpAPI, LLC (USA)
Reads Google AI Overviews & AI Mode for visibility scansUnited StatesNo transfer mechanism published by the vendor — do not send personal data
Tavily
Tavily (USA)
Supplementary web-search retrieval in research & content-brief featuresUnited StatesNo transfer mechanism published by the vendor — do not send personal data
OpenAI
OpenAI, L.L.C. (USA)
DPA →
AI-visibility scans (ChatGPT) and CrunchJunkie AI features · Retention: 30-day default; Zero-Data-Retention availableUnited States (EU in-region processing available via EU Project)EU–US Data Privacy Framework + Standard Contractual Clauses
Anthropic (Claude)
Anthropic, PBC (USA)
DPA →
CrunchJunkie AI features (report summaries, assistant) and Claude visibility scans · Retention: 7-day default; Zero-Data-Retention available (enterprise)United StatesStandard Contractual Clauses (+ Transfer Impact Assessment)
Google (Gemini)
Google LLC (USA)
DPA →
Gemini visibility scans and CrunchJunkie AI features · Retention: Not used to train models on paid API/VertexUnited States (EU regions available via Vertex AI)EU–US Data Privacy Framework + Standard Contractual Clauses
Perplexity
Perplexity AI, Inc. (USA)
DPA →
Perplexity visibility scansUnited StatesStandard Contractual Clauses (+ Transfer Impact Assessment)
Grok (xAI)
X.AI LLC (USA)
DPA →
Grok visibility scans and (optionally) CrunchJunkie AI features · Retention: Deleted within ~30 days of a deletion requestUnited StatesStandard Contractual Clauses (+ Transfer Impact Assessment)
DeepSeek(opt-in)
DeepSeek (China)
DeepSeek visibility scansChinaNo transfer mechanism published by the vendor — do not send personal data

Technical & organisational measures (Art. 32)

  • Encryption at rest — AI keys & OAuth tokens with AES-256-GCM at the application layer, over provider disk encryption
  • Encryption in transit — TLS 1.2+ with HSTS enforced
  • Tenant isolation — every query scoped to the authenticated team; cross-tenant access architecturally prevented
  • Access control — MFA required for production access; least-privilege; access logged and reviewed
  • Passwords — bcrypt (cost factor 12), never stored in plain text
  • Rate limiting — auth and critical API routes throttled per IP
  • Incident response — documented process; breach notification within 72 hours (Art. 33 GDPR)

The full TOM annex is part of our Data Processing Agreement.

Certifications

We build to the controls behind ISO 27001 (encryption, access control, logging, incident response, resilience). Formal ISO 27001 certification is on our roadmap; in the meantime we support your vendor-security review with a signed DPA, this sub-processor list, our TOMs, and a completed security questionnaire on request.

International transfers

Where data reaches a third-country sub-processor (primarily the US), we rely on the EU–US Data Privacy Framework where the provider is certified, backed by EU Standard Contractual Clauses and a Transfer Impact Assessment. We keep SCCs in place even for DPF-certified providers, so transfers stay lawful if the framework changes.

Documents for your review

Everything your compliance team needs. Need a signed DPA (AVV) or our security questionnaire? Email hello@crunchjunkie.io.

Signed-in customers can export a live data-location report under Settings → Data & residency.