Eterna Creative

How we handleyour data and security

We don't hold SOC 2, ISO 27001, or any other security certification. This page describes what we actually do instead - hosting you control, access by role, no training on your data, and a plan for when something goes wrong.

What we do

AreaPractice
AI providersWe usually build with OpenAI and Anthropic, and we've worked with more than 10 AI providers. We use whichever one your needs and your legal requirements allow.
Hosting regionYou choose where your data is hosted: the EU or the US.
AgreementsWe sign an NDA on almost every project, and a data processing agreement when your data needs one.
Model trainingWe don't train AI models on your data.
Access controlAccess to your systems - code repositories, no-code platforms, your project portal - is set up per client, by role.
Team agreementsEveryone on our team works under an agreement with us, and loses access when they stop working with us.
Client ownershipYou own the code, workflows, accounts and documentation.

How your data moves

  1. Your data enters the system you control - your CRM, your inbox, your uploaded files, or directly from your own users.
  2. When an AI call is needed, the request goes to the provider you approved, scoped to only the data that call needs. No client data is used to train a model.
  3. Data is stored in the hosting region you chose.
  4. Access to the system - code, no-code platform, project portal - is role-based and set up per client.
  5. When someone stops working with Eterna, their access is removed. What happens to the data itself follows the agreement for that project.

Who else touches your data

Used only where the project needs them - not every project uses all of these.

SubprocessorRoleWhen used
AnthropicAI model providerWhen Claude is the model used for the build
OpenAIAI model providerWhen GPT models are the model used for the build
SupabaseDatabase and backend hostingCustom application builds using Eterna's default stack
VercelApplication hostingCustom application and website builds
BubbleNo-code application platformNo-code builds
n8nAutomation and workflow platformAutomation engagements

If something goes wrong

We monitor for problems, contain and fix quickly, and tell you within 72 hours of confirming an incident that affects your data.

Agreements on request

We sign an NDA on almost every project, and a data processing agreement when your data needs one.

Ask for a data processing agreement or our full security questionnaire pack and we'll send it.

GDPR and the EU AI Act

We don't sell certificates. We design for your obligations from the start: a data processing agreement when needed, hosting in the region you choose, and access limited by role. If what you want to build falls under the EU AI Act, we'll tell you on the first call what it means for the design, which usually comes down to human oversight and a clear record of what the AI did.

See the full methodology

Have a security questionnaire?

Send it over and we'll fill it out from this page, plus whatever's specific to your project.

Book free strategy call