Skip to content
Security

What happens to your data

This page is written for the person who has to say no: your IT lead, your data protection officer, the sceptic on your team. Short claims, real specifics, and a clear line between what is true today and what is planned. Forward it.

The short version

Stored in Frankfurt. Chats, Documents and Memory live on servers in Frankfurt.
No training, ever. Nothing your team does trains a model.
You pick the model. For every message. The request then goes to whoever runs that model, which can be outside the EU, under EU standard contractual clauses.
OAuth where the tool offers it. You authorise Dory in the tool itself and can withdraw it there. Where a tool has no OAuth, an admin enters the credentials and we store them encrypted.
Your yes before it acts. Writing to your tools, sending anything and deleting anything wait for your approval. Reading does not ask.
AVV included. The data processing agreement is an annex of the terms, and it names every subprocessor we use.
01

Where your data lives

Everything Dory keeps for you is stored on servers in Frankfurt. Where those servers are is a fixed part of how Dory is set up, not something picked request by request. Traffic to and from Dory runs over TLS.

Stored, in Frankfurt Chats and their messages, Memory and Documents. They stay until you delete them, one by one or as a whole company.
What Dory reads from your tools Dory reads from your connected tools live, when a chat needs it. What it read then sits in that chat, like an email you paste into one. Dory does not copy your tools into a database of its own.
02

What the model providers see

When you send a message, your request and the content needed to answer it go to the model you picked. You pick that model per message, and you can see which one you are on before you send.

Your stored data does not move for this. What travels is the request and the context for that one answer. Storing and processing are two different things, and we keep them apart: what Dory stores for you is in Frankfurt, while a request goes to whoever serves the model you picked.

Where a request is processed OpenAI is called directly. Every other model is reached through a gateway that picks the provider by speed, with no region constraint, so processing can happen outside the EU. Those transfers run under EU standard contractual clauses. Voice messages go to a separate speech provider to be turned into text.
No training Your input does not train a model. No provider we send it to is permitted to train on it, and the data processing agreement names every one of them.
03

How integrations connect

Most integrations connect through OAuth. You authorise Dory in the tool itself, the way you would authorise any app, and you can withdraw that authorisation there at any time. Which integrations are available at all is your admins' decision.

Not every tool offers OAuth. For those, an API key or a service account is entered once and we store it encrypted. For the integrations in our catalogue that is an admin's decision, not something Dory asks a team member for.

Not your personal password Where OAuth exists, Dory never sees a password: it holds a token that you can revoke in the tool. Where it does not, an admin decides what credentials Dory gets, and they sit encrypted.
Never more than the account it was given With OAuth, Dory sees exactly what the person who connected the tool can see there. Where an admin entered a key instead, Dory sees what that key is allowed to see. No superuser access, no direct database access.
04

You stay in control

Before Dory writes to one of your tools, sends something out or deletes something, it shows you what will happen and waits. This is a mechanism in the product, not a promise in a document. Reading does not ask, apart from the first time Dory uses an integration you have just connected.

You decide how long a yes lasts: for this chat, for a set time, or for a month. You can take any of them back. Deleting a Document, a contact or an appointment is the exception: it asks every time and cannot be granted in advance.

The same openness applies to what Dory remembers. Memory is visible in the app, deletable entry by entry or all at once, and you can switch it off. Switching it off stops new entries, deleting removes the old ones, and the two are separate on purpose.

05

The paperwork

Your company stays the controller of its content. We process it on your instruction only, under Art. 28 GDPR. Every subprocessor we use is named in the data processing agreement (AVV), which is an annex inside the terms rather than a form you have to request. Where a subprocessor is outside the EU, transfers run under EU standard contractual clauses (Art. 46 GDPR).

06

What we do not claim yet

Three things a security review will ask about are on our roadmap and not in the product. We would rather tell you here than have you find out.

Planned ISO 27001 We hold no certification. The practices this page describes are real today, the audit stamp is not.
Planned SSO / SAML You can sign in with email and password, a magic link, or Google. SAML single sign-on is on the roadmap.
Planned Detailed audit logs Security-relevant events are logged internally. A customer-facing audit log is planned, not shipped.

Still have a question? Ask the people who built it.

No trust portal, no questionnaire form. Write to support@dory-ai.com and a person who works on the system answers. Your data protection officer is welcome to write directly.