EU processing, GDPR
Operated from Germany under the GDPR. Application data (accounts, conversation history, generated exports) is stored and processed in the EU (AWS eu-west-1, Ireland).
Trust
RafiHive is built for a regulated audience, so where your data lives and how it is used is a first-class concern. This page summarises our current posture.
Operated from Germany under the GDPR. Application data (accounts, conversation history, generated exports) is stored and processed in the EU (AWS eu-west-1, Ireland).
Questions and answers are processed to generate your response and are not used to train foundation models. The same applies to documents you upload.
Encryption in transit (TLS) and at rest, and a person outside your team cannot browse, search, attach or receive citations from your documents.
The uploader can remove a document. RafiHive stops using it in answers immediately and completes removal from private storage and searchable knowledge.
Operated from Germany under the GDPR. Application data (accounts, conversation history, generated exports) is stored and processed in the EU (AWS eu-west-1, Ireland). AI responses are generated by Amazon Bedrock in an EU region. We do not move regulated content to non-EU regions.
RafiHive is operated from Germany. Personal data is processed under the GDPR: the legal basis for each processing purpose, the processors we use, retention periods and your rights as a data subject are set out in the privacy policy. The terms of service are governed by German law. Hosting, storage and AI inference stay inside the EU; RafiHive holds no data in non-EU regions.
Questions and answers are processed to generate your response and are not used to train foundation models. The same applies to documents you upload. Amazon Bedrock does not use inputs or outputs to train its base models.
Your uploaded documents
Your documents are protected while they are sent to RafiHive and while they are kept for you. They are separated from every other team and personal workspace, and RafiHive checks that separation again whenever a document is listed, used in an answer or removed.
Keep a file inside one conversation, or deliberately make it available to your private team or personal knowledge.
A person outside your team cannot browse, search, attach or receive citations from your documents. Personal admin documents are visible only to that admin.
Your file is used only to provide the RafiHive features you selected. It is not advertising data and is not used to train foundation models.
The uploader can remove a document. RafiHive stops using it in answers immediately and completes removal from private storage and searchable knowledge.
The document can be used only in that conversation. It remains in My uploads until you remove it, but it cannot appear in another chat.
The document can support future chats in the private workspace you selected. It stays available until its uploader removes it.
Uploaded documents are never sent to optional web search, and private document locations are never shown in answers.
Your browser sends the file straight to EU storage over TLS with a signed link that expires in minutes. It is encrypted at rest on arrival.
The file type, declared size and content are checked before the file can be used, and the content must match what the browser declared. A file that fails is deleted from storage, not kept.
Keep a file inside one conversation, or deliberately make it available to your private team or personal knowledge.
The file is retrieved only to answer the questions you ask, alongside the official-source knowledge base, and findings cite what they came from.
The uploader can remove a document. RafiHive stops using it in answers immediately and completes removal from private storage and searchable knowledge.
Submitted questions, assistant answers, thread history and generated exports may be stored while your account is active so you can resume work and create audit-ready research trails. Export links are short-lived. Account deletion or export requests can be sent to info@rafihive.com; deletion is handled under the retention policy below and any signed customer agreement.
What RafiHive records today, per workspace and per user, so a research trail can be reconstructed and exported:
RafiHive is not presented as a validated GxP system. It does not provide electronic signatures, and it does not claim compliance with EU GMP Annex 11 or 21 CFR Part 11 unless that is established under a customer’s own validated implementation. Enterprise audit-log and export requirements are reviewed case by case — write to info@rafihive.com.
Retrieval is grounded in a reviewed knowledge base of official EU/EEA sources. Optional web search is off unless you switch it on for a conversation; its findings are labelled separately and are never treated as reviewed regulatory sources. Uploaded documents are never sent to web search, and confidential details are redacted from any query that leaves the trusted source set. Do not submit personal data you are not permitted to share.
Conversation history and account data are retained while your account is active, then deleted or anonymised within 90 days of account closure — except where longer retention is legally required (e.g. billing and tax records). In-app support requests stay in the EU with the rest of your data and are deleted 24 months after they are closed. See our Privacy Policy for details and your GDPR rights.
Amazon Web Services (hosting, AI, storage), Stripe (payments), LinkedIn (optional sign-in).
Team and enterprise evaluations can request a data-processing agreement, security FAQ, sub-processor summary, source coverage snapshot and AI governance statement. Contractual commitments should be confirmed in the signed customer agreement.
RafiHive is a decision-support tool, not a substitute for qualified regulatory-affairs professionals or legal advice. All outputs must be reviewed before use.