RafiHive

Trust

Data handling & security

RafiHive is built for a regulated audience, so where your data lives and how it is used is a first-class concern. This page summarises our current posture.

EU processing, GDPR

Operated from Germany under the GDPR. Application data (accounts, conversation history, generated exports) is stored and processed in the EU (AWS eu-west-1, Ireland).

No model training

Questions and answers are processed to generate your response and are not used to train foundation models. The same applies to documents you upload.

Encrypted and workspace-isolated

Encryption in transit (TLS) and at rest, and a person outside your team cannot browse, search, attach or receive citations from your documents.

Delete anytime

The uploader can remove a document. RafiHive stops using it in answers immediately and completes removal from private storage and searchable knowledge.

EU data residency

Operated from Germany under the GDPR. Application data (accounts, conversation history, generated exports) is stored and processed in the EU (AWS eu-west-1, Ireland). AI responses are generated by Amazon Bedrock in an EU region. We do not move regulated content to non-EU regions.

GDPR and German jurisdiction

RafiHive is operated from Germany. Personal data is processed under the GDPR: the legal basis for each processing purpose, the processors we use, retention periods and your rights as a data subject are set out in the privacy policy. The terms of service are governed by German law. Hosting, storage and AI inference stay inside the EU; RafiHive holds no data in non-EU regions.

Your data is not used to train models

Questions and answers are processed to generate your response and are not used to train foundation models. The same applies to documents you upload. Amazon Bedrock does not use inputs or outputs to train its base models.

Your uploaded documents

Private documents stay in the workspace you choose.

Your documents are protected while they are sent to RafiHive and while they are kept for you. They are separated from every other team and personal workspace, and RafiHive checks that separation again whenever a document is listed, used in an answer or removed.

You choose where it can be used

Keep a file inside one conversation, or deliberately make it available to your private team or personal knowledge.

Other workspaces cannot see it

A person outside your team cannot browse, search, attach or receive citations from your documents. Personal admin documents are visible only to that admin.

It is used to answer, not to train

Your file is used only to provide the RafiHive features you selected. It is not advertising data and is not used to train foundation models.

You remain in control

The uploader can remove a document. RafiHive stops using it in answers immediately and completes removal from private storage and searchable knowledge.

This chat only

The document can be used only in that conversation. It remains in My uploads until you remove it, but it cannot appear in another chat.

Personal or team knowledge

The document can support future chats in the private workspace you selected. It stays available until its uploader removes it.

Uploaded documents are never sent to optional web search, and private document locations are never shown in answers.

What happens to an uploaded document

  1. 01Encrypted upload

    Your browser sends the file straight to EU storage over TLS with a signed link that expires in minutes. It is encrypted at rest on arrival.

  2. 02Validation

    The file type, declared size and content are checked before the file can be used, and the content must match what the browser declared. A file that fails is deleted from storage, not kept.

  3. 03You choose where it can be used

    Keep a file inside one conversation, or deliberately make it available to your private team or personal knowledge.

  4. 04Used to answer, with citations

    The file is retrieved only to answer the questions you ask, alongside the official-source knowledge base, and findings cite what they came from.

  5. 05You delete it

    The uploader can remove a document. RafiHive stops using it in answers immediately and completes removal from private storage and searchable knowledge.

What does not happen
  • Your documents are not used to train foundation models — not ours, not the model provider's.
  • Your documents are never sent to the optional web search, and private document locations are never shown in answers.
  • Your documents are not moved outside the EU (AWS eu-west-1).
  • Your documents are not visible to another customer, another team, or a team member you did not share them with.
  • Nothing is uploaded at all unless you attach it — the gap check runs from a questionnaire if you prefer.

Confidentiality, storage, deletion & export

Submitted questions, assistant answers, thread history and generated exports may be stored while your account is active so you can resume work and create audit-ready research trails. Export links are short-lived. Account deletion or export requests can be sent to info@rafihive.com; deletion is handled under the retention policy below and any signed customer agreement.

Auditability and records

What RafiHive records today, per workspace and per user, so a research trail can be reconstructed and exported:

  • The question asked, the answer returned and the thread it belongs to, with timestamps.
  • The sources cited for each answer, including their authority and version status.
  • References to the uploaded documents an answer used, within the workspace that holds them.
  • The workspace and user account an item belongs to.
  • Exports of answers and check results as DOCX, XLSX, CSV, Markdown or HTML.
  • Document removal, and deletion or anonymisation of remaining service data after account closure.

RafiHive is not presented as a validated GxP system. It does not provide electronic signatures, and it does not claim compliance with EU GMP Annex 11 or 21 CFR Part 11 unless that is established under a customer’s own validated implementation. Enterprise audit-log and export requirements are reviewed case by case — write to info@rafihive.com.

Confidential queries & web fallback

Retrieval is grounded in a reviewed knowledge base of official EU/EEA sources. Optional web search is off unless you switch it on for a conversation; its findings are labelled separately and are never treated as reviewed regulatory sources. Uploaded documents are never sent to web search, and confidential details are redacted from any query that leaves the trusted source set. Do not submit personal data you are not permitted to share.

Encryption & access

  • Encryption in transit (TLS) and at rest (server-side encryption on S3 and DynamoDB).
  • Authentication via AWS Cognito; admin functions are role-gated at the API layer.
  • Exports are delivered as short-lived, pre-signed URLs.
  • A web application firewall (WAF) and rate limiting protect the public endpoints.

Retention

Conversation history and account data are retained while your account is active, then deleted or anonymised within 90 days of account closure — except where longer retention is legally required (e.g. billing and tax records). In-app support requests stay in the EU with the rest of your data and are deleted 24 months after they are closed. See our Privacy Policy for details and your GDPR rights.

Sub-processors

Amazon Web Services (hosting, AI, storage), Stripe (payments), LinkedIn (optional sign-in).

DPA & procurement review

Team and enterprise evaluations can request a data-processing agreement, security FAQ, sub-processor summary, source coverage snapshot and AI governance statement. Contractual commitments should be confirmed in the signed customer agreement.