Security and privacy

How we handle your data: honest, verifiable, without marketing language.

Where your data lives

We're transparent about where your data is. Some services run outside the EU. We're actively exploring EU alternatives for these services.

CCDC application hosting

EU 🇪🇺 (ISO 27001 certified)

All transaction data, documents, user accounts

Document analysis

Anthropic Claude API, United States

Temporary document processing for field extraction. Anthropic retains data for up to 7 days.

Email delivery

SendGrid (Twilio), likely United States, actively exploring EU alternative

Transactional emails (magic links, invitations, status updates)

DNS and CDN

Cloudflare, global edge network

HTTP traffic routing, DDoS protection (routing data only)

Technical security

Encryption in transit

HTTPS (TLS 1.3) on every connection. No connection without encryption.

Encryption at rest

Documents are stored encrypted on European servers. AES-256.

Role-based access

Each party only sees what belongs to their role. The selling agent does not see the buyer's documents.

Audit trail

Every action is logged: who, what, when. Available for audit purposes.

Cookies

This site uses one cookie: NEXT_LOCALE. It remembers your language choice so you return in the right language. The cookie only contains the text 'nl', 'en' or 'es'. This cookie is functional (remembering language preference) and falls under the GDPR exception that does not require explicit consent.

We use no tracking cookies. No Google Analytics, no Facebook Pixel, no marketing cookies. If we add any in the future, we'll tell you first and ask explicit consent.

What we don't have yet

We're honest about our maturity. This is what's on our roadmap for the coming months:

  • ISO 27001 certification for CCDC (our hosting provider is certified, CCDC as a company is not yet)
  • GDPR Data Processing Agreement available for customers
  • External penetration test
  • Migration from Anthropic API to European inference route (AWS Bedrock Frankfurt) for guaranteed EU data residency
  • SOC 2 Type II audit

For pilot customers we're available daily for security questions.

Questions about your data?

Email privacy@ccdc.es.

Email privacy@ccdc.es