Privacy at Trooper.AI covers two areas:
Do you offer a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR? Yes. On monthly plans, the DPA can be concluded online in just a few clicks. The full DPA is available for review within the online process before signing.
Is the DPA individually negotiable? Generally no. We provide one uniform standard bilingual (DE/EN) DPA for all customers. Individual amendments or side agreements are not available on standard plans. For extended requirements, see https://www.trooper.ai/enterprise
Is there a list of sub-processors? Yes, it is part of the DPA.
I want to use or recommend Trooper.AI servers for my own end customers – how does that work contractually? This creates a processing chain: you act as processor for your customers, and we act as sub-processor. The rules on sub-processing are set out in the DPA. Please note that your clients are not a party to the DPA between your company and us.
Where are the servers located, and who operates them? Exclusively within the EU (Germany, Netherlands, France). The provider is Media Trooper GmbH – a German limited liability company with a German owner and no US affiliation (no Cloud Act exposure).
Can I choose Germany as my server location? Yes. The location is part of your GPU Blib order – please make sure to select the correct Blib upfront.
Are the GPU servers dedicated or shared? GPU, CPU, and RAM are dedicated bare-metal – no vGPU sharing. You have full root access. Details: https://www.trooper.ai/docs/blibs
Are there certifications (ISO 27001 or similar)? Information on data center certifications is provided as part of the DPA and shown on the order page. For extended compliance requirements, see https://www.trooper.ai/enterprise
A general note on encryption: The DPA is the legal foundation that keeps the operation of your GPU server compliant and smooth. Encryption is available, but it can affect performance and overall experience. In many industries, encryption at rest is not legally required – so please consider carefully whether you actually need it.
Is encryption at rest possible? Yes – with full root access, you implement it yourself (e.g., LUKS). In a self-service product with dedicated root access, encryption, access management, and patch management at the operating system level are your responsibility by design. You can work with an encrypted container or a separate second partition (select at order).
Is processing “RAM only” possible? Yes. You have root-level access on your GPU Blib, so you are free to keep all processing in memory and store nothing on disk if you prefer.
Where can I find your TOMs? The TOM documentation is part of the DPA.
What data do you log about our instance? Only the minimum required for security and operations. Details: DPA and this Privacy Policy – we do not access your content.
Do instance, data, and ports persist across reboots? Yes. Port changes only occur on Freeze, Reset, or Migration.
Notice periods, SLA, billing? Bindingly governed by our Terms (https://www.trooper.ai/terms ), SLA options at https://www.trooper.ai/enterprise , billing at https://www.trooper.ai/docs/blibs/payment
The controller under the GDPR is:
Media Trooper GmbH
Am Güterbahnhof 4
65510 Idstein, Germany
📧 [email protected]
Data Protection Officer: Susann Bach
This part applies to:
Service-specific information applies in addition where provided. Customer workloads on GPU servers are also governed by Part 1 and, where applicable, the Data Processing Agreement (DPA).
Customers generally determine the purposes and means of processing personal data within our services and remain responsible for the legal basis, transparency obligations, and data-subject rights.
Where Media Trooper GmbH processes data on a customer’s behalf, we act as processor or sub-processor under the DPA and the customer’s documented instructions. We process customer workload data only to provide and secure the service, comply with the contract and DPA, or meet legal obligations.
Depending on your use of our services, we process:
Mandatory data must be provided where required to create an account, place an order, process payment, or deliver a requested service.
Strictly necessary cookies and similar technologies are used without consent under § 25(2) TDDDG. Non-essential analytics, marketing, or external-content technologies are activated only after consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR.
Consent can be withdrawn at any time through the consent settings. The current provider, purpose, and storage-duration details are maintained there.
We use providers for hosting and data-center operations, email, security, payments, customer support, consent management, analytics, marketing, and platform functionality. Processors are contractually bound under Art. 28 GDPR.
Depending on the service and consent, this may include Google Analytics, Meta/Facebook Pixel or SDK, Google Maps, Snazzy Maps, externally loaded Google Fonts, HubSpot, and Google reCAPTCHA. Non-essential services are activated only after consent. Necessary contractual or security services are based on Art. 6(1)(b) or (f) GDPR and the applicable requirements of § 25 TDDDG.
Our primary website and platform infrastructure is operated within the EU/EEA. Third-country processing is governed by Section 7.
We retain data only as long as required for the relevant purpose or by law. Website and security logs are kept only as needed for operation, troubleshooting, and abuse prevention. Account, contract, payment, and business correspondence data may be retained for statutory retention and limitation periods. Support data is retained until completion and afterwards only where required for documentation or legal claims. Consent records are retained as needed to demonstrate consent. Platform backups are generally overwritten after up to 10 days.
When the Trooper AI Scan App is used, visual data and related input may be processed through our Trooper Cloud and selected providers solely to provide the requested analysis or connected functionality.
The app may store data locally and, if configured by the customer, synchronise encrypted records with a connected CRM system. The customer is responsible for the lawful configuration and use of that CRM. Where we process data on behalf of a customer, the DPA and the customer’s documented instructions apply.
Personal data is not transferred outside the EU in general. Personal data is transferred outside the EU/EEA only under Art. 44 et seq. GDPR, for example on the basis of an adequacy decision, including the EU–U.S. Data Privacy Framework for certified U.S. recipients, or EU Standard Contractual Clauses with supplementary safeguards where required.
Information about the applicable transfer mechanism is available through the consent settings or from [email protected].
We apply appropriate technical and organisational measures under Art. 32 GDPR, including where appropriate encrypted transmission, access controls, authentication, logging, backup, and recovery measures. These measures are reviewed according to the nature and risks of the processing.
Third parties are responsible for data processing after you follow a link to an external website.
Removed.
For contact, support, and download forms, we process the information entered and technical submission data. The legal basis is Art. 6(1)(b) GDPR for contractual or pre-contractual requests and Art. 6(1)(f) GDPR for general enquiries, customer service, documentation, and abuse prevention. Marketing communication is sent only where legally permitted or based on consent.
Applicant data is processed for recruitment under Art. 6(1)(b) GDPR in conjunction with § 26 BDSG. Unsuccessful applications are generally deleted within six months after the process ends, unless longer storage is required for legal claims or separately consented to for a talent pool.
You may contact [email protected] to exercise your rights, including:
The competent supervisory authority is:
The Hessian Commissioner for Data Protection and Freedom of Information (HBDI)
Wilhelmstraße 7
65185 Wiesbaden, Germany
https://datenschutz.hessen.de
Personal data is deleted or anonymised when its purpose no longer applies and no contractual, statutory, security-related, or legal reason requires continued storage. Section 5 and, for customer workloads, the applicable service terms and DPA apply.
We may update this Privacy Policy where required by legal, technical, or operational changes. The current version is published on this page.
Last revised: Feb. 2026