Skip to content
← Back to guides

Security privacy and data protection

Administration ›Security & privacy
April 7, 2026Updated: April 7, 20265 min read
How Theka protects business data and ensures GDPR compliance

Security and privacy

Data isolation

Each tenant has its own separate PostgreSQL schema. One company's data is never accessible by another, not even at the database level.

Data ownership

Your data is yours:

  • Files → stored in your S3 bucket (your credentials)
  • AI analysis → through your API keys (your costs)
  • Database → isolated schema, exportable at any time

Theka does not own, access or use your documents or data for any purpose.

Encryption

  • In transit — HTTPS/TLS on all communications
  • Credentials — encrypted with Fernet (AES-128-CBC) in the database
  • At rest — depends on your S3 storage configuration

Audit log

Every action on documents is tracked:

  • Who viewed, downloaded, edited, shared
  • When and from which IP
  • Complete non-modifiable history

GDPR compliance

  • ✅ Privacy by design and by default
  • ✅ Per-tenant data isolation
  • ✅ Right to erasure: ability to delete all tenant data
  • ✅ Portability: complete data export
  • ✅ Complete audit trail
  • ✅ Sensitive credential encryption

📋 For full details, see our Privacy Policy and Terms of Service, accessible from the platform's legal section.