Security privacy and data protection
Administration ›Security & privacy
April 7, 2026Updated: April 7, 20265 min read
How Theka protects business data and ensures GDPR compliance
Security and privacy
Data isolation
Each tenant has its own separate PostgreSQL schema. One company's data is never accessible by another, not even at the database level.
Data ownership
Your data is yours:
- Files → stored in your S3 bucket (your credentials)
- AI analysis → through your API keys (your costs)
- Database → isolated schema, exportable at any time
Theka does not own, access or use your documents or data for any purpose.
Encryption
- In transit — HTTPS/TLS on all communications
- Credentials — encrypted with Fernet (AES-128-CBC) in the database
- At rest — depends on your S3 storage configuration
Audit log
Every action on documents is tracked:
- Who viewed, downloaded, edited, shared
- When and from which IP
- Complete non-modifiable history
GDPR compliance
- ✅ Privacy by design and by default
- ✅ Per-tenant data isolation
- ✅ Right to erasure: ability to delete all tenant data
- ✅ Portability: complete data export
- ✅ Complete audit trail
- ✅ Sensitive credential encryption
📋 For full details, see our Privacy Policy and Terms of Service, accessible from the platform's legal section.