Data security is our top priority.

Built in Europe, fynk's contract lifecycle management software is GDPR compliant by design. We constantly review and update all technical and organizational measures that protect your data. Best-in-class support can provide assistance whenever needed.

Data security is our top priority.

More than 3.000 teams chose fynk to outgrow legal chaos.

Built in Europe.
Secured by design.

fynk meets the highest standards for data protection, infrastructure security, and regulatory compliance. And that includes our AI, which plays by the same rules as everything else.

  • AI Assistant with data residency

    AI Assistant with data residency

    The fynk AI assistant is part of fynk itself. To ask a question about a contract, you don’t copy anything into another tool. The document stays where it is, under the same GDPR, server-location, and ISO 27001 guarantees as everything else you store with us. All AI processing happens within the European Economic Area, covered by our data processing agreements, and your data is never used to train AI models.

    You can also connect your own AI tools to fynk via MCP. That is great for working across systems, but it does mean contract data travels to your AI provider and is handled under their terms. For sensitive agreements, the built-in assistant is the safer path: everything stays in fynk.

    What that means for you: AI can read, search, and act on your contracts while the data stays exactly where it already is. Use the assistant for sensitive work, and MCP when your workflows need to reach other tools.

    Learn more
  • The AI providers behind fynk

    The AI providers behind fynk

    fynk does not train its own models. The assistant runs on established model providers, currently Microsoft Azure OpenAI Service and Mistral AI.

    Both operate under our data processing agreements, processing happens within the European Economic Area, and your data is never used to train AI models. Model providers appear in the same published subprocessor list as our hosting and e-signature partners, so you can check who is involved as the stack changes.

    What that means for you: you can see exactly which companies are involved in processing your contract data, and under which terms, without having to ask.

    See our subprocessors
  • ISO 27001 Certified

    ISO 27001 Certified

    fynk is ISO 27001 certified for its Information Security Management System (ISMS). Certified by DQS, accredited by the German Accreditation Body (DAkkS), our processes meet strict international standards for keeping information safe. Our company’s security management highlights our commitment to protecting your data and supporting GDPR compliance.
    Learn more
  • Secure infrastructure

    Secure infrastructure

    fynk’s contract lifecycle management software was developed in Europe and is GDPR compliant from the ground up. We use services from Amazon Web Services (AWS) as a hosting provider, among others. All contract data is stored on ISO/IEC 27001-certified servers within the European Economic Area. The server infrastructure meets our high standards for physical data security.
    Learn more
  • Availability & backup

    Availability & backup

    We continuously monitor uptime to be prepared for potential issues. fynk performs regular full backups to external servers to prevent data loss. Customer data is always transmitted over a secure communication channel and encrypted accordingly.

    What that means for you: We guarantee 99.5% availability of fynk on an annual average. This does not include times when the server cannot be reached due to technical problems beyond fynk’s control (in particular force majeure and fault of third parties) or planned maintenance work.

    Learn more
  • Data protection & GDPR

    Data protection & GDPR

    fynk complies with all relevant data protection regulations, in particular the requirements of the EU General Data Protection Regulation (GDPR), and thus meets the highest standards for data protection and data security. All technical and organizational measures to ensure the security of data processing are subject to continuous review and regular updates.

    What that means for you: fynk consistently follows the requirements of ISO/IEC 27001. To ensure security in all processing procedures and internal operations, we regularly train our employees and have appointed an external data protection officer.

    Learn more
  • Access to data

    Access to data

    All customer data can only be read after proper authentication at the respective database system. Legally, our customers remain the sole owners of all their data and the controller in terms of Art. 24 EU-GDPR. fynk never sells customer data or shares it with third parties for their own purposes. Where subprocessors help provide the service, they work under strict data processing agreements. You can review the DPA and the full list of subprocessors in our legal terms at any time.

    What that means for you: Only authorized and trained employees have event-related access to your fynk account. This is necessary to support the initial setup and the processing of service requests.

    Learn more

Frequently asked questions

  • Yes. fynk was built in Europe and is GDPR compliant by design. We comply with all requirements of the EU General Data Protection Regulation and continuously review our technical and organizational measures to ensure the highest standards for data protection.

  • All contract data is stored on ISO/IEC 27001-certified servers within the European Economic Area (EEA). We use Amazon Web Services (AWS) as our hosting provider and our server infrastructure meets the highest standards for physical data security.

  • fynk is ISO 27001 certified for its Information Security Management System (ISMS). The certification was issued by DQS and is accredited by the German Accreditation Body (DAkkS), ensuring our processes meet strict international standards.

  • You remain the sole owner of all your data and the controller in terms of Art. 24 EU-GDPR. Only authorized and trained fynk employees have event-related access to your account to support initial setup and service requests. fynk never sells your data or shares it with third parties for their own purposes. Where subprocessors help provide the service, they work under strict data processing agreements, and the full list is published in our legal terms.

  • Within the European Economic Area. The assistant is part of fynk, so contracts you ask about stay under the same GDPR, server-location, and ISO 27001 guarantees as the rest of the platform. AI processing is covered by our data processing agreements, and your data is never used to train AI models.

  • Both are supported, they just serve different needs. MCP connects fynk to your own AI agent, which can then work across fynk and all your other tools at once. Contract data travels to that agent and is handled under its vendor's terms. The built-in assistant keeps all processing inside fynk with EU data residency, so it is the better choice for sensitive agreements.

  • We guarantee 99.5% availability of fynk on an annual average. We continuously monitor uptime and perform regular full backups to external servers. All customer data is transmitted over secure, encrypted communication channels.

Still have questions?

Your data deserves the best protection.

Start managing contracts with a platform built for European security standards.

Try fynk free