Trust & security
Public data, servers in Germany, clear rules. The rest is documentation.
Reyo reads the marketing signals of your competitors – newsletters, push, Meta ads, websites. All of it is public. Where that data lives, who can see it and on what basis we process it is written down here – precisely enough to forward to your compliance team.
- Hosting
- EU, data centers in Germany
- Data centers
- ISO 27001-certified operators
- Legal basis
- Legal opinion, public sources only
- Login
- SSO via OIDC (Enterprise)
Your data does not leave the EU.
Reyo runs on servers in Germany, in data centers whose operators are certified to ISO 27001. Reyo itself is not certified – we say that this plainly because you should hear it from us, not from a questionnaire.
The platform, the database and the analysis run in Germany. Reyo receives newsletters through its own addresses and reads push notifications with its own device infrastructure – nothing is fetched from your systems. Which additional service providers we use, for what purpose and where, is listed in the subprocessor list you can request at any time.
Deletion: when your contract ends, we delete your tenant data – your campaigns, users and settings – on request, subject to statutory retention periods. The observed market data is public and not attributed to you; it remains part of the data set.
- Servers and database in Germany, data centers with ISO 27001-certified operators
- Subprocessor list on request
- Deletion of your tenant data at the end of the contract
We read what anyone can read.
Reyo processes publicly accessible sources only. Whether that holds up legally is not something we decided ourselves – we had it reviewed by lawyers.
Newsletters that brands send to every subscriber. Push notifications from public apps. Ads from the Meta Ad Library. Promotions on public websites. None of it is confidential, none of it is tied to a person. Reyo does not access customer accounts, login areas or non-public systems.
A legal opinion covers our data collection and the use of AI on these sources. Two principles from it run through the product: we process public sources only, and we show you original sources instead of screenshots – every recommendation points to the email, the ad or the page it comes from.
Personal data arises at Reyo mainly where you and your team use the platform: user accounts, login, requests. The GDPR applies to that without exception; a data processing agreement is available on request. The observed marketing signals are brand communication, not customer data of your competitors.
Reyo uses AI to classify campaigns and to substantiate recommendations – not to make decisions about people. We have mapped our AI use against the EU AI Act: recommendations are labelled as such, come with evidence and are approved by your team, never executed automatically.
- Public sources only: newsletters, push, Meta Ad Library, websites
- Legal opinion on data collection and AI use
- Original sources instead of screenshots in every recommendation
- GDPR: data processing agreement on request
- EU AI Act: recommendations with evidence, approved by people
Every brand sees only its own data.
Reyo is multi-tenant. The separation happens in the database, not in the interface.
Every customer – and every brand in a multi-brand setup – is its own tenant. Row-level security in the database ensures that a query only returns the rows that belong to the tenant of the signed-in user. The separation does not depend on the interface.
Within a tenant you assign roles: who configures competitors, who plans and approves campaigns, who only reads. Colleagues with your company domain can join the right tenant automatically if you want – no rounds of invitations.
Enterprise customers sign in with single sign-on via OIDC – for example with Microsoft Entra ID. Your identity provider then controls who has access and when it ends.
- One tenant per customer or brand
- Row-level security at database level
- Roles with graded permissions
- Auto-join via company domain (optional)
- SSO via OIDC, e.g. Microsoft Entra ID (Enterprise)
Enterprise
For teams where IT and procurement have a say.
The Enterprise plan bundles what larger organisations need before a tool gets approved.
Several brands in separate tenants, SSO through your identity provider, a dedicated account manager and a guaranteed response time of 24 hours. Terms are individual – we talk about your requirements before, not after.
- Multi-brand: separate tenants under one contract
- SSO via OIDC (e.g. Microsoft Entra ID)
- Dedicated account manager
- 24-hour response time (SLA)
- Up to 50 competitors, predictions includedBeta
For vendor assessments
Your compliance team’s questions – we have answered them before.
Reyo has been through the vendor assessment of an enterprise retailer. These documents are available on request.
- 01
Subprocessor list
Every service provider that processes data to run Reyo, with purpose and location.
- 02
Data processing agreement (DPA)
Under Art. 28 GDPR, covering the personal data of your team on the platform.
- 03
Technical and organisational measures
Description of hosting, encryption, access control and the deletion concept.
- 04
Data center evidence
The ISO 27001 certificate of the data center operator. Not a Reyo certificate – there is none, and we do not claim one.
- 05
Summary of the legal opinion
The key findings of the legal review of data collection and AI use.
- 06
Security questionnaires
We answer your questionnaire in your format.
Tell us which documents you need and at which stage of the review you are – then we send what fits, not everything.
Request documentsA question that is not answered here? Ask.
For security and privacy questions you reach us directly, without a ticket system. Reports of security vulnerabilities go to the same address.
Security and privacy questions
hello@reyo.aiSee Reyo with your real competitors.
30 minutes, your competitor set, one evidenced recommendation to take away. And if your IT has questions first: send them along.