Tech stack
What we work with — and why.
We know every tool from our own operations, not from a brochure. Here we disclose what we work with: data location, legal status and the reason for every tool — to your benefit and ours. We build with what we recommend, and we watch the tool landscape continuously.
In short — even if you have no IT department
- 1You operate none of these tools yourself. What runs in your project is operated by us or by the provider — or it sits on your hardware, if that is what you want.
- 2Your data is touched only by the 14 tools in the first table below — 13 of them with a data processing agreement or on our own hardware, for one the agreement is available on request (Bitwarden, contents end-to-end encrypted). In the project contract this becomes your list of sub-processors.
- 3For questions you reach Florian Großschmidt directly; data protection questions go to datenschutz@xaiteck.ai — no ticket system, no queue.
Five principles we select by.
Germany first, then Europe, then beyond
Every tool carries a data-location marker. Outside the EU only with a data processing agreement and transfer mechanism — or without customer data altogether.
Legally clean and documented
Data processing agreement per provider, transfer mechanism, record of processing activities. Every card states location and contract status.
GDPR and EU AI Act as guardrails
Data minimisation, transparency at the point of input, documentation. An internal guardian reviews questions of principle before we build.
Guardrails
A human approves every external effect, separate accounts for customer data, tenant separation, automatic security routines.
Every provider remains replaceable
No lock-in, open source where sensible, knowledge and data in our own files. Switching providers is a configuration step, not a project.
In numbers — from your point of view.
14
tools may touch your data in a project
13
of those with a data processing agreement or on our own hardware
6
tools run on our own hardware
27
tools in use in total
9
integrations at the AI workplace
Calculated from our tool inventory, as of August 2026. Markers and tables state the location of the main processing (database, server functions); exceptions such as backups, logs or worldwide delivery of static content are noted where they apply.
How we choose tools — five questions.
How sensitive is the data?
Personal, confidential, public? Everything else depends on this.
Where does it reside?
Germany, the EU or beyond — and where is the provider based?
DPA and transfer mechanism?
Data processing agreement, standard contractual clauses, certification, training excluded?
How do we get out again?
Export, open formats, exit effort. No tool without an exit.
Who operates it, and what does it cost?
Maintainability and running costs in two years — not just today.
Architecture and data location at a glance.
Three layers, three zones. Where a tool sits tells you where processing happens.
Layer 3
Workplace & processes
On our own hardware
In the EU
Outside the EU — with a DPA and only what is necessary, or without customer data altogether
Layer 2
Build & operate
On our own hardware
In the EU
Outside the EU — with a DPA and only what is necessary, or without customer data altogether
Layer 1
Models
On our own hardware
In the EU
—
Outside the EU — with a DPA and only what is necessary, or without customer data altogether
may touch your data
Layer 1
Models
The main model, second models for comparison, local models for sensitive content, image models for our own imagery.
Language model · Primary model
Claude (Anthropic)
Primary model for analysis, text and code — in Claude Code, Cowork and via the API on our own sites.
Open models · local
Ollama (local)
Open models (such as Gemma, Qwen, Llama) directly on our own machine, loaded as needed — for sensitive content, testing and offline operation.
Secondary model · Support role
OpenAI (Codex, gpt-image)
Second model as an automated helper for pure build tasks, plus an image model for our avatars — without customer data.
Speech · local
Whisper & Kokoro (local)
Speech recognition (Whisper) and speech output (Kokoro) on our own machine — transcription of recordings and voice mode.
Answer engine · Comparison
Google Gemini (API)
Answer engine that we query via the API to measure how AI search portrays a company — no personal data.
Answer engine · Comparison
Perplexity (API)
AI search engine that we query via the API to measure visibility in AI answers — no personal data.
Image & video model
Higgsfield
Image and video generation for our own visual world (avatars, motifs for posts) — without personal data of third parties.
Image model
Ideogram
Image generation via the API, strong on typography — for graphics without any personal reference.
Image model
Flux (Black Forest Labs)
Image generation via the API (Flux) for photorealistic motifs without any personal reference — a provider from Freiburg.
Layer 2
Build & operate
What we build, host and test customer software with.
Content management
Sanity
Editorial system for client websites — maintain content without a developer, with live preview.
Transactional email
Mailjet
Sending contact form and system emails for client websites — our standard.
Hosting
Vercel
Hosting for all websites; server functions in Frankfurt, delivery via a worldwide network.
Database
Supabase
PostgreSQL database with an API and access rules for our own applications and client software.
Small server functions
Cloudflare
Small server functions for internal processes, distributed across the provider's worldwide network.
Containers · self-hosted
Docker (local)
Self-hosted services (CRM, invoicing) in containers on our own hardware.
Document database
MongoDB Atlas
Document database (Atlas) for archives and analyses, cluster in Frankfurt.
Source code
GitHub
Source code management in private repositories; in the client's own repository on request.
Web stack · Open source
Next.js / React / TypeScript / Tailwind
Our web stack for websites and applications — open, widely used building blocks.
Testing & acceptance
Playwright
Automated tests and acceptance of websites in a real browser.
Layer 3
Workplace & processes
What we operate ourselves every day — and therefore know from our own experience.
AI workplace
Claude Code & Cowork
Our workplace: a team of agents with defined roles (see AI Team) and connections to the tools we work with every day.
Tasks & knowledge
Notion
Data layer of our internal command centre STELLA — tasks, ideas, follow-ups.
Idea inbox
Trello
Inbox for ideas and voice notes, editorial planning.
Email & office
Google Workspace
Business email, calendar, documents and file storage for xaiteck.ai.
CRM · In-house development
Rainmaker
Our own CRM extension inside the mailbox — contacts, pipeline and history where the conversations happen.
Invoicing · Open source
InvoiceShelf
Writing invoices, self-hosted.
Password manager
Bitwarden
Managing credentials in encrypted form — vault on EU servers, end-to-end encrypted.
Design
Canva
Templates, graphics and document styling; via a connection directly from our workplace.
Your systems we work with.
We integrate into what you have instead of building parallel worlds.
Starter stack for mid-sized businesses — who operates what
AI workplace with a data processing agreement
Operation: the provider · setup and rules: us
EU-hosted form and email tool
Operation: the provider
CRM, self-hosted
on your hardware or in an EU data centre · operation: you or us, as agreed
Automation with a self-hosted tool (for example n8n)
Operation as for the CRM
Setup as a fixed price after an initial conversation; running provider costs are itemised in the offer. Each building block can be removed again individually.
Example: a data-location decision
Contact forms on customer websites. Two providers were on the table: a US service, technically pleasant, with a data processing agreement — but without processing in the EU. And a French service that assures processing in EU data centres. Because customers may expect EU processing from us, Mailjet is our standard. Convenience does not decide, data location does.
Tested, not adopted — and why.
Mistral (Vibe)
European build assistant, trialled in 2026 — subscription ended. Not stable enough for our workflow in unsupervised operation; from a data protection perspective the strongest provider on this list (EU legal entity, EU hosting) and our first choice as soon as the purpose fits.
Resend
Tested for contact forms — not chosen for projects that require an EU guarantee. Technically pleasant and with a data processing agreement — but the data location decides, not the convenience.
Tracking tools of any kind
No cookies, no analytics pixels — on our pages and by default on the pages we build.
On our radar — what we are watching.
Our agent Daita reviews new models, tools and security reports every day. A selection, renewed monthly, with an assessment for mid-sized businesses.
Skills, files and browser control available via the API
Anthropic has made the Skills API, Files API and Browser Use generally available. A work instruction that today runs only on our machine thus becomes a building block that can run inside your solution. We are testing an existing skill via the API.
New Flash model at Google generally available
Gemini 3.7 Flash is available. For mid-sized businesses this changes little; for us it is a candidate for the next model comparison in visibility measurement.
New attack technique via tool integrations
Security researchers show how instructions are spread across several channels of a tool integration and reassembled by the agent (laboratory tests). This is exactly why our agents treat tool outputs as data, never as instructions, and a human approves every external effect.
Open 30-billion-parameter model that runs locally
A new agent model licensed under Apache 2.0 runs on a notebook with Apple Silicon. A serious candidate for document analysis that must not leave the building — slower and weaker than large cloud models, often sufficient for clearly defined tasks. We are testing it with real documents.
Processing in a named region and a cost cap per session
Anthropic adds the choice of inference region and hard session budgets for managed agents. For projects under a data processing agreement the region is the precondition, the budget makes fixed prices calculable. We are checking whether a European region is included — we do not promise it before that.
What this means for you.
We choose by data protection and maintainability, not by fashion. Every provider remains replaceable, and we ourselves build so that others could take over. Whatever touches your data is listed here with location, contract and retention.
Frequently asked questions
Questions we are actually asked about this.
Provider list to pass on.
Two tables, also as a PDF without a form. The first is the one your data protection, IT and procurement need.
A · Tools that may touch your data in a project (14)
| Provider | Purpose | Data categories | Processing location | Retention | DPA · transfer · evidence |
|---|---|---|---|---|---|
| Claude (Anthropic) USA (contracting party for the EU: Anthropic Ireland) | Primary model for analysis, text and code — in Claude Code, Cowork and via the API on our own sites. | Task texts, document extracts, code — only via accounts with a DPA | outside the EU Processing in the USA, Europe, Asia, Australia (routing), storage in the USA; no EU data residency selectable | 30 days at the provider, then deleted | DPA in place · EU Standard Contractual Clauses Part of the Commercial Terms (client-data accounts and API); the development account without a DPA never sees customer data |
| Ollama (local) — | Open models (such as Gemma, Qwen, Llama) directly on our own machine, loaded as needed — for sensitive content, testing and offline operation. | sensitive content, documents — never leave the machine | on our own hardware local on the Mac (Ollama Cloud not used) | local, deleted after processing | DPA not required |
| Whisper & Kokoro (local) — | Speech recognition (Whisper) and speech output (Kokoro) on our own machine — transcription of recordings and voice mode. | Recordings of conversations and transcripts — only with consent, never leave the machine | on our own hardware local on the Mac | local, deleted after processing | DPA not required |
| Sanity Norway (Sanity AS) | Editorial system for client websites — maintain content without a developer, with live preview. | Website content for your project (texts, images) | EU EU region Belgium (Google Cloud), secondary location USA; we do not use the AI add-on features that involve US sub-processors | until you delete it | DPA in place · EU Standard Contractual Clauses SOC 2 Typ 2 Part of the terms of service |
| Mailjet France (Mailjet SAS, Sinch group) | Sending contact form and system emails for client websites — our standard. | Contact form data from your website visitors (name, email, message) | EU EU data centres (provider statement, country not specified) | delivery logs at the provider according to its policy; we store nothing in addition | DPA in place · EU Standard Contractual Clauses + Data Privacy Framework ISO 27001 (Anbieterangabe: zusätzlich SOC 2, PCI DSS) Part of the service agreement (Sinch DPA) |
| Vercel USA | Hosting for all websites; server functions in Frankfurt, delivery via a worldwide network. | Website requests (server logs, IP address), form data in server functions | EU Frankfurt (fra1) for server functions; static delivery via 126 locations worldwide | Logs kept at the provider for a few days | DPA in place · EU Standard Contractual Clauses + Data Privacy Framework SOC 2 Typ 2, ISO 27001, TISAX AL2 Part of the terms of service; DPF-certified |
| Supabase Singapore (Supabase Pte. Ltd.) | PostgreSQL database with an API and access rules for our own applications and client software. | Application data for your project (database) | EU Frankfurt (AWS eu-central-1); backups, logs and add-on functions may reside outside | until you delete it; backups according to the provider's schedule | DPA in place · EU Standard Contractual Clauses SOC 2 Typ 2, ISO 27001 Part of the terms of service |
| MongoDB Atlas USA (MongoDB, Inc.) | Document database (Atlas) for archives and analyses, cluster in Frankfurt. | Archive and analysis data for your project | EU Frankfurt (AWS eu-central-1) | until you delete it | DPA in place · EU Standard Contractual Clauses + Data Privacy Framework Part of the cloud terms of service |
| GitHub USA (GitHub, Inc., Microsoft) | Source code management in private repositories; in the client's own repository on request. | Source code for your project — no personal data, no live data | outside the EU USA | until handover to your repository or deletion | DPA in place · EU Standard Contractual Clauses + Data Privacy Framework Data Protection Agreement, part of the customer agreement |
| Claude Code & Cowork USA (contracting party for the EU: Anthropic Ireland) | Our workplace: a team of agents with defined roles (see AI Team) and connections to the tools we work with every day. | Project documents and task texts — only via accounts with a DPA | outside the EU USA (Anthropic), routing also Europe/Asia/Australia | 30 days at the provider, then deleted | DPA in place · EU Standard Contractual Clauses Part of the Commercial Terms for the client-data accounts |
| Google Workspace USA (contracting party for the EU: Google Ireland) | Business email, calendar, documents and file storage for xaiteck.ai. | Your email correspondence with us, appointments, shared documents | outside the EU worldwide data centre network; data region ‘Europe' can be set for data at rest | until deletion / end of contract | DPA in place · EU Standard Contractual Clauses + Data Privacy Framework ISO 27001/27017/27018, SOC 2/3 (Google Cloud) Cloud Data Processing Addendum, part of the terms of service |
| Rainmaker our own software (database: Supabase) | Our own CRM extension inside the mailbox — contacts, pipeline and history where the conversations happen. | Contact details of your contact persons, conversation history | EU Frankfurt (AWS eu-central-1) | until deletion / immediately on request | DPA in place · EU Standard Contractual Clauses via Supabase (part of the terms of service) |
| InvoiceShelf Open source | Writing invoices, self-hosted. | Invoice data (company, contact person, services) | on our own hardware local (Docker) | statutory retention period | DPA not required |
| Bitwarden USA | Managing credentials in encrypted form — vault on EU servers, end-to-end encrypted. | Credentials for your systems — end-to-end encrypted | EU EU servers (vault.bitwarden.eu, Microsoft Azure EU; country not published) | until the end of the project, then deleted | DPA available on request · EU Standard Contractual Clauses + Data Privacy Framework SOC 2 Typ 2, SOC 3, ISO 27001 DPA available on request; contents are end-to-end encrypted, the provider cannot read them |
B · Our internal operations — do not touch your data (13)
| Provider | Purpose | Processing location | DPA |
|---|---|---|---|
| OpenAI (Codex, gpt-image) USA (contracting party for the EU: OpenAI Ireland) | Second model as an automated helper for pure build tasks, plus an image model for our avatars — without customer data. | outside the EU | no DPA — used without customer data only |
| Google Gemini (API) USA (Google) | Answer engine that we query via the API to measure how AI search portrays a company — no personal data. | outside the EU | no DPA — used without customer data only |
| Perplexity (API) USA (Perplexity AI, Inc.) | AI search engine that we query via the API to measure visibility in AI answers — no personal data. | outside the EU | no DPA — used without customer data only |
| Higgsfield USA | Image and video generation for our own visual world (avatars, motifs for posts) — without personal data of third parties. | outside the EU | no DPA — used without customer data only |
| Ideogram Canada/USA (Ideogram AI, Inc.) | Image generation via the API, strong on typography — for graphics without any personal reference. | outside the EU | no DPA — used without customer data only |
| Flux (Black Forest Labs) Germany (BFL GmbH, Freiburg) | Image generation via the API (Flux) for photorealistic motifs without any personal reference — a provider from Freiburg. | outside the EU | DPA available on request |
| Cloudflare USA | Small server functions for internal processes, distributed across the provider's worldwide network. | outside the EU | DPA in place |
| Docker (local) — | Self-hosted services (CRM, invoicing) in containers on our own hardware. | on our own hardware | DPA not required |
| Next.js / React / TypeScript / Tailwind Open source | Our web stack for websites and applications — open, widely used building blocks. | on our own hardware | DPA not required |
| Playwright Open source (Microsoft) | Automated tests and acceptance of websites in a real browser. | on our own hardware | DPA not required |
| Notion USA | Data layer of our internal command centre STELLA — tasks, ideas, follow-ups. | outside the EU | DPA in place |
| Trello USA (Trello Inc., Atlassian group) | Inbox for ideas and voice notes, editorial planning. | outside the EU | DPA in place |
| Canva Australia (Canva Pty Ltd) | Templates, graphics and document styling; via a connection directly from our workplace. | outside the EU | DPA in place |
For your data protection officer
Table A is our list of sub-processors; in the project contract it is tailored to your project. We provide the providers’ data processing agreements as dated printouts, also where they form part of the terms of service. Technical and organisational measures, deletion concept and incident reporting path are part of our data processing agreement with you. Contact: datenschutz@xaiteck.ai.
As of August 2026. We review these details regularly and update them when things change. The contracts concluded with the respective provider and with you are authoritative; no claims can be derived from this overview. A data processing agreement under Art. 28 GDPR is in place with the providers that process customer data, or it is available on request; the respective status is shown in table A. For some providers the agreement is incorporated as part of the terms of service. Where processing takes place outside the EU, it is based on the data processing agreement and the EU Standard Contractual Clauses; for certified providers additionally on the EU-US Data Privacy Framework.
What has changed
- 08/2026 — Page published.
- 08/2026 — Image models Ideogram and Flux assessed separately.
- 08/2026 — Function region of this website set to Frankfurt.
Ready to start?
You talk.
We listen.
We solve your problem.
Book appointment →30 min · non-binding · video call or phone
We waited two years. After the first workshop it was clear: the foundation was missing — not the AI.
Managing Director, manufacturing company, ~60 employees, Baden-Württemberg
