Everything on this page is generated from the same lists and settings the software runs on, so it changes when they change. It is a summary: the privacy policy and section 12 of the terms are the binding text.
When a workspace is created you choose where its AI works: standard or EU hosting. An owner can restrict it further, for the whole workspace or per department, on the Security page.
Every model your workspace allows, including providers in the USA. A new team starts on Claude (Anthropic PBC, USA).
European data centres: the EU, plus Switzerland and Norway where a provider's EU zone includes them.
AI processing only on these routes, where the provider is enabled on our deployment:
Web search, image and video generation and cloud embeddings have no EU route, so an EU-hosted workspace does not use them; the knowledge base uses a local embedder instead.
Under both options, the application, the database and your files are here:
Every company that may process your data on our behalf, with the country it processes in and the legal basis for the transfer. The privacy policy carries the same list with a description of each.
List version 2026-09-23, in force from 2026-10-26 for workspaces created before it.
Added two EU-resident model providers for EU-hosted workspaces: OpenAI's European data-residency region (eu.api.openai.com — OpenAI is already listed; this is its separate EU processing region, where prompts are processed and stored in Europe) and Google Cloud Vertex AI's EU multi-region (Gemini and Claude Fable, with ML processing inside EU member states — Google is already listed for the Gemini API). Neither processes anything for a workspace that does not use its models. Same revision: every entry now names the state it processes in and the transfer basis, and the platform processors (Render, Neon, Cloudflare R2 and edge, Resend, Stripe, Sentry) — already named in the privacy policy — are part of the versioned list. Two locations were corrected, not changed: Have I Been Pwned is operated from Australia (it receives a five-character hash prefix, not personal data) and the Seedance video engine processes in Johor, Malaysia.
We give at least 30 days' notice before we add or replace a sub-processor, and you may object (terms §12(d)).
Whether your business may use Vorenq depends on the secrecy rules of your profession. The short answer per profession:
The full answer with the statutes, per profession
This is orientation, not legal advice. Your professional association, a data protection officer or a lawyer decides the individual case.
You are the controller, we are your processor (DSG Art. 9). Section 12 of the terms is the data processing agreement: accepting the terms concludes it, and Swiss law requires no separate signature.
These mechanisms are built into the product and checked by our automated tests on every release. They are our own engineering checks; no outside auditor has assessed them.
The API tokens and sign-ins your employees use for connected tools are stored encrypted (AES-256-GCM), each bound to its workspace and connector, and decrypted only on the server when a connector runs.
Accounts can require a code from an authenticator app, with recovery codes. The authenticator secret itself is stored encrypted.
Connecting a mailbox, exporting the workspace, making someone an owner or spending money asks for the password again when the last sign-in is more than 15 minutes old.
A new password is checked against a local list of common passwords and against public breach data. Only five characters of a hash are sent, never the password.
Actions your approval rules cover wait for a person, and every approval and decision is recorded in the workspace's audit log.
Where a connector supports it, a change written to another system is read back from that system before a run reports it as done. A read that fails is reported as unverified, never as success.
Content written by people outside your company, such as incoming e-mails and web pages, is labelled as outsider-written before an employee reads it, and the run that read it is flagged.
Messages an AI employee sends on your behalf through the built-in channels open with a notice that AI wrote them for your company; public posts carry an AI label. The notice cannot be switched off.
Retention periods and your other rights are in the privacy policy.
Found a security problem, or received something harmful from a Vorenq employee? Use the report page, no account needed, or write to abuse@momentumq.com.