Correction

Colossyan — Colossyan Inc., Ungarn/USA

What happens to your submission

Your submission does not appear in the directory straight away. We look at the evidence and, if it holds, write a new assessment with a date and a record of the change. That separation is precisely what makes the entry worth something to your customers. It costs you nothing.

Current state
CriterionIn the directory
Data processing agreementColossyan erklärt, Auftragsverarbeitungsverträge zu führen: „We process personal data lawfully, maintain data processing agreements (DPAs), and support data subject access requests.“ Das Dokument liegt aber nicht offen: „Our privacy policy and DPA are available on request.“ Ein Kunde mit Sitz in der EU muss den Vertrag also anfordern und dessen Inhalt vorher prüfen — deshalb gelb.
Place of processingColossyan macht zum Speicherort zwei Angaben, die sich nicht decken. Die Datenschutzerklärung sagt: „Our Services are hosted in Germany and the UK and Colossyan is located in the United States.“ Die Sicherheitsseite sagt: „Colossyan runs on AWS infrastructure in EU and US regions.“ Einmal Deutschland und Vereinigtes Königreich, einmal EU **und USA** — das ist ein Widerspruch auf derselben Website, und er betrifft genau die Frage, auf die es ankommt. Solange er nicht aufgelöst ist, kann ein Betrieb allein innerhalb der EU nicht als zugesagt gelten. Wer Colossyan einsetzen will, sollte sich den Speicherort schriftlich bestätigen lassen. … share or have a legitimate interest in sharing your data. Data transfers Our Services are hosted in Germany and the UK and Colossyan is located in the United States (“Applicable Regions”). If you access our website or Services from any other region of th … (Quelle: https://colossyan.com/privacy, abgerufen 2026-08-20 · maschinell gefunden, Regelwerk 3.0, Regel „Anhaltspunkt: Verarbeitung im Drittland“)
Training on customer dataColossyan schließt die Verwendung zum Training in zwei Richtungen aus: „Your documents, scripts, and videos are never used to train our AI models“ und, für die eingesetzten Vorlieferanten, „Our AI vendors are contractually prohibited from training on Colossyan input“. Die zweite Zusage ist die seltenere und die wichtigere — sie deckt genau die Lücke, die entsteht, wenn ein Anbieter selbst nicht trainiert, sein Modelllieferant aber schon.
CertificationsColossyan weist SOC 2 Typ II aus, und zwar als eigene Zertifizierung: „Colossyan holds SOC 2 Type II certification, independently audited by a third-party firm. This covers security, availability, and confidentiality controls across our platform.“ Die Prüfung findet nach eigener Angabe jährlich statt. Nicht zu verwechseln ist damit die zweite Normnennung auf derselben Seite: „We prioritize AI vendors with ISO 27001 or SOC 2 Type II certification“ — das ist die Anforderung an die Vorlieferanten und keine eigene Zertifizierung. Eine ISO 27001 für Colossyan selbst ist nicht ausgewiesen.
SubprocessorsDie Sicherheitsseite nennt eine Unterauftragnehmer-Liste, die über das Trust Center des Anbieters zugänglich sei; abrufbar war sie uns nicht. Zusätzlich gibt der Anbieter an, seinen KI-Dienstleistern das Training auf Colossyan-Eingaben vertraglich zu untersagen und jede KI-Anbindung vor der Einführung rechtlich und sicherheitstechnisch zu prüfen, mit Vorrang für Anbieter mit ISO 27001 oder SOC 2 Typ II. (Quelle: https://colossyan.com/security, abgerufen 2026-08-01 · maschinell gefunden, Regelwerk 3.0, Wortlaut von Hand aus dem Archivstand gefasst)
A publicly retrievable page carrying the statement. Best on your own domain — what we can read there, your customers can read too.
For queries about this submission only. No mailing list, no sharing.

Would you like to maintain the entry and be heard before changes? A correction with evidence does not require that — it is covered by the vendor programme.

The interface is available in English. Directory entries, the AI register we produce, the quarterly record and the contract annexes remain in German — they are the authoritative documents.

Deutsch · English