How Airparser Protects Your Documents: Encryption, Retention, and Data Control

How Airparser handles document security: AES-256 encryption, configurable 1-180 day retention, no AI training on your data, and a DPA for every customer.

How Airparser Protects Your Documents: Encryption, Retention, and Data Control
TL;DR
Airparser encrypts documents in transit (TLS 1.2+) and at rest (AES-256), runs its core compute in Germany on ISO/IEC 27001-certified infrastructure, lets you choose how long documents are kept (1 to 180 days), never trains AI models on your data, and offers a Data Processing Agreement to every customer. This article explains each control, why it matters for document workflows, and what to ask any parsing vendor before you send them invoices, contracts, or resumes.

A document parser sees everything in your documents: customer names, bank details, salaries, signatures. So the question "what happens to my data once it is uploaded?" is not a legal formality. It decides whether a parsing tool can be used at all for finance, HR, healthcare, or logistics workflows.

This page answers that question for Airparser in plain language: where documents are processed, how they are protected, how long they live, who can touch them, and what happens when you want them gone. Every claim below maps to a control described on our security page or in our Data Processing Agreement, so you can verify it rather than take our word for it.

Where Airparser processes your documents

Airparser's core compute runs on Hetzner infrastructure in Germany, in Falkenstein and Nuremberg, with redundancy across two independent locations. Those data centers are ISO/IEC 27001 certified, the international standard for information security management.

Uploaded documents are kept in encrypted object storage, and account data and extraction schemas live in a managed database. Customer accounts, schemas, documents, and extraction results are logically separated from one another, so one customer's data is never mixed into another's workspace.

Every provider that handles data on our behalf is a named subprocessor, vetted for security and privacy practices before it gets any access. The full, current list is public on our subprocessors page, including each provider's purpose and location.

How documents are encrypted in transit and at rest

Encryption is applied at both stages where documents are exposed:

  • In transit: all traffic uses HTTPS with TLS 1.2 or higher, including communication with the AI providers that power extraction.
  • At rest: documents, application data, and backups are protected with AES-256 encryption.
  • Credentials: passwords are salted and hashed with bcrypt (work factor 12), so they are never stored in readable form.

Why this matters for parsing specifically: a parsing pipeline moves documents through several steps (upload or email ingestion, extraction, export). Encryption that covers only one step leaves the others exposed. Airparser applies it across all of them, including backups, which are often the forgotten copy.

How long Airparser keeps your documents (and how to delete them)

Retention is under your control. In each inbox you can configure automatic document deletion anywhere from 1 to 180 days. If your policy says invoices should not sit in a third-party tool for longer than a month, you can set exactly that.

You can also delete documents, schemas, or your entire account at any time, and deleted data is removed from active systems immediately. Backups rotate out on a cycle of 30 days or less, so nothing lingers indefinitely.

SituationWhat happens to your data
Automatic retention enabled (1 to 180 days)Documents are deleted automatically when the period ends
You delete a document, schema, or accountRemoved from active systems immediately
BackupsRotated out within 30 days or less

Does Airparser train AI models on your documents?

No. Airparser does not train or fine-tune models on customer documents. Every AI provider involved in extraction is bound by a contractual no-training commitment, and data sent to them is encrypted in transit. Your data is also never sold.

This is the question we hear most from teams evaluating AI-based extraction, and it is the right one to ask. A parser that improves its model by learning from customer invoices or resumes would be turning your confidential data into its own product. Airparser is built the other way around: your documents are used to produce your extraction results, and for nothing else.

Who can access your data

Access to customer data and production systems is limited to authorized team members with a business need, following the principle of least privilege, and access is audited regularly. Supporting controls include:

  • company-wide multi-factor authentication
  • a required company-wide password manager
  • full-disk encryption on all employee laptops
  • peer review before every release, plus continuous static analysis and dependency scanning

The practical effect: the people and systems that can reach your documents are a short, deliberate list, not "everyone at the company".

GDPR, the DPA, and international transfers

For the documents you parse, you are the data controller and Airparser is the data processor. That role split is written into our DPA, which is available to every customer, not just enterprise plans. It covers:

  • processing only on your documented instructions
  • security measures appropriate to the risk, in line with GDPR Article 32
  • authorization of subprocessors by you as the controller
  • notification of personal data breaches without undue delay
  • your right to request information and audits demonstrating compliance
  • Standard Contractual Clauses for any transfer outside the EEA

If you want the wider legal context (what counts as personal data in an invoice or resume, and what GDPR requires of you as the controller), read our guide to document parsing and GDPR.

Incident response and monitoring

Infrastructure is monitored around the clock with real-time alerts, and incident response and escalation procedures are documented. Where the law requires it, affected parties and authorities are notified within 72 hours. Payments are handled by Stripe, which is PCI DSS compliant, so card details never touch Airparser's own systems.

What to ask any document parsing vendor

Use these questions to compare vendors, Airparser included. A trustworthy answer is specific and points to a public page or contract clause.

  1. Is there a signed DPA, and does it apply to my plan? Look for it in public, not "on request".
  2. Which subprocessors touch my documents, and where are they located? A vendor should publish a list.
  3. Is my data used to train any model, by you or your AI providers? You want a flat no, backed by contract.
  4. Can I control retention? Fixed, undisclosed retention is a red flag.
  5. What happens to backups after I delete something? Ask for a number of days.
  6. What is encrypted, and with what? "Encrypted" alone is not an answer; look for TLS versions and AES-256 at rest.
  7. Who inside the company can access my documents? Look for least privilege, MFA, and audits.

Frequently asked questions

Is Airparser GDPR compliant?

Airparser offers a Data Processing Agreement to every customer, acts as your data processor, applies technical and organizational measures in line with GDPR Article 32, and uses Standard Contractual Clauses for transfers outside the EEA. You remain the controller of the documents you upload.

Where does Airparser process my documents?

Core compute runs in Germany on Hetzner infrastructure across two independent locations. The providers involved in storage and processing, with their locations, are listed on the subprocessors page.

Is my data used to train AI models?

No. Airparser does not train or fine-tune models on customer documents, and all AI providers are contractually bound not to train on your data.

How is my data encrypted?

Data in transit uses TLS 1.2 or higher. Documents, application data, and backups are encrypted at rest with AES-256.

How long does Airparser keep my documents?

As long as you choose. Automatic deletion can be set between 1 and 180 days per inbox, and you can delete documents, schemas, or your account manually at any time.

Can I get a Data Processing Agreement?

Yes. The DPA is available to all customers.

Who at Airparser can see my documents?

Only authorized team members with a business need, under least-privilege access that is audited regularly and protected by multi-factor authentication.

Who do I contact with a security question?

Write to [email protected]. The full overview is on the security page.

Bottom line

Good document automation is only worth having if you can trust what happens to the documents. Airparser's approach is to keep those controls concrete and checkable: encryption at every stage, retention you set yourself, no training on your data, a public subprocessor list, and a DPA for every customer. Review the details on the security page, then try the workflow with your own documents.