YOUR DATA STAYS
WHERE YOU PUT IT.
Two deployment options, one rule: nothing leaves except what you explicitly send to an agent you connect. Run CMP42 on our EU-hosted managed tier, or run the same binary on your own Postgres and object store.
A CRM IS PERSONAL DATA.
Every contact in a CRM is a person: a name, an email address, a role, a history of conversations. Under the GDPR that is personal data, and moving it outside the European Economic Area is a transfer that needs a legal basis under Chapter V — adequacy decisions, standard contractual clauses, transfer impact assessments. For many European companies, the simplest compliant answer is also the best one: keep the data in the EU.
For an AI-native CRM the question gets sharper. The value of CMP42 is that agents read rich context — meeting notes, proposals, playbooks. That makes it even more important to know exactly where the context lives and exactly when it leaves.
MANAGED IN THE EU. OR YOURS.
EU-hosted managed tier
We operate CMP42 for you in the EU. protagx acts as your processor; an AVV / DPA under Art. 28 GDPR is available on request. CMP42 does not train on your data, and the product ships no third-party analytics, fingerprinting or session replay.
Your environment
Same binary, same models, same MCP tool surface — running on your Postgres and your object store, in the region, cloud or data centre you choose. On self-hosted, nothing leaves your environment at all. Design Partners get the self-hosted image during Alpha; it is published with Beta in Q1 2027.
The managed tier runs on Hetzner Online GmbH in Germany — specifically the Falkenstein and Nuremberg data centres. A data-processing agreement under Art. 28 GDPR, dated 24 April 2025, is in place with Hetzner and covers both sites. Server processing stays inside the EU; sub-processors and third-country safeguards for the mailbox and outgoing mail path are listed in the privacy policy.
THREE COMMITMENTS. ONE NUANCE.
- No training on your data. CMP42 does not use your data to train models.
- No silent egress. On the managed EU tier, no data leaves — except what you explicitly send to an agent you connect.
- No third-party observers. No third-party analytics, no fingerprinting, no session replay.
YOUR MODEL PROVIDER IS YOUR CHOICE.
CMP42 ships no proprietary AI layer. When you point Claude Desktop, Claude Code, Cursor, Cline or a custom agent at your workspace, the context that agent retrieves is sent to whichever model provider runs it. That is not CMP42 exporting your data — it is you deciding to send it, to a provider you selected and contract with directly.
So the residency of your agent is part of your architecture decision. If EU processing matters to you, pick a model provider and plan that meet that requirement — and use CMP42's human-in-the-loop approval hooks and attribution to keep a record of what agents did with the context.
[ CMP42 workspace ] EU managed tier · or your own infra
│
│ MCP tool call: get_context / list_related
▼
[ MCP client you run ] Claude Desktop · Cursor · custom agent
│
│ prompt + retrieved context
▼
[ model provider ] your choice · your contract
│
│ write_note · attributed: agent:… · approved_by: human:…
▼
[ CMP42 workspace ] versioned · audit trailFIVE QUESTIONS TO ASK YOURSELF.
- Where does the model provider process requests? Check the region and whether a data processing agreement is available.
- Does the provider use your prompts for training? Check the business terms and get the answer in writing.
- Which data does the agent actually need? Lean models mean less context to send in the first place.
- Which writes need a human? Put approval hooks on the process steps that matter.
- Who reviews the audit trail? Attribution is only useful if someone looks at it.
HOSTED IN GERMANY.
The website you are reading is hosted on a Hetzner server in Germany. It loads no fonts, scripts or images from third-party CDNs — every asset comes from the same server — and it sets no cookies. How zero tracking is enforced →