PinMy

Security and data protection

PinMy stores your data in the EU only, on Google Cloud in Frankfurt, Dublin and the Netherlands. It is encrypted in transit and at rest, reachable only through role-based access control, and it is never used to train AI models and never sold. Everything on this page is stated in binding form in the privacy policy.

01 / 09

Data residency

Your files, pins, comments and voice notes are stored on Google Cloud infrastructure in the European Union — Frankfurt, Dublin and the Netherlands. There is no replication to a region outside the EU.

For a Spanish, German or Estonian construction firm this is usually the first question the client's legal team asks, so it is the first thing on this page.

02 / 09

Encryption

Everything is encrypted in transit with TLS, and encrypted at rest on the storage layer. That covers the media a site worker uploads over a bad 4G connection as much as it covers the database.

03 / 09

Access control

Access to a file is controlled per project and per person. Inside a file, only the person who created a pin can move or delete it — everyone else can reply but cannot alter the original. That rule exists so a site record stays defensible.

The Teams tier adds SSO, role-based access at organisation level, and audit logs.

04 / 09

AI and your content

Your content is never used to train AI models, and it is never sold. Not to us, not to a model provider, not to a data broker.

PinMy does use AI in one narrow, disclosed place: speech-to-text, so a voice note becomes searchable. That runs through a named sub-processor under a contract, on the audio you submit, for the purpose of returning a transcript to you — and for nothing else.

05 / 09

Sub-processors

Sub-processors are named in the privacy policy rather than described vaguely. Speech transcription is handled by Deepgram, engaged under Standard Contractual Clauses. Hosting is Google Cloud, in the EU regions listed above.

06 / 09

Reports are generated on your device

PDF report generation is client-side. The report is assembled on the phone, tablet or browser you are holding — the file is not shipped to a rendering server to be turned into a PDF.

PDF reports are shipped in beta. The layout and the export options are still changing.

07 / 09

Incident response

In the event of a personal data breach, affected users and the relevant supervisory authority are notified within 72 hours, as GDPR requires.

08 / 09

Retention and deletion

Retention periods are documented in the privacy policy. You can delete your content, and you can delete your account, from inside the product — deletion is user-initiated, not a support ticket.

09 / 09

Compliance

PinMy is GDPR-aligned, with the legal basis for each processing purpose set out in the privacy policy, and also covers CCPA and VCDPA rights. A Data Processing Agreement is available on the Teams tier.

PinMy holds no security certification it has not been audited for, and this page names none. If a certificate is a hard requirement for your procurement, say so before you buy rather than after.

The binding version

This page is a plain-language summary. The privacy policy is the document that actually binds PinMy OÜ, and it is where the legal bases, the full sub-processor list and your rights are set out.

Read the privacy policy