- Where the data sits
- Application, database and file uploads run exclusively in German data centres. No transfer to third countries without a legal basis.
- Encryption
- TLS throughout for transfer, passwords stored as hashes, sensitive fields encrypted on top in the database.
- Who can see what
- Permissions follow the role and the location. A staff member sees the calendar, not the revenue.
- Tenant separation
- Each location sees only its own data. Every query checks the tenant, not just the role.
- Logging
- Sign-ins, permission changes and access to customer data are logged and visible in the dashboard.
- Your customers' rights
- Access, export and deletion are features in the system, not a support ticket.
- Monitoring and backups
- Automatic backups with tested restores, plus error and uptime monitoring around the clock.
- Sub-processors
- Who we use is listed openly in the DPA. If someone is added, you hear about it beforehand.
- If you leave
- A full export of your data at any time. After the contract ends it is deleted, apart from statutory retention periods.