Customer data is logically isolated to prevent unauthorized access between tenants.
Role-based access management and the principle of least privilege is applied.
Data is encrypted during transmission using industry-standard protocols.
There are documented incident response procedures that are regularly tested.
30 days, unless otherwise required by law.
The Service is performed solely on infrastructure within the European Union. Administrative access is limited to personnel within the EU.