ISO/IEC 27001
Our information security management system is certified and re-audited annually by an accredited body.
Every layer of our platform — physical, network and organisational — is built around one commitment: your data stays inside the EU, protected, and entirely under your control.
Every claim on this page is backed by a certificate or audit report available on request.
Our information security management system is certified and re-audited annually by an accredited body.
A dedicated data protection function, a documented DPA, and a public sub-processor list kept up to date.
Every connection to our infrastructure, including internal traffic between data centers, is encrypted in transit.
Biometric access control, 24/7 CCTV and on-site security staff protect every facility we operate.
Network-layer filtering is active on every server by default, absorbing attacks before they cause impact.
Contractually guaranteed: your data is processed and stored only within our EU facilities, never outside.
These are the specific mechanisms behind every claim we make about data protection.
What our customers' legal and compliance teams usually ask first.
Every hosting contract includes a Data Processing Agreement, downloadable at any time from the Legal section of your client area, no request needed.
Only with sub-processors strictly necessary to deliver the service, such as payment processors, all of which are listed publicly and are themselves GDPR compliant.
Affected customers are notified within 72 hours of us becoming aware of a breach, in line with GDPR Article 33, along with a clear explanation of impact and remediation steps.
Submit a request through your client area or by emailing our data protection team, and we respond within 30 days as required under GDPR Article 15.
Yes. Every sub-processor we use is contractually bound to GDPR-equivalent standards and is based within the EU or an approved adequacy jurisdiction.