EU hosting
Frankfurt data centre, ISO 27001-certified processor. No transfer outside the European Union. No US Cloud Act.
Security · GDPR · EU
This tool is designed to the security standard expected of an approved Belgian social secretariat: EU hosting, GDPR by design, strict isolation per organisation, full access traceability.
Frankfurt data centre, ISO 27001-certified processor. No transfer outside the European Union. No US Cloud Act.
TLS 1.3 in transit, AES-256 at rest, keys managed in a separate KMS. Encrypted backup, rolling 30-day retention.
Postgres + Row Level Security on 100% of customer tables. A malformed query can never return another organisation's data.
Sign-in via email magic link (Supabase Auth). No stored password, no risk of leakage through credential stuffing.
Your data is never used to train a model. No third-party LLM provider receives your audits.
Full export + permanent deletion in 1 click from Settings > Privacy. Data purged from backup within 30 days.
Independent external firm, report available under NDA for Enterprise customers.
Dependencies continuously scanned (Snyk + Dependabot). Critical patches < 48 h.
Data Processing Agreement aligned with GDPR art. 28, available on request at dpo@groups.be.
No. EU hosting (Frankfurt), GDPR, TLS 1.3 encryption in transit and AES-256 at rest. No data is shared with any third party without your explicit consent. No AI model training on your data.
Frankfurt (Germany) with an ISO 27001 certified sub-processor. No transfers outside the EU. The DPA (Data Processing Agreement) is available upon request at dpo@groups.be.
Audit sessions: 36 months after the last activity (aligned with the Belgian Social Criminal Code's statute of limitations). PDF reports: kept as long as your account exists. You can export and delete all your data at any time from Settings > Privacy.
Strictly the users invited to your organisation (with admin or user roles). Group S never accesses your data except upon explicit support request (with consent via a ticket).
Annual pentest by an external firm, continuous dependency scans, ISO 27001 certificate undergoing renewal. See /security for details.
Yes. The tool does not make any automated decisions on your behalf: it presents legal rules audited by legal experts. No scoring of individuals, no profiling, not a high-risk AI system within the meaning of EU Regulation 2024/1689.
Documents available on request at dpo@groups.be or via your usual Group S contact.