Your data stays yours

Certified operations in the operator’s own data centre, encrypted data and clearly defined access. This page shows how that works in practice.

Encryption and transfer

The content of a record is unreadable to anyone who reaches the storage outside the app.

  • Data is stored encrypted
  • Communication runs exclusively over HTTPS with TLS 1.3
  • Cryptographic hashing guards transfer integrity

Who can reach the data

The scope of access is a setting, not an agreement. And every change leaves a trace.

  • Everyone works under their own credentials
  • Roles and permissions define the scope of access
  • Every record keeps a trace of who changed it and when

Availability and backups

The service runs in the operator’s own data centre. Backups are continuous and stored away from production.

  • The operator’s own data centre, not a rented platform
  • Continuous and daily backups, off-site
  • Key parts of the service run in duplicate

Disaster recovery

The recovery plan is not a document in a drawer – it is rehearsed, so we know how long it takes.

  • A minor outage is handled by duplication within minutes
  • Even for a serious incident the target is recovery in hours
  • Restoring from backup is rehearsed regularly

AI and your data

Assistant queries are processed by a language model from OpenAI. The assistant only works with data you can access yourself.

  • For EU customers the contracting party is OpenAI Ireland Ltd, acting as a processor under a data processing agreement (DPA)
  • This processing runs with zero data retention: the content of your queries is not stored
  • Your queries are not used to train the provider’s models

You stay in control

  • You stay in full control of your data and can delete it at any time.

  • Encrypted data is accessed only at your explicit request, for example during a support intervention.

  • Your data is never used to train or improve the product.

Internationally recognised certificates

ISO 27001

Information security management

The international standard for systematically managing and protecting an organisation’s information assets.

ISO 27017

Cloud security

Guidance for securing a cloud environment and reducing the risk of security incidents.

ISO 27018

Personal data in the cloud

Practices for protecting personal data in public cloud services.

The operator has been through a demanding certification process. DATIFY is also ready to meet GDPR requirements (EU Regulation 2016/679).

Need documents for a security audit?