Trust & Compliance

Protecting your data with GDPR-by-design

Operations in certified data centers in Germany, isolated hosting and transparent processes support the protection of your data.

SaaS-Secure is responsible for its own hosting and operational services within the contractually agreed scope. The certification statement applies to the data-center infrastructure, not to a certification held by SaaS-Secure. Information about the certification scope can be provided to qualified prospects during the technical review process.

What this page covers

  • How we isolate and protect every SaaS tenant
  • Data location and data-use principles
  • Data export options and Data Processing Agreements (Art. 28 GDPR)

GDPR-first operations in Germany

We follow the EU General Data Protection Regulation (GDPR) and apply the strict German privacy standards to every hosting.

Tenants are isolated from each other through separate container environments and firewall segmentation.

Need the legal details? Review our Privacy Policy for the full data protection statement.

Operational safeguards

  • Encrypted backups to isolated systems
  • Separate per-tenant containers
  • Firewall segmentation for every hosting node
  • Production data, backups and mirrors remain exclusively in Germany
Talk to a security engineer

Legal bases for processing

We process personal data only on clear legal bases under GDPR. Depending on the purpose, we rely in particular on contract performance (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR), or consent (Art. 6(1)(a) GDPR).

Where we act as a processor, we process data only on documented instructions from the controller under Art. 28 GDPR.

Data subject rights

You have rights of access, rectification, erasure, restriction of processing, data portability, and objection to certain processing activities.

Please submit requests via our privacy contact form or the contact details listed in our Privacy Policy.

Technical service providers

Hosting-service customer data, production data, backups and mirrors remain in Germany.

We do not sell personal data or disclose it for advertising purposes. Where technical service providers are used to deliver a service, they receive data only to the extent necessary and on a contractual basis.

Data export

Download exports from the Customer Center at any time. When you end hosting, we provide a final export of your data at no cost.

Exports include everything needed to restore your environment, except components that only run on our infrastructure.

Access Customer Center

Data Processing Agreement

Processing personal data under GDPR? Sign the commissioned data processing agreement (Art. 28 GDPR) directly in your account.

Use the online Data Processing Agreement tool in the Customer Center — no paperwork or email back-and-forth.

Sign DPA online

Retention and deletion

We store data only as long as needed for each processing purpose and to satisfy statutory retention obligations.

After contract termination, deletion and return periods are governed by the contract and Privacy Policy. Before deletion, we support you with data exports.

Data location and external website services

All hosting-service customer data remains in Germany, including production data, backups and mirrors.

Necessary information about external website services, contact forms and their processing is provided separately in our Privacy Policy.

Status

Updated 2026-07-29 · This page complements the legally binding details in our Privacy Policy and contractual documents.