Security & GDPR
Privacy by design — clear for your firm
Built with privacy as the default. Data in the EU, strict firm separation, and clear access rules.
GDPR-ready from the ground up
Security and privacy in every layer — firm separation, access control and EU hosting.
Strict separation per firm
Each firm has an isolated environment. Firm A’s clients never see firm B’s data.
Database access rules (RLS)
Row Level Security on the database ensures each user only sees data belonging to their firm and role.
EU hosting
All data is stored in the European Union.
Backups & JSON export
Automatic encrypted backups. Export your data as JSON whenever you want — on every plan.
Access control
Role-based access and tenant separation ensure only authorized users can reach the right data.
Subprocessors
Primary app data in the EU (Supabase / AWS eu-west-1). Email (Resend) and push (Google) may leave the EU. Full list:
- Hosting: Supabase / AWS eu-west-1 (EU)
- Analytics: Plausible / PostHog EU (when enabled)
- Email: Resend · Push: Google FCM · see /subverwerkers
Questions about security? Contact us at:
yassir@outside-boxes.nl