Skip to main content

Security & GDPR

Privacy by design — clear for your firm

Built with privacy as the default. Data in the EU, strict firm separation, and clear access rules.

GDPR-ready from the ground up

Security and privacy in every layer — firm separation, access control and EU hosting.

Strict separation per firm

Each firm has an isolated environment. Firm A’s clients never see firm B’s data.

Database access rules (RLS)

Row Level Security on the database ensures each user only sees data belonging to their firm and role.

EU hosting

All data is stored in the European Union.

Backups & JSON export

Automatic encrypted backups. Export your data as JSON whenever you want — on every plan.

Access control

Role-based access and tenant separation ensure only authorized users can reach the right data.

Subprocessors

Primary app data in the EU (Supabase / AWS eu-west-1). Email (Resend) and push (Google) may leave the EU. Full list:

  • Hosting: Supabase / AWS eu-west-1 (EU)
  • Analytics: Plausible / PostHog EU (when enabled)
  • Email: Resend · Push: Google FCM · see /subverwerkers
Full subprocessors list →

Questions about security? Contact us at:

yassir@outside-boxes.nl