Skip to content

GDPR-compliant server infrastructure

A GDPR-compliant server infrastructure protects personal data with EU hosting, encryption, access control and documented deletion periods.

Personal data

The GDPR requires appropriate protection for form submissions, customer accounts, orders and IP addresses in log files. Breaches can lead to fines, legal warnings and a loss of trust.

Technical measures

  • hosting in EU data centres

  • TLS 1.3 in transit, encryption at rest where necessary

  • personal accounts, two-factor authentication and logging

  • encrypted backups with defined retention periods

  • short log retention and truncated IP addresses

No unnecessary data flows

External fonts, maps or videos often transmit data before consent. We host them locally or load them only after consent.

Forms collect only necessary data and delete submissions after a set period.

Documentation

Every processor requires a data processing agreement. We document the technical and organisational measures in line with ISO 27001 and supply the details for your record of processing activities.

Approach

First, we record where personal data is processed. The measures are agreed with your data protection officer. They do not replace legal advice.

Project enquiry

Back to top