Außendienstapp stores core data (database, auth, file storage) exclusively in the EU (Frankfurt am Main), enters into a Data Processing Agreement (DPA) under Art. 28 GDPR, encrypts data at rest with AES-256 and in transit with TLS 1.2+, enforces tenant isolation via Row-Level Security and uses cookieless analytics. Third-country transfers only for specialist processors (payments, email delivery) via the EU-US Data Privacy Framework.
A transparent data protection framework for DACH B2B teams, documented with concrete technical and organisational measures.
Core data — database, file storage and application hosting — runs exclusively in the EU (AWS eu-central-1, Frankfurt). Narrowly-scoped specialist processors (e.g. payments, email, maps) are covered by the EU-US Data Privacy Framework or standard contractual clauses (SCCs) — details in the privacy policy (German) and Data Processing Agreement (German).
TLS/HTTPS for all data transfers. Encryption at rest at the database level (AES-256). Passwords are hashed with bcrypt (cost factor 10) — never stored in plain text.
Every database query is restricted to your organisation through Row-Level Security (RLS). Tenant isolation at the database level — not merely in application logic.
Managers see team data; field sales reps see only their own. No user can access another organisation's data. Inviting new users is restricted to managers.
Automatic daily database backups at our EU hosting partner (7-day retention) plus an encrypted off-site backup in separate storage (90-day retention). In the event of an incident, we restore your data from the most recent daily backup.
We use Vercel Analytics — completely without cookies and without tracking pixels. Only aggregated metrics are collected that cannot be used to identify individual persons. No cookie banner is required.
All documents you need for your own GDPR compliance — ready to review. Note: contract documents are in German and the German versions are legally binding.
Data Processing Agreement pursuant to Art. 28 GDPR — including technical and organisational measures (TOMs), sub-processor list and breach notification obligation. Contract language is German; the German version prevails.
View DPA (German)Your employees can export the personal data they have provided at any time as a ZIP file (right to data portability under Art. 20 GDPR) and delete their account independently (Art. 17 GDPR) — directly in the account settings. Organisation-wide data export by the manager is separate and takes place within the scope of data processing.
Full transparency about all data processing activities, legal bases, retention periods and sub-processors. Available in German only; the German version is legally binding.
Privacy policy (German)For optional GPS location recording we provide a Data Protection Impact Assessment (DPIA) template (Art. 35 GDPR) that you can use directly for your works council or data protection officer.
Complete list of all service providers involved in processing your data. The legally binding version with all obligations is available in the Data Processing Agreement (DPA) (German).
| Provider | Purpose | Data location | Transfer basis |
|---|---|---|---|
| Supabase | Database, auth, storage | EU Frankfurt | DPA under Art. 28 GDPR, EU SCCs |
| Vercel | Hosting, CDN, analytics | EU Frankfurt | EU-US Data Privacy Framework (DPF) |
| Cloudflare | Encrypted off-site backup (disaster recovery) | EU-jurisdiction bucket (Cloudflare R2; provider seat USA) | EU-US DPF + DPA (Cloudflare Customer DPA Art. 28 GDPR); contents client-side encrypted — no technical access by provider |
| Stripe | Payment processing | USA | EU-US DPF, PCI DSS Level 1 |
| Resend | Transactional emails (outbound) | USA | EU-US DPF |
| Google Workspace | Business email mailbox (incoming enquiries incl. attachments) | EU/USA (Google data centres) | DPA under Art. 28 GDPR (Google Workspace DPA), EU-US DPF, plus EU SCCs |
| Sentry | Error monitoring | EU (de.sentry.io) | EU region; EU-US DPF, plus EU SCCs |
| CARTO | Map tiles | USA | EU Standard Contractual Clauses (SCCs, Art. 46 GDPR) |
| Komoot | Geocoding (Photon, server-side) | Germany (Berlin) | EU seat, no third-country transfer |
| OpenStreetMap Foundation | Fallback geocoding (Nominatim, server-side) | United Kingdom | UK Adequacy Decision (28 June 2021) |
| Apple | iOS push notifications (APNs), ActivityKit — iOS app only | USA | Apple GDPR DPA, EU SCCs |
| Route export (optional user-initiated deeplink to Google Maps) | USA | EU-US Data Privacy Framework (DPF) | |
| Have I Been Pwned | Password security check via k-anonymity (no PII transferred) | Australia | k-anonymity — no personal data transferred |
| GitHub | CI/CD automation; technical execution of off-site backups (database/auth client-side encrypted, photo/document backups TLS + R2 encryption only) | USA | EU-US DPF, plus EU SCCs (GitHub DPA) |
List as of
Our infrastructure runs on platforms with industry-leading security standards.
Photos from visit reports are automatically deleted after 24 months — both from the database and from file storage. After cancellation, all data remains available for export for 30 days and is then irrevocably deleted. Data minimisation is not just a promise — it is an automated process.
The eight questions that DACH B2B buyers and data protection officers ask most often — answered directly.
Transparent plan, 30-day notice period, no credit card required.
What the app can do — template builder, dashboard, route planning — and what sits in which tier.
Complete Data Processing Agreement under Art. 28 GDPR incl. TOMs. Contract language is German.
All data processing activities, legal bases and retention periods in detail.
You can start on your own — or we set the app up together with you and answer every data-protection question along the way. The DPA and DPIA template are ready for you.