Skip to content
FeaturesPricingSecurity
DE|EN
Sign in
  • Features
  • Pricing
  • Security
DE|EN
Sign in

The field sales app for FMCG teams
in the DACH region. Simple. Fast. GDPR-compliant.

EU data protectionEU serversSSLBuilt in Düsseldorf, Germany
exali IT-Haftpflichtsiegel – Benedikt Bimmerle
ProductFeaturesPricingSecurityStart now
ResourcesBlog (German)Use cases (German)ROI calculator (German)
LegalImprint (German)Privacy (German)Terms (German)DPA (German)
Contactinfo@aussendienstapp.de+49 211 15 888 623
Laden im App Store
© 2026 AußendienstApp. All rights reserved.
Privacy (German)Terms (German)Deutsch

Security & Data Protection

AußendienstApp stores core data (database, auth, file storage) exclusively in the EU (Frankfurt am Main), enters into a Data Processing Agreement (DPA) under Art. 28 GDPR, encrypts data at rest with AES-256 and in transit with TLS 1.2+, enforces tenant isolation via Row-Level Security and uses cookieless analytics inside the application. On our public pages, additional consent-based services run — without consent, nothing is loaded and no cookie is set. Third-country transfers to the US are covered by the EU-US Data Privacy Framework or standard contractual clauses (SCCs); the mechanism that applies is listed per recipient in the privacy policy (German). They concern specialist processors (payments, email delivery, maps) as well as the consent-based services on our public pages.

A transparent data protection framework for DACH B2B teams, documented with concrete technical and organisational measures.

Core security principles

EU Hosting (Frankfurt)

Core data — database, file storage and application hosting — runs exclusively in the EU (AWS eu-central-1, Frankfurt). Narrowly-scoped specialist processors (e.g. payments, email, maps) are covered by the EU-US Data Privacy Framework or standard contractual clauses (SCCs) — details in the privacy policy (German) and Data Processing Agreement (German).

Encryption

TLS/HTTPS for all data transfers. Encryption at rest at the database level (AES-256). Passwords are hashed with bcrypt (cost factor 10) — never stored in plain text.

Row-Level Security

Every database query is restricted to your organisation through Row-Level Security (RLS). Tenant isolation at the database level — not merely in application logic.

Role-Based Access Control

Managers see team data; field sales reps see only their own. No user can access another organisation's data. Inviting new users is restricted to managers.

Daily Backups

Automatic daily database backups at our EU hosting partner (7-day retention) plus an encrypted off-site backup in separate storage (90-day retention). In the event of an incident, we restore your data from the most recent daily backup.

Cookieless Analytics

Our product analytics are cookieless (Vercel Analytics, without user identifiers). On our public pages, additional services, for example to improve our marketing pages, run only with your consent; without consent, nothing is loaded and no cookie is set.

Compliance & Documentation

All documents you need for your own GDPR compliance — ready to review. Note: contract documents are in German and the German versions are legally binding.

Data Processing Agreement (DPA)

Data Processing Agreement pursuant to Art. 28 GDPR — including technical and organisational measures (TOMs), sub-processor list and breach notification obligation. Contract language is German; the German version prevails.

View DPA (German)

GDPR Rights — Self-Service

Your employees can export the personal data they have provided at any time as a ZIP file (right to data portability under Art. 20 GDPR) and delete their account independently (Art. 17 GDPR) — directly in the account settings. Organisation-wide data export by the manager is separate and takes place within the scope of data processing.

Privacy Policy

Full transparency about all data processing activities, legal bases, retention periods and sub-processors. Available in German only; the German version is legally binding.

Privacy policy (German)

DPIA Template for GPS Tracking

For optional GPS location recording we provide a Data Protection Impact Assessment (DPIA) template (Art. 35 GDPR) that you can use directly for your works council or data protection officer.

Sub-Processors

Complete list of all service providers involved in processing your data. The legally binding version with all obligations is available in the Data Processing Agreement (DPA) (German).

ProviderPurposeData locationTransfer basis
SupabaseDatabase, auth, storageEU FrankfurtDPA under Art. 28 GDPR, EU SCCs
VercelHosting, CDN, analyticsEU FrankfurtEU-US Data Privacy Framework (DPF)
CloudflareEncrypted off-site backup (disaster recovery)EU-jurisdiction bucket (Cloudflare R2; provider seat USA)EU-US DPF + DPA (Cloudflare Customer DPA Art. 28 GDPR); contents client-side encrypted — no technical access by provider
StripePayment processingUSAEU-US DPF, PCI DSS Level 1
ResendTransactional emails (outbound)USAEU-US DPF
Google WorkspaceBusiness email mailbox (incoming enquiries incl. attachments)EU/USA (Google data centres)DPA under Art. 28 GDPR (Google Workspace DPA), EU-US DPF, plus EU SCCs
SentryError monitoringEU (de.sentry.io)EU region; EU-US DPF, plus EU SCCs
CARTOMap tilesUSAEU Standard Contractual Clauses (SCCs, Art. 46 GDPR)
KomootGeocoding (Photon, server-side)Germany (Berlin)EU seat, no third-country transfer
OpenStreetMap FoundationFallback geocoding (Nominatim, server-side)United KingdomUK Adequacy Decision (28 June 2021)
AppleiOS push notifications (APNs), ActivityKit — iOS app onlyUSAApple GDPR DPA, EU SCCs
GoogleRoute export (optional user-initiated deeplink to Google Maps)USAEU-US Data Privacy Framework (DPF)
Have I Been PwnedPassword security check via k-anonymity (no PII transferred)Australiak-anonymity — no personal data transferred
GitHubCI/CD automation; technical execution of off-site backups (database/auth client-side encrypted, photo/document backups TLS + R2 encryption only)USAEU-US DPF, plus EU SCCs (GitHub DPA)

List as of 3. Oktober 2026

Infrastructure Partner Certifications

Our infrastructure runs on platforms whose security controls are independently audited.

AWS SOC 2 Type II (infrastructure partner Supabase)
PCI DSS Level 1 (payment partner Stripe)
SOC 2 Type 2 (hosting partner Vercel — see Vercel Trust Center)
EU-US Data Privacy Framework (Vercel, Stripe, Resend) — Sentry error logging via EU data centre

Automatic Data Deletion

Photos from visit reports are automatically deleted after 24 months — both from the database and from file storage. After cancellation, all data remains available for export for 30 days and is then irrevocably deleted. Data minimisation is not just a promise — it is an automated process.

Frequently asked questions about security, GDPR and compliance

The eight questions that DACH B2B buyers and data protection officers ask most often — answered directly.

Core customer data — database, file storage (photos), auth data and application hosting — is processed exclusively in the EU (AWS eu-central-1, Frankfurt am Main). We additionally use specialist processors based in the USA: Stripe for payment processing (customer email, name, billing address, payment data) and Resend for transactional and marketing emails (recipient email address, mail metadata). These data transfers are covered by the EU-US Data Privacy Framework adequacy decision of 10 July 2023; Vercel, Stripe and Resend are actively DPF-certified. Sentry error logs are processed in an EU data centre (de.sentry.io); because the provider is based in the USA and its data processing addendum does not rule out access from there (for support purposes, for example), this processing is likewise safeguarded by the EU-US Data Privacy Framework and supplementary Standard Contractual Clauses. A complete sub-processor list with purpose, location and transfer safeguard is available in the privacy policy (/datenschutz, German) and the Data Processing Agreement (/avv, German).
Yes. We enter into a Data Processing Agreement pursuant to Art. 28 GDPR with every customer — this applies from first use and therefore also on the free plan. The agreement text is publicly available at /avv (German) and contains technical and organisational measures (TOMs), the complete sub-processor list and the breach notification obligation. You can review the DPA before signing — no hidden clauses.
After cancellation, your data remains available for export for 30 days (CSV/Excel + ZIP of photos). It is then irrevocably deleted from the database, storage and backups. On request we can shorten the 30-day window or extend it for migration projects. Data minimisation is automated — no manual application required.
At the application level, only users within your organisation, filtered by role: managers see team data, field reps see only their own customers and reports. At the database level this is enforced by Row-Level Security (RLS) — even a compromised user account cannot access other organisations. On the provider side, productive database access is performed exclusively by the provider itself — and only for support requests with explicit customer authorisation; support sessions in the application are logged.
GPS location recording is optional and can be disabled in the organisation configuration. It is only captured once at the start of a visit, not in the background. For deployment we provide a DPIA template (Data Protection Impact Assessment under Art. 35 GDPR) that you can use directly for your works council or data protection officer. Disabling GPS only removes automatic address validation — all other features remain available.
In the event of an incident, our breach response procedure applies: (1) internal escalation and forensics within 24 hours, (2) notification to affected customers with specific impacts and recommendations within the statutory 72-hour window under GDPR Art. 33/34, (3) notification to the responsible supervisory authority (State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia — LDI NRW). The notification obligation is contractually binding in our DPA.
All connections run over TLS 1.2 or higher (HTTPS, HSTS enabled). Database contents are encrypted at rest with AES-256. Passwords are never stored in plain text — they are hashed with bcrypt (cost factor 10). Service tokens and webhook secrets are stored in Vercel encrypted environment variables, not in the code repository.
Not directly at this time. Our infrastructure partners are certified: Supabase (SOC 2 Type II via AWS), Vercel (SOC 2 Type 2 + EU-US Data Privacy Framework + ISO 27001:2022), Stripe (PCI DSS Level 1). A separate certification is not cost-effective at our current scale — we rely on the audit results of our partners and a multi-level, internally documented security review process for code changes. A custom penetration test audit can be commissioned on request.

More about AußendienstApp

Pricing

Transparent plan, 14-day notice period, no credit card required.

All Features

What the app can do — template builder, dashboard, route planning — and what sits in which tier.

View Data Processing Agreement (German)

Complete Data Processing Agreement under Art. 28 GDPR incl. TOMs. Contract language is German.

Privacy Policy (German)

All data processing activities, legal bases and retention periods in detail.

Questions about security? We’ll walk through them with you.

You can start on your own — or we set the app up together with you and go through your data-protection questions with you. The DPA and DPIA template are ready for you.

Get in touchRequest a demo