Data & More

Security & Compliance

Security Center

How Data & More protects customer data. This page answers the security, privacy, and operations questions that vendor assessments and due-diligence questionnaires ask most often. Data & More builds GDPR and data-compliance software for banks, pension funds, insurers, real-estate and industrial companies.

ISAE 3000 & 3402 Type IIEU/EEA-only data processing24-hour breach notificationDedicated EU serversTLS 1.3 in transitOne sub-processor

Data & More ApS · Founded 2016 · Flæsketorvet 68, 1711 Copenhagen V, Denmark · CVR 38185659

Certifications & audits

Baker Tilly Denmark audits Data & More every year against two international assurance standards. The first reports were issued on 18 July 2025.

ISAE 3000 Type II
Covers GDPR and the compliance framework — issued with no remarks
ISAE 3402 Type II
Covers internal controls as a service organization
Audit cadence
Annual, performed by Baker Tilly Denmark
ISO/IEC 27001
In progress — certification expected by the end of 2026

Good to know

  • Hetzner, the hosting provider for SaaS deployments, is ISO/IEC 27001 certified.
Request the current ISAE reports through your Data & More contact or support@dataandmore.com.

Data hosting & residency

You choose where the platform runs. Customer data stays inside the EU/EEA in every deployment model.

Deployment models

  • SaaS — Data & More hosts the platform on dedicated bare-metal servers at Hetzner in Falkenstein (Germany) and Helsinki (Finland).
  • On-premise — the platform runs inside your own infrastructure.
  • Your data center — the platform runs on hardware in a data center you control.

Data residency

  • No multi-tenant public cloud: SaaS deployments run on dedicated physical servers.
  • All processing takes place within the EU/EEA. The data processing agreement contractually bars transfers outside the EU/EEA.
  • Staff outside the EU/EEA never access customer data.
  • Hetzner data centers use video-monitored perimeters, electronic access control, and logged entry.

GDPR & data processing

Data & More processes customer data as a processor under Article 28 GDPR. A data processing agreement (DPA) based on the Danish Data Protection Agency's (Datatilsynet) standard clauses governs every engagement.

How the platform handles data

  • Reads data at the source — Microsoft 365 via Microsoft Graph, on-premise Exchange, SharePoint, file shares, and Slack. No data migration.
  • Data Minimization Manager applies your retention and deletion policies. Nothing is deleted silently: every deletion requires explicit human approval in a validation workflow.
  • Data Subject Manager supports data subject access requests (DSARs), including export of results.
  • An immutable audit log records every deletion.
Processing location
EU/EEA only — transfers outside are contractually barred
DPA template
Danish Datatilsynet standard clauses
Erasure after contract end
Within 30 days

Sub-processors

Data & More uses a single sub-processor. No other third party processes customer data.

Sub-processor
Hetzner Online GmbH
Role
Physical hosting of SaaS deployments on dedicated bare-metal servers
Locations
Falkenstein, Germany · Helsinki, Finland
Change notice
30 days' advance notice before any sub-processor change

Access control & authentication

Access follows least privilege: every account is personal, scoped by role, and reviewed quarterly.

  • Single sign-on (SSO) through Microsoft Entra ID or Windows Active Directory, using OAuth 2.0 / OpenID Connect.
  • Multi-factor authentication (MFA) is mandatory for all administrators and for high-risk systems.
  • Role-based access control with four default roles: Administrator, DPO, Project Manager, and End-User.
  • Password policy follows NIST guidance: minimum 12 characters, no forced rotation when MFA is active.
  • No shared accounts. Access reviews run quarterly.
  • Developers have no access to live customer environments.

Environment permissions

Microsoft 365 access is granted through three consent packages. You only approve the package that matches how you use the platform. That is why the three exist: a demo never receives deletion or DLP-control rights, and DLP-only scopes are not requested until you turn DLP on.

DEMO
Read-only evaluation. Scans mail and files, reads the directory, and sends reports. Cannot delete, label, or change content.
Production
Full processing. Finds and classifies personal data, then applies approved deletions and labels across Exchange, OneDrive, SharePoint, and Teams.
Production + DLP
Production plus real-time Data Loss Prevention: alert or block sensitive sharing, including Copilot, and enforce Exchange transport rules.

Why each package is needed

  • DEMO — used for proofs of concept and trials. Microsoft Graph is limited to read scopes (Directory.Read.All, User.Read.All, Mail.Read, Files.Read.All) plus Mail.Send for reports. Write and delete scopes are omitted on purpose.
  • Production — Data Minimization Manager and Data Subject Manager need write scopes (Mail.ReadWrite, Files.ReadWrite.All, SharePoint Sites.ReadWrite.All / Sites.FullControl.All, Teams read, mailbox settings, and MIP label read) so approved retention, deletion, and labeling can run. Nothing is deleted without explicit human approval.
  • Production + DLP — adds Copilot read (AiEnterpriseInteraction.Read.All), Teams app install, audit-log query, and Exchange ManageAsApp so DLP can watch content as it is shared and alert or block in real time. Only customers who enable DLP consent to this package.

Encryption

Encryption protects customer data in transit, at rest, and in backups.

In transit
TLS 1.3
Outbound transfers
AES-256
At rest
Encrypted disks and endpoints
Backups
Encrypted

Security testing & development

Testing

  • Penetration testing is ongoing. An independent third party also runs an external penetration test four times a year. All findings are remediated.
  • Continuous vulnerability management, with daily checks for critical updates.

Secure development

  • Secure software development lifecycle (SSDLC) with Security and Privacy by Design.
  • Separated development, staging, and production environments.
  • No production personal data in development or test environments.
  • Two-person code review before changes ship.

Incident response

Data & More notifies affected customers within 24 hours of a confirmed personal-data breach.

  • A documented incident-response process covers severity triage, containment, and postmortem analysis.
  • Employees report suspected incidents immediately through a mandatory internal reporting duty.
Notification commitment
Within 24 hours of a confirmed personal-data breach
Track record
No security incidents or data breaches since the company was founded in 2016

Backups & data exit

Backups are encrypted and retained for 30 days. When a contract ends, customer data leaves Data & More systems on a fixed schedule.

Data exit

  • Workspace deletion removes all customer data from the platform.
  • Backups expire within 30 days.
  • The DPA commits Data & More to erasure within 30 days of contract end.

AI & data usage

The platform uses machine-learning components to find and classify personal data.

Components

  • SpaCy — named-entity recognition (NER) for detecting personal data in text.
  • YOLOv3 — image recognition.
  • Tesseract — optical character recognition (OCR).
  • A chat-based chart builder for dashboard graphs.

Optional capabilities

  • Optional MCP connection via API key — no access to personal data.
  • Optional local LLM — AI analysis that explains classification results.
All processing, including the AI components, stays within the EU/EEA.

Support & contact

Email
support@dataandmore.com — monitored 06:00–22:00 CET, every day
Phone
During office hours
Documentation
This support portal

For security questionnaires, audit reports, and DPA requests, contact your account manager or support@dataandmore.com.

Last reviewed: August 2026

This page summarizes Data & More's security and operations practices. Contractual commitments are defined in your agreement and data processing agreement.