Data & More

Security & Compliance

Trust Center

How Data & More protects customer data. This page answers the security, privacy, and operations questions that vendor assessments and due-diligence questionnaires ask most often. Data & More builds GDPR and data-compliance software for banks, pension funds, insurers, real-estate and industrial companies.

ISAE 3000 & 3402 Type IIEU/EEA-only data processing24-hour breach notificationDedicated EU serversTLS 1.3 in transitOne sub-processor

Data & More ApS · Founded 2016 · Flæsketorvet 68, 1711 Copenhagen V, Denmark · CVR 38185659

Certifications & audits

Baker Tilly Denmark audits Data & More every year against two international assurance standards. The first reports were issued on 18 July 2025.

ISAE 3000 Type II
Covers GDPR and the compliance framework — issued with no remarks
ISAE 3402 Type II
Covers internal controls as a service organization
Audit cadence
Annual, performed by Baker Tilly Denmark
ISO/IEC 27001
In progress — certification expected by the end of 2026

Good to know

  • Hetzner, the hosting provider for SaaS deployments, is ISO/IEC 27001 certified.
  • Data & More does not hold TISAX certification.
Request the current ISAE reports through your Data & More contact or support@dataandmore.com.

Data hosting & residency

You choose where the platform runs. Customer data stays inside the EU/EEA in every deployment model.

Deployment models

  • SaaS — Data & More hosts the platform on dedicated bare-metal servers at Hetzner in Falkenstein (Germany) and Helsinki (Finland).
  • On-premise — the platform runs inside your own infrastructure.
  • Your data center — the platform runs on hardware in a data center you control.

Data residency

  • No multi-tenant public cloud: SaaS deployments run on dedicated physical servers.
  • All processing takes place within the EU/EEA. The data processing agreement contractually bars transfers outside the EU/EEA.
  • Staff outside the EU/EEA never access customer data.
  • Hetzner data centers use video-monitored perimeters, electronic access control, and logged entry.

GDPR & data processing

Data & More processes customer data as a processor under Article 28 GDPR. A data processing agreement (DPA) based on the Danish Data Protection Agency's (Datatilsynet) standard clauses governs every engagement.

How the platform handles data

  • Reads data at the source — Microsoft 365 via Microsoft Graph, on-premise Exchange, SharePoint, file shares, and Slack. No data migration.
  • Data Minimization Manager applies your retention and deletion policies. Nothing is deleted silently: every deletion requires explicit human approval in a validation workflow.
  • Data Subject Manager supports data subject access requests (DSARs), including export of results.
  • An immutable audit log records every deletion.
Processing location
EU/EEA only — transfers outside are contractually barred
DPA template
Danish Datatilsynet standard clauses
Erasure after contract end
Within 30 days

Sub-processors

Data & More uses a single sub-processor. No other third party processes customer data.

Sub-processor
Hetzner Online GmbH
Role
Physical hosting of SaaS deployments on dedicated bare-metal servers
Locations
Falkenstein, Germany · Helsinki, Finland
Change notice
30 days' advance notice before any sub-processor change

Access control & authentication

Access follows least privilege: every account is personal, scoped by role, and reviewed quarterly.

  • Single sign-on (SSO) through Microsoft Entra ID or Windows Active Directory, using OAuth 2.0 / OpenID Connect.
  • Multi-factor authentication (MFA) is mandatory for all administrators and for high-risk systems.
  • Role-based access control with four default roles: Administrator, DPO, Project Manager, and End-User.
  • Password policy follows NIST guidance: minimum 12 characters, no forced rotation when MFA is active.
  • No shared accounts. Access reviews run quarterly.
  • Developers have no access to live customer environments.

Encryption

Encryption protects customer data in transit, at rest, and in backups.

In transit
TLS 1.3
Outbound transfers
AES-256
At rest
Encrypted disks and endpoints
Backups
Encrypted

Security testing & development

Testing

  • An independent third party runs a gray-box penetration test every year. All findings are remediated.
  • Continuous vulnerability management, with daily checks for critical updates.

Secure development

  • Secure software development lifecycle (SSDLC) with Security and Privacy by Design.
  • Separated development, staging, and production environments.
  • No production personal data in development or test environments.
  • Two-person code review before changes ship.

Incident response

Data & More notifies affected customers within 24 hours of a confirmed personal-data breach.

  • A documented incident-response process covers severity triage, containment, and postmortem analysis.
  • Employees report suspected incidents immediately through a mandatory internal reporting duty.
Notification commitment
Within 24 hours of a confirmed personal-data breach
Track record
No security incidents or data breaches since the company was founded in 2016

Backups & data exit

Backups are encrypted and retained for 30 days. When a contract ends, customer data leaves Data & More systems on a fixed schedule.

Data exit

  • Workspace deletion removes all customer data from the platform.
  • Backups expire within 30 days.
  • The DPA commits Data & More to erasure within 30 days of contract end.

AI & data usage

The platform uses machine-learning components to find and classify personal data.

Components

  • SpaCy — named-entity recognition (NER) for detecting personal data in text.
  • YOLOv3 — image recognition.
  • Tesseract — optical character recognition (OCR).
  • A chat-based chart builder for dashboard graphs.
All processing, including the AI components, stays within the EU/EEA.

Support & contact

Email
support@dataandmore.com — monitored 06:00–22:00 CET, every day
Phone
During office hours
Documentation
This support portal

For security questionnaires, audit reports, and DPA requests, contact your account manager or support@dataandmore.com.

Last reviewed: August 2026

This page summarizes Data & More's security and operations practices. Contractual commitments are defined in your agreement and data processing agreement.