Security & Compliance
Trust Center
How Data & More protects customer data. This page answers the security, privacy, and operations questions that vendor assessments and due-diligence questionnaires ask most often. Data & More builds GDPR and data-compliance software for banks, pension funds, insurers, real-estate and industrial companies.
Data & More ApS · Founded 2016 · Flæsketorvet 68, 1711 Copenhagen V, Denmark · CVR 38185659
Certifications & audits
Baker Tilly Denmark audits Data & More every year against two international assurance standards. The first reports were issued on 18 July 2025.
- ISAE 3000 Type II
- Covers GDPR and the compliance framework β issued with no remarks
- ISAE 3402 Type II
- Covers internal controls as a service organization
- Audit cadence
- Annual, performed by Baker Tilly Denmark
- ISO/IEC 27001
- In progress β certification expected by the end of 2026
Good to know
- Hetzner, the hosting provider for SaaS deployments, is ISO/IEC 27001 certified.
- Data & More does not hold TISAX certification.
Data hosting & residency
You choose where the platform runs. Customer data stays inside the EU/EEA in every deployment model.
Deployment models
- SaaS β Data & More hosts the platform on dedicated bare-metal servers at Hetzner in Falkenstein (Germany) and Helsinki (Finland).
- On-premise β the platform runs inside your own infrastructure.
- Your data center β the platform runs on hardware in a data center you control.
Data residency
- No multi-tenant public cloud: SaaS deployments run on dedicated physical servers.
- All processing takes place within the EU/EEA. The data processing agreement contractually bars transfers outside the EU/EEA.
- Staff outside the EU/EEA never access customer data.
- Hetzner data centers use video-monitored perimeters, electronic access control, and logged entry.
GDPR & data processing
Data & More processes customer data as a processor under Article 28 GDPR. A data processing agreement (DPA) based on the Danish Data Protection Agency's (Datatilsynet) standard clauses governs every engagement.
How the platform handles data
- Reads data at the source β Microsoft 365 via Microsoft Graph, on-premise Exchange, SharePoint, file shares, and Slack. No data migration.
- Data Minimization Manager applies your retention and deletion policies. Nothing is deleted silently: every deletion requires explicit human approval in a validation workflow.
- Data Subject Manager supports data subject access requests (DSARs), including export of results.
- An immutable audit log records every deletion.
- Processing location
- EU/EEA only β transfers outside are contractually barred
- DPA template
- Danish Datatilsynet standard clauses
- Erasure after contract end
- Within 30 days
Sub-processors
Data & More uses a single sub-processor. No other third party processes customer data.
- Sub-processor
- Hetzner Online GmbH
- Role
- Physical hosting of SaaS deployments on dedicated bare-metal servers
- Locations
- Falkenstein, Germany Β· Helsinki, Finland
- Change notice
- 30 days' advance notice before any sub-processor change
Access control & authentication
Access follows least privilege: every account is personal, scoped by role, and reviewed quarterly.
- Single sign-on (SSO) through Microsoft Entra ID or Windows Active Directory, using OAuth 2.0 / OpenID Connect.
- Multi-factor authentication (MFA) is mandatory for all administrators and for high-risk systems.
- Role-based access control with four default roles: Administrator, DPO, Project Manager, and End-User.
- Password policy follows NIST guidance: minimum 12 characters, no forced rotation when MFA is active.
- No shared accounts. Access reviews run quarterly.
- Developers have no access to live customer environments.
Encryption
Encryption protects customer data in transit, at rest, and in backups.
- In transit
- TLS 1.3
- Outbound transfers
- AES-256
- At rest
- Encrypted disks and endpoints
- Backups
- Encrypted
Security testing & development
Testing
- An independent third party runs a gray-box penetration test every year. All findings are remediated.
- Continuous vulnerability management, with daily checks for critical updates.
Secure development
- Secure software development lifecycle (SSDLC) with Security and Privacy by Design.
- Separated development, staging, and production environments.
- No production personal data in development or test environments.
- Two-person code review before changes ship.
Incident response
Data & More notifies affected customers within 24 hours of a confirmed personal-data breach.
- A documented incident-response process covers severity triage, containment, and postmortem analysis.
- Employees report suspected incidents immediately through a mandatory internal reporting duty.
- Notification commitment
- Within 24 hours of a confirmed personal-data breach
- Track record
- No security incidents or data breaches since the company was founded in 2016
Backups & data exit
Backups are encrypted and retained for 30 days. When a contract ends, customer data leaves Data & More systems on a fixed schedule.
Data exit
- Workspace deletion removes all customer data from the platform.
- Backups expire within 30 days.
- The DPA commits Data & More to erasure within 30 days of contract end.
AI & data usage
The platform uses machine-learning components to find and classify personal data.
Components
- SpaCy β named-entity recognition (NER) for detecting personal data in text.
- YOLOv3 β image recognition.
- Tesseract β optical character recognition (OCR).
- A chat-based chart builder for dashboard graphs.
Support & contact
- support@dataandmore.com β monitored 06:00β22:00 CET, every day
- Phone
- During office hours
- Documentation
- This support portal
For security questionnaires, audit reports, and DPA requests, contact your account manager or support@dataandmore.com.
Last reviewed: August 2026
This page summarizes Data & More's security and operations practices. Contractual commitments are defined in your agreement and data processing agreement.