Security & Compliance
Security Center
How Data & More protects customer data. This page answers the security, privacy, and operations questions that vendor assessments and due-diligence questionnaires ask most often. Data & More builds GDPR and data-compliance software for banks, pension funds, insurers, real-estate and industrial companies.
Data & More ApS · Founded 2016 · Flæsketorvet 68, 1711 Copenhagen V, Denmark · CVR 38185659
Certifications & audits
Baker Tilly Denmark audits Data & More every year against two international assurance standards. The first reports were issued on 18 July 2025.
- ISAE 3000 Type II
- Covers GDPR and the compliance framework — issued with no remarks
- ISAE 3402 Type II
- Covers internal controls as a service organization
- Audit cadence
- Annual, performed by Baker Tilly Denmark
- ISO/IEC 27001
- In progress — certification expected by the end of 2026
Good to know
- Hetzner, the hosting provider for SaaS deployments, is ISO/IEC 27001 certified.
Data hosting & residency
You choose where the platform runs. Customer data stays inside the EU/EEA in every deployment model.
Deployment models
- SaaS — Data & More hosts the platform on dedicated bare-metal servers at Hetzner in Falkenstein (Germany) and Helsinki (Finland).
- On-premise — the platform runs inside your own infrastructure.
- Your data center — the platform runs on hardware in a data center you control.
Data residency
- No multi-tenant public cloud: SaaS deployments run on dedicated physical servers.
- All processing takes place within the EU/EEA. The data processing agreement contractually bars transfers outside the EU/EEA.
- Staff outside the EU/EEA never access customer data.
- Hetzner data centers use video-monitored perimeters, electronic access control, and logged entry.
GDPR & data processing
Data & More processes customer data as a processor under Article 28 GDPR. A data processing agreement (DPA) based on the Danish Data Protection Agency's (Datatilsynet) standard clauses governs every engagement.
How the platform handles data
- Reads data at the source — Microsoft 365 via Microsoft Graph, on-premise Exchange, SharePoint, file shares, and Slack. No data migration.
- Data Minimization Manager applies your retention and deletion policies. Nothing is deleted silently: every deletion requires explicit human approval in a validation workflow.
- Data Subject Manager supports data subject access requests (DSARs), including export of results.
- An immutable audit log records every deletion.
- Processing location
- EU/EEA only — transfers outside are contractually barred
- DPA template
- Danish Datatilsynet standard clauses
- Erasure after contract end
- Within 30 days
Sub-processors
Data & More uses a single sub-processor. No other third party processes customer data.
- Sub-processor
- Hetzner Online GmbH
- Role
- Physical hosting of SaaS deployments on dedicated bare-metal servers
- Locations
- Falkenstein, Germany · Helsinki, Finland
- Change notice
- 30 days' advance notice before any sub-processor change
Access control & authentication
Access follows least privilege: every account is personal, scoped by role, and reviewed quarterly.
- Single sign-on (SSO) through Microsoft Entra ID or Windows Active Directory, using OAuth 2.0 / OpenID Connect.
- Multi-factor authentication (MFA) is mandatory for all administrators and for high-risk systems.
- Role-based access control with four default roles: Administrator, DPO, Project Manager, and End-User.
- Password policy follows NIST guidance: minimum 12 characters, no forced rotation when MFA is active.
- No shared accounts. Access reviews run quarterly.
- Developers have no access to live customer environments.
Environment permissions
Microsoft 365 access is granted through three consent packages. You only approve the package that matches how you use the platform. That is why the three exist: a demo never receives deletion or DLP-control rights, and DLP-only scopes are not requested until you turn DLP on.
- DEMO
- Read-only evaluation. Scans mail and files, reads the directory, and sends reports. Cannot delete, label, or change content.
- Production
- Full processing. Finds and classifies personal data, then applies approved deletions and labels across Exchange, OneDrive, SharePoint, and Teams.
- Production + DLP
- Production plus real-time Data Loss Prevention: alert or block sensitive sharing, including Copilot, and enforce Exchange transport rules.
Why each package is needed
- DEMO — used for proofs of concept and trials. Microsoft Graph is limited to read scopes (Directory.Read.All, User.Read.All, Mail.Read, Files.Read.All) plus Mail.Send for reports. Write and delete scopes are omitted on purpose.
- Production — Data Minimization Manager and Data Subject Manager need write scopes (Mail.ReadWrite, Files.ReadWrite.All, SharePoint Sites.ReadWrite.All / Sites.FullControl.All, Teams read, mailbox settings, and MIP label read) so approved retention, deletion, and labeling can run. Nothing is deleted without explicit human approval.
- Production + DLP — adds Copilot read (AiEnterpriseInteraction.Read.All), Teams app install, audit-log query, and Exchange ManageAsApp so DLP can watch content as it is shared and alert or block in real time. Only customers who enable DLP consent to this package.
Encryption
Encryption protects customer data in transit, at rest, and in backups.
- In transit
- TLS 1.3
- Outbound transfers
- AES-256
- At rest
- Encrypted disks and endpoints
- Backups
- Encrypted
Security testing & development
Testing
- Penetration testing is ongoing. An independent third party also runs an external penetration test four times a year. All findings are remediated.
- Continuous vulnerability management, with daily checks for critical updates.
Secure development
- Secure software development lifecycle (SSDLC) with Security and Privacy by Design.
- Separated development, staging, and production environments.
- No production personal data in development or test environments.
- Two-person code review before changes ship.
Incident response
Data & More notifies affected customers within 24 hours of a confirmed personal-data breach.
- A documented incident-response process covers severity triage, containment, and postmortem analysis.
- Employees report suspected incidents immediately through a mandatory internal reporting duty.
- Notification commitment
- Within 24 hours of a confirmed personal-data breach
- Track record
- No security incidents or data breaches since the company was founded in 2016
Backups & data exit
Backups are encrypted and retained for 30 days. When a contract ends, customer data leaves Data & More systems on a fixed schedule.
Data exit
- Workspace deletion removes all customer data from the platform.
- Backups expire within 30 days.
- The DPA commits Data & More to erasure within 30 days of contract end.
AI & data usage
The platform uses machine-learning components to find and classify personal data.
Components
- SpaCy — named-entity recognition (NER) for detecting personal data in text.
- YOLOv3 — image recognition.
- Tesseract — optical character recognition (OCR).
- A chat-based chart builder for dashboard graphs.
Optional capabilities
- Optional MCP connection via API key — no access to personal data.
- Optional local LLM — AI analysis that explains classification results.
Support & contact
- support@dataandmore.com — monitored 06:00–22:00 CET, every day
- Phone
- During office hours
- Documentation
- This support portal
For security questionnaires, audit reports, and DPA requests, contact your account manager or support@dataandmore.com.
Last reviewed: August 2026
This page summarizes Data & More's security and operations practices. Contractual commitments are defined in your agreement and data processing agreement.