Draft, subject to legal review. Not an offer or legal advice.
Security and data protection
Version 0.2 of 04/10/2026
A record of works contains employees' data and descriptions of their work. This page explains how we protect it. The legal terms are in the Data Processing Agreement (DPA), and the risk analysis in the DPIA support assessment.
Data stored and processed in the EU
All data is stored and processed in the European Union, including the AI review. The database and the application run in Frankfurt, and AI requests are handled only in AWS regions within the EU.
| Provider | Purpose | Location of processing |
|---|---|---|
| Supabase | Database, sign-in, files | EU (Frankfurt, AWS eu-central-1) |
| Vercel | Application hosting | EU (Frankfurt, fra1) |
| Amazon Web Services | AI pre-review (Amazon Bedrock); email sending (Amazon SES), when switched on | EU (AWS regions in the EU) |
Keeping companies apart
- Each company sees only its own data. The database itself enforces this (row-level security), not just the application.
- Automated tests on every code change check that a user of one company cannot read or change another's data, even when bypassing the application.
- Every new table must pass these tests before it reaches production.
Access and roles
- Roles within a company: submitter, approver, admin and auditor. Each person sees only what their role needs.
- Changes to settings, roles and users go through controlled functions and are recorded in the audit log.
- Attachments are private. Downloading requires permission and uses a link valid for 60 seconds.
A record that cannot be changed
- An approved submission is locked; a correction creates a new, linked version and the previous one is kept.
- Every submit stores a copy of the submission's content.
- The audit log is chained with checksums, so editing or removing an entry is detectable. Admins and auditors can check it in the app.
The AI review
- The AI model receives only the work entry and the review criteria, without names or email addresses from the system. We ask employees not to put personal data in descriptions.
- We use Claude models on Amazon Bedrock in the EU region. Data is not used to train models.
- The AI only advises: a person always makes the decision.
Technical protection
- Encrypted connections (TLS) and encryption at rest.
- Security headers (including Content Security Policy and HSTS) that limit attacks in the browser.
- Limits on text length and the number of operations that reduce the impact of misuse.
- Technical logs without submission content, names or email addresses.
GDPR
- We act as a processor under the Data Processing Agreement; your company is the controller.
- A company admin can export a person's data and correct it in the app.
- The retention period is a company setting (off by default; when on, at least 5 years). After it, data is removed and people who have left are anonymised.
Security questions or reporting a vulnerability: contact form.