Data & Security

Security is built into every product we run, not bolted on afterwards. Below is an overview of the infrastructure, encryption, and compliance standards that protect your data across our platforms.

At a glance

ISO 27001 certified company
Servers hosted in Germany (Hetzner)
Encryption at rest and in transit
GDPR compliant data handling
PCI DSS Level 1 payment processing via Stripe
24/7 threat monitoring and intrusion blocking

Infrastructure & Hosting

Our applications, including upSync, are hosted on servers operated by Hetzner Online GmbH, based in Germany. Hetzner is one of Europe's largest hosting providers, with data centres in Nuremberg and Falkenstein, Germany.

Hosting our infrastructure within Germany also ensures that data relating to EU residents remains within the European Union and subject to EU data protection law.

Encryption

Threat Monitoring

We use a globally recognised threat monitoring and protection service to continuously monitor inbound traffic to our platforms, automatically detecting and blocking malicious requests, denial-of-service attempts, and known attack patterns before they reach our application servers.

Payment & Card Data

We do not store credit card or payment card numbers on our own servers at any point. All payment processing is handled directly by Stripe, a certified PCI DSS Level 1 service provider, the highest level of certification available in the payments industry.

Data Retention & Deletion

We retain customer data only for as long as is necessary to provide our service. When a customer cancels or deletes their subscription, all associated data is permanently destroyed, including:

This ensures that no customer data is retained beyond the point at which it is no longer required to deliver the service.

GDPR & Data Protection

We comply with the EU General Data Protection Regulation (GDPR) in respect of the processing of personal data belonging to individuals residing in the European Union. This includes ensuring data is processed lawfully, fairly, and transparently, kept no longer than necessary, and protected by appropriate technical and organisational measures.

Compliance & Certification

Smart IT Group is an ISO 27001 certified company. ISO 27001 is the internationally recognised standard for information security management systems, requiring a documented, audited, and continually improved approach to managing information security risk across our organisation, not just our hosting environment.

Questions about our security?

Get in touch with our team and we'll be happy to help.

Contact Us