Security and Data Protection
What is enforced technically, where data is generated, and how long it is retained.
Tenant separation
Each company sees only its own data. The association is derived for every individual request from your verified sign-in, never from anything the request itself could include. This means that access to another tenant's record is not merely prohibited, it is impossible.
All security-related processes are recorded in a log that is append only and never changed.
Location data
There is no continuous location tracking. The app only requests foreground permission and retrieves exactly one point when the security officer clocks in or out.
At check-in, the time and coordinates are stored. At check-out, the point is only used for verification and then discarded. The data model simply has no field for it.
When a checkpoint is scanned, the location is optional and is only recorded.
Bank data is handled just as sparingly: a customer's IBAN is only an input value. In the Cockpit, it subsequently appears only masked, with the first and last four characters, and it does not appear at all in the customer portal. Entering it again replaces the stored value.
Legal texts and AVV
General Terms and Conditions, the privacy policy, terms of use, and the Auftragsverarbeitungsvertrag, meaning the data processing agreement, are versioned and presented for acceptance, only to the roles they concern.
The AVV requires a signature in text form, meaning a name typed by the user. A checkbox alone is expressly insufficient. The user, time, version, and IP address are logged. A confirmation can be sent by email on request.
The consent gate guides every role through the versions still open for them before they continue working. You remain responsible for implementing their content in your operations.
Retention and deletion
Closed support requests are deleted automatically after 14 days, Cockpit messages after 30 days, and incoming WhatsApp messages after 90 days.
Conversely, there are deletion locks: sites with guard logbook entries or patrol scans and security officers with an actual work history cannot be deleted. Deactivation is the correct path. Evidence that could be removed by deleting a master record would be worthless as evidence.
Related
- Team and RolesSix roles, with a finely structured set of permissions above them. What someone sees is determined by the permission, not the role alone.
- John AI, the Replacement AgentFinds replacements for uncovered shifts and contacts security officers in stages. Completely disabled by default.
- Customer PortalYour customer sees their sites without you sending anything by email. And without seeing more than you enable.
Updated on: 03.09.2026