What follows is the substance of our data processing agreement, in plainer words. Where the two differ, the agreement is what counts.
Where your data is
The service runs exclusively in data centres in Germany, operated by Schwarz Digits Cloud GmbH & Co. KG (STACKIT), Bad Friedrichshall. Everything stored in the service stays there: bills of materials, findings, cases, report texts and the audit log. Data is encrypted in transit and at rest.
E-mail
Sign-in links and alerts are delivered by Brevo GmbH, Berlin, whose servers are in the European Union. Brevo uses service providers and group companies outside the EU for hosting, delivery, support and maintenance; only what an e-mail needs can be affected, under the European Commission’s standard contractual clauses and, where applicable, the EU-U.S. Data Privacy Framework.
Who else processes your data
These two, and nobody else. The list is the one in Annex 3 of the data processing agreement.
Sub-processors of the BitHive Reporting Desk.
Processor
Service
Where
Third-country safeguards
Schwarz Digits Cloud GmbH & Co. KG (STACKIT), Bad Friedrichshall, Germany
Cloud hosting: servers, managed database, storage
Germany
Not applicable: no processing outside the EU
Brevo GmbH, Berlin, Germany
Delivery of transactional e-mail: sign-in links and alerts
European Union (servers in France and Belgium)
Standard contractual clauses and, where applicable, the EU-U.S. Data Privacy Framework, limited to what delivery requires
Technical and organisational measures
The same substance as Annex 2 of the data processing agreement.
Confidentiality
Data centres in Germany with access control and ISO/IEC 27001 certification; we operate no server rooms of our own.
Administrative access only through personal accounts with multi-factor authentication, no shared accounts, least privilege.
Strict separation of customers: every record carries its account, and the database enforces the separation with row-level security in addition to the application.
Sign-in without passwords, through one-time links; API tokens stored only as cryptographic hashes, restrictable and revocable.
Production, test and development are separate, and no customer data is used outside production.
Integrity
All connections encrypted with TLS 1.2 or higher.
Alert e-mails carry only what they need and link to the service.
An append-only audit log of every relevant action, per account, with time and user.
Every change is reviewed and passes automated tests, static analysis and a dependency vulnerability scan before deployment; images are built reproducibly.
Availability
Managed database with automatic backups and point-in-time recovery; the restore procedure is tested on every change in our pipeline and at least monthly against production.
Data encrypted at rest.
External monitoring outside our own infrastructure, which alarms us when the service, a data source or an alert delivery stops, and a documented incident procedure.
Review
Access rights reviewed at least quarterly; the measures at least annually and after significant changes.
Automated weekly checks for updates of the software components we use.
Data protection by default: only what the service needs, no tracking, no advertising, and no use of customer data for anything else, in particular not for training AI models.
The documents themselves
Terms, data processing agreement, privacy notice and service level agreement, each version at its own address.
How BitHive itself works — who has access to what, how a change reaches production, and how to report a vulnerability to us — is on the company’s security page.