Home › Security & compliance
We are American. Your data is not.
The audit trail part is straightforward: every entry is time-stamped, attributed and cannot be edited away afterwards. The question German procurement actually asks is what a Delaware parent means for their residents' data, so that is where this page starts.
Where the data actually sits
In Frankfurt, with a failover copy in Dublin. It is held and processed by Viewde EMEA Limited, which is an Irish company, and in normal operation it never leaves the EEA.
Who can access it
Support and engineering staff in Cork and remotely within the EU. Access is named, justified, multi-factor authenticated and logged, and every log is available to you on request.
What the New York office can see
Nothing, as a matter of routine. Three people work there and none has standing access. If a US engineer is genuinely needed during an incident, access is opened for that incident, expires by itself, and turns up in the write-up you receive. It happened four times last year.
Government access requests
We have never had one for European customer data. If we do, we will challenge it where there are grounds to and tell you unless we are legally barred from doing so. We publish a short statement on this twice a year, including when the answer is still nothing.
Sub-processors
Six, of which five are EU-established. The one US sub-processor handles marketing email for our own communications and never touches care data. The full register is published and customers receive 30 days' notice of changes.
No model training
Resident and staff data is not used to train machine learning models, ours or anyone else's. That sits in the contract rather than in a policy we could quietly rewrite. Interaction checking runs off a licensed clinical database.
The technical detail
| Hosting | Frankfurt primary, Dublin failover, both inside the EU. |
|---|---|
| Encryption | TLS 1.3 in transit, AES-256 at rest, keys in an EU-hosted HSM, rotated annually. |
| Authentication | PIN or biometric on shared devices, password and MFA on desktop, SAML single sign-on for Group customers. |
| Backups | Hourly incremental, nightly full, 35-day retention, all within the EU. RPO 15 minutes, RTO 2 hours. |
| Availability | 99.96% over twelve months. Monthly figures and incident write-ups published within five working days. |
| Certifications | ISO 27001:2022, audited annually. TISAX assessment at AL2, held because two German group customers asked for it. Certificates and the TISAX scope ID are sent on request, the latter through the ENX portal. |
| NIS2 | In scope as a digital provider to essential services in several member states. Our compliance position and incident reporting route are documented for customers. |
| EU AI Act | The platform contains no high-risk AI system. Transcription and translation are documented as limited-risk with transparency obligations met; the position is reviewed twice a year. |
| Accessibility | EN 301 549 and WCAG 2.2 AA, independently audited January 2026. Known gaps are listed in our accessibility statement. |
| Penetration testing | Annually by an external firm, plus targeted testing on major releases. Executive summary available under NDA. |
| Retention and deletion | Ten years by default for German care records, configurable per country. Permanent deletion 90 days after contract end unless instructed otherwise. |
| Breach notification | Customers notified within 24 hours of us becoming aware, with an initial assessment, whether or not the incident is notifiable. |
Documents for your procurement team
Nine documents, sent as one pack, usually within a working day. In German where a German version exists.
Ask info@viewde.com for the pack, or your implementation partner, who holds the current version.
Send the pack to your procurement team
One email gets all of it, usually within a working day, with a named person to ask about any of it.