Skip to content

Your data stays in the EU, under your control

Servers in Germany, backups in Finland, integration keys encrypted, access by roles. Below is how it works, without general words.

Where the data lives

Production servers

Nuremberg, Germany. A Hetzner site inside the European Union.

Backups

Helsinki, Finland. A separate site of the same provider.

Data does not leave the European Union. Infrastructure provider — Hetzner Online GmbH.

Backups

A backup nobody has tried to restore is not a backup.

  • Database snapshots — every hour.
  • A full backup — daily, copied to the remote site.
  • Snapshots of the remote storage — daily, ten days deep.
  • Restoring from a backup is verified automatically every week.
  • Snapshots of the remote storage are managed only from the provider console with two-factor sign-in: they cannot be deleted from the working server.

Access protection

  • HTTPS across the site and the application; certificates renew automatically.
  • Every account is an isolated workspace: one company cannot reach another company data.
  • Rights inside an account are set by roles, and the administrator configures the set.
  • Across a partner link the other side sees only what the data owner opened.
  • Public links to offers and showcases work on a one-time token — with an expiry and a revoke.
  • Integration keys (messengers, telephony, language models) are stored encrypted in the database, AES-256-GCM; the interface shows only the last characters.
  • User passwords are stored as a hash only (bcrypt).
  • Administrator actions and work with public documents go into the security event log.

Personal data

Data controller

Site operator

RICO Technology S.R.L., Chișinău, Republic of Moldova

Privacy policyCookies

What we collect, why and on what legal basis — in the privacy policy.

Privacy policy

Your rights

  • access to your data
  • correction of inaccuracies
  • erasure
  • withdrawal of consent

For clients in the EU we sign a data processing agreement (DPA, GDPR art. 28) — on request at onboarding.

Data questions: privacy@gmail.com

How long we keep it

We keep data no longer than the work and the bookkeeping require.

Account data after the subscription ends
Available for export for 90 days, then deleted
Customers and contacts
Deleted records can be brought back for 30 days, after that they are gone for good
Messages and attachments
24 months, or until the customer is deleted
Call recordings
Not kept on the platform — they stay with the telephony provider
Orders that carry personal data
Six years after the reporting year orders are anonymised: amounts and line items stay for bookkeeping
Public links to offers
90 days after the customer decision: the link goes dark, the document stays with you
Website enquiries without a deal
24 months
Security event log
24 months
Backups
Backups rotate: deleted data disappears from them within two weeks

What we do not promise

An honest list is shorter than a list of promises — and more useful.

We hold no ISO 27001 or SOC 2 certificate

We do not have them today. Once we do, we will say so plainly and show the document.

We do not publish penetration test reports

We keep them to ourselves. Security questions we work through at onboarding.

We do not offer storage outside the EU

Production servers and backups stay inside the European Union.