This page describes the technical and organizational measures Shopsy AS has in place to protect personal data and customer data in Onebase, in line with GDPR Article 32.
1. Hosting and Data Location
- Primary region: Hetzner Nuremberg, Germany (EU)
- Database: Managed PostgreSQL with daily encrypted snapshots
- File attachments: S3-compatible object storage in an EU region
- Backup region: Geographically separate region within the EEA
2. Encryption
- In transit: TLS 1.2+ with modern cipher suites for all client-server and server-subprocessor traffic
- At rest: AES-256 disk encryption on all database instances, backups and object storage
- Secrets: Environment variables and API keys are stored separately from source code and rotated as needed
3. Authentication
- One-time codes (OTP) to email as the primary sign-in method
- Passwords (where enabled) are hashed with modern algorithms via BetterAuth
- Session cookies expire after 7 days and are HttpOnly
- OTP rates are limited to 5 requests per 15 minutes per email address
4. Access Control
- All data access is filtered by tenant ID at the query layer — customers only see their own data
- Per-tenant roles: owner, admin, member
- Every mutation is logged in the audit log with timestamp, actor and before/after snapshot
5. Operator Access — what Onebase can do in your data
Onebase sets up the system for every customer and assists with support. That means our operators can open your environment — under the following rules, built into the platform:
- A reason is required. An operator cannot open your environment without stating a written reason. The access and the reason are written to your own audit log.
- Everything is attributed. Every change an operator makes is labeled "Onebase support" in your audit log — it can never be confused with changes made by your own staff.
- You can see us. The "Onebase access" overview under Settings → Privacy shows when Onebase was in, which operator, and how many actions — per day. You can always answer "was Onebase in our data, and when?".
- Setup before handover. While we build your system (before your first sign-in), operators work in the environment as part of the setup. In this phase the system sends no email and no billing starts.
- Setup templates without personal data. Reusable setup packs (reference lists, pipeline, channels etc.) contain configuration only. The export is technically restricted to configuration tables — it cannot read personal data.
6. Backups and Recovery
- Daily encrypted database snapshots, retained for 14 days
- Point-in-time recovery (PITR) up to the last 24 hours
- Backups stored in a geographically separate region within the EEA
- Restore drills run on a regular cadence
7. Incident Response
We maintain an internal response plan covering classification, escalation and notification. On confirmed personal-data breaches we notify Datatilsynet within 72 hours where required, and affected customers / data subjects without undue delay.
8. Vulnerability Disclosure
We follow a coordinated vulnerability disclosure process. See /security and security.txt.
9. Subprocessors
The full list is available at /trust/subprocessors.
10. Certifications
We pursue formal certifications (ISO 27001, SOC 2) when customer requirements call for it. Contact us for current status and roadmap.
11. Contact
For security questions, email post@shopsy.no. For privacy questions, use post@shopsy.no.