Where your data is
On our own server inside the European Union, physically in France. It is not shared hosting alongside unrelated projects: the machine is ours and the panel is the only thing running on it. Your data does not leave the European Economic Area, is not sold, is not passed to third parties for advertising and is not used to train any model.
| What data | Where it is stored | For how long |
|---|---|---|
| Your workers’ records: name, job, training, assigned PPE, authorisations | Own server, France (EU) | For the life of the contract, plus 30 days so you can export it |
| Plant documentation: procedures, LOTO, work permits, maintenance, incidents | Own server, France (EU) | For the life of the contract, plus 30 days so you can export it |
| Panel access log: who logged in, when, and what changed | Own server, France (EU) | 12 months |
| Your company’s billing data | Payment provider in the EU and our accounting | The mandatory tax and commercial retention period |
| Contact email and the messages you send us through the form | Email hosted in the EU | Until you ask us to delete it |
Who can get in
Each company sees only its own. There is no global view from which one client can peek at another’s data, not even where they are linked as principal and contractor: in that case the contractor decides which file to share and the principal sees that and nothing else.
- Inside your company, you set the permissions: what a shift supervisor sees, what an operator sees and what the safety manager sees.
- All connections are encrypted (TLS). The panel is not reachable over unencrypted HTTP.
- On our side, technical access to the server is limited to the people who maintain the system, with personal keys, and it is logged. We do not go in to look at your data out of curiosity or to build commercial statistics.
- If we ever need to enter your account to resolve a ticket you have opened, we tell you beforehand and it is recorded in the access log.
What we do if there is an incident in our infrastructure
This is not about what happens inside your plant: it is about our server going down, or someone reaching the machine holding your employees’ data without permission. Under the GDPR split, you are the controller and we are the processor. That means notifying the supervisory authority, within the 72-hour deadline of article 33, is yours to do; our duty is to inform you without undue delay and give you everything you need to comply. We pin it down in writing: we tell you within 24 hours of detecting it, risk or no risk, so you keep 48 hours of margin.
Contain
Isolate what is affected, revoke credentials and freeze the server state so it can be analysed afterwards. Stop it first, investigate second.
Assess
Which data exactly, from which clients, how many people, and whether there is real risk to those people. Without that answer the notice is useless.
Notify
You, within 24 hours: what happened, which data is involved and what we recommend you declare. If the risk to individuals is high, we also help with the communication to those affected required by article 34.
Explain afterwards
A written report for affected clients: what failed, what was done, what we are changing so it does not happen again. No corporate press-release language.
The data processing agreement
Article 28 GDPR requires a written contract between you and us. It is not decorative paperwork: it is the document an inspector will ask you for. It is generated automatically when your company is registered, with your details already filled in, and it is in the panel as a PDF from day one, unrequested and at no cost. You do not have to be a customer to read it: you can generate the full contract with your own details right here, print it and hand it to your advisers before signing up for anything.
- What data we process, for what, and for how long — in writing and specifically.
- The list of sub-processors, with a commitment to notify you before changing any of them.
- What happens at the end: everything returned in an open format and then deleted, with written confirmation of deletion.
Export and delete, whenever you ask
Your data is yours and leaving must not be a punishment. No “export to PDF and sort it out yourself”, no having to write three times before anyone answers.
- Full export to Excel and CSV from the panel itself, without asking anyone’s permission and as often as you like.
- Deletion on request: you write to us, we confirm, and it is deleted within 30 days at most, backups included as they rotate. You get written confirmation.
- If one of your workers exercises their rights with you, we give you what you need to answer in time. It is your obligation, but we are not leaving you alone with it.
Health data: what we decided not to store
Who we work with
Nobody runs a service entirely alone. These are the providers involved and what for. If we change any of them, we publish it here 30 days in advance and you may object.
| Function | Provider | Location |
|---|---|---|
| Panel server and database | Hostinger | France (European Union) |
| Public website hosting | Raiola Networks | Spain (European Union) |
| Subscription and kit payments | Stripe Payments Europe | Ireland (European Union), with chapter V GDPR safeguards for its group |
| Contact email and automated notices | Raiola Networks | Spain (European Union) |
We use no third-party analytics, no advertising pixels and no external fonts: neither the site nor the panel makes a single request to an outside server while you browse.
What we do not have yet
We write this part ourselves because we would rather you read it here than discover it later. If you are comparing providers, use this list to ask the others the same questions.
- We are not ISO 27001 or SOC 2 certified, and we will not imply that we are. We follow good practice, but that is not a certification and saying so would be.
- We have not passed an external security audit. The day we do, we will publish here who ran it, when, and what it found.
- We do not encrypt field by field inside the database. Traffic is always encrypted and the server is used by nobody else, but calling this “end-to-end encryption” would be inaccurate and we will not do it.
- We have no 24/7 on-call rota. If something goes down overnight, it is handled first thing. What is met regardless is the 24-hour breach notice, because your legal deadline depends on it.
- In progress: automatic daily backups with 30-day retention inside the same European region, and an access log you can export yourself. When they are done, this line moves up the page with the date.
Can my client company see my panel if we link up?
What happens to my data if I stop paying?
Do you use our data to train artificial intelligence?
Can I ask for the processing agreement before signing up for anything?
Have a question this page does not answer?
Write to us and we will answer in writing. If the question is a good one, we will also add it to this page for the next person who asks.
Write to IndustriaKit