Where your data is
On Raiola Networks hosting in Spain (European Union). It is managed hosting shared with the provider's other customers, and the panel keeps each account separately, outside the public part of the website. Form automation runs on a separate server in France. Your company's data is not sold, not passed to third parties for advertising and not used to train any model. It only leaves the European Economic Area if your company switches on the assistant's AI mode, and then under standard contractual clauses.
| What data | Where it is stored | For how long |
|---|---|---|
| Your workers’ records: name, job, training, assigned PPE, authorisations | Raiola Networks hosting, Spain (EU) | For as long as the contract lasts. When it ends you decide whether we return it, delete it or both: nothing is deleted without your instruction. |
| Plant documentation: procedures, LOTO, work permits, maintenance, incidents | Raiola Networks hosting, Spain (EU) | For as long as the contract lasts. When it ends you decide whether we return it, delete it or both: nothing is deleted without your instruction. |
| Panel access log: when someone signed in, with what type of browser and the account as a cryptographic hash | Raiola Networks hosting, Spain (EU) | For as long as the contract lasts, under the same rule |
| Your company’s billing data | Payment provider in the EU and our accounting | The mandatory tax and commercial retention period |
| Contact email and the messages you send us through the form | Email hosted in the EU | Until you ask us to delete it |
Who can get in
Each company sees only its own data. Each account is stored separately and the server only returns the data of the account that signed in: there is no global view from which one customer could look at another's data.
- Today the panel is accessed with a single Google account per company, with no passwords to store. Per-person permissions (what a shift leader or an operator sees) do not exist yet: if you need them, ask us before you subscribe.
- All connections are encrypted (TLS). The panel is not reachable over unencrypted HTTP.
- On our side, technical access to the server is limited to the people who maintain the system, with personal keys, and it is logged. We do not go in to look at your data out of curiosity or to build commercial statistics.
- If we ever need to enter your account to resolve a ticket you have opened, we tell you beforehand and it is recorded in the access log.
What we do if there is an incident in our infrastructure
This is not about what happens inside your plant: it is about our server going down, or someone reaching the machine holding your employees’ data without permission. Under the GDPR split, you are the controller and we are the processor. That means notifying the supervisory authority, within the 72-hour deadline of article 33, is yours to do; our duty is to inform you without undue delay and give you everything you need to comply. We pin it down in writing: we tell you within 24 hours of detecting it, risk or no risk, so you keep 48 hours of margin.
Contain
Isolate what is affected, revoke credentials and freeze the server state so it can be analysed afterwards. Stop it first, investigate second.
Assess
Which data exactly, from which clients, how many people, and whether there is real risk to those people. Without that answer the notice is useless.
Notify
You, within 24 hours: what happened, which data is involved and what we recommend you declare. If the risk to individuals is high, we also help with the communication to those affected required by article 34.
Explain afterwards
A written report for affected clients: what failed, what was done, what we are changing so it does not happen again. No corporate press-release language.
The data processing agreement
Article 28 GDPR requires a written contract between you and us. It is not decorative paperwork: it is the document an inspector will ask you for. It is generated automatically when your company is registered, with your details already filled in, and it is in the panel as a PDF from day one, unrequested and at no cost. You do not have to be a customer to read it: you can generate the full contract with your own details right here, print it and hand it to your advisers before signing up for anything.
- What data we process, for what, and for how long — in writing and specifically.
- The list of sub-processors, with a commitment to notify you before changing any of them.
- What happens at the end: you choose whether we return everything in an open format, delete it or both. We delete nothing before your instruction and we confirm the deletion in writing.
Export and delete, whenever you ask
Your data is yours and leaving must not be a punishment. No “export to PDF and sort it out yourself”, no having to write three times before anyone answers.
- Full export in an open format (JSON) from the panel itself, plus lists in CSV, without asking anyone and as often as you like.
- Deletion only when you ask for it. What you withdraw from the panel goes to a bin for 30 days in case of a mistake, and is deleted afterwards. If you ask us for full erasure, we carry it out and confirm it in writing.
- If one of your workers exercises their rights with you, we give you what you need to answer in time. It is your obligation, but we are not leaving you alone with it.
Health data: what we decided not to store
Who we work with
Nobody runs a service entirely alone. These are the providers involved and what for. If we change any of them, we publish it here 30 days in advance and you may object.
| Function | Provider | Location |
|---|---|---|
| Panel, database and attached files | Raiola Networks | Spain (European Union) |
| Hosting of the public website | Raiola Networks | Spain (European Union) |
| Contact email and automated notices | Raiola Networks | Spain (European Union) |
| Automation that receives forms and sends emails | Hostinger | France (European Union) |
| Sending emails from the automation | Brevo (Sendinblue SAS) | France (European Union) |
| Subscription and kit payments | Stripe Payments Europe | Ireland (European Union), with chapter V GDPR safeguards for its group |
| Panel sign-in (controller of its own service) | Google Ireland | Ireland (European Union) |
| Assistant AI mode, only if your company switches it on | Anthropic, PBC | United States, under the European Commission's standard contractual clauses and with no use of the data to train models |
We use no third-party analytics, advertising pixels or external fonts: while you browse, the site and the panel load nothing from outside servers. The only outgoing flows are those in the table: sign-in with Google, which you start, and AI mode, if your company switches it on.
What we do not have yet
We write this part ourselves because we would rather you read it here than discover it later. If you are comparing providers, use this list to ask the others the same questions.
- We are not ISO 27001 or SOC 2 certified, and we will not imply that we are. We follow good practice, but that is not a certification and saying so would be.
- We have not passed an external security audit. The day we do, we will publish here who ran it, when, and what it found.
- We do not encrypt field by field inside the database. Traffic is always encrypted and each account is stored outside the public part of the website, but calling this "end-to-end encryption" would be inaccurate and we will not do it.
- We have no 24/7 on-call rota. If something goes down overnight, it is handled first thing. What is met regardless is the 24-hour breach notice, because your legal deadline depends on it.
- In progress: automatic backups outside the main hosting and per-person permissions within each company. Today each account keeps its earlier versions on the server itself. When the new pieces are ready, this line will move to the list above with the date.
Can a customer or contractor company see my panel?
What happens to my data if I stop paying?
Do you use our data to train artificial intelligence?
Can I ask for the processing agreement before signing up for anything?
Have a question this page does not answer?
Write to us and we will answer in writing. If the question is a good one, we will also add it to this page for the next person who asks.
Write to IndustriaKit