PeerPilot

GDPR

Security and compliance

People collaborating

GDPR, security and compliance

PeerPilot is designed to support secure, GDPR-compliant processing. We keep all customer data within the EU and use sub-processors that are ISO/IEC 27001 certified and compliant with ISO/IEC 27017 controls for cloud services.

We process only the personal data needed to provide our services, for defined and transparent purposes. Data is encrypted in transit and at rest, while role-based access controls limit access to authorised personnel according to least-privilege principles.

Customers control how long their data is retained, with automatic deletion supported in line with their policies and when a service agreement ends. EU-based cloud infrastructure, monitoring, backups and incident-response procedures help protect the confidentiality, integrity and availability of customer data throughout its lifecycle.