Security & data protection

Your data is safe with us.

Servers in Germany, GDPR compliant, encryption throughout, granular access control. Here is what that means in practice.

Data protection

GDPR compliant.

Not as a checkbox, but as the foundation.

intuAid processes only the data needed to run the platform. Nothing is passed on to third parties. No tracking for advertising. On request we sign a data processing agreement that covers the legal requirements of the GDPR in full.

Data processing agreement

Available on request. It sets out clearly who is responsible for which data and how that data may be processed.

Access, deletion, portability

Your users have the right to see what is stored about them, to have it deleted in full on request and to export all of their own content.

No data outside the EU

All personal data stays in Europe. No transfer to third countries without an adequate level of protection.

Data protection officer

For anything touching data protection you can reach us directly. We answer within 72 hours.

Infrastructure

Servers in Germany.

ISO 27001 certified data centres.

All data is stored and processed in data centres in Germany. The infrastructure providers we use are certified to ISO 27001, the internationally recognised standard for information security management.

Located in Germany

No routing via servers outside the EU. The physical machines sit in German data centres with matching access controls.

ISO 27001 certification

The standard requires a complete management system for information security, annual external audits and continuous improvement.

Redundancy and backup

Data is backed up daily. Backups are stored encrypted at a second site in Germany. Recovery time is under 4 hours.

Availability

We aim for 99.9 % availability. Planned maintenance windows are announced in advance and fall outside core working hours.

Encryption

Encryption.

In transit. At rest. No exceptions.

Data is encrypted in two places: on the way from the browser to the server, and while it is stored. Neither is an optional feature, both are a fixed part of the architecture.

TLS 1.3 for every connection

All communication between browser, app and server runs over TLS 1.3. Outdated protocols such as TLS 1.0 or 1.1 are switched off.

AES-256 for stored data

All data on the servers is encrypted with AES-256. That covers documents, attachments, logs and user data alike.

Encrypted backups

Backups are encrypted before they are transferred to the backup site. No backup sits there in plain text.

No plain text passwords

Passwords are stored only as salted hashes. Even system administrators have no access to the actual password.

Access control

Roles & permissions.

Who gets to see what, and who does not.

Not every employee needs to see everything. intuAid distinguishes between internal users with different roles and external providers who can only reach what their job allows.

Role based access

Administrator, dispatcher, technician and external provider each have their own set of permissions. No technician sees customer data they do not need.

External providers kept separate

Subcontractors and outside firms get their own access with clearly limited visibility. They see their own jobs, not your entire installed base.

Complete audit logging

Every action in the system is logged with a timestamp, the user and the context. That protects against internal misuse and serves as evidence in a dispute.

Time limited access

External providers can be given an expiry date. After that date the access is blocked automatically.

Try intuAid on your own machines.

Create an account and bring your first machine online today. If you would rather see intuAid in action first: in the demo we scan the QR code on one of your machines live, with no pitch and no slide deck.

Free forever for up to 3 machines. No credit card required.

Screenshot of the intuAid app showing the device landing page after scanning the QR code