Security and operations

What your IT and compliance people ask about, in one place.

Where data is kept

System, database, uploaded documents, backups and the public passports are hosted by Simply.com A/S in Denmark. All traffic uses HTTPS.

Access control

Four roles: owner, administrator, editor and viewer. Two-factor authentication can be turned on per user and required for the whole company. API keys and access links are stored only as hashes and can be withdrawn.

Traceability

Every value has a source with document and page, and every approval has a name and a time. Values are never overwritten: a change keeps the old value in the history. The activity log shows who did what.

Backup

A backup of the database and files is taken daily. Issued declarations are kept as the PDF files that were issued, and published passports are kept in versions.

Automatic reading of documents

Documents are read with AI by a sub-processor on a paid tier where the content is not used to improve the provider's products. The values are proposals, and nothing is used until one of your users has approved it.

Export and no lock-in

At any time you can download products and batteries as Excel, CSV or JSON, and all passports, declarations and documents in one file. The passports follow GS1 Digital Link and can be read by other systems.

When a plan ends

Published passports and QR codes continue on the hosting package, so they stay online as the law requires. If you opt out, printed QR codes can be redirected to a new provider. Other data is deleted within the time limits in the terms.

Who on our side has access

Only the staff who run the system or help you with a task. When we view a customer's account it is read-only, and it is logged.

The binding terms are in the data processing agreement and the list of sub-processors: Data processing agreement · Sub-processors · Privacy policy

Do you have a security questionnaire for us?

Send it over and we answer by email.