Is GDPR also important to you?

If so, inscrive.io is the safe choice as we take GDPR very serious too.

With the following information we have tried to showcase that we take GDPR seriously, and that we care about your GDPR compliant use of our platform.

– Viktor L. Andersen, CEO at inscrive.io

GDPR Compliance

Our software solution is developed in the GDPR area, hence the principles of Privacy by design and default is an integral part of our software solution. In developing the solution, we have focused on data subjects and their rights, and we have designed the platform to support the catering of these rights as best as possible.

In addition, we are constantly trying to further develop the platform with solutions and features that help our customers to comply with their obligations, e.g. features supporting deletion policy compliance, the right to be forgotten, general data minimization features, and much more making GDPR compliant use of the platform easy.

In order for our customers, as data controllers, to control inscrive.io's processing of data on behalf of our customers in compliance with GDPR, we let ourselves be audited by an independent audit for the purpose of providing an audit report on GDPR compliance based on control reports.

Download our Control Report here

Data processing agreement

In all our customer relationships, inscrive.io processes personal data on behalf of our customers as the data controllers. Consequently, we as parties are obliged to enter into a data processing agreement.

inscrive.io uses the Danish Data Protection Agency’s standard contractual clauses as the basis for our standard data processing agreement. This has the advantage that we can fulfil our joint obligation to enter into a GDPR compliant data processing agreement.‍

Download our data processing agreement here

One of the most important things for our customers is transparency in the sub-processors we use to provide our services, hence a complete list of these, including copies of our data processing agreements with them, can be found here.‍

Your data is safe with us!

System description

Trust and confidence in our ability to safely process our customers data is of upmost importance to inscrive.io given the close ties this has to any customers wanting to do business with us.

Suppliers
Use of suppliers being sufficiently certified based on recognized standards such as ISO 27001:2013, 27017:2015, 27018:2014 and ISO 9001:2015, and use of suppliers being able to guarantee processing within EU/EEA data regions.
Hardware reuse
Hardware reuse is done by restoring factory settings only, and hardware destruction is done according to market standards for this, so data recovery is not possible.
Background checks
Background checks of employees.
Encryption
Full TLS and HTTPS encryption of data in transit and in rest.
Backup and anti-malware
Daily backup and updated anti-malware and anti-virus on all systems and devices.
Logging
Logging of access and actions in the platform and systems.
Procedures
Procedures for access to production environment and access to customer data.
Physical security of sites
Physical security of sites with individual access keys and codes as well as monitoring of facilities.
Redundancy
Full redundancy setup with main hosting and operations provider to ensure access and continuous operation of the platform.
Ongoing platform check
Ongoing check of platform and systems against OWASP top 10 vulnerabilities, as well as periodic testing of systems by an ethical hacker.
Network
Segmented and encrypted network and connection to Security Operation Center (SOC) via hosting provider.
Use of MFA login
Use of Multi Factor Authentication login for the platform and production environment.