Skip to main content

Data & Security

Security is built into every product we run, not bolted on afterwards. Below is an overview of the infrastructure, encryption, and compliance standards that protect your data across our platforms.

At a glance

  • ISO 27001 certified company
  • Servers hosted in Germany (Hetzner)
  • Encryption at rest and in transit
  • PCI DSS Level 1 payment processing via Stripe
  • GDPR compliant data handling
  • 24/7 threat monitoring and intrusion blocking

Infrastructure & Hosting

Our applications, including upSync, are hosted on servers operated by Hetzner Online GmbH, based in Germany. Hetzner is one of Europe's largest hosting providers, with data centres in Nuremberg and Falkenstein, Germany.

  • ISO/IEC 27001:2022 certified. Hetzner's information security management system, covering its data centre infrastructure, operations, and customer support, is independently certified to this international standard.
  • BSI C5 Type 2 certified. Hetzner's cloud services hold certification against the German Federal Office for Information Security's (BSI) Cloud Computing Compliance Criteria Catalogue, verifying that security controls are not only documented but operated effectively over time.
  • Classified as critical infrastructure (KRITIS). Hetzner is designated by the BSI as an operator of critical services under German KRITIS regulation, subject to additional regulatory oversight.
  • Physical security. Data centres are protected by restricted access controls, on-site security, and redundant power and network infrastructure.

Hosting our infrastructure within Germany also ensures that data relating to EU residents remains within the European Union and subject to EU data protection law.

Encryption

  • Credentials are encrypted. Any third-party connection credentials stored by our platforms, such as PSA or accounting software API keys, are encrypted at rest within our database.
  • Passwords are hashed. User passwords are never stored in plain text. We use industry-standard one-way password hashing, meaning your password cannot be retrieved or reversed by us or anyone else.
  • Backups are encrypted. All automated backups of customer data are encrypted before being written to storage.
  • Encryption in transit. All traffic between your browser, our applications, and connected third-party services is encrypted using TLS/HTTPS.

Threat Monitoring

We use a globally recognised threat monitoring and protection service to continuously monitor inbound traffic to our platforms, automatically detecting and blocking malicious requests, denial-of-service attempts, and known attack patterns before they reach our application servers.

Payment & Card Data

We do not store credit card or payment card numbers on our own servers at any point. All payment processing is handled directly by Stripe, a certified PCI DSS Level 1 service provider, the highest level of certification available in the payments industry.

  • Stripe is independently audited annually by a Qualified Security Assessor (QSA) against the full PCI DSS standard.
  • Card details are collected and transmitted directly to Stripe's secure vault, without passing through our servers, minimising our exposure to cardholder data and reducing risk for our customers.
  • We only ever store a reference token provided by Stripe to manage subscriptions and billing, never the underlying card details.

Data Retention & Deletion

We retain customer data only for as long as is necessary to provide our service. When a customer cancels or deletes their subscription, all associated data is permanently destroyed, including:

  • Accounting software connection credentials
  • PSA (Professional Services Automation) connection credentials
  • Synced invoice history and related records

This ensures that no customer data is retained beyond the point at which it is no longer required to deliver the service.

GDPR & Data Protection

We comply with the EU General Data Protection Regulation (GDPR) in respect of the processing of personal data belonging to individuals residing in the European Union. This includes ensuring data is processed lawfully, fairly, and transparently, kept no longer than necessary, and protected by appropriate technical and organisational measures.

Compliance & Certification

Smart IT is an ISO 27001 certified company. ISO 27001 is the internationally recognised standard for information security management systems, requiring a documented, audited, and continually improved approach to managing information security risk across our organisation, not just our hosting environment.

© 2026 SmartStack Ltd. All rights reserved.