How we protect your data
Here is exactly what we do to keep your data safe.
We are based in Spain and fully compliant with the EU GDPR.
We delete all your data 90 days after you cancel. Need it gone sooner? Just ask.
All production data is stored in Germany. Your data never leaves the EU.
Your clients' data is used only to send their appointment reminders. We never use it for marketing, profiling, or anything else.
Read more about our full GDPR compliance.
All payments go through Stripe. See their security documentation for details.
Your credit card details never touch our servers. Stripe handles all payment processing and is fully PCI compliant.
No one on our team — including management — can see your credit card information.
RicordamiApp runs on DigitalOcean cloud infrastructure in Germany. DigitalOcean holds ISO 27001 and SOC 2 certifications. We follow their best-practice guides and review server logs regularly for suspicious activity.
All data is encrypted at rest and in transit using AES-256-GCM. Unencrypted access is not possible.
Cloudflare WAF shields the app from SQL injection, XSS, and other exploits. Cloudflare also provides DDoS protection and geographic filtering to block traffic from high-risk regions.
All traffic is encrypted with TLS 1.2+. The app only accepts HTTPS connections.
We require 2FA on every system that supports it, covering infrastructure and customer data access.
Every team member uses a password manager so every credential is strong and unique.
Only vetted team members can access personal data. When someone leaves the team, we revoke all their access immediately.
We run frequent backups and test restores regularly. Backup access is protected by 2FA, password managers, encryption at rest, and strict access rules.
We run regular security audits against current data-protection guidelines and prioritize every finding.
Company Certifications:
• SOC 2: RicordamiApp does not currently hold a company SOC 2 certification.
• ISO 27001: RicordamiApp does not currently hold a company ISO 27001 certification.
Reach us at [email protected]
This policy was last updated: 2025-08-01