Security & data protection
Your whole business lives here. We protect it accordingly.
European data protection, isolated databases and solid infrastructure: the foundations decision-makers and IT teams ask about first.
Hosting in your region
For customers in the EU, each installation runs on a server in the EU. Servers outside the EU exist only for customers outside the EU, each in the region with the best latency for their users.
Nightly backups
Automatic every night, at least three versions on physically separate systems at a different location, automatically checked for recoverability. They are kept for up to one year.
Two-factor authentication
2FA protects every login against stolen or reused passwords.
Intrusion prevention
Active intrusion prevention and logged access on every installation.
A separate database per customer
The data is yours; we process it only on your instructions. It sits in a database no other customer is in, not in a shared table with a customer column. And because nothing is interwoven with anyone else’s data, you can get your records out as a whole at any time.
99.99% host uptime in 2026
Measured across all customer instances in the current year (internal monitoring). Solid infrastructure keeps the system your team relies on online. The contract guarantees 99.9% as an annual average.
Compliance
GDPR, by design.
Fidelo is built to be your system of record. Your data stays yours: isolated, logged, backed up and processed in line with European data-protection law.
For procurement & IT review
The DPA, our technical and organisational measures, the subprocessor list and the review checklist are available for download below. We issue the signed DPA and further evidence on request.
Request the security overviewIt starts with this website: it runs entirely without trackers, analytics scripts or tracking cookies.
Security questions
Is Fidelo GDPR-compliant?
Yes. Each installation runs on a server in the EU (for customers outside the EU, in their own region) with nightly backups to a separate server. Two-factor authentication, intrusion prevention, logged access and isolated databases protect your data in line with the GDPR.
Where is our data hosted?
For customers in the EU, on a server in the EU. Servers outside the EU exist only for customers outside the EU, each in the region with the best latency for their users. Your installation is isolated from other customers and backed up nightly to a separate server. For customers in the EU and the EEA, processing takes place within the EU and the EEA; any transfer to a third country requires your prior consent, as set out in the DPA.
Can we get a DPA or a security overview for procurement?
Yes. The data processing agreement, the technical and organisational measures, the subprocessor list and the template of our annual security review are available for download below. You receive the signed DPA together with your licence agreement.
Are you ISO 27001 certified?
No, we do not hold an external certification. Our internal processes follow the control objectives of ISO 27001 and Art. 32 GDPR. They are reviewed annually and after every major system change against a documented checklist, and senior management signs off the results.
What happens to our data when we cancel?
No later than the end of the licence agreement, or earlier on request, we hand your data over to you in a machine-readable format or delete it in line with data protection law, backups included, unless a statutory retention obligation applies. A deletion log is available on request. During the term you have full access to your data at all times.
How does Fidelo keep invoices unalterable?
Released invoices are unalterable and are never deleted; corrections run through cancellation invoices with their own number. Invoice numbering is sequential, with no gaps; every version of a document is kept with its author and timestamp, the released PDF is archived unchanged, and all access runs through personal accounts. In Spain invoices are registered with Verifactu. Record-keeping rules differ by country; documenting your own procedures remains your responsibility, and we provide the system description for it.
Documents for your review
Data processing agreement, technical and organisational measures, subprocessors, for procurement and data-protection officers.
Data processing agreement (DPA), template
Agreement under Article 28 GDPR, signed alongside your licence agreement. English.
Download PDF· Updated 09/2024
Technical and organisational measures
Access control, encryption, data centre, backups, breach handling and the annual review. Version 1.3, English.
Download PDF· Updated 10/2025
List of subprocessors
Every processor with location, service, data categories, processing location and legal basis. Version 1.3, English.
Download PDF· Updated 09/2025
Security and data protection review checklist
The template of the annual internal review under Article 32 GDPR, aligned with ISO 27001 control objectives. Version 1.1, English.
Download PDF· Updated 10/2025
Need the details for your security review?
Book a demo or request our security overview: we’ll walk your IT team through hosting, backups and access control.
Book a free demo