Security
How we look after your data
Your data is safe with Clientflow
Your customer records, appointments, invoices and files are your business. We treat them accordingly — and we're happy to put anything you or your advisor wants on paper in writing.
In short
Everything sits in the EU. Each company is isolated down in the database itself, not just in the app code. We take backups in two independent layers with two different providers, everything is encrypted end to end, and we run a real restore every quarter instead of hoping for one.
Where your data lives
- Database, user accounts, files, customer data etc.: EU (Frankfurt).
- Route optimization and map calculation: EU (Frankfurt).
- Offsite backup: Object storage under EU jurisdiction, with a different provider than the one running the database — with its own, separate access keys.
- Our own data centers: We don't have any. We host with established cloud providers whose data centers are ISO 27001- and SOC 2-certified. We're happy to state the name, region and account setup in writing.
Every company is isolated in the database
Row Level Security is enabled on every table in production — no exceptions — and the application connects to the database with a role that cannot bypass it. Separation between companies is therefore enforced by the database itself, not by the code on top of it. A bug in the application code cannot, on its own, show one company's data to another.
That's the strongest separation a multi-tenant platform can have. Many build it in the application layer, where a single forgotten clause in a query is enough. We've put it somewhere it can't be forgotten.
On top sits role management: administrators and office staff have full access within their own company, while field staff only see what their permissions allow — set per user.
Encrypted the whole way
- In transit: TLS 1.2 or newer on all communication.
- At rest: AES-256 with every provider we host with.
- Backups: Encrypted separately on top of that, before they leave our infrastructure.
Two independent backup layers
- 1
Point-in-time recovery
The database can be rolled back to any given second. It's a safety net with second-level precision — including when the accident happens at your end and a cleanup takes too much with it. Recovery takes about an hour.
- 2
Encrypted nightly copy with an entirely different provider
If our database provider becomes unavailable, a complete copy sits somewhere else, under its own keys: database, user accounts and all files and images. At most 24 hours of data loss.
Put in the numbers an advisor usually asks for: maximum data loss (RPO) is seconds on the first layer and up to 24 hours on the second. Maximum recovery time (RTO) is about an hour on the first layer and hours on the second.
Most stop at the first layer. We run both, because the first one lives inside the very system it's meant to protect.
The details behind it
- The backup job can write the copies, but not read them. Encryption uses a public key, and the private key is kept separately and never comes near the machine running the job. If the job or the storage is compromised, the attacker gets ciphertext.
- The file names are encrypted too — they routinely contain a customer address.
- Retention: daily copies for 30 days, monthly for 12 months. The monthly ones are locked with object lock, so they can't be deleted early — not even by a compromised key.
- We copy, we don't sync. A deletion in production therefore can't propagate into the backup.
We check that the backup is there — and that it works
- An alarm fires if no completed backup has arrived within 26 hours. A job that stops running therefore raises an alarm too — not just a job that fails.
- The job refuses to upload a dump that is suspiciously small. A truncated file otherwise looks like a perfectly good backup.
- We restore for real, every quarter. The latest backup is pulled, decrypted and rebuilt, and we compare both row counts and security policies against the original. A backup nobody has tried to restore is a promise. We'd rather have the proof.
Access and operations
Support access: If you need help with setup or troubleshooting, we can access your data with your consent. Every lookup in your data for that purpose is logged and documented with a reason per incident. You can decline support access at any time in writing.
- Access to production data is limited to a small, named group at our end, following the principle of least privilege. Access is removed when someone leaves.
- Short-lived access tokens that renew automatically.
- Critical events in the database are audit-logged.
- Separate environments for development, testing and production, and automated tests before anything goes live.
AI and processing outside the EU
We don't train models on your data. Neither we nor our AI providers use your data to train models, and the platform's own AI suggestions learn exclusively within your own company — never across customers.
Core operations sit in the EU. A few features use sub-processors that process data outside the EU. That happens under the European Commission's Standard Contractual Clauses (SCCs), and we have completed a Transfer Impact Assessment for each one.
- The AI features: Transcription, summarization, reply suggestions and search. They can be switched off under Settings → Company, including before you go live. Switch them off and the transfer stops; derived data already created is deleted on written request.
- Other features: Error monitoring, push notifications, maps and geocoding, and delivery of the platform itself.
The categories of sub-processors — with purpose, country and transfer basis — are public, and we send the full named list on request. The list forms part of our data processing agreement. If we add or replace a sub-processor, you're notified at least 30 days in advance and you can object.
See the sub-processor categoriesYour data is yours
- You can have it handed over at any time.
- Personal data on a contact can be deleted, so you can comply with an erasure request.
- On termination: you have 30 days to export. After that, all personal data is deleted from our production systems, and backups are overwritten no later than 90 days after termination. We confirm the deletion in writing.
- Files you send us for migration or import are deleted no later than 14 days after the import is complete — and we confirm that in writing.
If something goes wrong anyway
We monitor operations in real time and log errors centrally. In the event of a personal data breach, we have a documented procedure, and you're notified within 24 hours if you're affected.
Point of contact: support@clientflow.nu · +45 35 95 35 08
The formal part
We are the data processor for the personal data you put into Clientflow; you are the data controller. Our data processing agreement covers instructions, sub-processors with country and transfer basis, security measures, deletion, notification and liability — and we're happy to send it for signature.
See also
FAQ about data security
Where does our data live?
Can another company see our data?
Do you train AI models on our data?
Can your support staff see our data?
How quickly can you restore data after an outage?
Do we get a data processing agreement?
What happens to our data if we leave?
Missing an answer?
If you or your advisor have questions we haven't answered here, send them to us in writing. We'll answer in writing too.
Write to usLast updated: September 25, 2026