Data protection
Data is stored in the EU, kept separate per company and deleted on agreed timelines. Every processing activity has its own legal basis and documentation.
12 security areas
Data is stored in the EU, kept separate per company and deleted on agreed timelines. Every processing activity has its own legal basis and documentation.
TLS 1.2+ between the browser and Hours. The database and file storage at Supabase are encrypted at rest by the provider (AES-256). Bank, accounting and mailbox access tokens are encrypted by Hours with AES-256-GCM before they are stored. The application server disk at Hostinger has no documented encryption at rest.
Role-based access on least privilege. The private Audit Center requires two-factor authentication. In the customer app, two-factor authentication is enabled per user. No employee access to customer data without explicit permission.
Database in Frankfurt and servers in Lithuania, both inside the EU. Third-party services are assessed separately by processing location and transfer basis.
Database and documents are backed up automatically as part of operations. The restore test is run and documented before we call it a completed control.
Restore being verifiedCritical actions are recorded in an audit log, dependencies are scanned in every pull request, and operational status is public at hours.dk/pages/status.html.
Customers are notified without undue delay and within 48 hours at the latest. Vulnerabilities can be reported, and receipt is confirmed within 24 hours.
Sub-processors are named with purpose and transfer basis, and changes carry 30 days notice. A formal approval process is not finished yet.
In progressAI analysis is opt-in, and the provider is a named sub-processor under standard contractual clauses. A full governance framework is on the way.
In progressA data processing agreement under Article 28, documented instructions, and support for access, rectification, erasure and portability on request.
Code is reviewed before production, dependencies are scanned automatically, and every change to the platform is traceable in version control.
The continuity and disaster recovery plan is being written as part of the ISO 27001 preparation. It is not finished, and we do not present it as if it were.
In progressThe database runs in Frankfurt, the servers in Lithuania, and access to data is separated at database level, so one company's information cannot be read from another company's session. Where a service processes data outside the EU or EEA, the service, the purpose and the basis for the transfer are named in the data processing agreement. Not in a footnote.