Your data security is our top priority. Spreadly is built with enterprise-grade security standards and full compliance with European data protection regulations.
Spreadly meets the highest security standards and is compliant with all European data protection regulations.
Spreadly is ISO 27001:2022 certified, the internationally recognized standard for Information Security Management Systems (ISMS). This certification demonstrates our commitment to managing information security risks systematically.
Our platform is fully compliant with the EU General Data Protection Regulation (GDPR). We implement privacy by design and provide all necessary tools for you to fulfill your data protection obligations.
Spreadly is developed in Germany and exclusively hosted on servers operated by Hetzner in Germany. Your data never leaves the EU, ensuring compliance with strict European data protection laws.
Your data is protected by multiple layers of security throughout the entire data lifecycle.
Spreadly provides powerful security features that give you full control over your organization's data.
Connect Spreadly to your existing identity provider using SAML 2.0 or OAuth 2.0. Support for Microsoft Entra ID, Google Workspace, Okta, and other major providers.
Define granular permissions at the role and team level. Control who can view, edit, or manage different aspects of your digital business cards.
All data is encrypted both in transit and at rest. We use TLS 1.3 for secure communication and AES-256 encryption for data storage to ensure your information remains protected.
Comprehensive audit logs track all important actions within your organization. Export logs for compliance reporting and security analysis.
Your privacy is at the core of everything we build.
We never sell, share, or monetize your data. Your information is yours alone.
Export all your data at any time. We support standard formats for easy migration.
Delete your account and all associated data completely. We respect your right to be forgotten.
We provide a comprehensive DPA to ensure compliance with your internal policies.
Security is embedded in every aspect of our operations and development process.
Access our security and compliance documentation.
Common questions about our security practices and compliance.
All data is stored exclusively on servers in Germany, operated by Hetzner. Your data never leaves the European Union.
Yes, Spreadly is fully compliant with the EU General Data Protection Regulation (GDPR). We implement privacy by design, provide data processing agreements, and give you full control over your data.
Spreadly is ISO 27001:2022 certified. This internationally recognized certification demonstrates our commitment to information security management best practices.
Yes, we provide a comprehensive Data Processing Agreement (DPA) that documents our data handling practices and helps you meet your compliance obligations. You can find it in our Data Processing Agreement.
We have a documented incident response plan. In case of a security incident affecting your data, we will notify you within 72 hours as required by GDPR and work transparently to resolve the issue.
Enterprise customers can request additional security documentation including our ISO 27001 certificate, penetration test reports, and security questionnaire responses. Please contact our sales team.
When you delete your account, all your personal data is permanently removed from our systems within 30 days. Backups containing your data are purged according to our retention schedule.
Yes, we support SSO via SAML 2.0 and OAuth 2.0. This includes integration with Microsoft Entra ID (Azure AD), Google Workspace, Okta, and other major identity providers.
“Have questions about our security practices? I'm happy to help you understand how we protect your data.”
Any further questions? We are thrilled about your message.