We take data protection seriously. Sitenyx is designed with privacy by design and by default, ensuring full compliance with the General Data Protection Regulation (EU 2016/679).
Sitenyx acts as a data processor when handling your business data (customer records, invoices, financial data) and as a data controller for user account data (login credentials, profile information). This distinction is clearly documented in our Data Processing Agreement (DPA), which defines the scope, purpose, and duration of processing.
We process personal data only on legitimate legal bases as defined in GDPR Article 6:
Under GDPR Articles 15-22, you have the following rights that we fully support:
We implement comprehensive security measures as required by GDPR Article 32. This includes AES-256 encryption at rest, TLS 1.3 in transit, role-based access control, multi-tenant data isolation via Finbuckle query filters, regular security audits, and automated vulnerability scanning. Our development practices follow OWASP guidelines, and all code changes undergo security review.
In the event of a personal data breach, we follow the notification requirements of GDPR Articles 33 and 34. We will notify the relevant supervisory authority (Datatilsynet in Denmark) within 72 hours of becoming aware of a breach, and notify affected data subjects without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
We provide a comprehensive Data Processing Agreement (DPA) in accordance with GDPR Article 28. The DPA covers the subject matter and duration of processing, the nature and purpose of processing, the types of personal data, categories of data subjects, and your rights as the data controller. Contact [email protected] to request our DPA.
Run your business and build your online presence with Sitenyx — built for businesses across Europe.
View pricingWe accept