How we look after the security of our systems and data
We treat the security of our learners' data and the stability of the platform as a priority. We combine our employees' awareness, a knowledge of the latest directives and proven technical safeguards in order to protect the data entrusted to us at every level.
Security is a process, not a project
For us, protecting data is not a one-off task but a continuous process. We look after our employees' awareness and their up-to-date knowledge of the latest directives and good practice, while at the same time maintaining a modern technical architecture that we continuously monitor, update and test.
An updated security training session for employees
On 22.05.2026 an updated training session was held for our employees, covering the protection of personal data (GDPR), information security and cyber security. We make sure that the whole team knows the current regulations, the latest directives and good practice — because people are the first line of data protection.
Technical safeguards
Layered protection covering data location, monitoring, the network firewall, backups and regular testing.
Data in the EEA — servers in Frankfurt
We store learners' data on servers located in the European Economic Area — in a data centre in Frankfurt (Germany), in line with the requirements of the GDPR.
A SIEM system overseeing security
A SIEM-class system collects and analyses events from our infrastructure, making it possible to detect and respond quickly to potential security incidents.
Firewalls on every endpoint
We use network firewalls on all endpoints — including a Web Application Firewall (WAF) protecting the application and the website against network attacks.
Automated and off-site backups
Regular, automated backups, also stored in an external location — they ensure that data can be restored in the event of a failure.
System updates
We update our systems both automatically and manually, so as to eliminate known vulnerabilities on an ongoing basis and keep the environment in a secure state.
No technical debt
We eliminate technical debt and use only actively supported databases and framework versions — so that we always receive security patches.
Regular penetration tests
We regularly carry out pentests — penetration tests of the application and the website — in order to identify and fix vulnerabilities before anyone else exploits them.
Employee awareness
We make sure the team is trained regularly in the GDPR, data protection and cyber security, and keeps up with the latest directives and good practice.
Data encryption
We encrypt data both in transit (TLS/HTTPS) and at rest — so that it remains protected at every stage of processing.
Access control
We apply the principle of least privilege and role-based access (RBAC), multi-factor authentication (MFA/2FA) for administrative accounts, and access logging (audit trail).
Data minimisation and AI
We collect only the data necessary for the platform to operate. We do not sell data and we do not use learners' data to train artificial intelligence models.
Audit readiness
We support our clients in the vendor assessment process — we complete security questionnaires and provide the information needed to verify compliance.
Your rights (GDPR) and support for our clients
We respect the rights of data subjects and support our clients (data controllers) in fulfilling those rights towards the employees who use the platform.
- The right of access to the data and to information about how it is processed.
- The right to rectification of incorrect or out-of-date data.
- The right to erasure of data (the "right to be forgotten").
- The right to data portability in a structured, commonly used format.
- Support for our clients in handling requests from data subjects.
In brief
- We look after our employees' awareness and their knowledge of the latest directives — on 22.05.2026 an updated training session on the GDPR, data protection and cyber security was held.
- We store learners' data in the EEA — on servers in Frankfurt (Germany).
- Data encryption in transit (TLS/HTTPS) and at rest.
- Access control — least privilege, roles (RBAC), MFA/2FA for administrative accounts and access logs.
- A SIEM system overseeing the security of the infrastructure.
- Firewalls on every endpoint (WAF and other network firewalls).
- Automated and off-site backups.
- System updates — both automated and manual.
- Elimination of technical debt and use of only actively supported databases and framework versions.
- Regular pentests — penetration tests of the application and the website.
- Data minimisation — no sale of data and no use of learners' data to train AI models.
- Fulfilment of data subject rights (access, rectification, erasure, portability) and support for our clients in handling them.
- A transparent list of sub-processors and readiness for audits and security questionnaires.
Do you have questions about data security?
We will gladly answer any questions about data processing, GDPR compliance and the safeguards built into the VOCAbite platform. Get in touch with us.
Get in touch with us Privacy policy