Security Statement

Last updated: August 17, 2025

SNDQ is committed to protecting customer data and operating according to high security standards. On this page, we explain the technical and organizational measures we take to keep your data safe.

1. Information Security Policy (ISMS)

We maintain an information security program aligned with recognized industry standards. Our objectives are:

  • Comply with applicable legal and contractual security and privacy requirements
  • Manage risks across people, processes, and technology
  • Rapid detection, response, and continuous improvement

2. Data Storage & Hosting (EU)

  • Primary regions: Paris (France) and Frankfurt (Germany)
  • Location: Customer data is stored and processed exclusively within the European Union
  • Redundancy & availability: Multi-zone redundancy and automatic backups support resilience and recovery objectives

Our hosting partners operate EU data centers with recognized security certifications (e.g., ISO/IEC 27001). Current attestations are available upon request.

3. Data Protection & Privacy

  • SNDQ acts as a data processor for customer content and as a data controller for account and administrator data
  • We apply technical and organizational measures against unauthorized access, modification, disclosure, or destruction of personal data
  • Access to personal data is limited to authorized personnel, under confidentiality obligations and according to the least-privilege principle
  • For international transfers (if applicable), we use recognized mechanisms such as Standard Contractual Clauses

4. Encryption

  • In transit: All connections to SNDQ use HTTPS/TLS
  • At rest: Data is encrypted with modern algorithms
  • Secrets management: Keys and secrets are securely stored and periodically rotated

5. Identity & Access Management

  • Single sign-on (SSO) and multi-factor authentication (MFA) are available for internal staff; MFA can also be activated by customers
  • Role-based access control (RBAC) is applied in all environments
  • Administrator access is logged and regularly audited

6. Application & Product Security

  • Secure SDLC: Code review, dependency scanning, and security testing are integrated into our development cycle
  • Vulnerability management: We track, prioritize, and resolve issues based on risk and exploit potential
  • Configuration hardening: Network policies default to deny and service roles with minimal permissions
  • Tenant isolation: Logical controls separate customer data

7. Network & Infrastructure Security

  • Segmented VPC/VNet architecture with firewalls and security groups
  • Continuous logging and monitoring of infrastructure events and anomalies
  • Automatic patching for managed services; scheduled patch windows for other systems
  • DDoS protection via infrastructure and edge partners

8. Business Continuity & Disaster Recovery

  • Regular, encrypted backups with test recovery
  • Documented BC/DR plans with RTOs and RPOs appropriate to the service tier
  • Geo-redundant strategies across Paris and Frankfurt to mitigate single-region risks

9. Vendor & Sub-processor Management

  • We limit the number of sub-processors and only work with parties that maintain appropriate security measures
  • Data Processing Agreements (DPAs) are in place with relevant vendors
  • We periodically assess vendor controls and maintain an up-to-date sub-processor list available upon request

10. Payment Information

  • SNDQ does not store raw card numbers
  • All payment data is processed directly by our payment providers, who are PCI-DSS certified

11. Logging, Monitoring & Incident Response

  • Centralized log collection, alerts, and monitoring at application and infrastructure levels
  • Documented Incident Response plan including triage, containment, recovery, and evaluation
  • Customer notifications follow legal and contractual obligations

12. Your Responsibilities

Security is a shared responsibility. We advise customers to:

  • Enable MFA and use strong, unique passwords
  • Limit user permissions to what is strictly necessary
  • Regularly review audit logs and security alerts
  • Keep devices and browsers up to date

13. Changes to This Statement

We may update this page to reflect improvements in our security program or changes in legislation. Updates are effective upon publication.

14. Contact SNDQ

Have a security question or concern? Contact us via the form on our website (sndq.be) or through your SNDQ account manager.

Contact lijst itemHuurcontract lijst item

Start free today

Try SNDQ free for 14 days and discover how all-in-one management really feels! No payment methods, just try it out. Experience how easy it is to get a grip on your buildings and administration. After 14 days not for you? No problem, without a payment method your access expires automatically.

Security | How SNDQ protects your data