Security and Data Processing
Everything about data security and data processing when using KYP.
Table of contents
- Introduction
- ISO 27001 Certification
- Technical Security
- Access Security
- GDPR and the Data Processing Agreement
- What you can expect from KYP
- Questions?
Introduction
A large number of construction professionals in the Netherlands, Belgium, Germany and England work with our software every day. They trust us with project data, planning data and company information. We take that trust seriously.
In this article, we explain the steps we take to protect your data. We cover the ISO 27001 certification of our software developer the technical measures we apply, how we handle the GDPR, and what you can expect from us in terms of availability and continuity.
ISO 27001 certification
Our software is developed by Geckotech B.V., which is ISO 27001 certified. ISO 27001 is the international standard for information security. The certification sets requirements for how an organisation establishes, maintains and continually improves its information security, and covers both the software and the data processed in it.
What this means for you as a customer, partner or supplier
- Geckotech B.V. works with documented, verifiable policies and procedures for information security.
- Security risks are systematically identified, assessed and managed.
- Geckotech B.V. is periodically audited by an independent certification body.
- Security measures are continuously evaluated and improved.
ISO 27001 is not a one-off exercise but an ongoing process. At KYP, security never stands still.
Technical security
Data storage and access
Your data is stored on secure servers that are not publicly accessible. Access is only possible through a secure session and is restricted to a limited number of trusted administrators.
Encryption
All data sent to end users through the application is always encrypted over the public network (encryption in transit).
Data location: within the EU
All KYP applications, databases and storage services run within the European Union. Your data does not leave the EU. This is in line with the GDPR and gives you the assurance that your data falls under the European legal framework.
Backups and retention period
Daily backups are made of all production environments. These are retained for one month, so that data can be restored in the event of an incident.
Availability and continuity
KYP uses cloud infrastructure from leading European and international cloud providers with built-in availability and reliability guarantees. Our applications are being migrated step by step to a Kubernetes infrastructure, which automatically restarts services in the event of unexpected outages, providing a higher degree of self-healing capability.
Our technical team carries out active monitoring during business hours and passive monitoring outside business hours, so that disruptions are quickly detected and addressed.
Regular security scans
We regularly run automated security scans on our applications. These identify vulnerabilities (such as missing security settings or configuration issues), which are translated into concrete improvement actions that we actively follow up on. This is part of Geckotech B.V.'s ISO 27001 approach to continuous improvement.
Network and application security
Firewall and security components are active on all publicly accessible services to protect against unauthorised access and common types of attack. We are also working on additional measures, including a stricter network policy under which only explicitly permitted traffic is allowed by default.
Access security
Single Sign-On (SSO)
For additional access security, you can use SSO.
Roles and permissions
Our applications support role and permission management for users.
GDPR and the Data Processing Agreement
KYP processes personal data of users in the context of construction projects, such as name, email address and project role. We do this as a processor on behalf of our customers, who act as the controller. In doing so, we always act in accordance with the General Data Protection Regulation (GDPR).
Example: a construction company adds an employee to a project in KYP. The construction company has decided to register that employee. This makes the construction company the controller. KYP stores the name and email address in its database. This makes KYP the processor.
Data Processing Agreement
We conclude a Data Processing Agreement (DPA) with every customer. It sets out the rights and obligations of both parties regarding the processing of personal data. The DPA is a legal requirement under the GDPR and gives you, as a customer, the assurance that we only process the personal data you entrust to us for the purposes for which it was provided.
Our Data Processing Agreement covers, among other things:
- The nature and purpose of the data processing.
- The categories of personal data and data subjects.
- The retention periods for personal data.
- The obligations and rights of the controller.
- The security measures KYP takes to protect personal data.
- The conditions for engaging sub-processors.
Data minimisation and purpose limitation
We only collect the personal data that is necessary for our software to function and to provide our services to customers. Data is not kept longer than necessary and is not used for purposes other than those for which it was collected.
What you can expect from KYP
Security is not a project with an end date, but a continuous process. We continually invest in improving our technical and organisational measures. Here is an overview:
|
Topic |
What KYP does |
|
ISO 27001 |
Our software developer Geckotech B.V. is certified and periodically audited externally. |
|
Data storage |
Secure servers, accessible only to authorised administrators. |
|
Encryption |
Data is sent encrypted over the public network. |
|
EU data location |
All data is stored and processed within the EU. |
|
Backups |
Daily backups of production environments, retained for one month. |
|
Availability |
Cloud infrastructure, step-by-step migration to a self-healing Kubernetes environment, and monitoring during and outside business hours. |
|
Security scans |
Regular automated scans with active follow-up on findings. |
|
GDPR |
Data Processing Agreement with every customer; strict purpose limitation and data minimisation. |
|
SLA |
Agreements on availability and support are set out in our Service Level Agreement. |
Questions?
Do you have questions about our security measures, the Data Processing Agreement or the ISO 27001 certification of our software developer? Feel free to contact us. We are happy to answer your questions and help you work together securely.