Sandbank is built for GDPR-compliant operations
Sandbank implements privacy and security controls aligned with GDPR requirements. User data is protected with high operational standards.
Security and privacy standards are continuously maintained and expanded.
For legal details, see our Privacy Policy.
EU cloud hosting
Data stored in Sandbank remains in the EU. Sandbank and its data infrastructure are hosted in the EU.
No non-EU subprocessors are used for core data processing.
Data Processing Agreement (DPA)
A DPA is provided to customers and must be accepted where contractually required.
After subscription activation, users are guided through the required DPA acceptance flow before continued product usage.
End-to-end protection model
User data is technically protected and accessible only to authorized members inside the respective organization.
No one outside authorized members of that organization can access those user data assets.
Role and access control
Sandbank provides role-based controls to restrict access to data and product features.
Multi-factor authentication
Users are strongly encouraged to activate MFA in account settings.
Backups
Automated backups for application and user data are executed and retained under defined retention policies.
Audit logging
Security- and privacy-relevant events are logged and retained according to defined retention periods.
Data subject rights
Users can export and/or delete their stored data via privacy settings.
Data minimization
Data required to run Sandbank is regularly reviewed and kept minimal in line with privacy principles.
During upload, users can define which parts of a dataset should be stored.
Shared responsibility
Effective GDPR practice is partly technical and partly organizational. Internal access controls and clear operational processes remain essential on the customer side.
SANDBANK
Contact
We are happy to help and advise you, send an email to hi@sandbank.cloud.
Information about roadmap updates and submitting or voting on suggestions is available at /development.