IMS-Audit
Security & hosting

Your audit data: in Germany, on our own server, in your own database

Everything IT, data protection officers and works councils want to know before you start – on one page: hosting, encryption, access, backups, processors and contract.

The basics

Four pillars

100 % hosting in Germany

IMS-Audit Cloud runs on our own dedicated server hardware in a certified Hetzner data centre in Germany. No shared cloud hosting – the machine is used exclusively for IMS-Audit Cloud. Your data does not leave Germany.

A separate database per company

Every customer receives its own separate database on the PostgreSQL server – no shared system across companies. Within your company, multi-client capability separates plants, sites and departments.

Encrypted & secured

Transmission between browser and server is TLS-encrypted throughout. If you wish, you protect logins with two-factor authentication (Microsoft Authenticator, Google Authenticator or any TOTP app) – mandatory for everyone if required.

Backed up daily

Your database is backed up automatically every day, and the backups are stored on separate, geographically separated storage. In the event of a fault we restore operation from the last available backup.

Technical & organisational

Measures at a glance

  • Dedicated server hardware, not shared with third-party customers of the data centre
  • A separate database per customer company; client separation within the company
  • TLS encryption for all connections between browser and server
  • Roles and permissions concept: predefined roles or granular permissions per person
  • Optional two-factor authentication, enforceable on request
  • Field-level change tracking – traceable who changed what and when
  • Daily automatic backups on geographically separated storage
  • Own access per company, e.g. yourcompany.ims-audit.de
  • Central maintenance: we apply security updates without you having to install anything

The complete technical and organisational measures are part of the data processing agreement.

Transparency

Processors & service providers

Which companies are involved in operating IMS-Audit Cloud and this website – and for what purpose.

CompanyPurposeLocationNote
Hetzner Online GmbHOperation of IMS-Audit Cloud (servers, databases, backups)GermanyOwn dedicated hardware in the data centre; DPA concluded
IONOS SEHosting of this website and delivery of the contact formsGermanyConcerns the website only, not the cloud application
CleverReach GmbH & Co. KGNewsletter delivery (only on sign-up, double opt-in)GermanyDPA under Art. 28 GDPR; servers in Germany
DeepL SE (optional)Automatic translation of audit answers and cataloguesGermanyOnly if you enter your own DeepL API key – the contract is between you and DeepL

Details on purposes, legal bases and retention periods: Privacy policy (German).

Contractual

DPA, availability, data sovereignty

Data processing agreement (DPA)

As processor we conclude a DPA under Art. 28 GDPR with you that governs the technical and organisational measures – on request we provide it in advance for review.

Availability

We provide IMS-Audit Cloud with an availability of 98.5 % annual average; the data centre assures network availability of at least 99.9 %. Planned maintenance windows are excluded and are announced in good time.

Data sovereignty & export

You export evaluations yourself as Excel/CSV at any time. After the contract ends your database is kept locked for 30 days; on request you receive a complete copy as a PostgreSQL backup beforehand, after which it is irrevocably deleted.

Contract & termination

Minimum term 12 months from provisioning, automatic renewal for 12 months at a time; termination with three months’ notice to the end of the term in text form. Contracts and terms are concluded in German.

Full text: Terms (German) · FAQ Security & Hosting

Frequently asked questions

What IT and data protection ask

Where exactly is our data stored?

On our own dedicated server hardware in a certified Hetzner data centre in Germany. The machine is not shared with third-party customers of the data centre; every IMS-Audit customer has its own separate database on it. Data does not leave Germany.

Is IMS-Audit Cloud GDPR-compliant?

The hosting is GDPR-compliant in Germany: German data centre, a separate database per company, TLS encryption, DPA under Art. 28 GDPR. Responsibility for processing your audit and personal data remains with you as controller – we support you with the appropriate technical and contractual foundations.

Who has access to our database?

Your users according to the roles and permissions concept – and we as operator exclusively within the scope of the DPA for operation, maintenance and support. Other customers have no access: every company works in its own database.

Can we make 2FA mandatory for all users?

Yes. Two-factor authentication is optional and can be made mandatory for logins if your IT policy requires it – with Microsoft Authenticator, Google Authenticator or any TOTP app.

Do we receive the DPA before signing the contract?

Yes, on request we provide the data processing agreement in advance for review – a short e-mail to anfrage@ims-audit.de is all it takes.

Does your IT still have an open question?

We answer it directly – with the developer, no detours. On request we provide the DPA in advance.