Your audit data: in Germany, on our own server, in your own database
Everything IT, data protection officers and works councils want to know before you start – on one page: hosting, encryption, access, backups, processors and contract.
Four pillars
100 % hosting in Germany
IMS-Audit Cloud runs on our own dedicated server hardware in a certified Hetzner data centre in Germany. No shared cloud hosting – the machine is used exclusively for IMS-Audit Cloud. Your data does not leave Germany.
A separate database per company
Every customer receives its own separate database on the PostgreSQL server – no shared system across companies. Within your company, multi-client capability separates plants, sites and departments.
Encrypted & secured
Transmission between browser and server is TLS-encrypted throughout. If you wish, you protect logins with two-factor authentication (Microsoft Authenticator, Google Authenticator or any TOTP app) – mandatory for everyone if required.
Backed up daily
Your database is backed up automatically every day, and the backups are stored on separate, geographically separated storage. In the event of a fault we restore operation from the last available backup.
Measures at a glance
- Dedicated server hardware, not shared with third-party customers of the data centre
- A separate database per customer company; client separation within the company
- TLS encryption for all connections between browser and server
- Roles and permissions concept: predefined roles or granular permissions per person
- Optional two-factor authentication, enforceable on request
- Field-level change tracking – traceable who changed what and when
- Daily automatic backups on geographically separated storage
- Own access per company, e.g. yourcompany.ims-audit.de
- Central maintenance: we apply security updates without you having to install anything
The complete technical and organisational measures are part of the data processing agreement.
Processors & service providers
Which companies are involved in operating IMS-Audit Cloud and this website – and for what purpose.
| Company | Purpose | Location | Note |
|---|---|---|---|
| Hetzner Online GmbH | Operation of IMS-Audit Cloud (servers, databases, backups) | Germany | Own dedicated hardware in the data centre; DPA concluded |
| IONOS SE | Hosting of this website and delivery of the contact forms | Germany | Concerns the website only, not the cloud application |
| CleverReach GmbH & Co. KG | Newsletter delivery (only on sign-up, double opt-in) | Germany | DPA under Art. 28 GDPR; servers in Germany |
| DeepL SE (optional) | Automatic translation of audit answers and catalogues | Germany | Only if you enter your own DeepL API key – the contract is between you and DeepL |
Details on purposes, legal bases and retention periods: Privacy policy (German).
DPA, availability, data sovereignty
Data processing agreement (DPA)
As processor we conclude a DPA under Art. 28 GDPR with you that governs the technical and organisational measures – on request we provide it in advance for review.
Availability
We provide IMS-Audit Cloud with an availability of 98.5 % annual average; the data centre assures network availability of at least 99.9 %. Planned maintenance windows are excluded and are announced in good time.
Data sovereignty & export
You export evaluations yourself as Excel/CSV at any time. After the contract ends your database is kept locked for 30 days; on request you receive a complete copy as a PostgreSQL backup beforehand, after which it is irrevocably deleted.
Contract & termination
Minimum term 12 months from provisioning, automatic renewal for 12 months at a time; termination with three months’ notice to the end of the term in text form. Contracts and terms are concluded in German.
Full text: Terms (German) · FAQ Security & Hosting
What IT and data protection ask
Where exactly is our data stored?
On our own dedicated server hardware in a certified Hetzner data centre in Germany. The machine is not shared with third-party customers of the data centre; every IMS-Audit customer has its own separate database on it. Data does not leave Germany.
Is IMS-Audit Cloud GDPR-compliant?
The hosting is GDPR-compliant in Germany: German data centre, a separate database per company, TLS encryption, DPA under Art. 28 GDPR. Responsibility for processing your audit and personal data remains with you as controller – we support you with the appropriate technical and contractual foundations.
Who has access to our database?
Your users according to the roles and permissions concept – and we as operator exclusively within the scope of the DPA for operation, maintenance and support. Other customers have no access: every company works in its own database.
Can we make 2FA mandatory for all users?
Yes. Two-factor authentication is optional and can be made mandatory for logins if your IT policy requires it – with Microsoft Authenticator, Google Authenticator or any TOTP app.
Do we receive the DPA before signing the contract?
Yes, on request we provide the data processing agreement in advance for review – a short e-mail to anfrage@ims-audit.de is all it takes.
Does your IT still have an open question?
We answer it directly – with the developer, no detours. On request we provide the DPA in advance.