IMS-Audit
Security & hosting

Your audit data: in Germany, on our own server, in your own database

Everything IT, data protection officers and works councils want to know before you start – on one page: hosting, encryption, access, backups, processors and contract.

The basics

Four pillars

100 % hosting in Germany

IMS-Audit Cloud runs on our own dedicated server hardware in a certified Hetzner data centre in Germany. No shared cloud hosting – the machine is used exclusively for IMS-Audit Cloud. Your data does not leave Germany – unless you choose to store documents in your own SharePoint.

A separate database per company

Every customer receives its own separate database on the PostgreSQL server – no shared system across companies. Within your company, multi-client capability separates plants, sites and departments.

Encrypted & secured

Transmission between browser and server is TLS-encrypted throughout. If you wish, you protect logins with two-factor authentication (Microsoft Authenticator, Google Authenticator or any TOTP app) – mandatory for everyone if required.

Backed up daily

Your database is backed up automatically every day, and the backups are stored on separate, geographically separated storage. In the event of a fault we restore operation from the last available backup.

Optional · your own storage

Documents in your own SharePoint

On request, IMS-Audit Cloud stores uploaded documents and photos not on our server but in a SharePoint site of your organisation. If you already keep your records in Microsoft 365, everything stays in one place.

  • Your records stay in your Microsoft 365 – under your own rules for retention, access and backup
  • Readable folders with the original file names, e.g. “IMS-Audit Cloud / Audits / A-2026-009”
  • Access only to the one site your IT releases (Microsoft permission “Sites.Selected”) – no other sites, no mailboxes, no user list
  • Every file is checked before it is stored (file type, size, virus scan); no copy remains with us
  • Your users keep opening documents in IMS-Audit Cloud – with the permissions that apply there
  • Existing files move over at the push of a button, each one verified
  • Set up by your IT in a few steps; your administrator downloads the guide directly in the application

Good to know

  • Requires Microsoft 365 with SharePoint.
  • Stored there are uploaded documents and photos – on audits, questions, actions and complaints, in document control, for qualifications and test equipment.
  • All other data – audits, actions, master data, users – stays on our server in Germany.
  • For the files in your SharePoint, your contract with Microsoft determines the storage location. Backup and retention are your responsibility; our daily backup does not include them.
  • The rules are set out in our terms (German), § B-SaaS 7.
Technical & organisational

Measures at a glance

  • Dedicated server hardware, not shared with third-party customers of the data centre
  • A separate database per customer company; client separation within the company
  • TLS encryption for all connections between browser and server
  • Roles and permissions concept: predefined roles or granular permissions per person
  • Optional two-factor authentication, enforceable on request
  • Field-level change tracking – traceable who changed what and when
  • Daily automatic backups on geographically separated storage
  • Own access per company, e.g. yourcompany.ims-audit.de
  • Central maintenance: we apply security updates without you having to install anything

The complete technical and organisational measures are part of the data processing agreement.

Transparency

Processors & service providers

Which companies are involved in operating IMS-Audit Cloud and this website – and for what purpose.

CompanyPurposeLocationNote
Hetzner Online GmbHOperation of IMS-Audit Cloud (servers, databases, backups)GermanyOwn dedicated hardware in the data centre; DPA concluded
IONOS SEHosting of this website and delivery of the contact formsGermanyConcerns the website only, not the cloud application
CleverReach GmbH & Co. KGNewsletter delivery (only on sign-up, double opt-in)GermanyDPA under Art. 28 GDPR; servers in Germany
DeepL SE (optional)Automatic translation of audit answers and cataloguesGermanyOnly if you enter your own DeepL API key – the contract is between you and DeepL
Microsoft (optional)Storage of documents and photos in your SharePoint siteYour Microsoft 365Only if you set up SharePoint storage – your own Microsoft 365, the contract is between you and Microsoft

Details on purposes, legal bases and retention periods: Privacy policy (German).

Contractual

DPA, availability, data sovereignty

Data processing agreement (DPA)

As processor we conclude a DPA under Art. 28 GDPR with you that governs the technical and organisational measures – on request we provide it in advance for review.

Availability

We provide IMS-Audit Cloud with an availability of 98.5 % annual average; the data centre assures network availability of at least 99.9 %. Planned maintenance windows are excluded and are announced in good time.

Data sovereignty & export

You export evaluations yourself as Excel/CSV at any time. After the contract ends your database is kept locked for 30 days; on request you receive a complete copy as a PostgreSQL backup beforehand, after which it is irrevocably deleted. Files in your own SharePoint storage are with you anyway and stay there.

Contract & termination

Minimum term 12 months from provisioning, automatic renewal for 12 months at a time; termination with three months’ notice to the end of the term in text form. Contracts and terms are concluded in German.

Full text: Terms (German) · FAQ Security & Hosting

Frequently asked questions

What IT and data protection ask

Where exactly is our data stored?

On our own dedicated server hardware in a certified Hetzner data centre in Germany. The machine is not shared with third-party customers of the data centre; every IMS-Audit customer has its own separate database on it. Data does not leave Germany – except documents and photos you choose to store in your own SharePoint.

Can we store documents in our own SharePoint?

Yes. On request, IMS-Audit Cloud stores uploaded documents and photos in a SharePoint site of your organisation. Your IT releases exactly one site, and IMS-Audit Cloud gets access to that site only. Backup and retention of these files are then your responsibility; all other data stays on our server in Germany.

Is IMS-Audit Cloud GDPR-compliant?

The hosting is GDPR-compliant in Germany: German data centre, a separate database per company, TLS encryption, DPA under Art. 28 GDPR. Responsibility for processing your audit and personal data remains with you as controller – we support you with the appropriate technical and contractual foundations.

Who has access to our database?

Your users according to the roles and permissions concept – and we as operator exclusively within the scope of the DPA for operation, maintenance and support. Other customers have no access: every company works in its own database.

Can we make 2FA mandatory for all users?

Yes. Two-factor authentication is optional and can be made mandatory for logins if your IT policy requires it – with Microsoft Authenticator, Google Authenticator or any TOTP app.

Do we receive the DPA before signing the contract?

Yes, on request we provide the data processing agreement in advance for review – a short e-mail to anfrage@ims-audit.de is all it takes.

Does your IT still have an open question?

We answer it directly – with the developer, no detours. On request we provide the DPA in advance.