Security
Security and privacy: your resolutions stay in Europe
Resolutions rarely contain secrets, but they almost always contain names, voting behaviour and internal matters. This page describes where that sits, who can reach it and what we do about it – without badges we do not hold.
Servers in Germany
Operated by STRATO AG in Germany. No transfer to third countries, no provider outside the EU in the chain.
Encrypted transport
All connections use TLS. Passwords are stored only as hashes, client secrets encrypted.
Separation of organisations
Every query is technically scoped to the tenant. Access beyond your own organisation is refused, not merely hidden.
Integrity record
A SHA-256 checksum over every resolution PDF. It shows integrity – it is not an electronic signature.
Complete audit trail
Every action on a resolution is logged. Entries are appended, never overwritten or deleted.
Sign-in without standing passwords
Access through single sign-on or one-time links. For an identity provider outage there are recovery codes and an emergency route.
Data protection
What we contribute to your GDPR duties
Your organisation remains the controller for the processing of your members' data; Beschlussmanager is the processor. That is why we do not print “GDPR compliant” here like a seal – compliance is a property of your processing, not of our product. What we can do is make it easy to meet:
- Data processing agreement under Article 28 GDPR, without a negotiation round
- Description of technical and organisational measures under Article 32 GDPR
- List of sub-processors, kept current
- Data minimisation: casting a vote needs a name and an email address, nothing else
- Anonymous votes where voting behaviour should not be recorded
- Deletion after the contract ends, export of resolution documents at any time before
We send the agreement and the measures on request – one message is enough.
Common questions
Where is the data stored?
On servers in Germany, operated by STRATO AG. There is no transfer to third countries and no provider outside the EU in the processing chain.
Do you provide a data processing agreement?
Yes. For the use of Beschlussmanager we conclude an agreement under Article 28 GDPR, including a description of the technical and organisational measures and the list of sub-processors. You do not have to negotiate to get it.
Can other organisations see our resolutions?
No. Every organisation is its own tenant, and every database query is technically scoped to the tenant of the signed-in person. In addition the application checks on every request whether the person belongs to the organisation being addressed and refuses access otherwise.
Does this website set cookies?
Not to display content. There is no tracking, no analytics and no third-party script – hence no cookie banner. Only when you use a form is a technically necessary session cookie set.
What happens to our data if we leave?
Resolution PDFs can be downloaded at any time, including beforehand – we explicitly recommend filing them in your own records. After the contract ends the data is deleted; the details are in the data processing agreement.
Ready for the first resolution?
We set up your organisation and get back to you within one working day. No payment details, no contract as a first step.