Skip to content
BeschlussManager

Security

Security and privacy: your resolutions stay in Europe

Resolutions rarely contain secrets, but they almost always contain names, voting behaviour and internal matters. This page describes where that sits, who can reach it and what we do about it – without badges we do not hold.

Servers in Germany

Operated by STRATO AG in Germany. No transfer to third countries, no provider outside the EU in the chain.

Encrypted transport

All connections use TLS. Passwords are stored only as hashes, client secrets encrypted.

Separation of organisations

Every query is technically scoped to the tenant. Access beyond your own organisation is refused, not merely hidden.

Integrity record

A SHA-256 checksum over every resolution PDF. It shows integrity – it is not an electronic signature.

Complete audit trail

Every action on a resolution is logged. Entries are appended, never overwritten or deleted.

Sign-in without standing passwords

Access through single sign-on or one-time links. For an identity provider outage there are recovery codes and an emergency route.

Data protection

What we contribute to your GDPR duties

Your organisation remains the controller for the processing of your members' data; Beschlussmanager is the processor. That is why we do not print “GDPR compliant” here like a seal – compliance is a property of your processing, not of our product. What we can do is make it easy to meet:

  • Data processing agreement under Article 28 GDPR, without a negotiation round
  • Description of technical and organisational measures under Article 32 GDPR
  • List of sub-processors, kept current
  • Data minimisation: casting a vote needs a name and an email address, nothing else
  • Anonymous votes where voting behaviour should not be recorded
  • Deletion after the contract ends, export of resolution documents at any time before

We send the agreement and the measures on request – one message is enough.

Common questions

Where is the data stored?

On servers in Germany, operated by STRATO AG. There is no transfer to third countries and no provider outside the EU in the processing chain.

Do you provide a data processing agreement?

Yes. For the use of Beschlussmanager we conclude an agreement under Article 28 GDPR, including a description of the technical and organisational measures and the list of sub-processors. You do not have to negotiate to get it.

Can other organisations see our resolutions?

No. Every organisation is its own tenant, and every database query is technically scoped to the tenant of the signed-in person. In addition the application checks on every request whether the person belongs to the organisation being addressed and refuses access otherwise.

Does this website set cookies?

Not to display content. There is no tracking, no analytics and no third-party script – hence no cookie banner. Only when you use a form is a technically necessary session cookie set.

What happens to our data if we leave?

Resolution PDFs can be downloaded at any time, including beforehand – we explicitly recommend filing them in your own records. After the contract ends the data is deleted; the details are in the data processing agreement.

Ready for the first resolution?

We set up your organisation and get back to you within one working day. No payment details, no contract as a first step.