Security at fetchtax
We have clear rules for data protection and security and take that responsibility seriously.
GDPR compliant
- As a company based in Berlin, we meet the requirements of the GDPR and the BDSG.
Data processing in the EU
- We store and process your data exclusively within the EU.
- We make corresponding arrangements with sub-processors.
Certified infrastructure
- Lovable is ISO 27001:2022 certified and SOC 2 Type 2 audited.
- Supabase is ISO 27001 certified and SOC 2 Type 2 audited.
- n8n is SOC 2 Type 2 and SOC 3 audited.
- Mailgun is ISO 27001 certified and SOC 2 Type 2 audited.
Read-only access
- fetchtax only accesses your data in Shopify, Stripe or PayPal in read mode.
- You only grant fetchtax read permissions on your platforms.
- No risk to the ongoing operation of your business.
Secure by design
- Secure default settings
- Accounting data is processed only on your behalf.
- Sharing happens via a sharing link with an additional security code.
Encrypted transmission
- Data is always transmitted in encrypted form.
- A+ result from Qualys SSL Labs for fetch.tax
Encrypted storage
- Accounting data is stored encrypted using AES.
- Cryptographic keys are managed in dedicated key management systems wherever available.
GoBD compatible
- fetchtax can facilitate the legally compliant processing of accounting data.
Digitally signed emails
- Emails are sent exclusively via authorized servers.
- SPF and DKIM for authentication
- DMARC for continuously monitoring effectiveness
Two-factor authentication
- Microsoft Entra ID and biometric authentication via Microsoft Hello for Business are supported
- Google Workspace is supported as an identity provider
- Secure authentication via OpenID Connect
External security checks
- Regular security reviews by external service providers
Technical monitoring
- Tamper-proof access logs on separate systems
Data backup
- Regular data backups
- Backup access protection has the same security level as for the production system
No AI training
- Data processed on your behalf is not used for training artificial intelligence.
Defined deletion deadlines
- Customers can request deletion of their data at any time in accordance with the DPA
- Automatic deletion of data after defined deadlines according to the TOS