Security and data
Material for your review: where the data is stored, who can reach it, what is encrypted and which sub-processors are used.
Where the data sits
On a server inside the EU, with Netcup in Nuremberg or Vienna. Nothing is replicated outside the EU and nothing routes through the United States. We do not use AWS, Google Cloud or Azure, so there is no American cloud provider in the chain to write an impact assessment about.
Your data is your own database
Every customer runs in their own instance, with their own database file, their own system user and their own encryption key. You are not rows in a shared table with a customer column. A fault in another customer's instance cannot reach yours, and restoring your data touches nobody else.
Encryption
- All traffic is over TLS. HTTP redirects, HSTS is on.
- Your mailbox passwords and DKIM keys are encrypted in the database, not merely stored.
- Agent and contact passwords are hashed, never kept in plain text.
- Two-step sign-in with an authenticator app can be required for the whole workspace.
Backups
The database is copied every night to a different machine, not to the same disk. Copies are kept for fourteen days and checked automatically, so a broken copy is found in the week it breaks rather than on the day you need it.
Who can reach the data
Named staff only, and only for troubleshooting. No subcontractors and no consultants have access. If we need to go into your instance we ask first, and everything that happens in the system is written to an audit log you can read yourself.
Sub-processors
The whole list. It does not change without telling you first.
| Provider | What they do | Where |
|---|---|---|
| Netcup GmbH | The server the system runs on | Germany or Austria |
| Cloudflare | DNS for bargguo.com | EU |
| BACKUP PROVIDER | Stores backups | EU |
Outgoing email
Email is sent through your own mail account, from your own sender address. We are not the sender and your messages pass through no third-party sending service. Incoming mail is collected from your mailbox over IMAP with TLS.
What we do not do
- No AI. Your ticket text is never sent to a model provider, not for replies, not for summaries, not for training.
- No tracking. This website has no Google Analytics, no Tag Manager, no pixels and no cookies. The typeface is on our own server, so not even a font request leaves the page.
- No reselling. Your data is not sold, not shared, and not used to train anything.
Agreements
A data processing agreement is sent before you sign, not after. You also get a record of processing activities and a personal data breach procedure, with the 72-hour clock written into it.
Deletion and export
You own your data. Export whenever you like, as CSV or over the API. If you cancel, the instance is deleted and the backups age out within fourteen days. Individual personal data can be erased on request directly in the system.
Found something?
Email security@bargguo.com. You get an answer within one working day. We ask that you report to us before the information is shared further, so the issue can be corrected.