Forward this page to whoever signs off. Hosting, security, the data processing agreement, the subprocessors and how we handle AI: summarised, with links to the full documents. So a team that wants to use OwndUp doesn't get stuck on the paperwork.
Application, database and backups run at TransIP in the Netherlands. Your data doesn't leave the EU, except where a subprocessor requires it, and that's listed on our subprocessors page.
All traffic runs over HTTPS with TLS. Anything that can grant access (login links, invitations, action buttons in emails) is stored only as an irreversible hash. The token for a Microsoft connection is stored encrypted.
Login is via a magic link or a Microsoft 365 account, so there's no password to leak. Every list is private by default; only when you invite someone as reader or editor do they get access.
We take a full copy of the database daily (daily kept 14 days, weekly 120 days). You export your lists whenever you want and take your data with you, no vendor lock-in.
Put personal data into OwndUp and we are the processor while your organisation is the controller. That calls for a data processing agreement, as article 28 of the GDPR requires. We have a standard version for customers on Business and Continuity.
That agreement describes which data we process on your behalf, which subprocessors we use and how you object to a new one, how long we retain and within what period we delete, what we do in the event of a data breach, and how you take your data with you if you leave.
Request it via hello@owndup.com and we'll send it ready to sign. Add your organisation name and registration number and it'll be filled in correctly.
OwndUp has one optional AI feature: reading a document, such as a contract PDF, into a list. That document is processed in the EU (Mistral, Paris), not stored by us, and you confirm every row yourself before it's saved. The tracking itself (reminding, escalating, proving) is ordinary, explainable software, not AI.
Don't want that feature at all? An admin switches document extraction off per organisation, in a single toggle. Then no document touches an AI service, without losing the rest of OwndUp.
This page summarises. The underlying pages are always there: our security page with every measure, the subprocessor list and the privacy statement. Found a vulnerability? Report it responsibly via security@owndup.com.
Email us and we'll send the data processing agreement ready to sign, or answer your security questionnaire. In the meantime the team can just try it free for 30 days.