Your lists sometimes hold sensitive things: contracts, costs, expiry dates. We keep them carefully and within Europe, and below we write down exactly what that does and does not mean. You can take your data with you at any time.
The application, the database and the backups run at TransIP in the Netherlands. Your data does not leave the EU, except where a subprocessor brings that with it, and those are listed on our subprocessors page.
All traffic runs over HTTPS with TLS. Anything that can grant access, such as sign-in links, invitations and action buttons in emails, is stored only as an irreversible hash. The access token of a Microsoft connection is stored encrypted.
Every list is private by default. Only when you invite a colleague as a reader or editor does anyone else get access, and you decide exactly who can do what.
Sign in via a magic link in your email or with your Microsoft 365 account. No password to forget or to leak.
We make a full copy of the database every day. Daily copies are kept for 14 days, weekly copies for 120 days. A restore can therefore lose up to 24 hours of data. Restoring is done manually, and we do not commit to a recovery time.
You're never locked in. Export your lists whenever you like and take your data with you. No vendor lock-in, just your data.
OwndUp has been built with the GDPR in mind from the very first line of code. We only process what's needed to make your lists work and to warn you in time, and we keep that data within the EU. What you put in OwndUp stays yours.
Want to know exactly how we handle data, or want to view, export or delete your data? Our privacy statement explains how that works, and you can always email us about it directly.
If you use the optional feature to read a row from a PDF, that document is processed within the EU (Mistral, Paris), never stored by us, and you confirm every row yourself before it's saved. We keep a transparent list of the service providers that process data on our behalf.
If you put personal data into OwndUp, we are the processor and your organisation is the controller. That calls for a data processing agreement, as article 28 of the GDPR requires. We have a standard version for it, for customers on Business and Continuity.
That agreement sets out which data we process on your behalf, which subprocessors we engage and how you object to a new one, how long we keep data and within what period we delete it, what we do in the event of a data breach, and how you take your data with you if you stop.
Request it at hello@owndup.com and we will send it ready to sign. Add your organisation name and company registration number, and it will arrive filled in.
Think you've found a security issue? Report it to us before you make it public, and we'll fix it together. We respond fast and keep you posted.
Start today with a 30-day free trial. No credit card needed.