Naar inhoud

Your data is yours, and stays within the EU

Your lists sometimes hold sensitive things: contracts, costs, expiry dates. We keep them carefully and within Europe, and below we write down exactly what that does and does not mean. You can take your data with you at any time.

Hosted in the Netherlands

The application, the database and the backups run at TransIP in the Netherlands. Your data does not leave the EU, except where a subprocessor brings that with it, and those are listed on our subprocessors page.

Encrypted traffic, hashed tokens

All traffic runs over HTTPS with TLS. Anything that can grant access, such as sign-in links, invitations and action buttons in emails, is stored only as an irreversible hash. The access token of a Microsoft connection is stored encrypted.

Private until you share

Every list is private by default. Only when you invite a colleague as a reader or editor does anyone else get access, and you decide exactly who can do what.

Sign in without a password

Sign in via a magic link in your email or with your Microsoft 365 account. No password to forget or to leak.

Daily backups

We make a full copy of the database every day. Daily copies are kept for 14 days, weekly copies for 120 days. A restore can therefore lose up to 24 hours of data. Restoring is done manually, and we do not commit to a recovery time.

Your data, exportable

You're never locked in. Export your lists whenever you like and take your data with you. No vendor lock-in, just your data.

Privacy and GDPR

Built to the GDPR

OwndUp has been built with the GDPR in mind from the very first line of code. We only process what's needed to make your lists work and to warn you in time, and we keep that data within the EU. What you put in OwndUp stays yours.

Want to know exactly how we handle data, or want to view, export or delete your data? Our privacy statement explains how that works, and you can always email us about it directly.

If you use the optional feature to read a row from a PDF, that document is processed within the EU (Mistral, Paris), never stored by us, and you confirm every row yourself before it's saved. We keep a transparent list of the service providers that process data on our behalf.

Data processing agreement

A data processing agreement, ready to sign

If you put personal data into OwndUp, we are the processor and your organisation is the controller. That calls for a data processing agreement, as article 28 of the GDPR requires. We have a standard version for it, for customers on Business and Continuity.

That agreement sets out which data we process on your behalf, which subprocessors we engage and how you object to a new one, how long we keep data and within what period we delete it, what we do in the event of a data breach, and how you take your data with you if you stop.

Request it at hello@owndup.com and we will send it ready to sign. Add your organisation name and company registration number, and it will arrive filled in.

Responsible disclosure

Found something? Let us know

Think you've found a security issue? Report it to us before you make it public, and we'll fix it together. We respond fast and keep you posted.

Ready to keep your lists safe?

Start today with a 30-day free trial. No credit card needed.