GDPR Compliance

Learn how Zweigen helps you keep data handling practical, secure, and easy to explain inside your team.

Zweigen is designed for use in the EU and fulfills the requirements of the GDPR. This page describes the technical and organizational measures implemented for that purpose. For further legal details, see the Privacy Policy.

EU cloud

All data in Zweigen is stored and processed exclusively on servers within the EU. No dataset leaves the EU. All subprocessors used are also located in the EU.

Data processing agreement

Zweigen provides a data processing agreement (DPA). You can view and download it in Privacy Settings. Acceptance is required for sensitive organization actions such as data imports.

Encryption

Data is encrypted in transit and at rest. Only users who are explicit members of an organization can access that organization's data. Zweigen employees do not have access to your content.

Roles and access management

In Zweigen, you can define which users may access specific data sources and dashboards. Access management allows restrictions per role and per individual user. This lets you control data access according to the principle of data minimization.

Multi-factor authentication

You can enable multi-factor authentication (MFA) in Account Settings. MFA protects your account against unauthorized access even if credentials are compromised. MFA is recommended for teams with access to sensitive data.

Backups

Zweigen performs regular automated backups of application data. Backups are deleted according to defined retention periods. The exact periods depend on the booked plan and legal requirements.

Audit logging

Security-relevant and privacy-relevant events are logged. The audit log is retained for a defined period and can be reviewed in Administration.

Data subject rights

You can export or delete all your data stored in Zweigen at any time through Privacy Settings. The export includes all personal data associated with your account. Deletion is irreversible and takes effect immediately.

Data minimization

Zweigen stores only the data required to operate the platform. During data upload, you can decide which columns and fields should be imported. Data that is not needed does not need to be uploaded.

Your organizational responsibility

Technical measures alone are not enough for GDPR compliance. Internal processes such as access management, employee training, and documentation of processing activities remain your responsibility. Zweigen provides the technical prerequisites for that.

All Data. One system.

ZweigenZWEIGEN

Zweigen is a self-service BI platform with an integrated data foundation for teams and secure EU-hosted operations.

Contact

We are happy to help and advise. Send us an email at hi@zweigen.cloud or visit our socials.