End-to-end encryption
TLS in transit and encryption at rest for data and attachments.
Security and compliance
Encryption, access control, an audit log, verified backups, and a data processing agreement that reads without any surprises.
When an IT manager evaluates a platform they always ask the same things: where the data sits, who can reach it, what happens if there is a breach, and what the data processing agreement says. Kimobox answers with its own infrastructure inside the European Union, encryption in transit and at rest, role-based access with two-factor authentication, an audit log of every action, and an article 28 GDPR agreement written to be read rather than signed unseen.
TLS in transit and encryption at rest for data and attachments.
Role-based permissions, corporate SSO and an optional mandatory second factor.
Who saw or changed what, and when — including support-team access.
Data processing agreement, activity log and rights management.
Operations
Regulatory framework
Real examples
Company with an external DPO
Before The record was drawn up in 2019 and has not been touched since, even though the company has adopted three new tools.
After Each processing operation is registered with its legal basis, data categories, retention periods and recipients, and reviewed when the underlying system changes.
Manufacturing · contractor access
Before Nobody reviews permissions. There are accounts belonging to people who left in 2022 with access to quality documentation.
After Periodic access review by role and automatic deactivation tied to the personnel record. Access expires when the relationship does.
Services · customer audit
Before The system logs logins but not actions. Faced with a complaint, the company can neither confirm nor deny anything.
After An audit log with user, action, object and timestamp. The question "who downloaded this" has a dated answer.
Vocabulary
Frequently asked questions
In European Union data centers, on our own infrastructure.
Only support staff, with logged access and under your express authorization.
The service is operated under ISO 27001 controls; we provide documentation for your supplier assessment.
The customer company is the controller: it decides the purposes and the means. Kimobox acts as processor and only handles the data on documented instructions, under the agreement art. 28 of the GDPR requires.
Art. 33 of the GDPR requires notifying the supervisory authority within a maximum of seventy-two hours of becoming aware. The processing agreement includes the commitment to inform you without undue delay so you can meet that deadline.
Twenty million euros or four per cent of global annual turnover, whichever is higher, for infringements under art. 83.5. It is why these questions stopped being a formality.
Yes. The audit log stores user, action, object and timestamp, and is searchable and exportable. The question "who downloaded this" has a dated answer.
Access, rectification, erasure, restriction, portability and objection are handled from the platform, locating the data by data subject and logging the response within the one-month deadline of art. 12.3.
Yes, enabled per role. It is what turns a leaked password into an inconvenience rather than a serious problem.
We'll show you the module running with data similar to yours.
Keep exploring
Free learning path on the GDPR: principles, data subject rights, security measures, and breaches explained…
No clouds outside the European Union and no surprises in the data processing agreement. You know where your…
Asset inventory, risk analysis and Annex A controls, each with its status and owner.
Access authorization to the plant or office per employee, with card, PIN or biometrics, automatically…
Sources
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
The platform applies encryption in transit and at rest, profile-based access control, two-factor authentication, corporate SSO integration and an audit log of every action, including support-team access.
The service is provided from European Union data centers under a data processing agreement compliant with GDPR and Spain's LOPDGDD, with verified daily backups, separate environments and a tested continuity plan.