Our own servers in Europe · GDPR · Support in your language

Security and compliance

What your IT lead is going to ask

Encryption, access control, an audit log, verified backups, and a data processing agreement that reads without any surprises.

IT's five questions, answered

When an IT manager evaluates a platform they always ask the same things: where the data sits, who can reach it, what happens if there is a breach, and what the data processing agreement says. Kimobox answers with its own infrastructure inside the European Union, encryption in transit and at rest, role-based access with two-factor authentication, an audit log of every action, and an article 28 GDPR agreement written to be read rather than signed unseen.

Content reviewed on

Applicable framework
Regulation (EU) 2016/679 and Organic Law 3/2018 GDPR applicable since 25 May 2018; the Spanish law since December 2018
Processing agreement
Art. 28 of the GDPR With the minimum content the article itself lists
Breach notification
72 hours Art. 33 GDPR, from when the controller becomes aware
Maximum fine
20 million euros or 4 % of global turnover Whichever is higher, under art. 83.5
Data location
Data centres in the EU No international transfers requiring additional safeguards

End-to-end encryption

TLS in transit and encryption at rest for data and attachments.

Access and two-factor auth

Role-based permissions, corporate SSO and an optional mandatory second factor.

Audit log

Who saw or changed what, and when — including support-team access.

GDPR compliant

Data processing agreement, activity log and rights management.

Operations


How the service is kept running

  • 24/7 monitoring with alerts and on-call staff
  • Daily backups with periodic restore testing
  • Separate test and production environments
  • Planned updates, communicated in advance
  • Tested continuity and recovery plan
  • Periodic security audits and penetration testing
SECURITY AND AUDIT LOG ENCRYPTION In transit and at rest TWO-FACTOR Corporate SSO and 2FA per profile AUDIT LOG M. Soler Edited "Health & safety policy" 09:14 Support Authorised access to ticket #482 10:02 A. Puig Downloaded payroll report 11:47 J. Ferrer Signed in with 2FA 12:30 GDPR AND SPANISH DATA PROTECTION LAW, NO SMALL PRINT Data processor agreement and record of processing activities INCLUDING ACCESS BY OUR OWN SUPPORT TEAM

Real examples


What usually breaks

Company with an external DPO

An incomplete record of processing activities

Before The record was drawn up in 2019 and has not been touched since, even though the company has adopted three new tools.

After Each processing operation is registered with its legal basis, data categories, retention periods and recipients, and reviewed when the underlying system changes.

Manufacturing · contractor access

Accounts still active years later

Before Nobody reviews permissions. There are accounts belonging to people who left in 2022 with access to quality documentation.

After Periodic access review by role and automatic deactivation tied to the personnel record. Access expires when the relationship does.

Services · customer audit

Proving who saw a document

Before The system logs logins but not actions. Faced with a complaint, the company can neither confirm nor deny anything.

After An audit log with user, action, object and timestamp. The question "who downloaded this" has a dated answer.

Vocabulary


Terms to use precisely

Controller
Whoever determines the purposes and means of the processing. On a platform like this the controller is the customer company, not the provider.
Processor
Whoever processes data on the controller's behalf. They may only do so on documented instructions and under the art. 28 GDPR agreement.
Personal data breach
A breach leading to destruction, loss, alteration or unauthorised access to personal data. It must be notified to the authority within 72 hours unless a risk is unlikely.
Encryption at rest
Protection of data while stored, not only while it travels. It is what limits the damage if someone reaches the physical medium.
Record of processing activities
An inventory of the processing an organisation carries out, required by art. 30 GDPR. It is the first thing a supervisory authority asks for.
Two-factor authentication
Verification combining something known with something held. It turns a leaked password into an inconvenience rather than a serious incident.

Frequently asked questions


What people ask us before getting started

Where is the data hosted?

In European Union data centers, on our own infrastructure.

Who can see my data?

Only support staff, with logged access and under your express authorization.

Are you ISO 27001 certified?

The service is operated under ISO 27001 controls; we provide documentation for your supplier assessment.

Who is controller and who is processor?

The customer company is the controller: it decides the purposes and the means. Kimobox acts as processor and only handles the data on documented instructions, under the agreement art. 28 of the GDPR requires.

What happens if there is a data breach?

Art. 33 of the GDPR requires notifying the supervisory authority within a maximum of seventy-two hours of becoming aware. The processing agreement includes the commitment to inform you without undue delay so you can meet that deadline.

What is the maximum GDPR fine?

Twenty million euros or four per cent of global annual turnover, whichever is higher, for infringements under art. 83.5. It is why these questions stopped being a formality.

Can you tell who accessed a document?

Yes. The audit log stores user, action, object and timestamp, and is searchable and exportable. The question "who downloaded this" has a dated answer.

How are data subject rights handled?

Access, rectification, erasure, restriction, portability and objection are handled from the platform, locating the data by data subject and logging the response within the one-month deadline of art. 12.3.

Is two-factor authentication available?

Yes, enabled per role. It is what turns a leaked password into an inconvenience rather than a serious problem.

Pass our security sheet to your IT team

We'll show you the module running with data similar to yours.

Request a demo

Sources


Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. Regulation (EU) 2016/679, General Data Protection Regulation EUR-Lex · Applicable since 25 May 2018
  2. Organic Law 3/2018 on Data Protection and guarantee of digital rights BOE-A-2018-16673 · 6 December 2018
  3. Guidance on notifying personal data breaches Spanish Data Protection Agency · AEPD guidance
  4. ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022

Information security and GDPR compliance

The platform applies encryption in transit and at rest, profile-based access control, two-factor authentication, corporate SSO integration and an audit log of every action, including support-team access.

The service is provided from European Union data centers under a data processing agreement compliant with GDPR and Spain's LOPDGDD, with verified daily backups, separate environments and a tested continuity plan.