Security and privacy
Technical and organisational measures of the platform · Version of 22 May 2026
This is a convenience translation. Where a German version is published, the German text prevails for interpretation.
1. Purpose of this document
This document describes the technical and organisational measures by which the security, confidentiality, integrity and availability of data processed via the ClearOffert platform are safeguarded. It complements the privacy notice and also serves as a basis for the technical and organisational measures within the meaning of Art. 32 GDPR.
2. Hosting and infrastructure
The platform is operated on servers within the Federal Republic of Germany. The infrastructure of Hetzner Online GmbH is used, with data-centre sites in Falkenstein and Nürnberg. The administrative seat of SysTec Analytics Ltd in the United Kingdom does not, by itself, amount to a statement about international data transfers.
3. Encryption
Data transmission between the user’s device and the platform takes place exclusively over transport-encrypted connections according to current standards. Passwords are not stored in clear text, but solely as suitable cryptographic values.
4. Access and authorisation concept
Access to platform functions and data is controlled through a role and permission system. Each user receives only the permissions required for their task. Administrative access by the provider is separately secured and logged.
5. Tenant isolation
The platform is designed so that data and audit workflows of different users are processed in logical separation. Tenant separation is an architecture principle and ensures that one user does not obtain access to another user’s data.
6. Backup and recovery
The provider performs regular backups. Backup copies are held on systems separated from one another. Restorability of the data is verified at appropriate intervals. Independently of this, users are recommended to use the provided export functions for their own backup.
7. Protection against unauthorised access and attacks
The provider implements measures to protect against unauthorised access and attacks, in particular secured system configurations, protection mechanisms against common attack types, and ongoing updates of the components in use.
8. Logging and traceability
Security-relevant events and administrative accesses are logged. Log data are retained only for the period required for security purposes.
9. Handling of personal data breaches
The provider maintains a process for detecting, assessing and handling breaches of the protection of personal data. If, in the course of processing on behalf, the provider becomes aware of a breach affecting a user’s data, it informs the affected user without undue delay so that the user can fulfil notification and communication duties.
10. Organisational measures
Technical measures are complemented by organisational measures. These include binding persons entrusted with data processing to confidentiality, clear responsibilities, and internal rules for the secure handling of data and systems.
11. No sale of data
SysTec Analytics Ltd does not sell personal data. Offer and audit data are neither sold individually nor in aggregate to third parties, nor disclosed for third-party advertising.
12. Continuous improvement
The provider regularly reviews its security and privacy concept and adapts it as needed to the state of the art, new threat situations and changing legal requirements.
The description of measures does not constitute an assurance of a particular security level; the current operational status is decisive. The security and backup concept is continuously developed.