Data Protection and Security at oneVcard: a Promise to Our Customers
How oneVcard protects your data: a GDPR-compliant data center in Germany, encryption, two-factor authentication and clear policies.
Publié le 6 mars 2025 · 2 min de lecture

In today’s digital world, data protection and data security are central concerns. Companies and individuals place ever greater value on safeguarding sensitive data. At oneVcard we take this seriously and have implemented comprehensive measures so that your data is processed securely and in compliance with the GDPR.
Since 01.01.2025, Prof. Dr. Eberhard Schott, an expert in information security and data protection, has been our Data Protection Officer. With his support, we continue to uphold high standards.
Our Data Protection Principles at a Glance
- Data protection policy: Data on digital business cards is never used for profiling.
- Anonymized data collection: To improve our services, we collect anonymized data only.
- Storage in the EU: All data is held on servers within the European Union.
- Strict access controls: Access is limited to authorized personnel.
- Development team in Germany: Our apps are developed and maintained in Germany, with no outsourcing to third countries.
Data Security at a High Level
- Daily backups, retained for seven days.
- Two-factor authentication for sensitive systems.
- Protection against brute-force attacks through automatic blocking.
- Regular security reviews including penetration tests and audits.
Guidelines and Policies
- Data protection policy: defines principles, responsibilities and transparency obligations, and is updated regularly.
- DLP policy: protects sensitive information through role-based access, encryption and training.
- Internal controls: regular audits, documentation of all processes and data protection impact assessments when introducing new technologies.
Handling Customer Data
Customer data is used only for clearly defined purposes and is stored in encrypted form. Access follows the need-to-know principle with strict authentication mechanisms. Employees and contractors receive regular training.
Working with Subprocessors
Subprocessors are carefully vetted, are based in the EU and sign a data protection agreement before any collaboration begins. Compliance is monitored on an ongoing basis.
Incident Management and SLA
A clearly defined process ensures a rapid response to security incidents, including 24/7 readiness and an escalation plan. Our service-level agreements guarantee annual server availability of 99.5 percent and a recovery time of no more than six hours. The SLA is part of the oneVcard Teams Enterprise package.
Our Vision
For us, data protection is not just a legal requirement but a central pillar of our strategy. Whether you are a mid-sized business or an international enterprise, our solutions are scalable and tailored to your individual requirements.
Would you like to learn how oneVcard can support your company with secure solutions? Get in touch.