Security
SampleSync is built for procurement-sensitive environments. Here is what we store, where we store it, and how we protect it.
Location: All data is stored on Hetzner servers in Germany (EU). No data is transferred outside the European Economic Area.
What is stored: Material metadata (name, specs, files), scan events (timestamp, approximate location, device type), and account information for registered users.
What is not stored: We do not store payment card data. We do not build advertising profiles. We do not sell data to third parties.
In transit: All connections use TLS 1.2 or higher. HTTPS is enforced on every route.
At rest:Database volumes are encrypted at rest using AES-256 via Hetzner's managed infrastructure.
Secrets: Application secrets and API keys are stored as environment variables, never committed to source control.
Lawful basis for scan logging: Legitimate interest of the data controller (the material producer) to understand how their samples are being used.
Lawful basis for account data: Consent โ users explicitly register to unlock a material passport.
Data subject rights: Users can request access, correction, or deletion of their data by emailing [email protected]. Requests are handled within 30 days.
DPA: A Data Processing Agreement is available on request for enterprise customers. Email [email protected] to request one.
| Service | Purpose | Location |
|---|---|---|
| Hetzner | Hosting and database | Germany (EU) |
| Cloudflare R2 | File storage (sample assets) | EU |
| PostHog | Product analytics | EU (eu.posthog.com) |
| Sentry | Error monitoring | EU |
If you discover a security issue, please report it responsibly to [email protected]. We aim to acknowledge reports within 48 hours and resolve confirmed issues within 30 days.
Questions about how your data is handled? Get in touch or email [email protected].
Last updated: 24 May 2026