You are holding other people’s children’s data. So are we.
Everything below is a measure we are already contractually bound to, not a promise written for this page. Each group links to the clause that commits it, so you can check us rather than take our word.
Data stays in the EEA
Security measures
Where your data lives
- Hosted and primarily processed inside the European Economic Area.
- Production data sits with Google Cloud in the Netherlands; encrypted backups with AWS in Ireland.
- No child, family or staff data is stored on employee laptops or at our office - only in the designated data centre.
- Where a provider sits outside the EEA, transfers run on Standard Contractual Clauses.
Committed in DPA Schedule 2 and clause 6
How it is encrypted
- TLS 1.2 or higher on everything in transit.
- AES-256 or equivalent at rest.
- Backups are encrypted before they leave us, with the key held only by AcornCloud - the backup provider cannot read them.
- Removable media is prohibited for customer data. No USB drives, no external disks.
Committed in DPA Schedule 2
Who can reach it
- Multi-factor authentication is required for every AcornCloud staff account.
- Role-based access, least privilege, reviewed at least twice a year.
- Room Lounge runs on a per-person PIN, so a shared floor screen still identifies who did what.
- Accounts suspend automatically after three months idle; failed logins lock out.
Committed in DPA Schedule 2, Privacy Policy clause 9
How it is watched
- Every time our own staff touch customer data it is written to the application log, kept for six to seven months.
- Independent external penetration testing, annually.
- Independent third-party audit of information security and data protection, annually.
- Development and bug-fixing run on anonymised or synthetic data rather than live records wherever possible.
Committed in DPA clause 4 and Schedule 2
If the service goes down
- Full and incremental backups several times a day.
- Backups held across at least two geographically separate facilities.
- Restoration is tested regularly, not assumed.
- Data centres run redundant power and network, on generators as well as UPS.
Committed in DPA Schedule 2
What you can ask of us
- You are the data controller; we process only on your documented instructions.
- We tell you if an instruction you give us would breach data protection law, and can decline to act on it.
- On termination, we return your data in a machine-readable format or delete it and certify the deletion.
- We give 30 days' notice before adding or replacing a sub-processor, and you can object.
Committed in DPA clauses 3, 5 and 8
If something goes wrong.
No system is immune, and a security page that claims otherwise is not worth reading. What matters is what happens next, and how fast you hear about it.
- Immediately
We contain and remediate, and start the record that has to exist whether or not the breach is notifiable.
- Within 48 hours
You are notified with what we know: what happened, roughly who and how many are affected, the likely consequences, and what we are doing.
- Within 72 hours
The Data Protection Commission is notified where the breach is likely to risk people's rights, and affected individuals without undue delay.
The 48-hour commitment to you is in DPA clause 7; the 72-hour regulator notification is in Privacy Policy clause 9. We keep a record of every breach, including those that are not notifiable, and make it available to you on request.
Everyone else who touches it.
Six providers, each doing one job, all in the EU. This is the same register that sits in Schedule 3 of the DPA - the page reads it from there, so the two cannot drift.
| Sub-processor | Location | Purpose | Data Processed |
|---|---|---|---|
| Google Cloud | EU Region • Netherlands | Cloud infrastructure hosting and data storage for the Platform | All Customer Data |
| Amazon Web Services | EU Region • Ireland | Encrypted off-site backup storage. Provider has no access to decryption keys. | All Customer Data (encrypted at rest) |
| Gleap | EU Region | Customer support communications platform | Contact details and support ticket content |
| Sendgrid | EU Region | Transactional email and push notification delivery | Email addresses; notification content |
| Stripe | EU Region | Payment processing for subscription billing | Billing contact details; payment method metadata |
| Posthog | EU Region | Product analytics and usage measurement | Pseudonymised usage and interaction data |
We give you 30 days’ written notice before adding or replacing any of them, and you can object on data protection grounds - DPA clause 5.
Read the actual documents.
A security page is a summary. These are the things that bind us.
Security questions, or reporting something you think is wrong: [email protected]. Data protection queries go to [email protected].
Ready to get your evenings back?
Thirty minutes with our team and you’ll know whether AcornCloud fits your service.
- No card needed
- We migrate your data for free
- Live in two weeks
