You are holding other people’s children’s data. So are we.

Everything below is a measure we are already contractually bound to, not a promise written for this page. Each group links to the clause that commits it, so you can check us rather than take our word.

Data stays in the EEA

Security measures

Where your data lives

  • Hosted and primarily processed inside the European Economic Area.
  • Production data sits with Google Cloud in the Netherlands; encrypted backups with AWS in Ireland.
  • No child, family or staff data is stored on employee laptops or at our office - only in the designated data centre.
  • Where a provider sits outside the EEA, transfers run on Standard Contractual Clauses.

Committed in DPA Schedule 2 and clause 6

How it is encrypted

  • TLS 1.2 or higher on everything in transit.
  • AES-256 or equivalent at rest.
  • Backups are encrypted before they leave us, with the key held only by AcornCloud - the backup provider cannot read them.
  • Removable media is prohibited for customer data. No USB drives, no external disks.

Committed in DPA Schedule 2

Who can reach it

  • Multi-factor authentication is required for every AcornCloud staff account.
  • Role-based access, least privilege, reviewed at least twice a year.
  • Room Lounge runs on a per-person PIN, so a shared floor screen still identifies who did what.
  • Accounts suspend automatically after three months idle; failed logins lock out.

Committed in DPA Schedule 2, Privacy Policy clause 9

How it is watched

  • Every time our own staff touch customer data it is written to the application log, kept for six to seven months.
  • Independent external penetration testing, annually.
  • Independent third-party audit of information security and data protection, annually.
  • Development and bug-fixing run on anonymised or synthetic data rather than live records wherever possible.

Committed in DPA clause 4 and Schedule 2

If the service goes down

  • Full and incremental backups several times a day.
  • Backups held across at least two geographically separate facilities.
  • Restoration is tested regularly, not assumed.
  • Data centres run redundant power and network, on generators as well as UPS.

Committed in DPA Schedule 2

What you can ask of us

  • You are the data controller; we process only on your documented instructions.
  • We tell you if an instruction you give us would breach data protection law, and can decline to act on it.
  • On termination, we return your data in a machine-readable format or delete it and certify the deletion.
  • We give 30 days' notice before adding or replacing a sub-processor, and you can object.

Committed in DPA clauses 3, 5 and 8

If something goes wrong.

No system is immune, and a security page that claims otherwise is not worth reading. What matters is what happens next, and how fast you hear about it.

  1. Immediately

    We contain and remediate, and start the record that has to exist whether or not the breach is notifiable.

  2. Within 48 hours

    You are notified with what we know: what happened, roughly who and how many are affected, the likely consequences, and what we are doing.

  3. Within 72 hours

    The Data Protection Commission is notified where the breach is likely to risk people's rights, and affected individuals without undue delay.

The 48-hour commitment to you is in DPA clause 7; the 72-hour regulator notification is in Privacy Policy clause 9. We keep a record of every breach, including those that are not notifiable, and make it available to you on request.

Everyone else who touches it.

Six providers, each doing one job, all in the EU. This is the same register that sits in Schedule 3 of the DPA - the page reads it from there, so the two cannot drift.

Sub-processors, their location, purpose and the data they process
Sub-processorLocationPurposeData Processed
Google CloudEU Region • NetherlandsCloud infrastructure hosting and data storage for the PlatformAll Customer Data
Amazon Web ServicesEU Region • IrelandEncrypted off-site backup storage. Provider has no access to decryption keys.All Customer Data (encrypted at rest)
GleapEU RegionCustomer support communications platformContact details and support ticket content
SendgridEU RegionTransactional email and push notification deliveryEmail addresses; notification content
StripeEU RegionPayment processing for subscription billingBilling contact details; payment method metadata
PosthogEU RegionProduct analytics and usage measurementPseudonymised usage and interaction data

We give you 30 days’ written notice before adding or replacing any of them, and you can object on data protection grounds - DPA clause 5.

Read the actual documents.

A security page is a summary. These are the things that bind us.

Security questions, or reporting something you think is wrong: [email protected]. Data protection queries go to [email protected].

Ready to get your evenings back?

Thirty minutes with our team and you’ll know whether AcornCloud fits your service.

  • No card needed
  • We migrate your data for free
  • Live in two weeks