
NATUREOFFICE TRUST CENTRE
How we protect data, who can access it, and which rules apply to operation, development and collaboration.
Transparently protected · personally accessible.
OUR MISSION
Your data. Clear rules.
Trust is not created by a promise. It is created when it is understandable how data is processed, protected and deleted.
01
Data remains in Europe.
Customer and project data are processed in selected European data centres. Providers and locations are selected according to data protection and security criteria.
Technically confirm
02
Your content does not train AI.
Content provided by customers is not used for training publicly available AI models. Other use only takes place on a clear contractual basis.
Confirm contractually
03
Data is being encrypted.
Appropriate technical procedures protect information during transmission and – where necessary – during storage.
Add procedure
04
Access remains controlled.
Permissions are assigned according to role and need. Access to sensitive systems should be traceable and limited to the necessary minimum.
Confirm process
05
You are speaking with people.
For data protection or security questions, you can reach a responsible team and receive a specific answer to your concern.
Get in touch
Responsibility remains achievable.
Clear responsibilities build trust – in everyday life just as much as in exceptional circumstances.
SAFETY FRAME
What we safeguard organisationally and technically.
Information security does not only concern software. It starts with clear responsibilities and extends to the handling of service providers, access rights and incidents.
01
Information security management
Risks are recorded, assessed, and treated with appropriate measures. Recognised security standards serve as a guide; we only mention formal certifications if they are actually in place.
02
Cloud and data locations
Selected cloud and hosting providers are used for operations. Data locations, technical protective measures and contractual frameworks are documented.
03
Suppliers and partners
Service providers with access to data or systems are assessed according to their role, their need for protection, and their data protection and security measures.
04
Employees and Security Awareness
Binding rules and regular training help to detect and properly handle phishing, social engineering, and other risks at an early stage.
05
Data backup and erasure
Data backups, restoration tests, and defined retention and deletion processes protect against data loss and unnecessarily long storage.
06
Identities and access rights
Access is granted on a role-based basis and regularly reviewed. Additional login and approval procedures are used for systems requiring special protection.
07
Secure software development
Security requirements are taken into account during development, changes and releases. Tests should identify vulnerabilities before they go live.
08
Monitoring and security incidents
Technical anomalies and reported incidents are assessed, documented and processed according to an established procedure.
09
Emergency Preparedness and Business Continuity
Contingency plans, recovery procedures, and clear communication channels are intended to safeguard operations even in the event of outages or security incidents.
10
System hardening and physical security
Unnecessary services and permissions are reduced. For the physical security of the infrastructure used, the protective measures of the selected data centre and hosting providers apply.
DOCUMENTATION
What business partners can request.
02
Data Processing
Contractual regulations for services where natureOffice processes data on behalf.
On request
03
Technical and organisational measures
Overview of the protective measures for specific services and systems.
By agreement
STILL HAVE A QUESTION?
Security is best discussed in concrete terms.
Briefly describe what information you require for your audit, your procurement, or your data protection department. We will get back to you with the appropriate answer or documentation.