Photographer at a natureOffice event.

NATUREOFFICE TRUST CENTRE

Data security
needs clear
answers.

Data security
needs clear
answers.

How we protect data, who can access it, and which rules apply to operation, development and collaboration.

Transparently protected · personally accessible.

OUR MISSION

Your data. Clear rules.

Trust is not created by a promise. It is created when it is understandable how data is processed, protected and deleted.

01

Data remains in Europe.

Customer and project data are processed in selected European data centres. Providers and locations are selected according to data protection and security criteria.

Technically confirm

02

Your content does not train AI.

Content provided by customers is not used for training publicly available AI models. Other use only takes place on a clear contractual basis.

Confirm contractually

03

Data is being encrypted.

Appropriate technical procedures protect information during transmission and – where necessary – during storage.

Add procedure

04

Access remains controlled.

Permissions are assigned according to role and need. Access to sensitive systems should be traceable and limited to the necessary minimum.

Confirm process

05

You are speaking with people.

For data protection or security questions, you can reach a responsible team and receive a specific answer to your concern.

Get in touch

Responsibility remains achievable.

Clear responsibilities build trust – in everyday life just as much as in exceptional circumstances.

SAFETY FRAME

What we safeguard organisationally and technically.

Information security does not only concern software. It starts with clear responsibilities and extends to the handling of service providers, access rights and incidents.

01

Information security management

Risks are recorded, assessed, and treated with appropriate measures. Recognised security standards serve as a guide; we only mention formal certifications if they are actually in place.

02

Cloud and data locations

Selected cloud and hosting providers are used for operations. Data locations, technical protective measures and contractual frameworks are documented.

03

Suppliers and partners

Service providers with access to data or systems are assessed according to their role, their need for protection, and their data protection and security measures.

04

Employees and Security Awareness

Binding rules and regular training help to detect and properly handle phishing, social engineering, and other risks at an early stage.

05

Data backup and erasure

Data backups, restoration tests, and defined retention and deletion processes protect against data loss and unnecessarily long storage.

06

Identities and access rights

Access is granted on a role-based basis and regularly reviewed. Additional login and approval procedures are used for systems requiring special protection.

07

Secure software development

Security requirements are taken into account during development, changes and releases. Tests should identify vulnerabilities before they go live.

08

Monitoring and security incidents

Technical anomalies and reported incidents are assessed, documented and processed according to an established procedure.

09

Emergency Preparedness and Business Continuity

Contingency plans, recovery procedures, and clear communication channels are intended to safeguard operations even in the event of outages or security incidents.

10

System hardening and physical security

Unnecessary services and permissions are reduced. For the physical security of the infrastructure used, the protective measures of the selected data centre and hosting providers apply.

DOCUMENTATION

What business partners can request.

01

Privacy Policy

Information on the processing of personal data.

View

02

Data Processing

Contractual regulations for services where natureOffice processes data on behalf.

On request

03

Technical and organisational measures

Overview of the protective measures for specific services and systems.

By agreement

04

Subcontractors

Information on relevant technical service providers and their role.

On request

STILL HAVE A QUESTION?

Security is best discussed in concrete terms.

Briefly describe what information you require for your audit, your procurement, or your data protection department. We will get back to you with the appropriate answer or documentation.