Trust & Security
Trust is a feature here.
If you entrust someone with your inspection records, working hours and invoices, you want to know exactly where they are stored and who can see them. Here it is – in full, no fine print.
Where your data is stored
The cloud services of the irot family run on servers operated by Hetzner Online GmbH in its Falkenstein data center, Germany. A data processing agreement under Art. 28 GDPR is in place with Hetzner.
Each customer receives a dedicated instance with its own, separate database – no shared table in which only a customer number keeps your data apart from other customers' data. If you prefer not to use the cloud at all, you can run irot Audit and irot ZeitPro on your own premises under Windows, Linux or Docker – with the same features.
Technical and organizational measures
- All data is transmitted only in encrypted form (TLS), with HSTS.
- Server login only with cryptographic keys; password login is disabled.
- Separate data storage for each customer.
- Passwords are stored only as scrypt hashes, never in plain text.
- Lockout after repeated failed login attempts.
- Encrypted backups, deleted after 30 days.
- The application runs without system privileges in a restricted environment.
- Changes to records are logged; entries are voided rather than deleted.
The measures for irot Audit are documented in detail in the privacy policy of kalibrat.de (section 8).
Who else processes your data
For irot Audit – each under an agreement pursuant to Art. 28 GDPR, and only if the respective feature is used:
| Recipient | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Germany | Data center, hosting |
| Brevo (Sendinblue SAS) | France | Sending due-date and system notifications, if set up |
| Stripe Payments Europe, Ltd. | Ireland | Payments on a paid plan |
Image recognition stays switched off until you subscribe to it. Only then is a scanned calibration certificate – never the equipment register, never the inspection history – transferred to an AI service outside the EU (Alibaba Cloud, Singapore, or alternatively Anthropic, USA), on the basis of standard contractual clauses. Without this subscription, the application is fully usable.
For irot ZeitPro, the privacy policy on gnavo.de applies. The ZeitPro AI assistant stays off until an administrator gives consent, and by default works with personnel numbers instead of names – it never processes health data.
Your data belongs to you
- Export anytime – irot Audit to Excel and as a complete audit package.
- Nothing you already have gets locked: After the trial or a cancellation, your records remain readable, printable and exportable; with ZeitPro, clocking in and out and reports remain available without a license.
- After the contract ends, we hand over the data on request and then delete it – taking into account your statutory retention obligations.
- No use for our own purposes: We do not analyze your data, train our own models on it or sell it.
This website
irot.com sets no cookies, uses no analytics, tracking or advertising services, loads no content from third-party servers and stores no access logs. A strict Content Security Policy ensures that the browser enforces this too. Details can be found in the privacy policy.
Found a vulnerability?
Write to info@irot.com – we usually respond within one business day and fix confirmed vulnerabilities as a priority. Machine-readable contact details are available at /.well-known/security.txt.
Certifications – in all honesty
There is currently no ISO 27001 certification. Instead of a seal, we disclose what we do: the measures above are documented and verifiable, and your organization's information security team can receive information on every point upon request.
Questions from your IT department or data protection officer?
We complete information security questionnaires and conclude the data processing agreement before processing begins.