← iuseflow.ch

Security & data protection

How iUseFlow protects your company's data · As of: 29.09.2026

We only describe functions that are actually implemented here — no certifications without real evidence.

🔒 Company separation

Each company is a separate tenant. Database access is automatically limited to the own company; an account only sees its own company's data.

👥 Roles & permissions

Owner, dispatcher, employees and custom roles with fine-grained rights. Each company decides who may see and do what.

🔐 Encrypted transport

All access runs exclusively over HTTPS/TLS. Sign-in passwords are hashed; supported third-party credentials (e.g. OAuth tokens) are stored encrypted.

📜 Audit logs

Important changes are logged traceably (who, what, when) — including administration and access events.

💾 Backups

Our backups follow their own retention; our cloud provider's backup practice is governed by contract and not specified in detail here. Companies can additionally retrieve their data themselves through an on-request export (owner permission). The nightly encrypted backups cover the database; a complete backup and restore of files and receipts from these backups is not promised here.

📤 Data export & deletion

An export (e.g. as JSON) can be requested by the owner — it is not a guaranteed complete result on every request; if a single table fails, this is reported instead of silently leaving data out. We currently offer no automated self-service deletion — an actual deletion runs through a separate, manually supported process. Backups with us and with the cloud provider follow their own retention and are not deleted retroactively. Requests for access, correction, deletion or handover under the Swiss FADP are handled through the designated process — with no commitment on timing or scope here.

📎 File & document access

Photos, signatures and documents are bound to the respective job and company. The customer portal shows each customer only their own jobs.

🛡️ Session security

Time-limited session tokens, lockout after too many failed sign-ins (brute-force protection) and optional two-factor authentication (TOTP).

Hosting region

Since 16.09.2026 iUseFlow runs at Exoscale (Akenes SA, Lausanne) in zone CH-DK-2 (Zurich, Switzerland) — application, database and file storage. Encrypted backup copies of the database are stored nightly in the same zone; a complete backup of the file storage is not promised here. The former provider Railway (United States, region sfo) ran the platform until 16.09.2026; on 28.09.2026 the three former production services were removed and the original production volumes wiped once each. No conclusive statement is made about any remaining contents of historical backups at Railway, and current operation sends no new data there. We communicate this openly. The legal meaning is set out in section 8 of the privacy notice.

Security reports

Please report vulnerabilities or suspected incidents to security@iuseflow.ch. We take reports seriously and will get back to you.

No unproven certificates. iUseFlow currently holds no ISO 27001 or SOC 2 certification. Should such evidence exist in the future, it will be shown here with the auditing body and date.

More: Privacy notice · Cookie-Einstellungen · Terms · Legal notice