Security & Operations
Last updated: [DATE]
Birdly takes reasonable technical and organisational steps to protect Customer Data and personal information.
1. Hosting and location
Birdly currently uses Supabase for database/backend and Vercel for website/application hosting/delivery.
Birdly's primary production database region is currently Paris, France (EEA).
Other service providers may process limited data elsewhere under applicable safeguards. See Privacy and Sub-processors.
Do not describe all Birdly data as EU-only unless a technical audit confirms that for every provider and flow.
2. Encrypted connections
Traffic between browser/device and Birdly is protected using HTTPS/TLS encryption, the standard used across secure online services including online banking.
3. Access control
Production systems/data are restricted to people who need them. Sensitive credentials/keys are kept out of public source code/content. Administrative access uses appropriate controls.
4. Private links and uploads
Where Birdly uses private/personal links, signed URLs or time-limited access:
- links should use high-entropy identifiers;
- files should not be publicly indexed;
- access should be limited to intended workflows; and
- links/files should expire/delete according to retention rules.
5. Backups/recovery
Birdly uses backup/recovery mechanisms appropriate to the infrastructure. Backups help restoration after incidents but do not guarantee that every piece of data can always be recovered.
6. Availability
Birdly aims for high availability but does not promise 100% uptime. Planned maintenance is arranged to reduce disruption where reasonably possible. Outages are restored as quickly as reasonably practicable.
7. Security incidents
Birdly maintains processes to identify, assess, contain and respond to security/personal-data incidents. Where required, Birdly makes/supports legally required notifications.
The DPA contains the processor breach-notification commitment.
8. Suppliers
Birdly relies on external suppliers. See Sub-processors. Supplier use is subject to contractual/security/data-protection requirements appropriate to the service.
9. No certification claims unless true
Do not claim Birdly itself is ISO 27001, SOC 2, Cyber Essentials or otherwise certified unless Birdly genuinely holds that certification. Supplier certifications may be described only accurately and attributed to the supplier.
10. Contact
Security/privacy questions: support@birdly.dk