Control Who Can
See and Change Data.
Your data stays in the EU. Access is set by role. Important changes are logged. Participant records, invoices, certificates, and renewals stay ready for review.
Infrastructure
100% EU
Audit Logs
Immutable
Uptime SLA
99.9%
Security
Security Posture
EU Hosting
GDPR
Audit Trails
RBAC
Security built in, not bolted on
Security is built into how training records are handled.
EU-Native Hosting
100% EU-hosted. Data never leaves European jurisdiction. Immune to the U.S. CLOUD Act.
GDPR by Architecture
Consent, data minimisation, and the right to erasure are handled in the product, not in a separate spreadsheet.
Audit Trails Nobody Can Edit
Every action is logged and the log cannot be changed. A full record, ready for a review.
Who can do what
Access by Role
Set permissions by organisation, department, and role. SSO, BankID, and regional e-ID included.
Ready for Audits
Ready-made templates and evidence trails for Qualiopi, AZAV, and other national quality frameworks.
Open APIs
Full REST and GraphQL access, JSON-native. Connect your LMS, CRM, and accounting software with no lock-in.
Data Encryption
Encrypted at rest and in transit. Each customer's data kept separate. Regular pen testing. BSI C5 and SecNumCloud aligned.
Ready for the rules that apply to you
EU Data Act Compliant. No Lock-In.
We keep customers by being worth it, not by trapping them. Fully EU Data Act compliant, and we go further than the rules require.
- check_circle No lock-in. Leave any time.
- check_circle Full data export in portable formats.
- check_circle We help you move, even to a competitor.
Security & Compliance Pack
Security answers for IT, legal, and compliance review.
Certifications & Controls
- ISO/IEC 27001 certified
- Covers infrastructure, development, and operations
- Statement of Applicability available under NDA
- Annual third-party audits
GDPR & Data Protection
- We process; you control
- DPA included with all contracts
- Subprocessor changes notified in advance
- Access, rectification, portability, erasure
- DPIA support on request
Hosting & Data Residency
- All data in EU/EEA data centres
- No transfers outside EU/EEA
- Contractual residency guarantees
- Isolated from non-EU legal frameworks
Access Control & Auditability
- RBAC by organisation, department, role
- Least privilege by default
- Logs: admin actions, auth events, permission and data changes
- Exportable in standard formats
Security Operations
- Documented incident response
- Vulnerability management
- Secure SDLC with code review and dependency scanning
- Security training for all production staff
Reliability & Continuity
- Automated backups with point-in-time restore
- Tested disaster recovery
- 99.9% uptime SLA (plan-dependent)
- Annual continuity plan review
Legal & Commercial
Procurement FAQ
Common questions from security, legal, and IT teams.
Core features
The training records security protects
Security needs to cover the whole training lifecycle: course setup, booking, participant data, trainer qualifications, invoices, certificates, and renewal communication.
Course management
Build course dates, set capacity, assign rooms, and keep participant lists up to date.
See feature arrow_forwardOnline booking
Let customers book one seat or a whole group, then collect participant details later.
See feature arrow_forwardTrainer management
Give trainers their courses, participant lists, attendance, materials, and feedback.
See feature arrow_forwardInvoicing & finance
Turn bookings and attendance into invoices, with checks before month-end.
See feature arrow_forwardRenewals & messaging
Send joining instructions, reminders, certificate expiry messages, and renewal links.
See feature arrow_forwardA platform your security
team can sign off.
See how CompetenceFlow protects your training data and keeps records ready for review.