FeaturesPricingSecurity
DE|EN
Sign in
FeaturesPricingSecurity
DE|EN
Sign in

The field sales app for FMCG teams
in the DACH region. Simple. Fast. GDPR-compliant.

EU data protectionEU serversSSLBuilt in Düsseldorf, Germany
exali IT-Haftpflichtsiegel – Benedikt Bimmerle
ProductFeaturesPricingSecurityStart for free
ResourcesBlog (German)Use cases (German)ROI calculator (German)
LegalImprint (German)Privacy (German)Terms (German)DPA (German)
Contactinfo@aussendienstapp.de+49 211 15 888 623
© 2026 Außendienstapp. All rights reserved.
Privacy (German)Terms (German)Deutsch

Security & Data Protection

Außendienstapp stores core data (database, auth, file storage) exclusively in the EU (Frankfurt am Main), enters into a Data Processing Agreement (DPA) under Art. 28 GDPR, encrypts data at rest with AES-256 and in transit with TLS 1.2+, enforces tenant isolation via Row-Level Security and uses cookieless analytics. Third-country transfers only for specialist processors (payments, email delivery) via the EU-US Data Privacy Framework.

A transparent data protection framework for DACH B2B teams, documented with concrete technical and organisational measures.

Core security principles

EU Hosting (Frankfurt)

Core data — database, file storage and application hosting — runs exclusively in the EU (AWS eu-central-1, Frankfurt). Narrowly-scoped specialist processors (e.g. payments, email, maps) are covered by the EU-US Data Privacy Framework or standard contractual clauses (SCCs) — details in the privacy policy (German) and Data Processing Agreement (German).

Encryption

TLS/HTTPS for all data transfers. Encryption at rest at the database level (AES-256). Passwords are hashed with bcrypt (cost factor 10) — never stored in plain text.

Row-Level Security

Every database query is restricted to your organisation through Row-Level Security (RLS). Tenant isolation at the database level — not merely in application logic.

Role-Based Access Control

Managers see team data; field sales reps see only their own. No user can access another organisation's data. Inviting new users is restricted to managers.

Daily Backups

Automatic daily database backups at our EU hosting partner (7-day retention) plus an encrypted off-site backup in separate storage (90-day retention). In the event of an incident, we restore your data from the most recent daily backup.

Cookieless Analytics

We use Vercel Analytics — completely without cookies and without tracking pixels. Only aggregated metrics are collected that cannot be used to identify individual persons. No cookie banner is required.

Compliance & Documentation

All documents you need for your own GDPR compliance — ready to review. Note: contract documents are in German and the German versions are legally binding.

Data Processing Agreement (DPA)

Data Processing Agreement pursuant to Art. 28 GDPR — including technical and organisational measures (TOMs), sub-processor list and breach notification obligation. Contract language is German; the German version prevails.

View DPA (German)

GDPR Rights — Self-Service

Your employees can export the personal data they have provided at any time as a ZIP file (right to data portability under Art. 20 GDPR) and delete their account independently (Art. 17 GDPR) — directly in the account settings. Organisation-wide data export by the manager is separate and takes place within the scope of data processing.

Privacy Policy

Full transparency about all data processing activities, legal bases, retention periods and sub-processors. Available in German only; the German version is legally binding.

Privacy policy (German)

DPIA Template for GPS Tracking

For optional GPS location recording we provide a Data Protection Impact Assessment (DPIA) template (Art. 35 GDPR) that you can use directly for your works council or data protection officer.

Sub-Processors

Complete list of all service providers involved in processing your data. The legally binding version with all obligations is available in the Data Processing Agreement (DPA) (German).

ProviderPurposeData locationTransfer basis
SupabaseDatabase, auth, storageEU FrankfurtDPA under Art. 28 GDPR, EU SCCs
VercelHosting, CDN, analyticsEU FrankfurtEU-US Data Privacy Framework (DPF)
CloudflareEncrypted off-site backup (disaster recovery)EU-jurisdiction bucket (Cloudflare R2; provider seat USA)EU-US DPF + DPA (Cloudflare Customer DPA Art. 28 GDPR); contents client-side encrypted — no technical access by provider
StripePayment processingUSAEU-US DPF, PCI DSS Level 1
ResendTransactional emails (outbound)USAEU-US DPF
Google WorkspaceBusiness email mailbox (incoming enquiries incl. attachments)EU/USA (Google data centres)DPA under Art. 28 GDPR (Google Workspace DPA), EU-US DPF, plus EU SCCs
SentryError monitoringEU (de.sentry.io)EU region; EU-US DPF, plus EU SCCs
CARTOMap tilesUSAEU Standard Contractual Clauses (SCCs, Art. 46 GDPR)
KomootGeocoding (Photon, server-side)Germany (Berlin)EU seat, no third-country transfer
OpenStreetMap FoundationFallback geocoding (Nominatim, server-side)United KingdomUK Adequacy Decision (28 June 2021)
AppleiOS push notifications (APNs), ActivityKit — iOS app onlyUSAApple GDPR DPA, EU SCCs
GoogleRoute export (optional user-initiated deeplink to Google Maps)USAEU-US Data Privacy Framework (DPF)
Have I Been PwnedPassword security check via k-anonymity (no PII transferred)Australiak-anonymity — no personal data transferred
GitHubCI/CD automation; technical execution of off-site backups (database/auth client-side encrypted, photo/document backups TLS + R2 encryption only)USAEU-US DPF, plus EU SCCs (GitHub DPA)

List as of 6. August 2026

Infrastructure Partner Certifications

Our infrastructure runs on platforms with industry-leading security standards.

AWS SOC 2 Type II (infrastructure partner Supabase)
PCI DSS Level 1 (payment partner Stripe)
SOC 2 Type 2 (hosting partner Vercel — see Vercel Trust Center)
EU-US Data Privacy Framework (Vercel, Stripe, Resend) — Sentry error logging via EU data centre

Automatic Data Deletion

Photos from visit reports are automatically deleted after 24 months — both from the database and from file storage. After cancellation, all data remains available for export for 30 days and is then irrevocably deleted. Data minimisation is not just a promise — it is an automated process.

Frequently asked questions about security, GDPR and compliance

The eight questions that DACH B2B buyers and data protection officers ask most often — answered directly.

More about Außendienstapp

Pricing

Transparent plan, 30-day notice period, no credit card required.

All Features

What the app can do — template builder, dashboard, route planning — and what sits in which tier.

View Data Processing Agreement (German)

Complete Data Processing Agreement under Art. 28 GDPR incl. TOMs. Contract language is German.

Privacy Policy (German)

All data processing activities, legal bases and retention periods in detail.

Questions about security? We’ll walk through them with you.

You can start on your own — or we set the app up together with you and answer every data-protection question along the way. The DPA and DPIA template are ready for you.

Start for freeRequest a demo