
Data Residency & Security Statement
Last Updated: July 2026
rightWFM Ltd · Registration: 208126768 · VAT: BG208126768
Lozenets Street 17A, 1421 Sofia, Bulgaria · privacy@rightwfm.com
1. Where is Your Data Stored? (100% EU Residency)
At rightWFM, we take data sovereignty and compliance seriously. All customer databases, application servers, logs, and backups are hosted entirely in the European Union:
- Primary Hosting Location: Amsterdam, Netherlands (hosted on HostNet B.V.).
- Backup Locations: Encrypted backups are stored securely on Backblaze B2 (EU Region in Amsterdam, Netherlands).
- Zero US Cloud Data Transfers: Operational customer data is hosted within the European Union and is not intentionally transferred outside the EEA except where required to provide specific services disclosed in this statement.
2. Database Separation & Tenant Isolation
To prevent cross-tenant exposure, rightWFM Hub is built on a segregated database routing model:
- Schema Isolation: Each customer environment is mapped to its own isolated database instance. Connection pools are dynamically assigned per tenant based on authenticated client tokens.
- Zero Shared Access: There are no shared data views or query tables between different organizations, guaranteeing complete logical separation of scheduling information.
3. Security Protocols & Cryptography
We implement defense-in-depth protections to keep customer records secure:
- Transit Protection: Every session, API call, and SAML payload is encrypted in transit using industry-standard TLS 1.3 encryption.
- Rest Encryption: Backup dump archives and primary database blocks are stored with AES-256 encryption.
- Authentication: rightWFM Hub supports Multi-Factor Authentication (MFA) and Single Sign-On (SSO) through Microsoft Entra ID and SAML 2.0 providers. Passwords are never stored in plaintext and are hashed using Argon2id.
- Immutable Action Logs: All modification events (including shift creations, preference updates, and user role adjustments) are captured in write-once audit files to maintain trace history. Audit logs are retained for a minimum of 12 months.
4. AI & Machine Learning Exclusion
Your scheduling details belong to you. rightWFM Hub does not analyze, process, or utilize customer schedules, employee availability records, or user-contributed content to train machine learning models, neural networks, or artificial intelligence engines.
5. Incident Response
In the event of a confirmed security incident affecting customer data, affected customers will be notified without undue delay in accordance with applicable law. rightWFM maintains an incident response plan covering detection, containment, eradication, and recovery phases.
6. Responsible Disclosure
If you discover a security vulnerability in rightWFM Hub, please contact security@rightwfm.com. We request that you do not publicly disclose vulnerabilities until they have been investigated and resolved.
7. Sub-Processors & Partners
We partner with a limited group of providers to deliver rightWFM Hub services. All sub-processors are vetted for GDPR alignment:
| Partner | Service Provided | Security & Compliance | Location / Jurisdiction |
|---|---|---|---|
| HostNet B.V. | Primary virtual servers and relational database storage | ISO 27001 certified, SOC 2 Type II, 24/7 physical security, DDoS protection | Amsterdam, Netherlands (EU) |
| Backblaze, Inc. (EU Region) | Offsite encrypted backup archive synchronization | AES-256 encrypted at rest, TLS 1.3 in transit, SOC 2 Type II, 99.999999999% durability | Amsterdam, Netherlands (EU) |
| Mailgun Technologies, Inc. (EU Region) | Delivery of transactional system notifications and magic sign-in links | TLS encryption for all email, SOC 2 Type II, EU data region, SCCs in place | Frankfurt, Germany (EU) |
| GitHub, Inc. | Source code hosting and deployment triggers (never handles user or operational client data) | SOC 2 Type II, ISO 27001 certified, encrypted at rest (AES-256), mandatory 2FA for organisation access | United States / Global — SCCs in place |
| Google LLC & Apple Inc. | Distribution of platform wrappers via Google Play and Apple App Store | Both SOC 2 Type II, ISO 27001 certified, app signing, sandboxed execution | Global — SCCs in place |
8. Data Processing Agreement (DPA)
Customers may request a Data Processing Agreement (DPA) that complies with Article 28 GDPR. Please contact legal@rightwfm.com to request a signed DPA.
9. GDPR Alignment & Sovereign Cloud
By hosting rightWFM Hub entirely on European infrastructure (HostNet NL and Backblaze EU B2) and operating under European companies, operational customer data is hosted within the European Union and is not intentionally transferred outside the EEA except where required to provide specific services disclosed in this statement. All data management remains fully aligned with the strict standards of the European General Data Protection Regulation (GDPR).