rightWFM
← Back to Sign In

Data Residency & Security Statement

Last Updated: July 2026

rightWFM Ltd · Registration: 208126768 · VAT: BG208126768
Lozenets Street 17A, 1421 Sofia, Bulgaria · privacy@rightwfm.com

1. Where is Your Data Stored? (100% EU Residency)

At rightWFM, we take data sovereignty and compliance seriously. All customer databases, application servers, logs, and backups are hosted entirely in the European Union:

  • Primary Hosting Location: Amsterdam, Netherlands (hosted on HostNet B.V.).
  • Backup Locations: Encrypted backups are stored securely on Backblaze B2 (EU Region in Amsterdam, Netherlands).
  • Zero US Cloud Data Transfers: Operational customer data is hosted within the European Union and is not intentionally transferred outside the EEA except where required to provide specific services disclosed in this statement.

2. Database Separation & Tenant Isolation

To prevent cross-tenant exposure, rightWFM Hub is built on a segregated database routing model:

  • Schema Isolation: Each customer environment is mapped to its own isolated database instance. Connection pools are dynamically assigned per tenant based on authenticated client tokens.
  • Zero Shared Access: There are no shared data views or query tables between different organizations, guaranteeing complete logical separation of scheduling information.

3. Security Protocols & Cryptography

We implement defense-in-depth protections to keep customer records secure:

  • Transit Protection: Every session, API call, and SAML payload is encrypted in transit using industry-standard TLS 1.3 encryption.
  • Rest Encryption: Backup dump archives and primary database blocks are stored with AES-256 encryption.
  • Authentication: rightWFM Hub supports Multi-Factor Authentication (MFA) and Single Sign-On (SSO) through Microsoft Entra ID and SAML 2.0 providers. Passwords are never stored in plaintext and are hashed using Argon2id.
  • Immutable Action Logs: All modification events (including shift creations, preference updates, and user role adjustments) are captured in write-once audit files to maintain trace history. Audit logs are retained for a minimum of 12 months.

4. AI & Machine Learning Exclusion

Your scheduling details belong to you. rightWFM Hub does not analyze, process, or utilize customer schedules, employee availability records, or user-contributed content to train machine learning models, neural networks, or artificial intelligence engines.

5. Incident Response

In the event of a confirmed security incident affecting customer data, affected customers will be notified without undue delay in accordance with applicable law. rightWFM maintains an incident response plan covering detection, containment, eradication, and recovery phases.

6. Responsible Disclosure

If you discover a security vulnerability in rightWFM Hub, please contact security@rightwfm.com. We request that you do not publicly disclose vulnerabilities until they have been investigated and resolved.

7. Sub-Processors & Partners

We partner with a limited group of providers to deliver rightWFM Hub services. All sub-processors are vetted for GDPR alignment:

PartnerService ProvidedSecurity & ComplianceLocation / Jurisdiction
HostNet B.V.Primary virtual servers and relational database storageISO 27001 certified, SOC 2 Type II, 24/7 physical security, DDoS protectionAmsterdam, Netherlands (EU)
Backblaze, Inc. (EU Region)Offsite encrypted backup archive synchronizationAES-256 encrypted at rest, TLS 1.3 in transit, SOC 2 Type II, 99.999999999% durabilityAmsterdam, Netherlands (EU)
Mailgun Technologies, Inc. (EU Region)Delivery of transactional system notifications and magic sign-in linksTLS encryption for all email, SOC 2 Type II, EU data region, SCCs in placeFrankfurt, Germany (EU)
GitHub, Inc.Source code hosting and deployment triggers (never handles user or operational client data)SOC 2 Type II, ISO 27001 certified, encrypted at rest (AES-256), mandatory 2FA for organisation accessUnited States / Global — SCCs in place
Google LLC & Apple Inc.Distribution of platform wrappers via Google Play and Apple App StoreBoth SOC 2 Type II, ISO 27001 certified, app signing, sandboxed executionGlobal — SCCs in place

8. Data Processing Agreement (DPA)

Customers may request a Data Processing Agreement (DPA) that complies with Article 28 GDPR. Please contact legal@rightwfm.com to request a signed DPA.

9. GDPR Alignment & Sovereign Cloud

By hosting rightWFM Hub entirely on European infrastructure (HostNet NL and Backblaze EU B2) and operating under European companies, operational customer data is hosted within the European Union and is not intentionally transferred outside the EEA except where required to provide specific services disclosed in this statement. All data management remains fully aligned with the strict standards of the European General Data Protection Regulation (GDPR).

rightWFM Ltd · Lozenets Street 17A, 1421 Sofia, Bulgaria · VAT: BG208126768 · Built using industry-standard security practices