Security, GDPR and compliance

Security by design. ISO 27001 certified.

Protect participant data with ISO 27001-certified security and tools for GDPR compliance. Our servers are in the European Union, where participant data is stored and processed.

Access by responsibility
Access by responsibility

The right view for each role.

Map the records each person needs.

TrainerParticipants & attendance
Delivery
CoordinatorCourses & assignments
Planning
FinanceBookings & billing
Invoicing
Access follows the role
Illustrative role map · access agreed during setup
Into Certification — ISO/IEC 27001 certified

Independently audited

A certified approach to protecting your data.

Our ISO/IEC 27001-certified information security management covers how we develop, maintain and support our cloud services, including the systems and processes behind them.

Issued by Into Certification, a FINAS-accredited certification body. This gives your procurement team independent evidence of our security management.

01

Security by design, in daily use

Protecting participant information starts with product development and continues through each course. Give people the access their job needs and keep track of how personal data is used.

  • Role-based access to records.
  • Encryption during transfer and storage.
  • Logs of who handled personal data.
  • Protected, time-limited reports for sharing.
02

Servers in the European Union

CompetenceFlow runs in audited, ISO 27001-certified EU data centres. Participant information is stored and processed within the EU. Ask for hosting and subprocessor details as part of your procurement review.

03

Built for GDPR compliance

Handle personal data throughout the course lifecycle with tools that support the General Data Protection Regulation (GDPR). You remain the data controller; we act as processor and provide a data processing agreement (DPA).

  • Collect privacy acknowledgements and marketing consent at registration.
  • Limit access to the people who need it.
  • Support requests to review personal information.
  • Schedule anonymisation and retain course statistics.
  • Set retention periods and delete data when it is no longer needed.
04

A certified backbone for agentic workflows

Gain the benefits of modern AI workflows while CompetenceFlow provides the ISO 27001-certified backbone for your business records and core operations. Build around maintained data storage, access controls, encryption and activity logs instead of recreating them in a standalone vibe-coded system.

  • Use ChatGPT, Claude or a Microsoft Copilot Studio agent for supported course tasks through MCP.
  • Keep course and participant records in the system your delivery team uses.
  • Agree AI access, provider data handling and human review during setup.
05

Evidence for your compliance review

Bring your IT and data protection requirements to the conversation. We can walk through the certification and the arrangements for your setup.

  • ISO/IEC 27001 certificate and its scope.
  • Data processing agreement and subprocessor information.
  • Hosting, retention and data export arrangements.
  • Access controls and activity records.
  • Support, incident handling and service commitments.

Questions from training providers

Where are CompetenceFlow’s servers located?

Our servers are in the European Union, in audited, ISO 27001-certified data centres. Participant data is stored and processed in the EU. We provide hosting and subprocessor information for your procurement review.

How does CompetenceFlow support GDPR compliance?

CompetenceFlow supports privacy notices, marketing consent, role-based access, personal data review, anonymisation and deletion. We provide a DPA as your data processor. Your organisation sets the purpose, lawful basis and retention rules for the data it collects.

What does the ISO 27001 certification cover?

The certification covers information security management across the development, maintenance and support of our cloud services, including the internal systems and processes behind them.

Who issued the certificate?

Into Certification, a FINAS-accredited certification body, issued the certificate following an independent audit.

Bring your security and compliance requirements.

Review GDPR, server locations, the ISO 27001 certificate and data processing documentation with our team.