IT security & data protection
Certified security for your company
Data protection and information security are a central component of the products and services of Helm & Nagel GmbH. The protection of your data is a priority for us and is certified in accordance with the ISO 27001 standard. You can find all further information on this page or in our Trust Center.


Made in Germany, Hosted in Europe
The services of Helm & Nagel GmbH are developed in Germany and processed on servers within the EU. The data centers are also localized in Germany.


Certified data protection
The Konfuzio software and the entire information security management system at Helm & Nagel GmbH are certified in accordance with the ISO27001 standard.


Reliable cloud partnerships
With Telekom Systems and Hetzner as cloud providers, Helm & Nagel GmbH relies on experience and high security standards from Germany.
Any questions?
Feel free to contact us or find out more about data protection & secure hosting on this page.
Data security
Data Governance for data & processes
Data governance describes the development, implementation and maintenance of rules, policies and procedures for the effective management of data in an organization. It is a comprehensive framework that ensures that data is stored and processed in a high-quality, consistent, available, secure and accountable manner.
Data quality
Valuable knowledge through
Data integrity
Data integrity is the decisive quality criterion for data. It describes the integrity of the data and includes the correctness, completeness and consistency of the data as well as its security. Integrity defines the trustworthiness of the database. To ensure data integrity, it is essential that data is not processed, deleted or changed without authorization.
Data Privacy
AI from Germany
GDPR & more
Companies are obliged to comply with a large number of legal and regulatory provisions when handling data. In particular, compliance with the GDPR and other European data protection directives is a priority for companies. Konfuzio is developed in Germany and operated on ISO-certified servers within the EU.
FAQ
Frequently Asked Questions
01.
Is the Konfuzio application compliant with the EU Data Protection Basic Regulation (EU-GDPR)?
Yes, Konfuzio meets all requirements of the EU General Data Protection Regulation and is data protection compliant as an organization and as software in accordance with the EU GDPR.
02.
What does Helm & Nagel GmbH do on an organisational level to ensure the protection of personal data and the security of its IT systems?
Helm & Nagel GmbH provides services in compliance with the GDPR and in accordance with ISO27001. In addition, it takes into account industry-specific requirements, such as the data protection code of the German Insurance Association (GDV). Helm & Nagel GmbH strives to continuously improve its data protection and information security processes and structures.
The company's own requirements for data protection and information security are refined with further trainings and education. Not only are internal processes and protective measures continuously improved, but security gaps in other companies are identified and reported. For example, BASF SE has named Florian Zyprian, the CTO, as "Hero of BASF" after detecting a security breach.
03.
Is customer data transmitted and stored in encrypted form?
Yes, state-of-the-art encryption is used on all databases and storage facilities used by Helm & Nagel GmbH, so that the data can only be read after proper authentication.
All personal or personal-related data that is transferred from the Konfuzio application to a client or to other platforms must also be encrypted using Transport Layer Security (TLS). To do this, a secure connection must first be established between the two connection partners (client and server) before data can be transferred.
04.
Which hosting providers does Konfuzio work with?
Our hosting partners are Hetzner and the Open Telekom Cloud, both renowned providers with the highest security standards.
The data centers used are ISO/IEC 27001 certified and thus meet our high requirements for the physical security of our customers' data. The terms and conditions for SaaS hosting and the use of app.konfuzio.com can be found in German here.
07.
What mechanisms does Helm & Nagel GmbH use to ensure availability?
Helm & Nagel GmbH relies specifically on a redundant design of the server infrastructure with regard to productive data and backups as well as the physical security of the data centers (e.g. uninterruptible power supply, alarm system, fire alarm system, etc.) and also operates a continuous capacity management to monitor the resources used and the distribution of necessary resources.
08.
Are regular backups performed or do customers have to back up their data themselves?
In order to ensure adequate availability, Helm & Nagel GmbH implements a backup concept for the database with the client's data stored on it according to the latest state of the art. The backups of the database systems are stored exclusively in encrypted form. This means that the customer does not need to carry out his own backups. Regular restore tests are carried out to ensure proper storage of backups and their restoration in the event of data loss.
09.
What happens to the customer data in case of a total failure of our system, for example due to a natural disaster or similar?
In the unlikely event of a total system failure, the redundant design of the data centers (productive and backup data) ensures that your data will not be lost. In this case, we will ensure the fastest possible recovery according to our emergency plan/disaster recovery concept.
10.
What happens to the data if the customer terminates the contract or Helm & Nagel GmbH ceases business operations?
Upon termination of the business relationship, authorized persons of the customer may request the release of the data in a machine-readable format. The data will then be irretrievably deleted after the contractually defined period has expired.
In the unlikely event that Helm & Nagel GmbH ceases business operations, there is no deviation from this, as the customer is the "master of the data" and Helm & Nagel GmbH is merely the processor. In addition, escrow protection is possible: the source code of the software can be deposited in trust with an independent third party. This ensures that the customer has access to the software in this unlikely event and can continue to use it.
