Tugus

How We Protect Your Data

Trust is the foundation of a tracking platform. This page provides an overview of the key measures Tugus takes to protect personal data.

Detailed technical and organizational measures (TOMs) within the meaning of Art. 32 GDPR are available to contractual partners upon request.

Hosting & Data Location

  • Fully hosted in Germany: All servers are located in an ISO 27001-certified data center operated by Netcup GmbH in Nuremberg.
  • No third-country transfers of core data: Account data, configurations, stored events, and backups remain within the EU.
  • Marketing integrations: Data is only forwarded to platforms outside the EU if you, as the customer, actively configure such an integration. See the Subprocessor List.

Privacy by Design

  • PII is hashed: Email addresses, phone numbers, and names are cryptographically hashed before being stored.
  • Consent Mode v2 compliant: Granular consent signals are taken into account on a per-event basis. Without consent, only anonymized signals are transmitted.
  • Data minimization: Only data necessary to fulfill the contracted services is processed.
  • GDPR tools in the dashboard: Data export (Art. 20 GDPR), deletion requests (Art. 17 GDPR), and account deletion are available at any time.

Encryption

  • In Transit: All connections (HTTPS, SMTP, webhooks) are protected using current TLS encryption.
  • At Rest: Database volumes and backups are stored on encrypted storage.
  • Credentials: API credentials for marketing platforms are stored in encrypted form.
  • Passwords: Passwords are stored using a modern hashing algorithm (bcrypt) — never in plain text.

Data Processing Agreements under Art. 28 GDPR

  • DPA with all subprocessors: We only engage subprocessors that operate in compliance with the GDPR.
  • Processing only on instruction: Data is only forwarded to platforms that you actively enable.
  • Transparent Subprocessor List: Publicly available, with changes communicated in advance.
  • Data Flow Description: See Data Flow.

Access Control & Tenant Isolation

  • Strict tenant isolation: Data belonging to different customers is technically and logically separated.
  • Role-Based Access Control (RBAC): Granular permissions are available per property — Owner, Admin, Editor, Viewer.
  • API keys: Configurable scopes and expiration dates. Keys are displayed only once and are subsequently stored as hashes.

Incident Response

  • Notification under Art. 33 GDPR: In the event of a personal data breach, we notify affected customers within 24 hours of becoming aware of the breach.
  • Monitoring: Continuous monitoring of the event pipeline with automated anomaly detection.

Compliance & Audits

Upon request, we provide contractual partners with detailed technical and organizational measures (TOMs) and additional compliance documentation. Where there is a legitimate interest (e.g. a security audit requirement as part of a business relationship), we enable security audits by agreement and in coordination with the customer.

How We Protect Your Data