Data Security at portier and GDPR

portier Vision runs on-premise, your data stays in your own database, and this article lists every outbound connection the software can make.

Introduction

Protecting your data is a high priority at portier. We regularly get questions about where your data sits and which connections portier Vision can make to the outside. This article answers them and is written to be passed on to your data protection officer.

Where is the Data Stored?

portier Vision is an on-premise software solution, meaning all data is stored and managed directly on the customer's premises. Neither portier nor any third parties have access to this data unless explicitly permitted by the customer. This architecture ensures that you maintain full control over your data. The database runs on your own infrastructure, either on Firebird or on Microsoft SQL Server.

Which Outbound Connections Exist?

portier operates two services itself. Every other connection is one you set up yourself in the portier Vision Companion. None of them exists until you configure it.

Operated by portier:

  • Licence server (Chargebee): licence management and billing. Hosted in the EU and fully compliant with GDPR. More information can be found here.

  • CRM (HubSpot): our internal CRM, with data also hosted within the EU. It holds contact and contract data, not the data from your Vision database. Details about HubSpot's data infrastructure can be found here.

Set up by you:

  • Entra ID sync: reconciles personnel records against your own Microsoft tenant. The connection runs from your machine to Microsoft, not to portier. You set it up through a wizard and sign in with a certificate. You see a preview of the changes before anything is written.

  • Reminder emails: three delivery routes are available. Your own SMTP server, the portier Mail Service as a relay, or a local log driver that sends nothing. With the portier Mail Service, reminder content travels through portier infrastructure. Which route an installation uses is set in its configuration.

  • Scheduled personnel import: reads from a file or a folder on your own network. No outbound connection.

  • Export and provisioning tasks: write to the destination you specify.

  • Data retention cleanup: deletes in your own database only. No outbound connection.

The Background Service on Your Machine

Scheduled tasks do not run in the application window. The installer registers a background service (companion_services.exe) on your own machine for that. It checks at fixed intervals whether a task is due, runs it, and writes the result to the Vision database and to the Windows Event Log. On startup it runs six self-checks. As long as no task is configured, it has nothing to do.

Deletion under GDPR Art. 17

Retention periods have their own scheduled task. It deletes according to the rules you set, and it works only in your own database. There is no copy at portier, because the data never reaches portier.

Security Measures

  • Data Storage at the Customer's Site: Since portier Vision is operated on-premise, your data is stored locally on your own infrastructure.

  • External Services: The licence server and CRM are hosted in the EU and comply with GDPR requirements. Every other outbound connection is one you switch on and off yourself.

  • Access Control: Access to your data is only granted to individuals authorised by you. We do not have visibility or control over your locally stored data.

  • Certification: portier is certified to ISO 27001. We provide the certificate on request.

Conclusion

portier, with its on-premise solution portier Vision, offers you the ability to keep your data entirely under your control. This is supported by the use of GDPR-compliant external services hosted within the EU. Every further outbound connection is your decision, and the list above is complete. If you have any further questions, our support team is happy to assist you.

Did this answer your question?
😞
😐
😁