P anaceum.cc
Trust Center

Data protection you can verify, not just read about

Panaceum processes personal data on your behalf as a processor under Art. 28 GDPR, in Poland also under RODO with the UODO as supervisory authority. This page lists the agreements, the subprocessors, the regions and the technical controls behind those claims.

Art. 28 GDPR processor RODO · UODO EU-only processing No transfers outside the EEA
Agreements

Paperwork signed before the first import

Data processing agreement

DPA under Art. 28 GDPR describing purpose, categories of data, duration, security measures and deletion. Polish counterpart: umowa powierzenia przetwarzania danych osobowych.

Confidentiality

Staff are bound by confidentiality obligations that survive the end of the engagement; access is granted per role and revoked on change.

Incident notification

Personal data breaches are reported to you without undue delay and in any case within 24 hours of detection, with the facts known at that point.

Subprocessors

Current subprocessor list

Every subprocessor is named with its role and processing location. Changes are announced 30 days in advance and you may object in writing; if the objection cannot be resolved, you may terminate the affected service.

Subprocessor
Role
Location
Data
Hetzner Online GmbH
Infrastructure and backups
Falkenstein, Nuremberg · DE
Application data, backups
Data center partner PL
Infrastructure for Polish tenants
Warszawa · PL
Application data
Email delivery provider
Transactional email
EU region
Contact data, invoice notices
Payment providers
Payment processing
EU region
Payment identifiers, amounts
Error monitoring
Diagnostics and uptime
EU region
Technical logs, pseudonymised identifiers
Regions

Where the data lives

Production

Frankfurt and Warszawa. The region is fixed per tenant and is visible in the admin panel.

Backups

Encrypted backups stay in the same region as production, with a documented retention period.

Support access

Support works from inside the EU only. No access from third countries, no remote sessions outside the EEA.

Data subject rights

Requests and how they are executed

Every request is tracked with an identifier, an owner and a deadline. You stay the controller; Panaceum executes on your instruction and returns written confirmation.

Request
Mechanism
Deadline
Access
Machine-readable export of the client record, services, invoices and tickets
5 business days
Rectification
Direct edit in the admin panel with an audit entry
immediate
Erasure
Scheduled deletion of the client record and derived data, with retention exceptions listed
30 days
Portability
Structured export in JSON or CSV, per client or per tenant
5 business days
Restriction
Account and service freeze without deletion
immediate
Technical controls

What is enforced in the product

Access audit log

Every view, export and change of personal data is recorded with account, time and object, and is available to you.

Two-factor authentication

Mandatory for all staff accounts; sessions are server-side and revocable centrally.

Least privilege

Role-based permissions with named scopes; API keys are limited to the endpoints they need.

Encryption

TLS in transit, encryption at rest for backups, secrets stored outside the application database.

Pseudonymisation

Staff appear to clients as pseudonymised identities; real names and photos are never shown.

Retention

Documented retention per data category, with automatic deletion once the period ends.

Need the DPA or the subprocessor list as a document

We send the signed agreement, the current subprocessor list and the security overview before any data leaves your systems.