
EU hosting · Tenant separation
Security and data protection – where the data is stored and who sees it
Anyone who introduces time tracking or a digital operations logbook entrusts software with their employees' data. This page answers the questions that rightly come up — and every statement here is backed in detail in the data protection declaration (German) and the data processing agreement (German).
Try Premium for 30 days, no payment details. After that your business carries on free on the Start plan; records stay readable and exportable.
The sign-up form is in German for now. Inside the app, everyone picks their own language — nine languages, English included.
Venheim stores all business data in the EU: database, sign-in and files at Supabase in Ireland, the application runs at Vercel in Dublin. Every business is separated in the database by row-level security, employees are not tracked, and the owner can export or delete their data completely at any time — without having to ask us.
“What if you close down?”
The question is fair, and no provider can promise to exist forever. That is why Venheim is built so that a business never depends on our existence — the data belongs to the business, and it can get at it at any time without us.
Full export — by you yourself
The owner can download a complete package at any time: every table as a CSV file plus all stored files. No subscription barrier, no request to us, no waiting — the button is in your own admin area.
Records stay readable
Even after a subscription ends, viewing and exporting stay free. HACCP and working-time records are legal duties — with us they are never held hostage to a payment status.
Backed up daily, tested monthly
Database and file storage are fully backed up every day and stored encrypted (AES-256). Once a month a backup is restored as a test and the result logged — a backup that was never tested is only a hope.
Where the data is stored — EU hosting, honestly listed
Database, sign-in and file storage run at Supabase in the EU region Ireland; the application itself runs at Vercel, pinned to the EU region Dublin. Which other service providers are involved is listed here in full — including the providers based in the USA. The contractual basis per service (data processing agreement, EU standard contractual clauses) is in the data protection declaration — none of it only in the small print.
| Service | Purpose | Based in / region |
|---|---|---|
| Supabase | Database, sign-in (auth) and file storage (private buckets for receipts, records, profile pictures) | Data in the EU (Ireland, region eu-west-1); contracting party Supabase Pte. Ltd., based in Singapore |
| Vercel | Running and delivering the application, scheduled jobs (cron) | US provider (Vercel Inc.); execution is pinned to the EU region “dub1” (Dublin) |
| Resend | Email delivery: sign-up and password emails, monthly hygiene report, order emails to suppliers, monthly package for the tax advisor | US provider (Plus Five Five, Inc.) |
| Stripe | Payment processing, subscription management, customer portal, invoices. For fraud prevention and to meet its own legal obligations, Stripe processes payment data as an independent controller | Stripe Payments Europe (Ireland), parent company in the USA |
| Push services of the browser makers | Delivering notifications when a person explicitly turns on push | depending on the browser or operating system used |
| Groq — when the optional AI explanation aid is used | on an explicit click, phrases an already calculated suggestion list in two to three sentences; the decision itself is always made by the app's rule logic | US provider |
The same list is Annex 1 to the data processing agreement (German) and is set out with the contractual bases in detail in the data protection declaration (German).
One business never sees another
The separation of businesses does not depend on the interface but on the database itself — where it holds even for direct access that bypasses the interface.
Separation in the database
Row-level security on every table: each row belongs to an organisation and a site, and the database only hands out what belongs to your own. Even two sites of the same business are strictly separated.
Two-factor for managers
Manager accounts are secured with two-factor sign-in (TOTP) — enforced in the database itself, not just in the sign-in window: without the second factor the database hands out nothing, even on direct access.
Attacks before every release
Before every release, automated security tests run against the database with simulated identities — they deliberately attempt unauthorised access, including from another organisation.
What actually protects employees
Time tracking runs into the GDPR exactly where it collects more than it needs to. Venheim is built the other way round — data minimisation is a design principle, not a setting.
GPS only at the moment of clocking
Only the distance to the business in metres is stored — never coordinates, never between clock entries. The measurement tolerance is capped at 50 metres. No continuous tracking, no movement profiles.
Only what the business needs
A sick note is a date without a diagnosis. Date of birth and home address are not recorded at all, the profile photo is voluntary — what is not stored cannot go missing.
No measurement behind the login
In the signed-in application no audience measurement runs at all — neither the cookieless visitor count nor Google Analytics. No measurement service learns anything about the team's work.
Third parties' data has an expiry date too
Guests of the online booking
Anyone who books through a business's online booking is anonymised automatically 90 days after the booking day — without the business doing anything and without a subscription barrier. Guest data is not a stock to hoard.
Abuse brake without plain IP
The throttle against mass sign-ups and booking abuse stores only salted hashes — never the plain IP address and never the plain email address. After 24 hours these rows are deleted as well.
Deleting without asking
The owner deletes the entire business themselves — in one go in the database, without leftovers and without having to ask us or wait for us. The full export is one click away, so everything can be saved before deleting.
- Deletion is atomic in the database — all or nothing, no orphaned data
- Beforehand, the complete export at any time: CSV per table plus all files
- Inside the app records are never deleted, only corrected — with a reason and a log
To be honest
Venheim has no ISO 27001 or SOC 2 certification and carries no seal — and “100% secure” does not exist anywhere in IT, including with us. What there is stands on this page, is enforced in the database and is held by automated tests. Security remains work — anyone who wants to check more deeply will find the data processing agreement and the data protection declaration publicly, without signing in (both in German).
Security and data protection are not an add-on module but the foundation of the digital operations logbook — with roster, time tracking and HACCP records. To the operations logbook.
One price per site, unlimited team
€39.90 Pro·€69.90 Premiumper site per month. Prices shown are final prices — as a small business under § 6 (1) no. 27 of the Austrian VAT Act (UStG), we do not charge VAT. The Start plan is free for good — with roster, time clock, chat and HACCP recording including Excel download.One-off €199.00 setup fee with monthly payment — waived with annual payment. All prices
Frequently asked questions
Where exactly is our data stored?
Can the manager see where my team is right now?
Who can read our data?
Is there a data processing agreement (DPA)?
What happens in the event of a data breach?
What happens to our data after the subscription ends?
Is there audience measurement or advertising in the app?
Is Venheim ISO-certified or externally audited?
Trust can be checked
Test with real routines instead of promises: set up the business, invite the team — and try the full export on the very first day. It works from the start.
Try Premium for 30 days, no payment details. After that your business carries on free on the Start plan; records stay readable and exportable.
The sign-up form is in German for now. Inside the app, everyone picks their own language — nine languages, English included.

