Venheim
Empty pass of a professional kitchen after closing: bare stainless steel surfaces, above them the golden heat lamps

EU hosting · Tenant separation

Security and data protection – where the data is stored and who sees it

Anyone who introduces time tracking or a digital operations logbook entrusts software with their employees' data. This page answers the questions that rightly come up — and every statement here is backed in detail in the data protection declaration (German) and the data processing agreement (German).

Try Premium for 30 days, no payment details. After that your business carries on free on the Start plan; records stay readable and exportable.

The sign-up form is in German for now. Inside the app, everyone picks their own language — nine languages, English included.

In short

Venheim stores all business data in the EU: database, sign-in and files at Supabase in Ireland, the application runs at Vercel in Dublin. Every business is separated in the database by row-level security, employees are not tracked, and the owner can export or delete their data completely at any time — without having to ask us.

Closing downExport · backup

“What if you close down?”

The question is fair, and no provider can promise to exist forever. That is why Venheim is built so that a business never depends on our existence — the data belongs to the business, and it can get at it at any time without us.

Full export — by you yourself

The owner can download a complete package at any time: every table as a CSV file plus all stored files. No subscription barrier, no request to us, no waiting — the button is in your own admin area.

Records stay readable

Even after a subscription ends, viewing and exporting stay free. HACCP and working-time records are legal duties — with us they are never held hostage to a payment status.

Backed up daily, tested monthly

Database and file storage are fully backed up every day and stored encrypted (AES-256). Once a month a backup is restored as a test and the result logged — a backup that was never tested is only a hope.

HostingEU · Ireland

Where the data is stored — EU hosting, honestly listed

Database, sign-in and file storage run at Supabase in the EU region Ireland; the application itself runs at Vercel, pinned to the EU region Dublin. Which other service providers are involved is listed here in full — including the providers based in the USA. The contractual basis per service (data processing agreement, EU standard contractual clauses) is in the data protection declaration — none of it only in the small print.

ServicePurposeBased in / region
SupabaseDatabase, sign-in (auth) and file storage (private buckets for receipts, records, profile pictures)Data in the EU (Ireland, region eu-west-1); contracting party Supabase Pte. Ltd., based in Singapore
VercelRunning and delivering the application, scheduled jobs (cron)US provider (Vercel Inc.); execution is pinned to the EU region “dub1” (Dublin)
ResendEmail delivery: sign-up and password emails, monthly hygiene report, order emails to suppliers, monthly package for the tax advisorUS provider (Plus Five Five, Inc.)
StripePayment processing, subscription management, customer portal, invoices. For fraud prevention and to meet its own legal obligations, Stripe processes payment data as an independent controllerStripe Payments Europe (Ireland), parent company in the USA
Push services of the browser makersDelivering notifications when a person explicitly turns on pushdepending on the browser or operating system used
Groq — when the optional AI explanation aid is usedon an explicit click, phrases an already calculated suggestion list in two to three sentences; the decision itself is always made by the app's rule logicUS provider

The same list is Annex 1 to the data processing agreement (German) and is set out with the contractual bases in detail in the data protection declaration (German).

Separationin the database

One business never sees another

The separation of businesses does not depend on the interface but on the database itself — where it holds even for direct access that bypasses the interface.

Separation in the database

Row-level security on every table: each row belongs to an organisation and a site, and the database only hands out what belongs to your own. Even two sites of the same business are strictly separated.

Two-factor for managers

Manager accounts are secured with two-factor sign-in (TOTP) — enforced in the database itself, not just in the sign-in window: without the second factor the database hands out nothing, even on direct access.

Attacks before every release

Before every release, automated security tests run against the database with simulated identities — they deliberately attempt unauthorised access, including from another organisation.

Employeesdata minimisation

What actually protects employees

Time tracking runs into the GDPR exactly where it collects more than it needs to. Venheim is built the other way round — data minimisation is a design principle, not a setting.

GPS only at the moment of clocking

Only the distance to the business in metres is stored — never coordinates, never between clock entries. The measurement tolerance is capped at 50 metres. No continuous tracking, no movement profiles.

Only what the business needs

A sick note is a date without a diagnosis. Date of birth and home address are not recorded at all, the profile photo is voluntary — what is not stored cannot go missing.

No measurement behind the login

In the signed-in application no audience measurement runs at all — neither the cookieless visitor count nor Google Analytics. No measurement service learns anything about the team's work.

Third partiesexpiry date

Third parties' data has an expiry date too

Guests of the online booking

Anyone who books through a business's online booking is anonymised automatically 90 days after the booking day — without the business doing anything and without a subscription barrier. Guest data is not a stock to hoard.

Abuse brake without plain IP

The throttle against mass sign-ups and booking abuse stores only salted hashes — never the plain IP address and never the plain email address. After 24 hours these rows are deleted as well.

Deletionwithout asking

Deleting without asking

The owner deletes the entire business themselves — in one go in the database, without leftovers and without having to ask us or wait for us. The full export is one click away, so everything can be saved before deleting.

  • Deletion is atomic in the database — all or nothing, no orphaned data
  • Beforehand, the complete export at any time: CSV per table plus all files
  • Inside the app records are never deleted, only corrected — with a reason and a log

To be honest

Venheim has no ISO 27001 or SOC 2 certification and carries no seal — and “100% secure” does not exist anywhere in IT, including with us. What there is stands on this page, is enforced in the database and is held by automated tests. Security remains work — anyone who wants to check more deeply will find the data processing agreement and the data protection declaration publicly, without signing in (both in German).

In the logbook

Security and data protection are not an add-on module but the foundation of the digital operations logbook — with roster, time tracking and HACCP records. To the operations logbook.

Price

One price per site, unlimited team

€39.90 Pro·€69.90 Premiumper site per month. Prices shown are final prices — as a small business under § 6 (1) no. 27 of the Austrian VAT Act (UStG), we do not charge VAT. The Start plan is free for good — with roster, time clock, chat and HACCP recording including Excel download.One-off €199.00 setup fee with monthly payment — waived with annual payment. All prices

Start free
Questions8 answers

Frequently asked questions

Where exactly is our data stored?
Database, sign-in and file storage run at Supabase in the EU region Ireland (eu-west-1); the application itself runs at Vercel in the EU region Dublin. Some contracting parties are based outside the EU — Supabase in Singapore, for example, Vercel in the USA; both are bound by data processing agreements with EU standard contractual clauses. The complete list is further up this page and, word for word, in the data protection declaration.
Can the manager see where my team is right now?
No. The check happens only at the moment of clocking in or out: the app compares the position with the stored site and saves only the distance in metres, never coordinates. There is no continuous tracking and no movement profile; the measurement tolerance is capped at 50 metres. To be honest: the position comes from the device — the check is plausibility and deterrence, not proof.
Who can read our data?
Within the business a role model governs this: the team sees its working areas; business data such as receipts, prices and reports is restricted to the manager — enforced by row-level security in the database, not just in the interface. Other businesses see nothing; even sites of the same business are strictly separated. We ourselves, as processor, only access data for operation, backup and support — under the rules of the data processing agreement.
Is there a data processing agreement (DPA)?
Yes. The data processing agreement under Art. 28 GDPR is publicly available — with its annexes: the list of all sub-processors and the technical and organisational measures under Art. 32 GDPR. For businesses with employees it is the contractual basis for using software like Venheim; the data protection declaration adds the information under Art. 13 and 14 for visitors and customer businesses. Both documents are in German.
What happens in the event of a data breach?
For a customer business's data we are the processor: we report a personal data breach to the affected business — without undue delay and without an assessment period of our own — so that it can meet its deadlines under Art. 33 and 34 GDPR towards the authority and the people affected. The procedure is documented internally; incidents that in the end trigger no notification are recorded as well.
What happens to our data after the subscription ends?
Nothing is locked away: viewing and exporting always stay free, even with an expired subscription — HACCP records and records under § 26 AZG must never disappear behind a paywall. The owner can take the full export at any time or delete the entire business themselves; final deletion after the end of the contract is governed by the data processing agreement. A blocked account as leverage does not exist with us.
Is there audience measurement or advertising in the app?
No. In the signed-in application no measurement runs at all — neither the cookieless visitor count nor Google Analytics. Both exist only on the public pages, Google moreover only with explicit consent in the cookie banner. No measurement service learns anything about the employees' work, and employee data is never used for advertising.
Is Venheim ISO-certified or externally audited?
No — there is currently no ISO 27001 or SOC 2 certification, and we do not claim one. What there is instead: security rules enforced in the database itself, automated security tests with simulated identities before every release, and daily encrypted backups with a monthly restore test. Security is ongoing work for us, not a state reached once.

Trust can be checked

Test with real routines instead of promises: set up the business, invite the team — and try the full export on the very first day. It works from the start.

Try Premium for 30 days, no payment details. After that your business carries on free on the Start plan; records stay readable and exportable.

The sign-up form is in German for now. Inside the app, everyone picks their own language — nine languages, English included.