Trust Center
Documents
ISO/IEC 27001 Certificate
Request documentPenTest Report
Request documentInformation Security Policy
apadua operates an information security management system (ISMS) certified according to ISO/IEC 27001:2022, covering all business operations. Last audit: May 2026. Certification body: Proks Certification, accredited by DAkkS. As part of our ISMS, we publish our current Information Security Policy (POL-01). If you have any questions, please contact your apadua representative or isms@apadua.com.
Version 1.2 – September 2026
The purpose of this Information Security Policy is to establish a framework for protecting the confidentiality, integrity, and availability of the organization's information assets in accordance with ISO 27001 standards. This policy ensures that security risks are identified, assessed, and mitigated through appropriate controls, fostering a culture of continuous improvement and compliance with legal, regulatory, and contractual obligations. By implementing this policy, the organization aims to safeguard sensitive data, maintain business continuity, and build trust with stakeholders, customers, and employees.
This Information Security Policy applies to all information assets, systems, processes, and personnel within the organization that handle, process, store, or transmit data. It covers employees, contractors, third-party service providers, and any other stakeholders with access to the organization's information resources. The policy encompasses all physical, digital, and cloud-based environments, ensuring compliance with ISO 27001 requirements and relevant legal, regulatory, and contractual obligations. This document serves as a foundation for implementing security controls, risk management practices, and continuous improvement efforts to protect the organization's information security posture.
What is an ISMS?
An Information Security Management System (ISMS) is a structured framework of policies, processes, and controls designed to protect the confidentiality, integrity, and availability of an organization's information. It helps systematically manage and reduce the risks related to information security, ensuring that sensitive data—such as customer details, financial records, and intellectual property—is adequately protected.
Why do we need an ISMS?
Information is one of the organization's most valuable assets. With increasing cyber threats, regulatory demands, and the need to protect customer trust, safeguarding information has never been more critical. An ISMS provides a proactive approach to protecting data, ensuring the organization can: Comply with legal, regulatory, and contractual requirements. Protect against data breaches, cyber-attacks, and accidental loss of information. Ensure business continuity in the event of a disruption or security incident. Build and maintain trust with customers, partners, and stakeholders.
How does it work?
Plan: Identify risks and set objectives for addressing them.
Do: Implement the necessary security measures and controls.
Check: Regularly monitor and evaluate the effectiveness of the security measures.
Act: Make improvements based on assessments and emerging risks.
The ISMS is not a one-time implementation but an ongoing process that adapts to changes in the business, technology, and external threats.
Alignment with ISO/IEC 27001
The ISMS is aligned with the internationally recognized ISO/IEC 27001:2022 standard. This standard provides a best-practice framework for managing information security. By adhering to ISO/IEC 27001, the organization demonstrates its commitment to: Global best practices in information security management. Ensuring compliance with applicable laws, regulations, and industry standards. Continuous improvement in managing information security risks and safeguarding critical information assets.
ISO/IEC 27001 requires organizations to take a systematic approach to managing sensitive information and ensuring that security measures are continually reviewed, improved, and updated. Our ISMS helps us meet these requirements by integrating security into every part of the business, from IT infrastructure to human resources and operations.
The organization's InfoSec Team will receive comprehensive resources such as experienced employees, tools, additional training and best practices tailored to different roles and responsibilities to uphold the standards of security excellence. The goal is to ensure that every member of the organization is equipped with the necessary resources to effectively safeguard sensitive data, mitigate risks and contribute to a culture of security awareness.
Management Commitment
Information security is a management responsibility, and decision-making for information security is not delegated. While specialists and advisors play an important role in helping to make sure that controls are designed properly, functioning properly and adhered to consistently, it is the manager in charge of the business area involved who is primarily responsible for information security.
Primary Departments Working on Information Security
Guidance, direction and authority for information security activities are centralized for all organizational units in the Information Security Program and summarized in this document. The management is responsible for establishing and maintaining organization-wide information security policies, standards, guidelines and procedures. Compliance checking to ensure that organizational units are operating in a manner consistent with these requirements is the responsibility of department managers. Investigations of system intrusions and other information security incidents are the responsibility of the InfoSec Team. Disciplinary matters resulting from violations of information security requirements are handled by CISO working in conjunction with the HR department.
ISMS Activities
The scope defines the core processes, technology aspects, people and exclusions of the ISMS. It results in a governance framework which takes internal & external factors, interested parties, business objectives, legal requirements and interfaces & dependencies into consideration. Based on these factors, the Information Security Objectives were identified and described. They provide the higher level direction for the ISMS operations.
Information Security Objectives
The organization has defined the following information security objectives to protect information assets, reduce risks and increase awareness.
Confidentiality - Ensure that sensitive data is accessible only to authorized individuals or systems.
Availability - Securing availability of provided services, and data through business continuity measures.
Risk Reduction - Minimizing security risks and protecting business continuity.
Compliance - Ensuring adherence to industry standards and regulations.
Integrity - Ensure the accuracy and reliability of data throughout its lifecycle.
Continuous Improvement - Ensures the ISMS evolves to respond to new threats, incidents, and opportunities for enhancement.
Process Standardization - Improving processes by reducing manual efforts and creating standardized procedures.
Increased Awareness - Conduct frequent information security awareness training.
Review and Maintenance
This Information Security Policy will be reviewed at least annually, or when significant changes occur in the organization's business environment, regulatory landscape, or operational structure. The CISO, along with top management, will be responsible for ensuring the policy remains current and aligned with business goals and evolving security threats. Revisions and updates will be documented in the version and approval history.
Policy Statements
Risk Management
The organization will identify, assess, and manage risks to its information assets through a formal risk management process. This process includes: Regular risk assessments to evaluate and categorize risks based on their likelihood and impact. Risk treatment plans that outline mitigation strategies, including risk acceptance, reduction, avoidance, and transfer, in accordance with the risk management policy. Continuous monitoring of the risk environment to address emerging threats.
The organization will comply with all relevant legal, regulatory, and contractual requirements. The ISMS will be monitored through regular internal & external audits, management reviews, and assessments to ensure its continued effectiveness and compliance with this policy. Weaknesses identified through these processes will be addressed through corrective actions and continuous improvement initiatives.
Asset Management
The organization will identify, document, and classify all information assets based on their sensitivity and importance to the business. Appropriate controls will be applied throughout the asset lifecycle (e.g., from creation to disposal) to ensure data protection.
Access Management
Access to the organization's information systems and data will be based on the principle of least privilege. Access to systems and privileges rights will be reviewed regularly to ensure that users have only the permissions necessary to perform their job functions. Multi-factor authentication (MFA) and other access control measures will be implemented where applicable.
Incident Management
The organization will maintain an incident management process for the identification, reporting, and resolution of information security incidents. Employees and third parties are required to report security incidents immediately to the CISO. The organization will conduct root cause analysis and lessons-learned exercises to improve its incident response capability.
Personal data breaches are assessed without undue delay. Where required, they are notified to the competent supervisory authority within 72 hours (Art. 33 GDPR) and to affected clients in accordance with the applicable data processing agreements.
Business Continuity
The organization will develop and maintain a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) to ensure that critical business functions can continue in the event of a security incident or major disruption. These plans will be tested regularly, and results will be used to improve the effectiveness of the continuity strategy.
Backup Management
The organization implemented regular and secure backups of critical data, systems, and configurations to ensure business continuity and data integrity. Backups must be encrypted, stored securely, and tested periodically for reliability. Retention periods and recovery procedures shall be defined based on business, legal, and regulatory requirements. Unauthorized access, modification, or deletion of backups is strictly prohibited.
Logging and Monitoring
The organization implemented comprehensive logging and monitoring activities to detect and analyze security events. All critical systems must generate and retain protected security logs. Automated monitoring will identify anomalies and suspicious activities. Logs must be regularly reviewed and analyzed. Retention periods will be defined based on requirements. Incident response procedures will be in place, and responsibilities will be clearly defined.
Vulnerability Management
The organization implements a comprehensive vulnerability management process to safeguard its systems against potential risks. Vulnerabilities in critical systems, networks, and applications are identified through regular vulnerability scans. Automated tools are utilized for continuous monitoring to detect emerging threats in real-time. Once vulnerabilities are identified, they are promptly addressed through an established patch management process. All findings, actions, and outcomes are thoroughly documented for tracking and future audits, ensuring transparency and compliance.
Personnel Security
The organization implemented a standardized recruiting, on-boarding and offboarding process to ensure that all employees and contractors understand their responsibilities in maintaining information security. This includes comprehensive screening activities, standardized contracts and confidentiality agreements, as well as remote access requirements. Annual security awareness trainings are also implemented and obligatory for all employees to foster the organization's security culture. All violations and security breaches will be handled based on defined disciplinary actions.
Vendor Management
Vendors and third-party partners are integral to the organization's operations, and their security practices directly impact the organization's risk profile. During the onboarding process, each vendor undergoes a thorough assessment to evaluate their security measures and compliance with organizational standards. Contracts include explicit security requirements, such as data protection obligations and incident management methodologies. Regular risk evaluations are conducted to ensure vendors maintain compliance over time, and vendors are required to report any security incidents promptly. The organization collaborates with its partners to mitigate risks effectively and uphold a secure operational environment. Offboarding processes for vendors are standardized and documented according to ISMS requirements.
Physical Security
Physical and environmental security controls are implemented as part of our ISMS in accordance with ISO/IEC 27001:2022. Details are disclosed upon request.
Secure Software Development
The organization integrated security best practices throughout the software development lifecycle (SDLC) to ensure the confidentiality, integrity, and availability of applications. Security requirements must be defined, implemented, and tested at each process stage. The development lifecycle is carried out in a development, test and productive environment. Code reviews and automated tests are obligatory. Developers must follow secure coding guidelines and receive ongoing security training. Any identified security vulnerabilities must be promptly remediated before deployment.
Violations & Enforcement
Compliance with this policy is mandatory and is a fundamental requirement for the secure and compliant handling of information of the organization. Violations to this policy may result in disciplinary action according to the Information Security Policy, depending on the severity of the offense.
Our goal is to create a safe and trustworthy work environment. If there are any challenges in implementing this policy or suggestions for improvement, please contact the Chief Information Security Officer (CISO) or the InfoSec Team.
Privacy Policy
Version: September 2026
This privacy policy consists of Part A (website apadua.com) and Part B (apadua platform, apadua.app).
PART A – WEBSITE
A1. Controller
apadua GmbHSubbelrather Str. 20050823 Cologne, GermanyManaging directors: Gregory N. Vider, Markus SinzPhone: +49 221 6430 3470Data protection contact: isms@apadua.com
A2. Hosting and website analytics (Lovable)
This website is hosted by Lovable Labs Incorporated AB, Stockholm, Sweden. When you visit the site, your IP address, the date and time of access, browser type, operating system and referrer URL are processed in server logs to deliver the website securely. We also use Lovable's built-in visitor analytics, which measures aggregated traffic (e.g. page views, visit duration, traffic source, device type and approximate location). Lovable also processes log data as an independent controller for security and product development purposes; see lovable.dev/privacy.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure website and in understanding overall website usage).
Retention: in accordance with Lovable's retention periods.
Link preview images are delivered via Cloudflare, Inc., USA. Transfers to the USA are based on the EU-U.S. Data Privacy Framework.
A3. Cookies and consent
Technically necessary storage is used on the basis of § 25(2) No. 2 TDDDG. External content (HubSpot) is only loaded after your consent, given either in the cookie settings or by clicking a "Book a meeting" button (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). You can change or withdraw your consent at any time via "Cookie settings" in the footer of this website.
A4. Contact, forms and meeting booking (HubSpot)
We use HubSpot (HubSpot Ireland Ltd., Dublin, Ireland; parent company HubSpot, Inc., USA) for contact forms, document requests, meeting bookings and customer relationship management. The HubSpot meeting calendar is only loaded when you click a "Book a meeting" button; by clicking, you consent to it being loaded. HubSpot forms embedded on our pages are only loaded after you consent to the "External content" category. Data you enter (e.g. name, email address, company, message) is stored in HubSpot.
Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR (pre-contractual measures).
Retention: We store this data for as long as it is required to process your request and to maintain the business relationship. It is deleted when it is no longer required for these purposes or upon your request, unless statutory retention obligations apply.
Transfers to the USA are based on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
If you contact us by email, we process your data to handle your request (Art. 6(1)(b) or (f) GDPR) and delete it once your request has been fully processed, unless statutory retention obligations apply.
A5. Social media links
Our website contains simple links to LinkedIn. No data is transferred to LinkedIn until you click the link.
A6. Your rights
You have the right to:
- access your personal data (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- withdraw your consent at any time with effect for the future (Art. 7(3) GDPR)
Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(f) GDPR, you may object to the processing at any time on grounds relating to your particular situation.
To exercise your rights, contact isms@apadua.com.
A7. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority, for example the authority responsible for us:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestr. 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de
A8. Obligation to provide data
You are not obliged to provide personal data. Without the data marked as mandatory in forms, we cannot process your request.
A9. Automated decision-making
No automated decision-making within the meaning of Art. 22 GDPR takes place on this website.
PART B – PLATFORM (APADUA.APP)
B1. Scope and roles
Part B applies to users of the apadua platform, in particular employees of contractors (vendors) who register via apadua.app.
- apadua is the controller for user accounts, login and security data, and platform communication by apadua.
- Within a tender, the client running the tender is the controller for tender content (e.g. offers, documents, questions and answers). apadua processes this data on the client's behalf (Art. 28 GDPR). Requests concerning tender content should be addressed to the respective client; we will forward requests we receive.
Processing of personal data for clients using the platform is governed by separate agreements with those clients.
B2. Data, purposes and legal bases
- Account data (name, business email address, phone number, company, role): to create and manage your account and to provide the platform. Legal basis: Art. 6(1)(b) GDPR, or Art. 6(1)(f) GDPR where you act on behalf of your employer.
- Verification of profile data: to ensure that only verified organisations participate in tenders. Legal basis: Art. 6(1)(f) GDPR.
- Login and security logs: to secure the platform and detect misuse. Legal basis: Art. 6(1)(f) GDPR.
- Email notifications (e.g. invitations, deadlines, answers): Art. 6(1)(b) or (f) GDPR.
- Product analytics (PostHog): configured without cookies or persistent identifiers, to improve the usability of the platform. Legal basis: Art. 6(1)(f) GDPR.
B3. AI-supported functions
The platform uses Google Gemini (Google Cloud, EU region) for AI-supported functions such as text drafting, translation and analysis. Content is processed exclusively in the EU and is not used to train AI models. AI outputs are suggestions; decisions such as awards are always made by people.
B4. Recipients (processors)
- Hosting: Microsoft Azure (Microsoft Ireland Operations Ltd.), data centre region Germany
- Email notifications: Microsoft Azure (Microsoft Ireland Operations Ltd.), data centre region Germany
- Google Cloud (AI functions, EU region)
- PostHog Inc. (EU cloud)
Transfers to third countries only take place on the basis of an adequacy decision (e.g. the EU-U.S. Data Privacy Framework) or Standard Contractual Clauses.
B5. Retention
- Account data: stored for the duration of the account and deleted after termination of the account or upon request.
- Security logs: stored for as long as required to secure the platform and to investigate security incidents.
- Tender content: in accordance with the instructions of the respective client.
Statutory retention obligations remain unaffected (e.g. § 257 HGB, § 147 AO).
B6. Automated decision-making
Offer scores are calculated on behalf of the respective client as decision support. The award decision is made by the client's employees. No automated decision within the meaning of Art. 22 GDPR takes place.
Sections A6 (Your rights), A7 (Right to lodge a complaint) and A8 (Obligation to provide data) apply to Part B accordingly.
DATA SECURITY AND CHANGES
Data is transmitted using TLS encryption. Further technical and organisational measures are described in our Information Security Policy above. We update this privacy policy when our services or the legal requirements change. The current version is always available on this page.
