Billerang Logo

Compliance & Data Protection

How we protect your data, maintain regulatory compliance, and ensure your billing operations meet the highest standards.

GDPR Compliance

Billerang is fully compliant with the EU General Data Protection Regulation (GDPR). We serve as a data processor for customer billing data and as a data controller for our own business operations.

We provide Data Processing Agreements (DPA) to all customers, documenting the scope, nature, and purpose of data processing, along with the technical and organizational measures we implement to protect personal data.

Our Data Protection Officer (DPO) oversees compliance activities and serves as the point of contact for data protection authorities. For DPO inquiries, contact us at contact@shareteal.com.

Key Points

  • Lawful basis documented for all processing activities
  • Data Processing Agreements available for all customers
  • Privacy Impact Assessments conducted for new features
  • Data breach notification procedures within 72 hours
  • Regular staff training on data protection obligations

Data Residency

All customer data is hosted exclusively within the European Union. Our primary data center is located in Frankfurt, Germany (Linode/Akamai), ensuring compliance with EU data sovereignty requirements.

We do not transfer customer data outside the European Economic Area (EEA) unless explicitly required and authorized by the customer, with appropriate safeguards in place such as Standard Contractual Clauses.

Key Points

  • Primary hosting in Frankfurt, Germany (EU)
  • Backup data centers within the EU
  • No data transfers outside the EEA by default
  • Standard Contractual Clauses available for authorized transfers

Multi-Tenant Isolation

The Billerang platform implements strict multi-tenant isolation to ensure that each customer's data is completely separated from other tenants at every layer of the stack.

Database-level isolation ensures queries can never access data belonging to another tenant. Application-level controls enforce tenant boundaries on every API request. Network policies restrict communication between tenant workloads.

Key Points

  • Database-level tenant isolation enforced on all queries
  • Application middleware validates tenant context on every request
  • Network policies restrict cross-tenant communication
  • Regular penetration testing validates isolation boundaries
  • Tenant-specific encryption keys for sensitive data

Audit Trail

Every operation in the Billerang platform is logged in an immutable audit trail. This includes user actions, system events, configuration changes, and data access operations.

Audit logs are retained for a minimum of 12 months and are available to customers through the platform dashboard or via API export. Logs include timestamp, actor, action, resource, and outcome for complete traceability.

Key Points

  • Immutable audit logs for all operations
  • Minimum 12-month retention period
  • Exportable via dashboard or API
  • Includes user actions, system events, and configuration changes
  • Tamper-evident log storage

Right to Access & Delete

We fully support data subject rights under GDPR, including the right to access, rectification, erasure, restriction of processing, data portability, and the right to object.

Customers can exercise these rights on behalf of their end users through the Billerang platform API and dashboard. For requests related to your own account data, contact our team directly.

Key Points

  • Self-service data export through platform API
  • Data deletion requests processed within 30 days
  • Automated tools for customers to manage end-user data subject requests
  • Verification procedures to prevent unauthorized access requests

Compliance Questions?

Our compliance team is available to discuss data protection requirements, provide documentation for your vendor assessment, or arrange a security review.

Contact Our Team