Event data, handled like enterprise data
Happenee runs events for banks, telcos, public institutions and media, where how data is stored, processed and proven matters as much as what the software does. Here's how we protect it.
Certifications & data protection
Compliant by design, not by exception
ISO/IEC 27001 certified
Information security managed under a certified information security management system.
GDPR compliant
Built and operated to meet EU data protection requirements as a data processor.
EU data residency
All data is stored and operated within EU territory.
We don't sell your data
We never sell the personal information of customers or their attendees to third parties.
DPA available
A Data Processing Agreement sets out roles, obligations and processing terms for customers.
Sub-processor transparency
We maintain a list of sub-processors (including Microsoft Azure), available to customers on request.
Infrastructure & encryption
Encrypted in transit, encrypted at rest, hosted in the EU
AES encryption at rest
All stored data is encrypted using AES. Access to encryption keys is restricted to minimal staff.
256-bit TLS in transit
All traffic to the website and APIs is served over TLS with a 256-bit SSL certificate.
Microsoft Azure, EU
Cloud service hosted on Microsoft Azure, with infrastructure operated within the EU.
More on Azure security and Azure compliance.
Application security & operations
Tested, monitored and built to keep running
Built and maintained in-house
Web and mobile apps are developed, tested, deployed and maintained in-house, not outsourced.
Penetration testing
OWASP Top Ten scans, automated pentesting via Indusface Apptrana, plus independent manual penetration testing.
Backups & disaster recovery
Daily full and incremental backups, with a documented, step-by-step disaster recovery plan.
99.5% uptime commitment
A defined availability commitment, with routine vulnerability scans against production servers.
Access control & logging
Access to systems, data and keys is restricted on a need-to-know basis. System and infrastructure access is logged.
For financial-sector customers
Supporting your DORA obligations
For regulated financial customers, Happenee acts as an ICT third-party service provider. The obligation under DORA is yours, but where our service is in scope, our posture is built to support it.
Responsible disclosure
Found a vulnerability? We'd like to hear from you. We don't currently run a public bug bounty program, but we review every report.