Security
Last updated: January 1, 2026
At Offsoo B.V., the security of data and the continuity of our service come first. We process data for accounting and bookkeeping firms and take appropriate technical and organisational measures to protect that data against loss, misuse, unauthorised access and other unlawful processing. This page describes in outline how Offsoo handles information security.
Scope
These measures apply to:
- the Offsoo application (SaaS), including the web and mobile apps and the API;
- the underlying infrastructure;
- personal data Offsoo processes as a processor on the instructions of customers;
- the operational processes around support, monitoring and incident handling.
Website and marketing processing falls outside this scope and is described in the Privacy Statement and the Cookie Policy.
Architecture and hosting
- The Offsoo application is hosted primarily within the European Union (DigitalOcean in Amsterdam).
- Backups are stored within the EU.
- Offsoo uses cloud providers and tooling that apply common security measures.
Access management
- Access to systems is limited to authorised people and based on least privilege.
- Access to production environments is restricted and, where appropriate, logged.
- For Offsoo administrators, multi-factor authentication (MFA) is used and enforced where possible.
- Customers are themselves responsible for managing user accounts and passwords carefully, and for applying a 2FA policy within their own Offsoo environment.
Network and connection security
- All connections to the Offsoo application run over encrypted HTTPS/TLS.
- Unencrypted connections are not supported.
- Network traffic and application behaviour may be monitored to detect abuse, attacks and anomalies.
Backups and recovery
- Database backups are usually made every hour.
- File and object-storage backups are usually made daily.
- Backups have a maximum retention of three (3) months.
- Backups are intended for recovery from incidents and disasters; recovery depends on the nature and scale of the incident.
Logging and monitoring
Offsoo monitors systems to safeguard stability, security and performance. This includes:
- application and server logs;
- errors and exceptions (Sentry, for example);
- performance and availability measurements (Nightwatch/Ping, for example).
Aggregated or limited metadata is used where possible.
Incident response and data breaches
Offsoo has an incident procedure.
In the event of an incident:
- the incident is assessed and classified;
- measures are taken to limit the impact;
- it is established whether there is a personal data breach within the meaning of the GDPR.
Where there is a data breach, Offsoo reports it to the customer (the controller) without undue delay, within the target period set out in the DPA.
Contact point for security incidents and vulnerabilities:
Subprocessors and transfers
Offsoo uses Subprocessors for hosting, support, monitoring and email. Some suppliers may be established outside the EEA (in the US, for example). Where that is the case, Offsoo uses valid transfer mechanisms (such as SCCs and/or the DPF where applicable). A current overview is on the Subprocessors page.
The customer's responsibility
Customers remain responsible for:
- the lawfulness of the personal data and content they process in Offsoo;
- managing user accounts and access rights carefully;
- preventing unnecessarily sensitive data (such as passwords or 2FA codes) from being stored in Offsoo;
- complying with applicable privacy law towards their own clients and staff.
Retention and deletion
- After termination, the environment is no longer accessible to the customer.
- Customer data remains available to Offsoo (for administration and export on request) until the customer requests deletion, with a maximum retention period of one (1) year after termination.
- Backups expire automatically according to the configured retention (a maximum of 3 months).
Changes
Offsoo may amend this policy. The most recent version is available on the website.