Repax helps producers meet EPR and PPWR obligations across European markets. Our customers trust us with their product, packaging and supply chain data, and we treat that as the core of the product rather than an afterthought.
This page summarises how we host and protect that data. For detailed security documentation or a completed security questionnaire, contact hello@repax.io.
Your data stays in the EU
Repax runs entirely on infrastructure located in Germany, operated by Hetzner Online GmbH. Production systems, backups and all supporting infrastructure are within the European Union.
We do not transfer platform data outside the EU/EEA. No sub-processor involved in storing or processing the data you submit to Repax is located in a third country, so the transfer mechanisms that complicate many SaaS agreements, such as standard contractual clauses and transfer impact assessments, do not apply to your data in our platform.
For customers whose own compliance obligations require EU data residency, we can confirm this in writing on request.
How we protect it
Encryption. All traffic to and from Repax is encrypted in transit using current TLS standards. Data at rest, including backups, is encrypted.
Access control. Access to production systems is limited to personnel with an operational need, protected by multi-factor authentication and individual named accounts. Access rights are reviewed regularly and revoked promptly when someone changes role or leaves.
Tenant separation. Repax is a multi-tenant platform. Customer data is logically isolated: every request and query is scoped to the customer's own tenant at the application layer.
Vulnerability management. Dependencies are kept current and reviewed for known vulnerabilities, infrastructure is patched on a regular cadence, and critical vulnerabilities are prioritised for immediate remediation.
Monitoring. Application errors and anomalies are tracked with alerting through EU-hosted error monitoring.
Error tracking without personal data. Our error monitoring is configured for EU data residency and to exclude personal data. User context and request contents are removed before anything is transmitted.
How we build
Every change to Repax goes through a reviewed pipeline before it reaches production:
- Automated unit and integration test suites must pass before any change can be merged
- Production data is never used in development or testing
We take the view that automated tests are the most honest security control available to a company our size: they run on every change, they either pass or they don't, and they can be evidenced rather than asserted.
Backups and continuity
Customer data is backed up on an automated schedule to encrypted storage in a separate physical location from our production environment.
We test restores on a recurring schedule and record the results, because an untested backup isn't a backup. Our recovery objectives are available on request.
Privacy and GDPR
Repax acts as data processor on your behalf; you remain the data controller for personal data you submit to the platform.
- Our GDPR Article 28 data-processing terms are built into our Terms of Service (clause 26); there is no separate agreement to sign
- The personal data we process is limited to business contact details of your personnel who use the platform. We do not process special categories of personal data
- We maintain a record of processing activities; our current sub-processors are listed on this page
- We notify you in advance of any change to our sub-processors, with a right to object
- We notify you without undue delay after confirming a personal data breach affecting your data
- Following termination, your data is available for export for 30 days and is then permanently deleted from production systems. Residual copies in encrypted backups are purged as those backups age out of our retention window, within 60 days. Records we are legally required to retain are kept for the statutory period
- You can export your data at any time, and we assist you in responding to data subject requests
Our Privacy Policy covers how we handle personal data in our own right: website visitors, prospects and customer contacts. Export and retention terms are set out in our Terms of Service.
Sub-processors
We use a small number of carefully chosen sub-processors, all EU-hosted:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Infrastructure hosting | Germany |
| Sentry | Application error monitoring (no personal data) | EU |
| Brevo | Transactional email delivery | France |
| Stripe Payments Europe, Ltd. | Payment processing | Ireland |
Platform data, everything you submit to Repax, stays within the EU. Billing is handled separately by Stripe under our own commercial relationship, and no platform data is shared with our payment processor.
This is the complete and current list. We update this page when it changes.
Governance and documentation
We maintain a documented internal security policy set covering access control, secure development, change management, backup and recovery, incident response and vendor management. Policies are version-controlled and reviewed annually.
Our infrastructure provider, Hetzner, is ISO 27001 certified for its datacentre operations.
For security reviews we can provide detailed security documentation and a completed security questionnaire. If your procurement process has specific framework requirements, get in touch and we'll tell you exactly where we stand.
Reporting a security issue
If you believe you've found a vulnerability in Repax, please email hello@repax.io. We'll acknowledge your report within two business days and keep you updated on remediation.
We ask that you give us a reasonable opportunity to address the issue before public disclosure, and that testing is limited to accounts you control.
Questions
Security reviews are part of buying software, and we'd rather make yours quick.
hello@repax.io for security documentation, questionnaires, or anything this page doesn't answer. We aim to respond within two business days.