Security and data protection
Your customer list and your invoices are the most valuable data of your company. This page explains where the data is kept, who can access what, and what can be restored when something goes wrong.
- Servers in Germany
- Nightly backups
- Two-factor authentication
Data location and backups
The application and the database are hosted in Germany, in the data centre in Falkenstein. All connections are encrypted (TLS 1.2 and 1.3). The database is backed up every night and the health of the backups is checked every day.
- Daily backups are kept for 16 days, weekly backups for 8 weeks
- Monthly backups are kept for 4 months, yearly backups for 2 years
- Data is not deleted even if the account is suspended
- Lists can be downloaded as Excel and CSV at any time
Account security
Passwords must have at least 10 characters and contain letters and digits; passwords that appear in known breach lists are not accepted. Two-factor authentication works with an authenticator app. When the password is changed, the sessions on other devices are closed.
- Two-factor authentication (TOTP) and recovery codes
- Rate limit on failed sign-in attempts
- Changing the email address requires the current password
- Login history: time, device and IP address
Permissions and activity log
Who sees what, and who changes what? Roles are defined with view, add, edit and delete permissions for each module. Changes to records are kept for one year with the user and the time.
- Predefined roles and roles specific to your company
- Nobody can grant a permission they do not have themselves
- The company owner is notified of deletions
- An issued invoice cannot be changed afterwards
Separation of companies
BilgeERP is a multi-company system; every query is filtered by company and a record of one company is not shown to another. Passwords of email accounts are stored encrypted in the database, and API keys are stored only as a hash.
- Data separation by company
- Read or write permission and expiry for API keys
- Customer portal links with random keys
GDPR and the Turkish data protection law (KVKK)
The privacy policy states which data is processed for which purpose. Marketing emails are sent only to people who have given consent, and every email contains an unsubscribe link.
- Fonts and scripts are loaded from our own server
- No third-party tracking cookies
- Contact address for your data requests
Frequently asked questions
In which country is my data?
In Germany. The application and the database run in the data centre in Falkenstein.
What happens to my data when my subscription ends?
The account first becomes read-only: you can view and download your data but cannot enter new records. After that the account is suspended; the data is not deleted.
Is there single sign-on (SSO)?
No. You sign in with email and password, and optionally with two-factor authentication.
Who do I write to if I find a security vulnerability?
Write to us through the contact form or at the email address at the bottom of the page.
Related features
XRechnung e-invoicing
XRechnung 3.0 (EN 16931, UBL) e-invoice file for Germany, with Leitweg-ID support.
Learn moreMulti-company
Several companies from one account; data kept apart, users and storage shared if you wish.
Learn moreData import
Customer, supplier, product and user lists are imported from an Excel or CSV file.
Learn moreTry it with your own data
All modules are open for 14 days. No card details are requested and nothing needs to be installed.
14 days free, no card required