Communication and administration

Security and data protection

Your customer list and your invoices are the most valuable data of your company. This page explains where the data is kept, who can access what, and what can be restored when something goes wrong.

  • Servers in Germany
  • Nightly backups
  • Two-factor authentication

Data location and backups

The application and the database are hosted in Germany, in the data centre in Falkenstein. All connections are encrypted (TLS 1.2 and 1.3). The database is backed up every night and the health of the backups is checked every day.

  • Daily backups are kept for 16 days, weekly backups for 8 weeks
  • Monthly backups are kept for 4 months, yearly backups for 2 years
  • Data is not deleted even if the account is suspended
  • Lists can be downloaded as Excel and CSV at any time

Account security

Passwords must have at least 10 characters and contain letters and digits; passwords that appear in known breach lists are not accepted. Two-factor authentication works with an authenticator app. When the password is changed, the sessions on other devices are closed.

  • Two-factor authentication (TOTP) and recovery codes
  • Rate limit on failed sign-in attempts
  • Changing the email address requires the current password
  • Login history: time, device and IP address
Profile page: two-factor authentication setup with QR code, key and verification code field.

Permissions and activity log

Who sees what, and who changes what? Roles are defined with view, add, edit and delete permissions for each module. Changes to records are kept for one year with the user and the time.

  • Predefined roles and roles specific to your company
  • Nobody can grant a permission they do not have themselves
  • The company owner is notified of deletions
  • An issued invoice cannot be changed afterwards
Role editing screen: modules in rows, view, add, edit and delete permissions in columns.

Separation of companies

BilgeERP is a multi-company system; every query is filtered by company and a record of one company is not shown to another. Passwords of email accounts are stored encrypted in the database, and API keys are stored only as a hash.

  • Data separation by company
  • Read or write permission and expiry for API keys
  • Customer portal links with random keys

GDPR and the Turkish data protection law (KVKK)

The privacy policy states which data is processed for which purpose. Marketing emails are sent only to people who have given consent, and every email contains an unsubscribe link.

  • Fonts and scripts are loaded from our own server
  • No third-party tracking cookies
  • Contact address for your data requests

Frequently asked questions

In which country is my data?

In Germany. The application and the database run in the data centre in Falkenstein.

What happens to my data when my subscription ends?

The account first becomes read-only: you can view and download your data but cannot enter new records. After that the account is suspended; the data is not deleted.

Is there single sign-on (SSO)?

No. You sign in with email and password, and optionally with two-factor authentication.

Who do I write to if I find a security vulnerability?

Write to us through the contact form or at the email address at the bottom of the page.

Try it with your own data

All modules are open for 14 days. No card details are requested and nothing needs to be installed.

14 days free, no card required