Lease a Bike guarantees the protection of personal data and compliance with the GDPR through a strict security architecture, encryption, strong access controls, and regular independent audits.
Security and data protection measures:
- Security and Privacy by Design: All new features, processes, and supplier collaborations undergo a mandatory security and data protection review before the collection or processing of personal data begins.
- Strong access controls: Access to personal data is governed by the principles of least privilege (least privilege) and need to know (need to know). The platform also applies multifactor authentication (MFA) and strict password requirements.
- Data encryption: All personal data on the platform is encrypted both at rest (at rest) and in transit (in transit) using modern security protocols.
- Supplier management and data processing agreements: When working with external suppliers, data processing agreements are established. Suppliers are evaluated and audited annually based on SOC 2 reports or equivalent security certifications.
- Independent audit (KPMG & SOC 2): An independent IT audit firm (KPMG) audits the platform’s security and data protection measures. The audit results in a SOC 2 attestation report confirming the operational effectiveness of the measures.
- Annual risk analysis and legislative review: Annual IT risk analyses and Business Impact Assessments (BIA) are conducted to ensure that privacy and data protection measures continuously comply with applicable data protection legislation.