The security, availability and reliability of Postcode.eu's services are essential to business operations. Therefore, appropriate technical and organisational measures are applied to protect APIs, systems and data against unauthorized access, loss, misuse and disruption.

This page provides an overview of the approach to information security, privacy, continuity and compliance.

Technical and organisational measures (TOMs)

Postcode.eu applies technical and organisational measures to protect the confidentiality, integrity and availability of systems, services and data. The measures are tailored to the risks and criticality of the relevant systems and processes.

Access security

Personal, password-protected accounts are the standard. Shared accounts are avoided and any exceptions are assessed and secured with additional measures.

Access to systems and information is granted based on role, responsibility and necessity. The principle of least privilege is applied.

Administrator rights are limited to authorized employees and are reviewed periodically. Multi-factor authentication is applied for administrative access where technically possible. External access to internal and production environments takes place via secure connections.

Network and infrastructure security

Production environments are only accessible to authorized persons. Network security, network segmentation and restrictions on external access are applied to prevent unauthorized access.

Appropriate measures are taken for publicly accessible services against misuse, unwanted traffic and overload.

Encryption

Critical data is encrypted during transport. For secure connections, a minimum of TLS 1.2 is used, with TLS 1.3 preferred when supported.

Backups and storage media on work devices are encrypted. Passwords, API credentials and other confidential data are stored securely and are only accessible to authorized persons.

Logging and monitoring

User and administrator activities on production environments are centrally logged. Log sources are time-synchronized so that events can be reliably investigated.

Critical warnings are assessed immediately. After relevant changes and updates, logs are checked for anomalies and unexpected behavior.

Vulnerabilities and security updates

Technical vulnerabilities are assessed as part of regular system management. Identified vulnerabilities are reported to the responsible system owner or the Security Officer and followed up based on risk.

Systems are updated monthly as a rule. Critical security updates are applied as quickly as reasonably possible. Installation of software on operational systems is limited to authorized employees.

Change management

Changes to systems and services are assessed for possible consequences for information security and availability.

Critical changes are tested in advance in a separate test or staging environment before implementation in the production environment. When a planned change may have noticeable consequences for customers, the customers involved are informed in a timely manner.

Backup and recovery

Critical data is backed up every hour. Backups are stored encrypted.

The ability to restore data from backups is tested and recorded at least annually. Production systems are set up redundantly where possible to limit the consequences of failure of an individual component.

Employees and company assets

Employees are bound by confidentiality obligations and are informed about responsibilities in the field of information security and privacy.

Fixed procedures apply for onboarding, job changes and offboarding. Access rights and company assets are adjusted or revoked when they are no longer necessary.

Storage media are appropriately wiped or destroyed prior to reuse or disposal.

Incidents and continuity

Postcode.eu has procedures for recognising, reporting, registering, assessing, escalating and resolving information security and privacy incidents.

Incidents are classified based on impact and urgency. After serious incidents, the cause is investigated and corrective and preventive measures are taken where necessary.

When an incident affects service delivery, personal data or contractual obligations, customers involved are informed when legally or contractually required.

Critical processes, systems and suppliers are assessed for their importance to the continuity of service delivery. Based on this, appropriate recovery and continuity measures are established.

The current availability of the services can be consulted via our status page.

Privacy and processing of personal data

Postcode.eu as controller

When using the address APIs, the customer acts as the controller and Postcode.eu as the processor. Postcode.eu processes personal data solely on behalf of the customer and for the performance of the agreed address services.

The processing consists of validating and, where applicable, supplementing address data provided by the customer or an end user of the customer via the API. The following personal data may be processed:

  • street name;
  • house number;
  • postal code;
  • city name.

No special categories of personal data are requested for this service.

Postcode.eu applies appropriate technical and organisational measures to protect the processed personal data. These measures include, among others:

  • encryption during transport;
  • access security;
  • logging and monitoring;
  • secure system and network management;
  • backup and recovery measures;
  • limitation of the retention period;
  • incident and data breach procedures.

An overview of the main technical and organisational measures is included on this page. Additional information may be made available upon request, depending on the nature of the request and the confidentiality of the information.

Processor agreement

The processor agreement is included in article 5 of the Terms and Conditions. This includes agreements on:

  • the nature and purpose of the processing;
  • the categories of personal data;
  • information security;
  • support for data breaches;
  • support for data subject requests;
  • engagement of sub-processors;
  • audits by customers;
  • international transfers;
  • return or deletion of personal data after termination of the service.

When a data breach is discovered that relates to personal data processed for a customer, the customer is informed as soon as possible and no later than 48 hours after discovery.

Sub-processors and international transfers

Sub-processors may be engaged for parts of the service. Written agreements are made with these parties regarding data protection and information security.

Customers are informed about engaged sub-processors and planned additions or replacements, in accordance with the Terms and Conditions.

When personal data is processed outside the European Economic Area, appropriate transfer mechanisms are applied, such as Standard Contractual Clauses or the EU-U.S. Data Privacy Framework.

Postcode.eu as processing controller

For personal data that Postcode.eu processes for its own business operations, such as contact, account, administration, support and billing data, Postcode.eu itself acts as the controller.

More information about these processing activities, retention periods and privacy rights is included in the privacy statement.

Suppliers and sub-processors

Carefully selected suppliers are used for infrastructure and supporting services.

Suppliers relevant to information security, privacy or continuity are assessed and, where necessary, periodically evaluated. Relevant security and privacy obligations are contractually established.

When a supplier processes customer personal data on behalf of Postcode.eu, it acts as a sub-processor. Written agreements are made with sub-processors that align with the obligations from the processor agreement.

Customers are informed about engaged sub-processors and planned additions or replacements, in accordance with the Terms and Conditions.

Below is the current overview of the sub-processors involved in the delivery of the services.

Processor nameService/RoleCountry/RegionTransfer outside EEABase transfer
CrispSupportFrance (EU/EEA)Non/a (EU/EEA – no transfer outside EEA)
Proton AGEmail / calendar / documentsSwitzerlandYes (CH)Adequacy Decision CH
KadasterRecipient BAG feedbackThe NetherlandsNon/a (NL government)
LeasewebHosting / infrastructureThe NetherlandsNon/a (EU/EEA - no transfer outside EEA)
DirectVPSHosting / infrastructureThe NetherlandsNon/a (EU/EEA - no transfer outside EEA)
HetznerHosting / infrastructureGermany (EU/EEA)Non/a (EU/EEA - no transfer outside EEA)
MoneybirdPayment processingThe NetherlandsNon/a (EU/EEA - no transfer outside EEA)
StackheroHosting / infrastructureFrance (EU/EEA)Non/a (EU/EEA - no transfer outside EEA)
CloudflareHosting / infrastructure / CDNUSYes (potentially)SCC / EU-US DPF

ISO/IEC 27001

Postcode.eu has established an Information Security Management System based on ISO/IEC 27001.

The management system supports a structured approach to risk management, access security, incident management, continuity, supplier assessment and continuous improvement.

The independent certification process is currently underway.

Status: ISO/IEC 27001 certification in progress

Upon completion of the certification process, the certificate and the associated certification scope will be published.

Available documentation

This page contains information about:

  • the technical and organisational security measures;
  • the processing of personal data;
  • the engagement of suppliers and sub-processors;
  • the status of the ISO/IEC 27001 certification.

The following information is publicly available:

Additional confidential information about security measures or independent assessments may be made available upon request under confidentiality, depending on the nature of the request and the service.

Internal risk registers, full audit results, technical configurations, security logs and information about specific vulnerabilities are not shared publicly.

Security contact

For additional questions about information security, privacy or compliance, contact can be made via:

info@postcode.eu

Suspected vulnerabilities in systems or services can also be reported via this address. A report preferably contains a clear description and sufficient information to investigate the issue.

When investigating a possible vulnerability, no data from others may be viewed, modified or deleted and service delivery may not be disrupted.