Built and operated from the French Alps. Every prospect record, email, and reply stays in the EU — under GDPR, with the legal, technical, and organizational controls your security team asks about on day one.
All prospect records, generated emails, replies, and engagement events live on EU-region infrastructure (Neon Postgres in Frankfurt). No replicas outside the EU. No backhaul to U.S. data centers.
Lawful basis for every processing activity, opt-outs honoured within 24 hours, DPA available on request, and a published sub-processor register.
TLS 1.2+ in transit (HTTPS-only, HSTS preload). AES-256 at rest on the database volume. TLS for in-cluster service traffic.
Least-privilege RBAC, SSO available on the Scale tier, MFA required for every Lanceva staff member, and an audit log of every login and admin action.
Our controls are mapped to SOC 2 and we are working toward a Type 1 report; we do not currently claim certification.
Yes, EU-only. Database in Frankfurt. Application servers in Frankfurt and Paris. No copies leave the EU.
Legitimate interest under Art. 6(1)(f) for B2B outreach; consent for any marketing-class activity. DPA available on request; we publish a sub-processor register.
Our controls are mapped to SOC 2 Type 1 and we are actively working toward an audit report. We are not yet certified — we don’t claim to be.
Account data is deleted within 30 days per our privacy policy; we can provide a deletion certificate on request.
Only authorized on-call engineers via a short-lived, audited break-glass workflow. MFA required; sessions are logged.
Outbound mail goes through the Polsia email proxy (EU-resident). We do not relay through U.S.-based ESPs.