Security and continuity
This page answers, in writing, the questions anyone asks before handing their clients’ data to a supplier. It is not a certification: these are the facts of the infrastructure, verifiable and current as of this date.
1. Where the data lives
- Production servers: United Kingdom (Erith datacentre, OVH infrastructure). The UK is covered by the European Commission’s adequacy decision, renewed until 27 December 2031: data that stays there needs no additional safeguard.
- Off-site backups: United States (California).
- System support: United States and India, provided by the hosting supplier’s staff, bound by confidentiality obligations and limited to what technical support requires.
The hosting supplier is a US company. Transfers to the United States and India are covered by Standard Contractual Clauses (EU Decision 2021/914, Modules 2 and 3) concluded directly with it, supplemented by a transfer impact assessment.
2. Encryption
- HTTPS enforced on every endpoint (TLS 1.2 or higher), with HSTS enabled and a strict connection between the CDN and the origin server.
- OAuth tokens (Google Search Console, Analytics, WordPress, Drive), e-invoicing tokens and two-factor authentication secrets are encrypted at rest with AES-128 (Fernet).
- Passwords are stored only as hashes (Argon2/PBKDF2) — never in plain text, never recoverable.
3. Backups and retention
- Daily backups of the database, filesystem and mailboxes, with at least 10-day retention, to a destination outside the production server. The actual window depends on the backup storage purchased: as of the date of this page, 30 days are restorable.
- A full database dump before every release to production.
- Maximum theoretical data loss in the event of a serious failure (RPO): 24 hours.
4. Who can access the data
- Miraqo is a sole proprietorship: processing is carried out by the owner. Any collaborators are appointed in writing and bound by confidentiality.
- Administrative access is restricted and logged.
- Data is separated by organisation and by project: every request is scoped to the organisation of the user making it.
- Public share views require an unguessable token, with an expiry date and an optional password.
- Two-factor authentication (TOTP) is available to every user; API tokens can be revoked at any time.
5. What happens in the event of an incident
If a personal data breach affects a client’s data, we notify them without undue delay and in any case within 48 hours of becoming aware of it, at the account administrator’s address, stating: the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed.
Where the client is the controller, notifying the supervisory authority and the data subjects remains their obligation: our job is to put them in a position to meet it in time.
6. Recovery and continuity
- Documented recovery procedure, with backups of the entire account (database, filesystem, mail).
- A staging environment separate from production, where every release is verified before going live.
- An automated test suite runs before every release; the most sensitive features stay behind feature flags.
We do not publish a guaranteed recovery time (RTO): restoring a full account also depends on the hosting supplier’s own timings, and we would rather not state a number we have not measured under real conditions.
7. What we do not do
- We do not sell, transfer or share data with third parties for profiling, marketing or data brokering.
- We do not use client data — including data from Google Search Console and Analytics — to train artificial intelligence models, whether ours or third parties’.
- We neither request nor process special categories of data (Article 9 GDPR).
8. Documents available on request
- Data Processing Agreement (Article 28 GDPR) ready for signature, with annexes covering the data processed, the technical and organisational measures and the list of sub-processors.
- Current list of sub-processors, with location, service and transfer basis.
- Standard Contractual Clauses concluded with the hosting supplier.
- Record of processing activities under Article 30 GDPR, available on reasoned request.
To obtain them, or for any question about this page, write to [email protected]. We reply within 30 days, usually much sooner.