Security and privacy
Privacy and security are not an add-on: they are the foundation of how Vytal stores your space's and your members' data.
“We treat each organization's data as if it were our own. No fine print, no certifications we don't have yet.”
Four principles
GDPR by design
Recorded consents, right to be forgotten and each organization's data isolated from the rest, from day one.
Organization isolation is enforced on the server, not just on screen: every request is validated against the space it belongs to.
EU hosting
Data in European datacenters, encrypted in transit (SSL/TLS) and at rest.
The network layer and the database live in the European Union, so your members' data never leaves the right regulatory space.
Backups
Automatic backups with recovery, and export of your data whenever you want: it's yours.
You can take your data with you at any time. No lock-in contracts, no lock-in, no hostages.
Role-based access
Owner, coach and athlete see only what they should. Destructive actions stay reserved for admins.
Each role has a clear read and write boundary, so a mistake doesn't turn into an incident.
What we don't claim yet
We don't claim certifications we don't have yet (no fake ISO or SOC) and we don't invent metrics. Certified fiscal issuing is in preparation, through a certified partner integration: always check with your local accountant.
Legal documents