Transparency about how we protect your data. No marketing fluff, just facts about our security practices.
security@elkqr.comFull implementation of EU data protection requirements
Implemented in CodeSecurity controls following SOC 2 Trust Service Criteria
Controls ImplementedAll data stored in Amsterdam, Netherlands (EU)
DigitalOcean AMS3Note: We have implemented SOC 2 security controls but have not yet undergone formal SOC 2 Type 2 audit.
These are the actual security measures implemented in our codebase, not marketing promises.
All sensitive data encrypted at rest
All connections use HTTPS
Each workspace has unique encryption key
30-day retention with AES encryption
DDoS protection and edge caching
Isolated storage with daily backups
TOTP-based 2FA for all accounts
Industry-standard password security
24-hour expiration, secure cookies
Owner, Editor, Viewer permissions
Scoped permissions per API key
60-240 req/min based on plan
Admin access limited, reviewed under least-privilege
Full JSON export of all your data
Complete account deletion
Clear opt-in for marketing
Automated user notification system
GDPR-compliant cookie banner
Only collect what's necessary
Tamper-proof logging with SHA-256
Full audit trail for compliance
Who did what, when, from where
URLhaus threat intelligence integration
Failed login detection
Old/new value logging for edits
Third-party services that process data on our behalf
Cloud VPS Servers, Spaces (Backups)
CDN, DDoS Protection, R2 File Storage
Transactional Email Delivery
Payment Processing & Billing
Malware URL Detection
QR Scan Location Analytics (visitor consent managed via workspace GDPR settings)
Custom Domain SSL Certificates
Error Tracking & Analytics
All data is stored in the European Union. Your database is hosted in DigitalOcean's Amsterdam (AMS3) data center, and your files (logos, PDFs, images) are stored in Cloudflare R2 (EU).
Yes. All data is encrypted at rest using AES-256 encryption with PBKDF2 key derivation. Data in transit uses TLS 1.2+. Each workspace has its own unique encryption key.
We follow industry-standard security best practices and implement SOC 2 aligned security controls at the code level to protect your data.
Yes. Under GDPR Articles 17 and 20, you can export all your data in JSON format or request complete account deletion. Both options are available in your account settings.
Yes. DPA is available for our monthly and annual subscribers. Contact hello@elkqr.com for details.
Please email security@elkqr.com with details of the vulnerability. We take all reports seriously and will respond within 48 hours. We welcome responsible security researchers.