Security & Compliance

This page describes in detail the technical and organizational measures implemented by Iopole to protect personal data and guarantee the security of its customers' information.

As part of its secure transmission of electronic invoices, Iopole has taken security measures at various levels.

SoA

ISO/IEC 27001 Statement of Applicability

ISO 27001

IOPOLE's ISO 27001 Certificate

Certifications

ISO27001GDPRPeppol Access Point Certified ProviderPlateforme Agréée

Our commitment to service quality

At Iopole, we are committed to providing a reliable, high-performance and responsive service. Our SLA (Service Level Agreement) guarantees our customers high availability and rapid response in the event of an incident.

Maximum availability

We guarantee an availability of over 99.9% for sending and receiving invoices and documents according to the plan you subscribed.

Reactive & Expert Support

Our support team is available 24/7 via our ticketing platform and responds in French and English. We guarantee fast response times depending on the severity of the incident.

Safety & Compliance

Our services meet the highest standards of electronic invoicing and regulatory compliance.

At Iopole, we place reliability and customer satisfaction at the heart of our commitments.

Measures we’ve put in place

Customer data

Redundancy of its servers in separate geographical zones.

Regular backups of all the data you entrust to us, including unalterable archives of these backups.

A particular focus on security, both in terms of production infrastructure and workstations, development methods and in-house tools and software.

All security measures are implemented and strictly controlled as part of its ISO 27001 certification. These measures include strict access control, encryption of all communications on internal and external networks, systematic encryption of secret information and customer data at rest, and regular security audits and tests by external service providers.

Vulnerability management

Vulnerability management is based on a dedicated policy for classifying and historizing vulnerabilities, with weekly updates of workstations. Dependencies are analyzed via automated scans, blocking insecure deployments. A weekly security watch is performed to detect new vulnerabilities.

Privacy and personally identifiable information

This text sets out measures for the protection of personally identifiable information, including data collection, storage and management.

  • The collection of PII is limited to essential business needs and requires a legal basis for sensitive data.
  • PII is stored on secure systems with access restricted according to the principle of least privilege.
  • In the event of a data breach, a notification procedure is put in place and employees are trained in the protection of PII.
  • PII is kept only for as long as necessary, and securely deleted after this period.

Relations with subcontractors

Iopole imposes strict security requirements on its subcontractors, including up-to-date ISO 27001 certification**, and annually assesses the criticality of suppliers according to their dependence and access to the information system. Each subcontractor is required to comply with personal data protection standards by means of a subcontracting agreement.

Our data protection commitments

Why choose IOPOLE?

Total compliance

We rigorously apply our Data Protection Addendum (DPA) to all our customers, regardless of the service they use. In case of conflict with other contractual conditions, our DPA always prevails.

Privacy

We implement advanced technical and organizational measures to protect your data against unauthorized access or unlawful processing. Your information is treated confidentially and used only for the purposes specified in our contract.

Transparency and control

You remain in control of your data. We inform you immediately in the event of a data breach and assist you in exercising your rights in accordance with current regulations, such as the RGPD.

Ongoing commitment

We will never sell or share your personal data. All data is processed exclusively within the framework of our business relationship and for the purposes specified in our contract.

Sub-processors involved in Iopole products

SUB-PROCESSORPROCESSING ACTIVITYDATA RESIDENCYINTERNATIONAL TRANSFER MECHANISM
Cloud TempleHosting of the Accredited Platform (PA) infrastructure on a SecNumCloud-certified sovereign cloud (high-availability architecture, 3 regions)FranceData hosted in France
OVHCloudResidual hosting of application services currently being migrated to Cloud TempleFranceData hosted within the EEA
NamirialIdentity verification and personal data processing within the customer onboarding moduleEUData hosted within the EEA
XeliansLegally admissible electronic archivingEUData hosted within the EEA
MailJetTransactional notification delivery (alerts and partner notifications)EUData hosted within the EEA

Other Sub-processors involved in Iopole's operations

SUB-PROCESSORPROCESSING ACTIVITYDATA RESIDENCYINTERNATIONAL TRANSFER MECHANISM
Microsoft (Microsoft 365)Business email, collaboration, and internal productivityEU (EU Data Boundary)Data hosted within the EEA
AtlassianProject management and internal collaborationEUData hosted within the EEA
Atlassian (Jira)Partner support ticket management (may contain references to customer data)EUData hosted within the EEA
HubSpotCRM, marketing automation, and prospect data collection via formsGermanyData hosted within the EEA
YousignElectronic signature for contractual documentsEUData hosted within the EEA
LeexiTranscription and analysis of sales call recordingsBelgiumData hosted within the EEA
Google Analytics (GA4)Website analytics (truncated IP addresses, pseudonymized data)EU (with transfers to the US)Standard Contractual Clauses (SCCs)
Google Tag ManagerTag management for analytics and advertisingEU (with transfers to the US)Standard Contractual Clauses (SCCs)
Google AdsAdvertising conversion trackingEU (with transfers to the US)Standard Contractual Clauses (SCCs)
LinkedIn AdsAdvertising targeting and conversion tracking (LinkedIn Insight Tag)EU (with transfers to the US)Standard Contractual Clauses (SCCs)

FAQ

Trust Center

Yes.

Why trust us?

Expertise and Reliability: With years of experience in managing sensitive data, we have developed robust processes to guarantee the security and integrity of your information.

Regulatory compliance : We comply with all applicable data protection laws and regulations, including the RGPD and CCPA, to ensure that your rights are always protected.

Regular Audits : We carry out regular internal audits to verify the effectiveness of our security measures, and are committed to correcting any weaknesses identified.

When you choose IOPOLE, you're choosing a trusted partner who places the protection of your data at the heart of its priorities. Join us and discover how we can help you secure your information while optimizing your operations.