Security & Compliance
This page describes in detail the technical and organizational measures implemented by Iopole to protect personal data and guarantee the security of its customers' information.
As part of its secure transmission of electronic invoices, Iopole has taken security measures at various levels.

Certifications
Our commitment to service quality
At Iopole, we are committed to providing a reliable, high-performance and responsive service. Our SLA (Service Level Agreement) guarantees our customers high availability and rapid response in the event of an incident.
Maximum availability
We guarantee an availability of over 99.9% for sending and receiving invoices and documents according to the plan you subscribed.
Reactive & Expert Support
Our support team is available 24/7 via our ticketing platform and responds in French and English. We guarantee fast response times depending on the severity of the incident.
Safety & Compliance
Our services meet the highest standards of electronic invoicing and regulatory compliance.
At Iopole, we place reliability and customer satisfaction at the heart of our commitments.
Measures we’ve put in place
Customer data
Redundancy of its servers in separate geographical zones.
Regular backups of all the data you entrust to us, including unalterable archives of these backups.
A particular focus on security, both in terms of production infrastructure and workstations, development methods and in-house tools and software.
All security measures are implemented and strictly controlled as part of its ISO 27001 certification. These measures include strict access control, encryption of all communications on internal and external networks, systematic encryption of secret information and customer data at rest, and regular security audits and tests by external service providers.
Vulnerability management
Vulnerability management is based on a dedicated policy for classifying and historizing vulnerabilities, with weekly updates of workstations. Dependencies are analyzed via automated scans, blocking insecure deployments. A weekly security watch is performed to detect new vulnerabilities.
Privacy and personally identifiable information
This text sets out measures for the protection of personally identifiable information, including data collection, storage and management.
- The collection of PII is limited to essential business needs and requires a legal basis for sensitive data.
- PII is stored on secure systems with access restricted according to the principle of least privilege.
- In the event of a data breach, a notification procedure is put in place and employees are trained in the protection of PII.
- PII is kept only for as long as necessary, and securely deleted after this period.
Relations with subcontractors
Iopole imposes strict security requirements on its subcontractors, including up-to-date ISO 27001 certification**, and annually assesses the criticality of suppliers according to their dependence and access to the information system. Each subcontractor is required to comply with personal data protection standards by means of a subcontracting agreement.
Our data protection commitments
Why choose IOPOLE?
Total compliance
We rigorously apply our Data Protection Addendum (DPA) to all our customers, regardless of the service they use. In case of conflict with other contractual conditions, our DPA always prevails.
Privacy
We implement advanced technical and organizational measures to protect your data against unauthorized access or unlawful processing. Your information is treated confidentially and used only for the purposes specified in our contract.
Transparency and control
You remain in control of your data. We inform you immediately in the event of a data breach and assist you in exercising your rights in accordance with current regulations, such as the RGPD.
Ongoing commitment
We will never sell or share your personal data. All data is processed exclusively within the framework of our business relationship and for the purposes specified in our contract.
Sub-processors involved in Iopole products
| SUB-PROCESSOR | PROCESSING ACTIVITY | DATA RESIDENCY | INTERNATIONAL TRANSFER MECHANISM |
|---|---|---|---|
| Cloud Temple | Hosting of the Accredited Platform (PA) infrastructure on a SecNumCloud-certified sovereign cloud (high-availability architecture, 3 regions) | France | Data hosted in France |
| OVHCloud | Residual hosting of application services currently being migrated to Cloud Temple | France | Data hosted within the EEA |
| Namirial | Identity verification and personal data processing within the customer onboarding module | EU | Data hosted within the EEA |
| Xelians | Legally admissible electronic archiving | EU | Data hosted within the EEA |
| MailJet | Transactional notification delivery (alerts and partner notifications) | EU | Data hosted within the EEA |
Other Sub-processors involved in Iopole's operations
| SUB-PROCESSOR | PROCESSING ACTIVITY | DATA RESIDENCY | INTERNATIONAL TRANSFER MECHANISM |
|---|---|---|---|
| Microsoft (Microsoft 365) | Business email, collaboration, and internal productivity | EU (EU Data Boundary) | Data hosted within the EEA |
| Atlassian | Project management and internal collaboration | EU | Data hosted within the EEA |
| Atlassian (Jira) | Partner support ticket management (may contain references to customer data) | EU | Data hosted within the EEA |
| HubSpot | CRM, marketing automation, and prospect data collection via forms | Germany | Data hosted within the EEA |
| Yousign | Electronic signature for contractual documents | EU | Data hosted within the EEA |
| Leexi | Transcription and analysis of sales call recordings | Belgium | Data hosted within the EEA |
| Google Analytics (GA4) | Website analytics (truncated IP addresses, pseudonymized data) | EU (with transfers to the US) | Standard Contractual Clauses (SCCs) |
| Google Tag Manager | Tag management for analytics and advertising | EU (with transfers to the US) | Standard Contractual Clauses (SCCs) |
| Google Ads | Advertising conversion tracking | EU (with transfers to the US) | Standard Contractual Clauses (SCCs) |
| LinkedIn Ads | Advertising targeting and conversion tracking (LinkedIn Insight Tag) | EU (with transfers to the US) | Standard Contractual Clauses (SCCs) |
FAQ
Trust Center
Yes.
Why trust us?
Expertise and Reliability: With years of experience in managing sensitive data, we have developed robust processes to guarantee the security and integrity of your information.
Regulatory compliance : We comply with all applicable data protection laws and regulations, including the RGPD and CCPA, to ensure that your rights are always protected.
Regular Audits : We carry out regular internal audits to verify the effectiveness of our security measures, and are committed to correcting any weaknesses identified.
When you choose IOPOLE, you're choosing a trusted partner who places the protection of your data at the heart of its priorities. Join us and discover how we can help you secure your information while optimizing your operations.



