Your contact information
Natuvion Cloud Platform (NCP)
The Natuvion Cloud Platform (NCP) is the central, web-based interface through which you access the web-based products and features of the Natuvion Data Conversion Suite (DCS). It consolidates login, user management, and authorization management in one place, thereby creating a unified foundation for working with our products. In this section, you’ll learn how we organize information security within the platform.
Scope and Operation
-
What is the scope of information security and data protection for the NCP?
-
What certifications apply to the NCP?
The NCP is included within the scope of the ISO 27001 certification.
-
In which operating models is NCP available?
The NCP is a web-based platform through which users can access Natuvion products. It provides core functions for login, user management, and access control.
Hosting: Natuvion operates the NCP on established cloud platforms, typically within the EU. Depending on the agreed-upon requirements, other hosting regions may also be used.
On-premises: The NCP can be operated in an environment provided by the customer. This may also include a cloud environment selected by the customer.
The operating models differ primarily in terms of the location of operations, responsibilities for the underlying infrastructure, and, where applicable, the available scope of functionality. -
How are responsibilities divided between Natuvion and the customer?
Natuvion and the customer share responsibilities in accordance with the respective operating model. Responsibility for the data processed by the customer generally remains with the customer.
Hosting: Natuvion is responsible for operating the platform and the underlying infrastructure, as well as for providing updates. Basic access control is provided by Natuvion. The management of access rights within the respective tenant may be delegated to the customer.
On-Premises: Natuvion provides the software and corresponding updates. Operation, infrastructure, data backup, and monitoring of the environment are the responsibility of the customer.
-
What does the customer need to keep in mind to ensure safe operation?
Hosting: The customer ensures the secure use of the platform within its area of responsibility. This includes, in particular, the appropriate assignment and configuration of roles and permissions, as well as compliance with the agreed-upon security requirements.
On-Premises: The customer is also responsible for the secure deployment and operation of its own environment. Additional responsibilities are determined by the agreed-upon operating model.
Data Protection and Data Processing
-
What personal data does NCP process?
In particular, the NCP processes personal data necessary for the use and administration of the platform, such as user and account data. Additional personal data may arise from the Natuvion products used via the NCP and is described in more detail there.
Hosting: The processing of personal data is carried out in accordance with the agreed-upon data protection regulations.
On-Premises: Processing takes place in the environment specified by the customer.
-
Where is data processed and stored?
Hosting: By default,data is processed and stored by established cloud service providers within the EU. Depending on the agreed-upon hosting requirements, other regions may also be used.
On-premises: Processing and storage take place in the environment specified by the customer.
-
What operational, log, and support data does Natuvion process?
Hosting: Natuvion processes operational, log, and usage data to the extent necessary for the secure and reliable operation of the platform and to ensure the traceability of relevant processes.
On-Premises: Operational and diagnostic data from the customer’s environment is provided to Natuvion only within the scope of the agreed-upon support services and to the extent necessary. -
How are data from different customers kept separate from one another?
Customer data is segregated by client and protected through appropriate technical and organizational measures. The effectiveness of client segregation is regularly reviewed as part of security and operational processes.
-
Are AI features used, and what happens to customer data in the process?
Optional AI-powered features are available in the NCP. The platform’s core features are also available without the use of AI.
Hosting: AI features are provided via established cloud platforms within the EU. Customer data is not used to train the underlying AI models.
On-Premises: The customer decides whether and which AI models are integrated into their environment.
Retention and Deletion
-
What happens to the data when the contract ends?
Hosting: Upon termination of the contract, the data stored in the environment operated by Natuvion will be deleted in accordance with the contractual agreements. For data processed in connection with other Natuvion products, the information provided on the respective product pages applies in addition.
On-Premises: The data remains in the environment operated by the customer and is therefore the customer’s responsibility.
Identity and Access Management
-
How do users log in?
The NCP can be integrated with the customer’s central user management system. This allows the security features and policies for authentication and access control established there to also be used for accessing the NCP.
Alternatively, user accounts can be managed directly within the NCP and protected by additional security mechanisms such as multi-factor authentication. -
How are roles and permissions managed?
Roles and permissions are managed according to a defined permissions framework. Permissions are granted as needed and are based on the principle of the necessary access rights. The customer is responsible for configuring and regularly reviewing these permissions.
-
How does Natuvion protect administrative and support access?
Hosting: Administrative and support-related access by Natuvion is limited to authorized users and designated access channels, is appropriately secured, and is traceable.
On-Premises: Access by Natuvion occurs only within the scope of the agreed-upon support services and to the extent permitted or authorized by the customer.
Secure Development and Operation
-
How are vulnerabilities and security updates handled?
Vulnerabilities and security risks are reviewed, assessed, and addressed according to their relevance as part of established development and security processes.
Hosting: Security updates are taken into account and applied as part of the operations managed by Natuvion.
On-Premises: The implementation of security updates is based on the agreed-upon operating model and is carried out by Natuvion or the customer. -
How are releases managed?
Releases are versioned, tested prior to delivery, and made available through a controlled release process.
Hosting: Natuvion handles the installation of new releases.
On-Premises: Depending on the agreed-upon operating model, the installation is performed by Natuvion or by the customer. -
How are security and operational events monitored?
Hosting: Natuvion monitors the environment it operates for relevant events and anomalies as part of its established operational and security processes.
On-Premises: Monitoring of the customer’s environment is generally the customer’s responsibility and is governed by the customer’s own operational and security processes.
Incident Management
-
How are security incidents handled?
Hosting: Security incidents are detected and assessed according to defined processes, handled appropriately, documented, and followed up on.
On-Premises: Security incidents in the customer’s environment are generally handled by the customer. Natuvion provides support within the scope of the agreed-upon support services. -
How are customers notified of security incidents?
Natuvion notifies affected customers of relevant security incidents in accordance with applicable legal and contractual requirements.
Business Continuity
-
How is the availability of the NCP ensured?
-
What are the procedures for data backup and recovery?
Hosting: Natuvion performs regular data backups and verifies recoverability in accordance with defined procedures. There are established emergency and recovery processes in place to resume operations.
On-Premises: Data backup and recovery are the responsibility of the customer.
Subcontractor
-
Which external service providers are relevant to the NCP?External service providers are screened against defined requirements before being contracted. Relevant suppliers and service providers are regularly monitored and evaluated as part of the supplier management process.
Hosting: Natuvion uses established cloud platforms to operate NCP, typically within the EU. Subcontractors and relevant processing locations are taken into account within the framework of contractual and data protection agreements.
On-Premises: The selection and management of service providers used by the customer are the customer’s responsibility.
Contact
Would you like to learn more? Simplyfill out the contact form, and we’ll get back to you as soon as possible.
Contact Us Now