Security & Data Protection

Updated 23 September 2026. Security · Subprocessors · Data Processing Agreement · Privacy Policy

Studios trust Naayya with their business and their customers’ data. This page summarises how we protect it.

Data hosting in the EU

Your database and uploaded files are hosted in Frankfurt, Germany. Backups are stored separately, within the EU.

Encryption

Data is encrypted in transit with TLS and at rest, including backups.

Access control

Access to customer data is limited to authorised staff who need it for their work, and multi-factor authentication is required on our systems.

Backups and recovery

Your data is backed up daily to separate, encrypted storage in the EU, and we test restoration. Retention periods are available to business customers under the DPA.

Payments

Card payments are processed by Stripe, a PCI DSS Level 1 certified provider. Card details are never stored on Naayya servers.

Secure development

Changes are reviewed and tested before release, with automated checks for exposed secrets and vulnerable dependencies.

Incident response

We maintain a documented incident response plan. If a personal-data breach affects your business, we notify you without undue delay.

Policies and assessments

Naayya maintains a written Information Security Policy and Incident Response Plan. We take part in the SME cybersecurity programme of Luxembourg’s National Cybersecurity Competence Center (NC3), including its CyberCheck assessment.

Your part in security

Businesses control who on their team has access, and should give each person their own login and keep their devices secure. Card details entered in Stripe’s payment fields are protected by Stripe.

Reporting a vulnerability

If you believe you have found a security issue, email support@naayya.com with the subject “Security” and enough detail to reproduce it. We acknowledge reports within three business days. Please do not access other people’s data, disrupt the service or disclose the issue publicly before we have had a reasonable chance to fix it. We will not take legal action over good-faith research that follows these rules.

See our subprocessor list for the providers we use. Our Data Processing Agreement and your service agreement are the binding terms; this page is a summary.