Processor Security Card
General overview of security measures of the aprovo.eu platform
Last updated: June 6, 2026
This document constitutes a general description of the security measures implemented by AMS SOFTWARE SP. Z O.O. (hereinafter: "Processor") within the aprovo.euplatform. This document is made available to Data Controllers (clients of the platform) to facilitate the fulfillment of their obligation to verify the processor pursuant to Article 28(1) of the GDPR.
A detailed description of the technologies used and the security architecture is available upon request of the Controller at contact@aprovo.eu.
1. Data Processor Details
| Name | AMS SOFTWARE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ |
| Registered office | ul. Józefa Wajzera 19/22, 41-808 Zabrze, Poland |
| KRS | 0001242326 |
| NIP (Tax ID) | 6482836354 |
| REGON | 544821193 |
| Data Protection Contact | contact@aprovo.eu |
| DPO | Not designated (as of 06.2026) |
2. Data Processing Location
- All personal data is processed exclusively within the European Economic Area (EEA), in the Frankfurt, Germany region.
- Database: managed PostgreSQL service — Frankfurt, DE region.
- File storage (PDF documents, photos): Amazon S3 — eu-central-1 region, Frankfurt, DE.
- Application hosting: cloud platform — Frankfurt, DE region.
3. Data Encryption
- Encryption at rest: Highly sensitive personal data (PESEL/national ID number, email, phone number, document number) is encrypted using an AES-256 class algorithm at the application layer before being written to the database.
- Encryption in transit: All connections are secured using TLS 1.2+ protocol (HTTPS).
- Pseudonymization: Searching encrypted data is performed using a blind index (salted hash), without requiring decryption.
- Document integrity: Each signed document features a cryptographic hash enabling verification of whether it has been modified after signing.
4. Access Control
- Authentication via sessions protected against XSS attacks (HttpOnly cookies).
- Optional two-factor authentication (2FA).
- Role-based access control system following the principle of least privilege (OWNER / MANAGER / OPERATOR).
- Additional security PIN on shared devices (tablets in practice/treatment rooms).
- Strong password policy (minimum 10 characters, salted hashing).
5. Data Isolation (Multi-tenancy)
- Data for each salon/clinic is logically isolated at the database level.
- Every database query is automatically restricted to the data of the given tenant.
- Multi-level validation prevents unauthorized access to other tenants' data.
6. Application Security
- Protection against CSRF, XSS, and HTML injection attacks.
- HTTP security headers (CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy).
- Rate limiting.
- Sanitization of all input data.
7. Business Continuity and Backups
- Automated database backups with Point-in-Time Recovery (PITR) mechanism.
- Continuous system availability and performance monitoring.
- Error tracking without exposing PII (Personally Identifiable Information).
8. Testing and Audits
- Automated security and functional tests executed on every deployment (CI/CD).
- Event log (Audit Trail) recording all significant operations on personal data.
- Automated dependency audit for known vulnerabilities.
9. Organizational Measures
- Written Non-Disclosure Agreements (NDAs) with all individuals having access to data.
- Named, written authorizations to process personal data.
- Record of Categories of Processing Activities (Article 30(2) of the GDPR).
- Training in personal data protection.
10. Sub-processors
The current list of approved sub-processors is available inAnnex No. 2 to the Data Processing Agreement.
All personal data processed by sub-processors physically remains within the EEA (Frankfurt, Germany).
11. Legal Documentation
This card is for informational purposes only and does not constitute an offer within the meaning of the Civil Code. The binding specification of security measures is contained in the Data Processing Agreement (DPA) and is available upon request at contact@aprovo.eu.