Knowledge base / Data & integrations / Data security & storage

Data security & storage

Your data is stored in a hardened, audited environment, encrypted in transit, with access tightly controlled and logged.

In brief

Data sits in a Tier III or higher data centre with redundant power, climate control and 24/7 monitoring, on Microsoft SQL Server with a containerised application layer and RAID 10 storage, backed up both on-site and off-site. For South African data subjects, personal information is processed within South Africa.

Traffic to and from the platform is encrypted with HTTPS (SSL/TLS); data at rest is protected by access controls and network-level protections. Access is need-to-know and logged, and on the platform what each person sees is set by role, down to the individual measurement point (see Roles & access). Augos runs bi-annual security audits.

The full agreement, including data ownership, retention and what happens on termination, follows.

The agreement in full

Document owner: Finishing Touch Trading 516 (Pty) Ltd t/a Augos. Reproduced in full.

This section outlines the data security, storage, and management practices employed by Augos to ensure the confidentiality, integrity, and availability of customer data. By entering into this agreement, the Customer acknowledges and agrees to the following terms:

1. Data Ownership and Usage Rights

1.1 Customer Data Ownership and Limited License: The Customer retains full ownership of all data collected and stored within the Augos platform, including all measurement data, user inputs, and historical records. The Customer grants Augos a non-exclusive, worldwide, royalty-free license to use, copy, modify, distribute, and create derivative works of the data solely for the purpose of providing and improving the Augos platform and services, and only in an anonymized and aggregated format as described in Section 1.3.

1.2 Access and Control: The Customer has full access to their data during the contract period and may download or export data as needed. Augos will provide appropriate tools and support to facilitate this access.

1.3 Anonymized Data Usage: Augos reserves the right to use the data in an anonymized and aggregated form for analytical purposes, product improvements, and market research. Under no circumstances will this anonymized data include any user-identifiable information.

2. Data Storage and Security Measures

2.1 Data Storage Architecture:

  • Data is stored on dedicated servers hosted in a Tier III or higher data center, ensuring compliance with industry standards for security, availability, and operational resilience.
  • The data center infrastructure provides redundant power supply, advanced climate control, and 24/7 security monitoring to support high availability and disaster recovery.
  • The infrastructure comprises:
    • A high-performance database server running Microsoft SQL Server for secure and efficient data management.
    • A scalable, containerized application server environment, designed for high availability, load balancing, and seamless service delivery, ensuring minimal service disruption.

2.2 Redundancy and Backup Strategy:

  • All active data is stored on RAID 10 configurations, providing high availability, fault tolerance, and data redundancy.
  • SQL logging is enabled for effective recovery management and data integrity.
  • Augos employs a multi-layered backup strategy, including:
    • On-site backups stored on separate and secure storage systems within the primary environment. These backups are distributed across multiple servers to ensure data availability even in the event of a critical hardware failure.
    • Off-site cloud backups to ensure disaster recovery and data availability, even in the event of catastrophic hardware failure.

2.3 Data Security Measures:

  • All servers are protected by an enterprise-grade firewall with advanced threat protection and intrusion prevention systems.
  • Only necessary ports are open, minimizing exposure to external threats while maintaining operational functionality.
  • All web access, including user platforms, APIs, and data processing services, is secured using HTTPS with SSL/TLS encryption to protect data in transit.

3. Data Access and Termination Protocol

3.1 Access Control:

  • Access to servers, databases, and backup systems is restricted to authorized Augos staff members or staff members of the data center who require access for maintenance and operational purposes.
  • Access is granted on a need-to-know basis, with regular reviews and audits to ensure strict adherence to data security protocols.
  • All access is logged and monitored to maintain accountability and traceability.

3.2 Termination of Access:

  • Upon contract termination, the Customer’s access to the Augos platform will be immediately revoked.
  • Devices responsible for data collection may be remotely deactivated or disabled.
  • Historical data will be retained in a secure archived state to facilitate potential contract reactivation.
  • No data access or retrieval will be possible for the Customer once the contract is terminated.

4. Data Encryption

4.1 Data Protection at Rest:

  • Data stored within the database environment is protected through access controls and secure storage practices to prevent unauthorized access.
  • The database environment is secured with network-level protections, including firewall restrictions and access monitoring, to safeguard data integrity and confidentiality.
  • Only authorized personnel have access to the data storage systems, and all access is logged and audited to ensure accountability.

4.2 Encryption in Transit:

  • All data transmitted to and from the platform, including user interactions, API calls, and data processing, is encrypted using HTTPS with SSL/TLS protocols, ensuring secure data transmission.

5. Security Audits and Compliance

5.1 Firewall and Network Security:

  • All servers are protected by an enterprise-grade firewall with advanced threat protection and intrusion prevention systems.
  • Only necessary ports are open, minimizing exposure to external threats while maintaining operational functionality.
  • All web access, including user platforms, APIs, and data processing services, is secured using HTTPS with SSL/TLS encryption to protect data in transit.

5.2 Security Audits and Reviews:

  • Augos conducts bi-annual security audits to evaluate and enhance security measures, including:
    • Internal security reviews to assess data access controls and infrastructure security.
    • Vulnerability assessments to identify and mitigate potential risks.
    • Compliance checks to ensure adherence to industry security standards and data protection regulations.

6. Data Retention Policy

6.1 Retention and Storage Duration:

  • All data collected during the contract period is retained for a minimum of 5 years during the active contract period.
  • Historical data is securely archived on dedicated storage systems to ensure long-term accessibility for the duration of the retention period.
  • After the minimum retention period, Augos reserves the right to delete or permanently archive data that is no longer active or required for operational purposes.

6.2 Data Deletion and Disposal:

  • Upon contract termination, all access to the data is revoked as outlined in Section 3.2.
  • Data will be retained in an archived state for a minimum of 5 years to facilitate potential contract reactivation.
  • After the retention period, Augos reserves the right to permanently delete historical records that are no longer required, ensuring responsible data management practices.

7. Compliance and Legal Obligations

7.1 Compliance with Data Protection Laws:

  • Augos complies with relevant data protection regulations to ensure the safe handling and storage of customer data.
  • The anonymization of data for analytical purposes is conducted in compliance with applicable privacy laws.

7.2 Customer Responsibilities:

  • The Customer is responsible for ensuring that any data collected and processed through the Augos platform complies with their internal policies and relevant legal requirements.

8. Amendments and Updates

Augos reserves the right to amend this Data Security and Storage Agreement as necessary to adapt to evolving security standards, technological advancements, or legal requirements. Customers will be notified of any significant changes to this policy.

9. Acceptance and Agreement

By signing this agreement, the Customer acknowledges that they have read, understood, and agreed to the terms and conditions outlined in this Data Security and Storage Agreement.