ISO 27001, BSI C5, and GDPR Article 28 compliant. All certifications, policies, and data processing agreements available for review.
Active compliance status as of February 2026
Information Security Management System (ISMS) certification. Covers risk management, security controls, incident response, and continuous improvement.
Valid Until
2027-03-15
Scope
Hetzner Cloud infrastructure (Falkenstein, Germany)
German Federal Office for Information Security (BSI) Cloud Computing Compliance Criteria Catalogue. Covers 114 cloud-specific security requirements.
Valid Until
2027-06-30
Scope
Kubernetes orchestration layer, WordPress hosting platform
Data Processing Agreement (DPA) compliance. We process customer data as a processor on behalf of controllers.
Valid Until
Ongoing
Scope
All WordPress sites, email infrastructure, databases
All customer data stored exclusively in Germany (EU). No cross-border data transfer.
50.4779°N, 12.3713°E
Datacenter
Hetzner DC Park 1
Services
Kubernetes cluster (primary), MySQL databases, WordPress pods
49.4521°N, 11.0767°E
Datacenter
Hetzner DC Park 13
Services
Backup storage (Hetzner Object Storage), disaster recovery cluster
Download DPAs, security whitepapers, and compliance reports
GDPR Article 28 compliant DPA template. Defines data processing scope, security measures, subprocessors, and data subject rights.
Technical architecture overview: Kubernetes security, network policies, encryption standards, access controls, and monitoring infrastructure.
Complete list of third-party subprocessors with GDPR Article 28 compliance status: Hetzner Cloud, Let's Encrypt, Cloudflare, Sentry.
Security incident classification, escalation procedures, notification timelines (72-hour GDPR requirement), and post-incident analysis process.
Note: Download links above are placeholders for demonstration. In production, these would link to signed S3 URLs with audit logging. Contact compliance@unionstack.dev to request actual compliance documentation.
We support all GDPR Article 15-22 rights for data subjects
Request copies of all personal data we process. Response time: 7 days.
Request deletion of all personal data (GDPR "Right to be Forgotten"). Executed within 30 days.
Export personal data in machine-readable JSON format. Available via dashboard.
To exercise your rights, contact our Data Protection Officer:
dpo@unionstack.devOur compliance team is available to discuss certifications, audit reports, and data processing agreements.
Contact Compliance Team