Enterprise-Grade Security & Privacy

Your users' data is safe, secure, and never for sale

uQualio is a GDPR and ISO 27001 compliant video LMS. All data is encrypted with AES-256, stored on EU servers in Frankfurt, and protected by 24/7 monitoring. We don’t sell data. We don’t share it. We don’t move it outside the EU.

No code · No hassle · Plans from $19.99/month

Security and realiability hero image

Data never sold or shared with third parties

AWS Frankfurt: EU only, never transferred outside

ISO 27001 compliant

72-hour breach notification

AES-256 encryption at rest and in transit

Sending this to your customers' legal team?

Here’s what they need to know: all uQualio data is stored on EU servers (AWS Frankfurt, Germany). Data is never transferred outside the EU. We are GDPR-compliant and ISO 27001-aligned. We never sell or share user data with third parties. A Data Processing Agreement is available on request.

If your customer’s procurement team needs documentation, the full legal library – including General Terms, Privacy Policy, and Joint Data Controller Agreement 

View all legal documentation
Sell Online Courses - uQualio User on a laptop

Philosophy

Security by design, not by checkbox

uQualio was founded in Denmark, one of the world’s strictest data protection jurisdictions. The Danish Data Protection Authority (Datatilsynet) sets a high bar. That’s the baseline we’ve built to, not the minimum we comply with.

Security isn’t a configuration layer added after the product was built. It’s built into the platform architecture. Every employee passes a compliance test on sensitive data handling. Every new process involving personal data requires a documented purpose and supervisor sign-off. Platform development includes data verification at the design stage.

Security and compliance across every layer

GDPR compliance

uQualio is compliant with EU Regulation 2016/679 (GDPR), the Danish Personal Data Law, and the Data Protection Act (DPA).

What this means in practice:

  • All personal data processes are identified with defined responsibilities
  • Every uQualio employee passes a compliance test on sensitive data management
  • Compliance test results are stored and available to the Data Protection Officer
  • Platform development includes data verification at the design stage
  • New records involving personal data require documented content and purpose

Your users have full GDPR rights on the platform:

  • Right to access — any user can request a copy of their personal data
  • Right to erasure — all data deleted on request (“right to be forgotten”)
  • Right to portability — data provided in machine-readable format on request
  • Consent management — explicit consent mechanisms for all marketing communications
  • Role-based access — admins can only access data appropriate to their role
See how it works

ISO 27001 compliance

uQualio is built in alignment with ISO 27001 — the international standard for information security management systems. Our infrastructure, processes, and data handling practices meet the requirements of the standard.

Note for procurement teams: uQualio operates as ISO 27001 compliant-by-design. If your vendor assessment requires a formal third-party certification certificate, contact the team to discuss current certification status and documentation available.

Data storage — EU only, always

All customer data is physically stored on Amazon Web Services (AWS) servers in Frankfurt, Germany. Data never leaves the EU. We do not use data centres outside the European Union, and we do not transfer personal data to third countries.

Infrastructure is protected by Cloudflare at the network layer.

Encryption

All data at rest is encrypted with AES-256 — the same standard used by governments, banks, and defence organisations worldwide. All data in transit is encrypted via HTTPS/TLS. There is no unencrypted path to customer data.

Payment security

uQualio does not handle or store payment card data. Course sales are processed through Stripe, which is fully PCI DSS Level 1 compliant — the highest level of payment security certification. uQualio never touches the card data.

Vulnerability management

Security is a continuous programme, not a one-time audit. uQualio undergoes regular vulnerability scanning and penetration testing by multiple independent external consultants. A bug bounty programme is in place for responsible disclosure.

All customer-uploaded documents are automatically virus-scanned on upload.

Accessibility

Security and accessibility are not in conflict. uQualio is committed to WCAG 2.1 compliance.

  • AI-generated subtitles and closed captions for all video content
  • Text-to-speech for course content (AI-generated audio)
  • 18+ UI languages — learners access training in their own language
  • Fully responsive — desktop, tablet, and mobile

Accessibility - Features

  • WCAG 2.1 accessibility compliance commitment
  • Text-to-Speech: AI-generated audio versions of course content
  • AI-generated subtitles and closed captions for all video content (if enabled)
  • 18+ UI languages, so users can access training in their own language
  • Fully responsive interface. Accessible on desktop, tablet, and mobile
See how it works

24/7 monitoring and breach response

All critical system instances are monitored 24/7 with automated anomaly detection and real-time alerts. In the event of a confirmed data breach.

  • The Danish supervisory authority (Datatilsynet) is notified within 72 hours
  • Affected individuals are notified without unnecessary delay
  • All details of the breach, its effects, and remedial actions are fully documented

Accessibility - Features

  • WCAG 2.1 accessibility compliance commitment
  • Text-to-Speech: AI-generated audio versions of course content
  • AI-generated subtitles and closed captions for all video content (if enabled)
  • 18+ UI languages, so users can access training in their own language
  • Fully responsive interface. Accessible on desktop, tablet, and mobile
See how it works

User Account Security

User Account Security - Features

  • Minimum 8-character passwords required
  • Unique username (ID, email, or phone number) per account
  • Email and phone number changes are logged as user activity
  • Password changes are logged as user activity
  • Accounts lock after three failed login attempts
  • Admins can block any user account immediately
  • No Apple ID or Facebook login: we believe their data use policies are not sufficiently transparent
See how it works

Security and compliance across every layer

GDPR compliance

uQualio is compliant with EU Regulation 2016/679 (GDPR), the Danish Personal Data Law, and the Data Protection Act (DPA). What this means in practice:

What this means in practice:

  • All personal data processes are identified with defined responsibilities
  • Every uQualio employee passes a compliance test on sensitive data management
  • Compliance test results are stored and available to the Data Protection Officer
  • Platform development includes data verification at the design stage
  • New records involving personal data require documented content and purpose

Your users have full GDPR rights on the platform:

  • Right to access — any user can request a copy of their personal data
  • Right to erasure — all data deleted on request (“right to be forgotten”)
  • Right to portability — data provided in machine-readable format on request
  • Consent management — explicit consent mechanisms for all marketing communications
  • Role-based access — admins can only access data appropriate to their role

ISO 27001 compliance

uQualio is built in alignment with ISO 27001, the international standard for information security management systems. Our infrastructure, processes, and data handling practices meet the requirements of the standard.

Note for procurement teams: uQualio operates as ISO 27001 compliant-by-design. If your vendor assessment requires a formal third-party certification, contact the team to discuss current certification status and documentation available.

Start 14-day free uQualio trial

Encryption

All data at rest is encrypted with AES-256, the same standard used by governments, banks, and defence organisations worldwide. 

All data in transit is encrypted via HTTPS/TLS. There is no unencrypted path to customer data.

Start 14-day free uQualio trial

Vulnerability management

Security is a continuous programme, not a one-time audit. 

uQualio undergoes regular vulnerability scanning and penetration testing by multiple independent external consultants. A bug bounty programme is in place for responsible disclosure.

All customer-uploaded documents are automatically virus-scanned on upload.

Start 14-day free uQualio trial

Payment security

uQualio does not handle or store payment card data. 

Course sales are processed through Stripe, which is fully PCI DSS Level 1 compliant, the highest level of payment security certification. uQualio never touches the card data.

Start 14-day free uQualio trial

Data storage: EU only, always

All customer data is physically stored on Amazon Web Services (AWS) servers in Frankfurt, Germany. Data never leaves the EU. 

We do not use data centres outside the European Union, and we do not transfer personal data to third countries.

Infrastructure is protected by Cloudflare at the network layer.

Start 14-day free uQualio trial

Accessibility

Security and accessibility are not in conflict. uQualio is committed to WCAG compliance.

  • AI-generated subtitles and closed captions for all video content
  • Text-to-speech for course content (AI-generated audio)
  • 18+ UI languages: Learners access training in their own language
  • Fully responsive: Desktop, tablet, and mobile
Find latest report

User Account Security

  • Minimum 8-character passwords required
  • Unique username (ID, email, or phone number) per account
  • Email and phone number changes are logged as user activity
  • Password changes are logged as user activity
  • Accounts lock after three failed login attempts
  • Admins can block any user account immediately
  • No Apple ID or Facebook login: we believe their data use policies are not sufficiently transparent
Start 14-day free uQualio trial

24/7 monitoring and breach response

All critical system instances are monitored 24/7 with automated anomaly detection and real-time alerts. In the event of a confirmed data breach:

  • The Danish supervisory authority (Datatilsynet) is notified within 72 hours
  • Affected individuals are notified without unnecessary delay
  • All details of the breach, its effects, and remedial actions are fully documented
Start 14-day free uQualio trial

What your customers need to know

Running due diligence? Here's the short version.

If you’re a B2B services company sending uQualio to your own customers for onboarding, your customers’ procurement or legal teams may ask about the training platform. This is what to send them.

Your onboarding training runs on uQualio, a GDPR and ISO 27001 compliant video learning platform founded in Denmark and hosted on AWS Frankfurt (EU). All data is stored in the EU and never transferred outside it. Data is encrypted with AES-256 at rest and HTTPS/TLS in transit. uQualio does not sell or share user data with third parties. Users have full GDPR rights including right to erasure. 

View all legal documentation

How uQualio's security posture compares

uQualioTypical SMB LMS
Data location✅ EU only — AWS FrankfurtOften US-based or unspecified
Encryption at rest✅ AES-256Varies — often not stated
Encryption in transit✅ HTTPS/TLSUsually yes
GDPR compliance✅ FullOften partial or claimed
ISO 27001 alignment✅ Compliant-by-designRarely
72-hour breach notification✅ Required by law, built into processOften manual, unspecified
Bug bounty programme✅ ActiveRare at this price point
Third-party penetration testing✅ Ongoing, multiple vendorsTypically none
Data never sold✅ Policy and legal commitmentOften ad-funded models
Payment card handling✅ Stripe (PCI DSS L1) — zero card data storedVaries
Apple ID / Facebook login❌ Declined on data policy groundsOften enabled
Data Processing Agreement available✅ On requestVaries
Start 14-day free uQualio trial

Get started

Security documentation, legal terms, and trial access

For procurement teams evaluating uQualio, the full legal library is publicly available, no NDAs or gate required to review our terms. Start your free 14-day trial today, no risk.

✓ GDPR & ISO 27001 Compliant ✓ EU Data Storage  ✓ AES-256 Encrypted

FAQ - Security and compliance questions