Enterprise-Grade Security & Privacy
Your users' data is safe, secure, and never for sale
uQualio is a GDPR and ISO 27001 compliant video LMS. All data is encrypted with AES-256, stored on EU servers in Frankfurt, and protected by 24/7 monitoring. We don’t sell data. We don’t share it. We don’t move it outside the EU.
No code · No hassle · Plans from $19.99/month

Sending this to your customers' legal team?
Here’s what they need to know: all uQualio data is stored on EU servers (AWS Frankfurt, Germany). Data is never transferred outside the EU. We are GDPR-compliant and ISO 27001-aligned. We never sell or share user data with third parties. A Data Processing Agreement is available on request.
If your customer’s procurement team needs documentation, the full legal library – including General Terms, Privacy Policy, and Joint Data Controller Agreement

Philosophy
Security by design, not by checkbox
uQualio was founded in Denmark, one of the world’s strictest data protection jurisdictions. The Danish Data Protection Authority (Datatilsynet) sets a high bar. That’s the baseline we’ve built to, not the minimum we comply with.
Security isn’t a configuration layer added after the product was built. It’s built into the platform architecture. Every employee passes a compliance test on sensitive data handling. Every new process involving personal data requires a documented purpose and supervisor sign-off. Platform development includes data verification at the design stage.
Security and compliance across every layer
Security and compliance across every layer
GDPR compliance
uQualio is compliant with EU Regulation 2016/679 (GDPR), the Danish Personal Data Law, and the Data Protection Act (DPA). What this means in practice:
What this means in practice:
- All personal data processes are identified with defined responsibilities
- Every uQualio employee passes a compliance test on sensitive data management
- Compliance test results are stored and available to the Data Protection Officer
- Platform development includes data verification at the design stage
- New records involving personal data require documented content and purpose
Your users have full GDPR rights on the platform:
- Right to access — any user can request a copy of their personal data
- Right to erasure — all data deleted on request (“right to be forgotten”)
- Right to portability — data provided in machine-readable format on request
- Consent management — explicit consent mechanisms for all marketing communications
- Role-based access — admins can only access data appropriate to their role
ISO 27001 compliance
uQualio is built in alignment with ISO 27001, the international standard for information security management systems. Our infrastructure, processes, and data handling practices meet the requirements of the standard.
Note for procurement teams: uQualio operates as ISO 27001 compliant-by-design. If your vendor assessment requires a formal third-party certification, contact the team to discuss current certification status and documentation available.
Encryption
All data at rest is encrypted with AES-256, the same standard used by governments, banks, and defence organisations worldwide.
All data in transit is encrypted via HTTPS/TLS. There is no unencrypted path to customer data.
Vulnerability management
Security is a continuous programme, not a one-time audit.
uQualio undergoes regular vulnerability scanning and penetration testing by multiple independent external consultants. A bug bounty programme is in place for responsible disclosure.
All customer-uploaded documents are automatically virus-scanned on upload.
Payment security
uQualio does not handle or store payment card data.
Course sales are processed through Stripe, which is fully PCI DSS Level 1 compliant, the highest level of payment security certification. uQualio never touches the card data.
Data storage: EU only, always
All customer data is physically stored on Amazon Web Services (AWS) servers in Frankfurt, Germany. Data never leaves the EU.
We do not use data centres outside the European Union, and we do not transfer personal data to third countries.
Infrastructure is protected by Cloudflare at the network layer.
Accessibility
Security and accessibility are not in conflict. uQualio is committed to WCAG compliance.
- AI-generated subtitles and closed captions for all video content
- Text-to-speech for course content (AI-generated audio)
- 18+ UI languages: Learners access training in their own language
- Fully responsive: Desktop, tablet, and mobile
User Account Security
- Minimum 8-character passwords required
- Unique username (ID, email, or phone number) per account
- Email and phone number changes are logged as user activity
- Password changes are logged as user activity
- Accounts lock after three failed login attempts
- Admins can block any user account immediately
- No Apple ID or Facebook login: we believe their data use policies are not sufficiently transparent
24/7 monitoring and breach response
All critical system instances are monitored 24/7 with automated anomaly detection and real-time alerts. In the event of a confirmed data breach:
- The Danish supervisory authority (Datatilsynet) is notified within 72 hours
- Affected individuals are notified without unnecessary delay
- All details of the breach, its effects, and remedial actions are fully documented
What your customers need to know
Running due diligence? Here's the short version.
If you’re a B2B services company sending uQualio to your own customers for onboarding, your customers’ procurement or legal teams may ask about the training platform. This is what to send them.
Your onboarding training runs on uQualio, a GDPR and ISO 27001 compliant video learning platform founded in Denmark and hosted on AWS Frankfurt (EU). All data is stored in the EU and never transferred outside it. Data is encrypted with AES-256 at rest and HTTPS/TLS in transit. uQualio does not sell or share user data with third parties. Users have full GDPR rights including right to erasure.
How uQualio's security posture compares
| uQualio | Typical SMB LMS | |
|---|---|---|
| Data location | ✅ EU only — AWS Frankfurt | Often US-based or unspecified |
| Encryption at rest | ✅ AES-256 | Varies — often not stated |
| Encryption in transit | ✅ HTTPS/TLS | Usually yes |
| GDPR compliance | ✅ Full | Often partial or claimed |
| ISO 27001 alignment | ✅ Compliant-by-design | Rarely |
| 72-hour breach notification | ✅ Required by law, built into process | Often manual, unspecified |
| Bug bounty programme | ✅ Active | Rare at this price point |
| Third-party penetration testing | ✅ Ongoing, multiple vendors | Typically none |
| Data never sold | ✅ Policy and legal commitment | Often ad-funded models |
| Payment card handling | ✅ Stripe (PCI DSS L1) — zero card data stored | Varies |
| Apple ID / Facebook login | ❌ Declined on data policy grounds | Often enabled |
| Data Processing Agreement available | ✅ On request | Varies |
Get started
Security documentation, legal terms, and trial access
For procurement teams evaluating uQualio, the full legal library is publicly available, no NDAs or gate required to review our terms. Start your free 14-day trial today, no risk.
✓ GDPR & ISO 27001 Compliant ✓ EU Data Storage ✓ AES-256 Encrypted
FAQ - Security and compliance questions
- Where is uQualio customer data stored?
All customer data is physically stored on Amazon Web Services (AWS) servers in Frankfurt, Germany. Data never leaves the EU. uQualio does not use data centres outside the European Union, and does not transfer personal data to third countries.
- Is uQualio GDPR compliant?
Yes. uQualio complies with EU Regulation 2016/679 (GDPR), the Danish Personal Data Law, and the Data Protection Act. All personal data processes are documented with defined responsibilities. Users have full rights to access, erasure, and portability of their data. A Data Processing Agreement is available on request.
- Is uQualio ISO 27001 certified?
uQualio is built in alignment with ISO 27001, the international standard for information security management. Our infrastructure and processes meet the requirements of the standard. Contact the team for current certification documentation relevant to your procurement process.
- Does uQualio sell or share user data with third parties?
No. User data is never sold or shared with third parties. uQualio’s business model is subscription-based. Learner data is used solely to deliver the platform functionality the account holder has configured.
- What encryption does uQualio use?
Data at rest is encrypted with AES-256, the industry gold standard used by governments, banks, and defence organisations. Data in transit is encrypted via HTTPS/TLS. There is no unencrypted path to customer data.
- How does uQualio respond to a data breach?
The Danish supervisory authority (Datatilsynet) is notified within 72 hours of a confirmed breach. Affected individuals are notified without unnecessary delay. All details of the breach, its effects, and remedial actions are fully documented. This process is built into platform operations, not handled ad hoc.
- Who owns the data on a uQualio platform?
You do. When you purchase and use uQualio, you are the data owner. You are responsible for your users and their data. uQualio provides the platform and tools. This relationship is documented in the Data Processing Agreement and General Terms.
- How is payment data secured?
uQualio does not handle or store payment card data. All payment processing runs through Stripe, which holds PCI DSS Level 1 certification, the highest level of payment security compliance. uQualio never sees the card data.
- Can my customers' procurement team review uQualio's legal documentation?
Yes. The full legal library is publicly available at uqualio.com/legal-terms. No registration or NDA required. Documentation available includes General Terms, Data Processing Agreement, Conditions, Commercial Terms, Corporate Permissions Terms, Joint Data Controller Agreement, and Privacy Policy.
- Is uQualio accessible for learners with disabilities?
uQualio is committed to WCAG compliance. The platform includes AI-generated subtitles and closed captions for all video content, text-to-speech for course material, 18+ UI languages, and a fully responsive interface accessible on desktop, tablet, and mobile.
