← Back to Baila
Security

Secure and reliable. And verifiable.

At Baila, trust is not a promise. You can read it back in how the platform is built and in what is on paper.

Your data, your environment.

Every school runs in its own environment with its own database. Your data does not sit among that of other schools.

Hosted in the EU

The platform runs at Hetzner in Germany, within the European Union.

Daily backups

Backups run every day, on a tiered schedule: 30 days daily, 90 days weekly and 365 days monthly.

Encrypted and off-site

The backups are stored encrypted in a data centre in Amsterdam, separate from the production environment.

Documented erasure process

When an environment is deleted, a documented erasure process follows, in which the backups are cleaned up as well.

Every school its own database.

Access and security.

Who can see and do what is arranged per staff member. And what changes is recorded.

Two-step verification

Signing in can use two-step verification, as an extra step on top of the password.

Roles per staff member

Access is role-based. A staff member only sees and does what belongs to their role.

Audit trail

Changes to over thirty kinds of data are recorded: who changed what, and when.

Encrypted keys

Integration keys and mail connection passwords are stored encrypted.

Rate limits

Sign-in and payment paths carry rate limits that slow down automated attempts.

The money flow does not run through Baila.

Payments run through your school’s own Mollie account. Mollie is the licensed payment service provider.

Baila does not hold any money. It handles what happens around the payment: customer, order, invoice.

Agreements on paper.

The agreements about your data are published on the site. You do not have to ask for them.

  • Data processing agreement

    The data processing agreement is published on the site. The sub-processors are named in it, including where they are based.

  • New sub-processors

    A new sub-processor comes with an announcement and objection arrangement.

  • Notice within 48 hours

    A data breach that affects your school is reported within 48 hours.

  • Privacy and cookies

    The privacy statement and the cookie explanation are published on the site.

  • AI named and switchable

    AI processing is named transparently, including the option to turn it off.

  • Recovery runbook

    There is a recovery runbook with a recovery objective of two hours.

  • Privacy rights of members

    Access, correction and deletion run through privacy@baila.me, as the privacy statement describes.

What we comply with.

GDPR
A data processing agreement, security measures and a duty to report data breaches.
Cookie rules
A cookie notice with an explanation. The customer portal only sets necessary cookies, so there is nothing to accept.
Invoice requirements
Invoices from Baila follow the legal invoice requirements.
Payment regulation
Payments run through Mollie, the licensed payment service provider. Baila does not hold any money.

Prefer to read it yourself?

The money flow is explained on the Mollie Connect page. The agreements sit with the terms and policies.