Data protection and technical infrastructure
GeoSewerTrack takes data protection and technical separation into account in the structure of the platform itself.
A customer instance is not merely a user area within one large shared database. Each GeoSewerTrack instance is operated as an independent customer environment with its own subdomain, its own configuration and its own database.
A separate database for every customer instance
Each GeoSewerTrack customer instance uses its own database.
Productive data belonging to different customers is therefore not stored together in one common customer database and separated only by user identifiers.
This technical separation is an essential part of the GeoSewerTrack architecture.
The Main system and customer instance are separated
GeoSewerTrack consists of two distinct areas.
The central Main system handles, among other things, the administration of customer accounts, contracts, settings and the respective instance configuration.
The actual productive work with projects, drawings and employees takes place within the customer-specific GST instance.
The customer instance therefore does not have to access the Main system for every individual page request.
Instead, it receives its own configuration intended for the respective customer.
Only the configuration data that is required
The principle of data minimisation applies when customer-specific settings are transferred between Main and the GST instance.
The configuration contains only the information required for the operation of the respective instance.
Internal data from the Main system that is not required should not form part of the customer configuration.
Secret credentials and other secrets also do not belong in these configuration files.
Protected data transmission
Access to GeoSewerTrack takes place via encrypted HTTPS connections.
This protects communication between the user’s browser and the GeoSewerTrack systems while data is being transmitted.
This applies both to access to the platform and to data transmitted within the application.
Access only for authorised users
Even within a customer instance, the following does not apply automatically:
Being signed in means having full access.
Projects must be approved for the relevant employees. Their permissions can then be restricted further.
Access to data is therefore controlled not only by the user account, but also by the respective task and permissions.
Protected files and documents
Files and documents that are not intended for public availability should not simply be accessible through freely reachable file paths.
Access to protected content takes place through functions of the application that check user permissions.
This makes it possible to take into account which user is allowed to access a particular document.
Data minimisation as a basic principle
GeoSewerTrack follows the principle of providing only the data within a system or customer instance that is actually required for the relevant purpose.
This applies particularly to the separation between the central customer portal and the productive GST instance.
Information from areas such as billing or internal system administration does not automatically have to form part of an employee’s operational working environment.
Controlled administrative access
Administrative and extended Staff access is assigned to individual persons.
Shared general administrator accounts should be avoided.
Technical and administrative permissions are restricted to those people who actually require them for their tasks.
The same principle applies here:
As much access as necessary, as little access as possible.
Customer data and processing on behalf of customers
Where personal data is processed within a customer instance on behalf of a customer, the allocation of roles between the customer and GeoSewerTrack must be defined according to the relevant processing and contractual arrangement.
GeoSewerTrack provides the required contractual and technical separation between customer administration and customer-specific data processing for this purpose.
Backup and recovery
The technical infrastructure also includes a concept for backing up and restoring the data required for operation.
The central database and the individual customer instances are considered separately.
Because each customer has an independent database, backup and recovery processes can technically also be focused on individual customer instances.
Specific backup intervals, retention periods and any contractually agreed recovery services depend on the defined operating and service scope.
Technical separation, not only organisational separation
Data protection in GeoSewerTrack therefore consists of more than a privacy policy or individual user permissions.
The separation begins in the technical structure of the platform itself:
a separate customer instance,
a separate database,
customer-specific configuration,
data-minimised information exchange,
encrypted communication
and controlled user and access permissions.
This creates a clearly separated GeoSewerTrack environment for each customer in which technical architecture and permission management work together to protect the data provided.