Recht & Datenschutz
Der Schutz von Kunden- und Besucherdaten ist ein wichtiger Bestandteil davon, wie wir Lobbipad konzipieren, entwickeln und betreiben. Wir setzen auf bewährte Cloud-Infrastruktur, Zugriffskontrollen, Verschlüsselung, Backups und sichere Entwicklungspraktiken, um die Vertraulichkeit, Integrität und Verfügbarkeit der über unsere Plattform verarbeiteten Informationen zu schützen.
Zuletzt aktualisiert am September 6, 2026.
Lobbipad's infrastructure is hosted using Amazon Web Services (AWS). We do not operate our own physical data centres.
AWS data centres are designed with multiple layers of physical and environmental security. Physical access is restricted to authorised personnel and protected through measures including access controls, monitoring, video surveillance, intrusion detection and multi-factor authentication.
Lobbipad employees do not have physical access to AWS data centres.
Access by Lobbipad personnel to our cloud infrastructure is restricted to authorised team members based on their responsibilities and operational requirements.
We use encryption to protect data while it is transmitted between users and Lobbipad.
Connections to the Lobbipad platform are encrypted in transit using HTTPS/TLS.
Passwords are not stored in plaintext and are securely hashed using established password-protection mechanisms.
Access to Lobbipad systems and customer information is restricted according to role and operational need.
We apply the principle of least privilege: team members should only have access to the systems and information necessary to perform their responsibilities.
Access to production environments is restricted to authorised personnel.
When access to customer information is necessary to investigate a support request or technical issue, our team aims to access only the information required to resolve that issue.
Lobbipad maintains backups of relevant production data to support recovery in the event of an operational incident or data loss.
Our infrastructure is built on AWS and designed with reliability and availability in mind.
We monitor our services and infrastructure to identify availability, performance and security issues.
Security is considered throughout the development and maintenance of Lobbipad.
Changes to our platform are tested before deployment, and our development practices are designed to reduce common web application security risks, including cross-site scripting (XSS), cross-site request forgery (CSRF) and SQL injection.
Dependencies and infrastructure are maintained and updated as necessary to address identified security vulnerabilities.
We monitor our infrastructure and applications for operational and security-related issues.
Potential security incidents are investigated and addressed according to our internal procedures. Where a personal data breach occurs, we follow applicable legal and contractual notification requirements.
Access to internal systems is provided according to employees' roles and responsibilities.
Access rights are adjusted when responsibilities change or access is no longer required.
Employees and contractors with access to confidential information are required to protect that information and comply with applicable internal security and confidentiality requirements.
Security and privacy go hand in hand.
Lobbipad is committed to protecting personal data in accordance with applicable data protection legislation, including the GDPR.
Where Lobbipad processes personal data on behalf of a customer, our responsibilities regarding that processing are described in our Data Processing Agreement.
We take reports of potential security vulnerabilities seriously.
If you believe you have discovered a security issue affecting Lobbipad, please contact us at security@lobbipad.com.
Please include sufficient information for our team to understand and reproduce the issue. We ask security researchers not to access, modify or delete customer data while investigating potential vulnerabilities.
Are you evaluating Lobbipad for your organisation?
Our team can provide additional security and data protection information to customers and prospective customers upon request.