Trust & security
Security & data protection at DataLion
Market research means sensitive respondent data. DataLion protects it with hosting in ISO 27001-certified data centers in Germany, encrypted transport and granular access control. The DPA under Art. 28 GDPR is included.
DataLion is hosted in ISO 27001-certified data centers in Germany (Hetzner), encrypts all traffic with TLS and backs up its database hourly. The Data Processing Agreement under Art. 28 GDPR is included. Roles and granular access profiles control who sees what; two-factor authentication and SSO can be enabled. On-premise deployment is available.
- 🇩🇪 Made in Munich
- GDPR-compliant
- DPA included
- Hosted in Germany
- 🌐 Interface in EN, DE, FR, ES, IT & NL
Trusted by research institutes, brands & insights teams
- 50+ interactive chart types
- 20+ statistical methods
- SPSS · Excel · CSV import without data loss
- ISO 27001 certified data centers (Germany)
Hosting in ISO 27001-certified data centers
DataLion is hosted with Hetzner Online GmbH in Germany, at the Nuremberg and Falkenstein locations. The data centers are ISO 27001-certified; the certification applies to the data centers and the hosting, not to DataLion as a company or software. The hosting is climate-neutral.
Your data is processed and stored in Germany. A data processing agreement under Art. 28 GDPR is in place with the hosting provider. For enterprises, institutes and the public sector this means short paths, German law, and no third-country transfer of respondent data through the hosting.
- Hetzner, Nuremberg and Falkenstein locations
- ISO 27001-certified data centers (certification of the hosting, not of DataLion)
- Climate-neutral hosting
- Data stays in Germany
Backups: hourly incremental, daily full
The database is backed up incrementally every hour and in full every day. Backups are kept for seven days. If the worst happens, a recent state is ready to restore.
You can check the current operational status of the platform publicly at any time: status.datalion.
- Hourly incremental database backups
- Daily full backup
- Seven-day retention
- Public status page
Encryption & hardening
All connections to DataLion are TLS-encrypted (HTTPS), with HSTS and security headers such as X-Frame-Options and restrictive referrer and permissions policies. Session cookies are encrypted, HttpOnly and Secure.
Passwords are stored only as salted hashes, never in plain text; a password history prevents reusing old passwords. Particularly sensitive stored values (2FA secrets, stored AI API keys) are additionally encrypted at the application level with AES-256.
Login attempts and API access are rate-limited to slow down brute-force and abuse attempts. On request, access can be restricted to fixed IP ranges, such as your corporate network.
Development itself is secured, too: every code change runs through automated security scans covering static code analysis (SAST), dependency audits and secret scanning.
- TLS/HTTPS with HSTS and security headers
- Encrypted, HttpOnly and Secure session cookies
- Passwords stored only as salted hashes, with password history
- AES-256 encryption of stored secrets (2FA, API keys)
- Rate limiting for logins and API, IP restriction available
- Automated security scans in the development pipeline (SAST, dependencies, secrets)
Roles, permissions & access profiles
DataLion controls access on three levels: roles (admin, editor, viewer), per-dashboard permissions (edit, view, no access) and granular per-project access profiles. These determine who may see, filter, export or share data, down to read-only client accounts and row-level data filters via access profiles.
Technically, a strict principle applies: every resource is protected by an access policy that denies by default (fail-closed). That every single data model actually carries such a policy is verified automatically with every release.
More detail on the roles & permissions and access profiles pages.
- Roles: admin, editor, viewer
- Permissions per dashboard and report
- Per-project access profiles: export, filter and sharing rights, read-only accounts
- Row-level data filters via access profiles
- Fail-closed access policies, automatically verified with every release
Support access: only with your approval, fully logged
Access by DataLion itself is regulated, too: support access to your environment runs through an audited support access system. You set the mode: disabled, approval per case, or standing permission.
Every support session is bound to an SSO-verified @datalion.com identity, limited to 45 minutes and immediately revocable at any time. A complete access log records which staff member accessed what and when, and a banner shows the active support session while it runs.
- Three modes: disabled, approval per case, standing permission
- SSO-verified staff identity (@datalion.com)
- Sessions limited to 45 minutes, immediately revocable
- Complete access log including the personal identity
Two-factor authentication & single sign-on
Beyond email and password, DataLion supports two-factor authentication (TOTP) via authenticator app. It can be enabled per user or made mandatory for the entire installation.
For password-less login, single sign-on via Google or Microsoft (OAuth) and via the DataLion Identity Server can be enabled. Enterprise customers connect their own identity provider. Details on the single sign-on page.
- TOTP 2FA via authenticator app, optionally mandatory
- SSO via Google and Microsoft (OAuth)
- DataLion Identity Server
- Own identity provider for Enterprise
GDPR & Data Processing Agreement
DataLion is a German company and operates 100% GDPR-compliant. You receive the Data Processing Agreement (DPA) under Art. 28 GDPR digitally, right away, with no lengthy negotiation. For Enterprise customers it is individually negotiable.
Our service providers are chosen EU-first, too: hosting with Hetzner in Germany, email delivery and product analytics on EU instances. All details, legal bases and sub-processors are transparently documented in our privacy policy.
Data minimisation applies internally as well: usage activity is recorded only as a coarse daily signal without project, content or IP reference, and pruned automatically.
- DPA under Art. 28 GDPR included digitally
- Enterprise: DPA individually negotiable
- EU-first service providers and sub-processors
- Data-minimal activity signals with no project, content or IP reference
- Transparent privacy policy
AI features with documented EU approval
The DataLion default route uses HybridAI GmbH under the DPA electronically accepted on 28 August 2026. The approved destination is hybridai.one with model Qwen/Qwen3.6-27B-FP8, recorded as A6-HYBRIDAI-PROD-2026-001. The selected contract variant B limits processing to the EU/EEA with no third-country transfer; training or fine-tuning on DataLion data is excluded.
PII masking is enabled but remains a best-effort measure under the DPA. Chat/log data and uploaded documents are contractually retained for no more than 90 days; backups have separate retention periods. The signed copy contains personal acceptance metadata, so it is not published publicly and is provided to authorised customers and auditors through a controlled evidence request.
Features that transfer open-text responses check the host and model against this approval and block a different route. Ask your data does not transfer raw open-text responses; it sends the user question, project metadata and aggregated result tables. Each workspace can alternatively configure its own model and endpoint, but a BYOM route needs its own matching approval before open-text responses can be sent. Stored API keys are encrypted.
The Claude / MCP integration starts read-only: write access requires an explicit setting, API tokens are scoped, and debug logs are redacted.
- Default: HybridAI/Qwen, EU/EEA, DPA dated 28 August 2026
- Assurance record A6-HYBRIDAI-PROD-2026-001 for the exact host and model ID
- No training; best-effort PII masking; maximum 90-day retention
- BYOM remains available; open-text transfer requires matching route approval
- AI keys stored encrypted
- MCP connection read-only by default, scoped API tokens
On-premise & dedicated hosting
If your compliance requires it, run DataLion on-premise in your own infrastructure (a Docker-based installation with a license key) or as a dedicated instance on separate hardware in Germany. You keep full control over location, operation and data flows.
Behind all of this is a German company: made in Munich, with German-language support and contacts who know the requirements of European market research.
- On-premise as a Docker-based installation
- Dedicated hosting on a separate instance
- Made in Munich, German-language support
Memberships
DataLion GmbH is a participant in the Allianz für Cyber-Sicherheit (Alliance for Cyber Security), an initiative of the German Federal Office for Information Security (BSI). Participation stands for the ongoing exchange on BSI recommendations and current threat intelligence — it is a membership, not a certification.
See DataLion with your own data
Start free with your own raw data. Or book a personal demo of the path to a finished dashboard.
What users say about DataLion
- via G2
Very professional company, attentive to the customer needs, provider of a great software and service.
Generoso M. · CRM Analyst, Automotive - via G2
The contacts at DataLion are very committed. If you have problems, you can count on help. DataLion reacts quickly to requests for new functions.
Robert Q. · Managing Director - via G2
User-friendliness, especially for market research topics. Structured backend with many customization options.
Verified user · Market Research - via G2
The embedding function allows us to generate insights of our data for our audience and customers by far less than half of the usual time needed before.
Verified user · Leisure, Travel & Tourism
We now work much more efficiently, giving us more time to take care of the derivations and insights from the data for the customers.
Security in DataLion: the feature pages
Common questions about security
Where is my data stored?
Is DataLion ISO 27001-certified?
Is there a Data Processing Agreement (DPA)?
Does DataLion support two-factor authentication and SSO?
How often are backups created?
What happens to my data when I use the AI features?
Can I run DataLion in my own infrastructure?
Can DataLion staff access my data?
Secure market research from Germany
Try DataLion for free, or get a personal demo with a detailed walkthrough of the security setup.
