Trust & security

Security & data protection at DataLion

Market research means sensitive respondent data. DataLion protects it with hosting in ISO 27001-certified data centers in Germany, encrypted transport and granular access control. The DPA under Art. 28 GDPR is included.

DataLion is hosted in ISO 27001-certified data centers in Germany (Hetzner), encrypts all traffic with TLS and backs up its database hourly. The Data Processing Agreement under Art. 28 GDPR is included. Roles and granular access profiles control who sees what; two-factor authentication and SSO can be enabled. On-premise deployment is available.

  • 🇩🇪 Made in Munich
  • GDPR-compliant
  • DPA included
  • Hosted in Germany
  • 🌐 Interface in EN, DE, FR & NL

Trusted by research institutes, brands & insights teams

  • YouGov
  • Mediengruppe RTL Deutschland
  • SevenOne Media
  • Nielsen Sports
  • Spiegel Institut
  • Messe Berlin
  • Hartmann
  • 50+ interactive chart types
  • 20+ statistical methods
  • SPSS · Excel · CSV import without data loss
  • ISO 27001 certified data centers (Germany)

Hosting in ISO 27001-certified data centers

DataLion is hosted with Hetzner Online GmbH in Germany, at the Nuremberg and Falkenstein locations. The data centers are ISO 27001-certified; the certification applies to the data centers and the hosting, not to DataLion as a company or software. The hosting is climate-neutral.

Your data is processed and stored in Germany. A data processing agreement under Art. 28 GDPR is in place with the hosting provider. For enterprises, institutes and the public sector this means short paths, German law, and no third-country transfer of respondent data through the hosting.

  • Hetzner, Nuremberg and Falkenstein locations
  • ISO 27001-certified data centers (certification of the hosting, not of DataLion)
  • Climate-neutral hosting
  • Data stays in Germany

Backups: hourly incremental, daily full

The database is backed up incrementally every hour and in full every day. Backups are kept for seven days. If the worst happens, a recent state is ready to restore.

You can check the current operational status of the platform publicly at any time: status.datalion.

  • Hourly incremental database backups
  • Daily full backup
  • Seven-day retention
  • Public status page

Encryption & hardening

All connections to DataLion are TLS-encrypted (HTTPS), with HSTS and security headers such as X-Frame-Options and restrictive referrer and permissions policies. Session cookies are encrypted, HttpOnly and Secure.

Passwords are stored only as salted hashes, never in plain text; a password history prevents reusing old passwords. Particularly sensitive stored values (2FA secrets, stored AI API keys) are additionally encrypted at the application level with AES-256.

Login attempts and API access are rate-limited to slow down brute-force and abuse attempts. On request, access can be restricted to fixed IP ranges, such as your corporate network.

Development itself is secured, too: every code change runs through automated security scans covering static code analysis (SAST), dependency audits and secret scanning.

  • TLS/HTTPS with HSTS and security headers
  • Encrypted, HttpOnly and Secure session cookies
  • Passwords stored only as salted hashes, with password history
  • AES-256 encryption of stored secrets (2FA, API keys)
  • Rate limiting for logins and API, IP restriction available
  • Automated security scans in the development pipeline (SAST, dependencies, secrets)

Roles, permissions & access profiles

DataLion controls access on three levels: roles (admin, editor, viewer), per-dashboard permissions (edit, view, no access) and granular per-project access profiles. These determine who may see, filter, export or share data, down to read-only client accounts and row-level data filters via access profiles.

Technically, a strict principle applies: every resource is protected by an access policy that denies by default (fail-closed). That every single data model actually carries such a policy is verified automatically with every release.

More detail on the roles & permissions and access profiles pages.

  • Roles: admin, editor, viewer
  • Permissions per dashboard and report
  • Per-project access profiles: export, filter and sharing rights, read-only accounts
  • Row-level data filters via access profiles
  • Fail-closed access policies, automatically verified with every release

Support access: only with your approval, fully logged

Access by DataLion itself is regulated, too: support access to your environment runs through an audited support access system. You set the mode: disabled, approval per case, or standing permission.

Every support session is bound to an SSO-verified @datalion.com identity, limited to 45 minutes and immediately revocable at any time. A complete access log records which staff member accessed what and when, and a banner shows the active support session while it runs.

  • Three modes: disabled, approval per case, standing permission
  • SSO-verified staff identity (@datalion.com)
  • Sessions limited to 45 minutes, immediately revocable
  • Complete access log including the personal identity

Two-factor authentication & single sign-on

Beyond email and password, DataLion supports two-factor authentication (TOTP) via authenticator app. It can be enabled per user or made mandatory for the entire installation.

For password-less login, single sign-on via Google or Microsoft (OAuth) and via the DataLion Identity Server can be enabled. Enterprise customers connect their own identity provider. Details on the single sign-on page.

  • TOTP 2FA via authenticator app, optionally mandatory
  • SSO via Google and Microsoft (OAuth)
  • DataLion Identity Server
  • Own identity provider for Enterprise

GDPR & Data Processing Agreement

DataLion is a German company and operates 100% GDPR-compliant. You receive the Data Processing Agreement (DPA) under Art. 28 GDPR digitally, right away, with no lengthy negotiation. For Enterprise customers it is individually negotiable.

Our service providers are chosen EU-first, too: hosting with Hetzner in Germany, email delivery and product analytics on EU instances. All details, legal bases and sub-processors are transparently documented in our privacy policy.

Data minimisation applies internally as well: usage activity is recorded only as a coarse daily signal without project, content or IP reference, and pruned automatically.

  • DPA under Art. 28 GDPR included digitally
  • Enterprise: DPA individually negotiable
  • EU-first service providers and sub-processors
  • Data-minimal activity signals with no project, content or IP reference
  • Transparent privacy policy

AI features with a configurable endpoint

For AI features like "Ask your data" and sentiment & topic analysis, each workspace stores its own AI model: its own key, its own model, its own endpoint, chosen from HybridAI, OpenAI, Anthropic, Azure OpenAI and Mistral. The endpoint is freely configurable, and EU or on-premise operation of the language model is possible. Stored API keys are encrypted.

The Claude / MCP integration starts read-only: write access requires an explicit setting, API tokens are scoped, and debug logs are redacted.

  • Bring your own model: HybridAI, OpenAI, Anthropic, Azure OpenAI, Mistral
  • Freely configurable endpoint, EU/on-premise possible
  • AI keys stored encrypted
  • MCP connection read-only by default, scoped API tokens

On-premise & dedicated hosting

If your compliance requires it, run DataLion on-premise in your own infrastructure (a Docker-based installation with a license key) or as a dedicated instance on separate hardware in Germany. You keep full control over location, operation and data flows.

Behind all of this is a German company: made in Munich, with German-language support and contacts who know the requirements of European market research.

  • On-premise as a Docker-based installation
  • Dedicated hosting on a separate instance
  • Made in Munich, German-language support

See DataLion with your own data

Start free with your own raw data. Or book a personal demo of the path to a finished dashboard.

Top rated

4.5 out of 5 stars on G2 and OMR Reviews

What users say about DataLion

  • via G2
    Very professional company, attentive to the customer needs, provider of a great software and service.
    Generoso M. · CRM Analyst, Automotive
  • via G2
    The contacts at DataLion are very committed. If you have problems, you can count on help. DataLion reacts quickly to requests for new functions.
    Robert Q. · Managing Director
  • via G2
    User-friendliness, especially for market research topics. Structured backend with many customization options.
    Verified user · Market Research
  • via G2
    The embedding function allows us to generate insights of our data for our audience and customers by far less than half of the usual time needed before.
    Verified user · Leisure, Travel & Tourism
Read all 16 reviews on G2 →
We now work much more efficiently, giving us more time to take care of the derivations and insights from the data for the customers.
Jens Falkenau, Vice President of Market Research · Nielsen Sports
Read the case study →

Security in DataLion: the feature pages

Common questions about security

Where is my data stored?
In ISO 27001-certified data centers operated by Hetzner Online GmbH in Germany, at the Nuremberg and Falkenstein locations. Your data is processed and stored in Germany.
Is DataLion ISO 27001-certified?
The data centers where DataLion is hosted are ISO 27001-certified. The certification applies to the hosting and the data centers, not to DataLion as a company or software.
Is there a Data Processing Agreement (DPA)?
Yes. The DPA under Art. 28 GDPR is included digitally with no negotiation required. Enterprise customers can negotiate it individually.
Does DataLion support two-factor authentication and SSO?
Yes. TOTP two-factor authentication via authenticator app can be enabled per user or made mandatory for the entire installation. Single sign-on is available via Google, Microsoft (OAuth) and the DataLion Identity Server; Enterprise customers connect their own identity provider.
How often are backups created?
The database is backed up incrementally every hour and in full every day. Backups are kept for seven days.
What happens to my data when I use the AI features?
Each workspace stores its own AI model with its own key and a freely configurable endpoint; EU or on-premise operation of the language model is possible. Stored keys are encrypted, and the Claude / MCP connection starts read-only.
Can I run DataLion in my own infrastructure?
Yes. DataLion can run on-premise as a Docker-based installation with a license key, or as a dedicated hosted instance, with full control over location and operation.
Can DataLion staff access my data?
Only through the audited support access system — and only if you allow it. You choose between disabled, approval per case, or standing permission. Every session is bound to an SSO-verified @datalion.com identity, limited to 45 minutes, immediately revocable, and fully logged.

Secure market research from Germany

Try DataLion for free, or get a personal demo with a detailed walkthrough of the security setup.