Frequently asked questions
Where is my data hosted?
In data centers located in Spain, and backups in object storage in
Spain. We do not take your data out of Spain in normal operation. Details
in Data residency.
Is my data separated from other customers'?
Yes. Each environment is logically isolated, with its own database, its
own identity and its own segmented network. Details in
Isolation between environments.
How is my data and my credentials protected?
Your communications travel encrypted in transit (HTTPS/TLS 1.2-1.3) and
your credentials and secrets are kept encrypted in a dedicated
secrets manager, with rotation and minimal access. Details in
Encryption.
Is my data encrypted at rest?
Secrets are: credentials, keys and tokens are stored encrypted with AES-256 in
a dedicated manager. Your environment's data and its backups are not: the
storage they rely on does not currently support server-side encryption, and
closing that gap is open work with our infrastructure provider. We would rather
say it than leave it out. What does protect that data is isolation between
environments, minimal access from an administration network that is not exposed
to the Internet, residency in Spain, and backup immutability, which prevents
deletion for 7 days — by us too. Details in Encryption.
Can I use my company's single sign-on?
Yes, we integrate access with your corporate identity provider using
standard protocols (OIDC / SAML / OAuth2). Details in
Access control.
How often do you back up, and how long do you keep backups?
As a standard: a daily backup of the database and the file system
with 14 days of retention and, in Kubernetes-based environments,
point-in-time recovery for the database within that same window (restoring to
an exact moment). The database backup runs every night, between 01:00 and 05:00
(Spanish time), and the last 7 days are immutable: they cannot be
deleted or altered, not even by us. You can adjust this policy to your
needs. Details in Backups.
What happens if a component goes down?
The platform self-heals: it restarts or replaces the component
automatically and redirects traffic in the meantime, aiming to restore service in
under 2 minutes from detection. Details in
High availability.
And if an entire server goes down?
The cluster running the environments is made up of several machines: the
components that were on the failing one are rescheduled onto the others.
To reinforce this, an environment can run with several instances of the
application and with a database replica with automatic failover. Details
in High availability.
What happens during a month-end close, a campaign or a peak in activity?
Your environment is sized for your load, and that sizing is adjusted:
more instances, more resources per instance, or a split deployment model
in which heavy processes do not compete with your users. If you know a
foreseeable peak is coming, tell us and we prepare for it beforehand; if we
detect it ourselves through measurement, we propose it to you. The change is
applied to your current environment and with no perceptible cutover.
Details in Scaling and capacity.
Can I run bulk integrations against my environment?
Yes. Bear in mind that in front of your application there are reasonable
request limits, designed so that anomalous traffic does not degrade the
service. They are adjustable: if your integration needs a higher
throughput, coordinate it with us and we raise it. Details in
Scaling and capacity.
Who is responsible for what?
We are responsible for the platform and its secure operation; you, for
the use and business data. Details in
Responsibility model.
What happens to my data if I stop being a customer?
We provide you with an export of your data and, after the agreed period,
we delete your data and its backups. Details in
Retention and deletion.
Do you have ISO 27001 certification?
As of September 2026 we are in the process of ISO/IEC 27001
certification in Spain. Dynapps NV (Belgium), the Dynapps group's
parent company, is certified to ISO/IEC 27001 — certificate renewed in
February 2026 — and the scope of that certificate does not cover
Spain. Dyncloud's infrastructure is built applying the controls and
security guidelines of that certified system. We do not claim as active any
certification that is not yet in effect. Details in
Certifications.
Write to us. We provide contractual documents (DPA, SLA, list of
sub-processors) and details specific to your environment on request.